CHAPTER I
GENERAL PROVISIONS
The Personal Data Security Policy (hereinafter – the Policy) is intended to ensure the security of the collection and processing of personal data of employees and employees of third parties (partners, customers, public authorities) carried out by KML TRADING MB, legal entity code 305643170, Saulėtekio al. 15-1, LT-10224 Vilnius (the Data Controller, the Company), and the proper protection and implementation of data subjects’ rights.
This Policy establishes the main principles and procedures for the collection, processing and storage of personal data applied by the Data Controller. This Policy has been prepared in accordance with the Law on Legal Protection of Personal Data of the Republic of Lithuania and other legislation governing the collection, processing and storage of personal data, as well as the EU General Data Protection Regulation (GDPR or the Regulation).
Description of terms:
| Term | Description |
|---|---|
| Personal data | Any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name and surname, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. |
| Company | KML TRADING MB, legal entity code 305643170, Saulėtekio al. 15-1, LT-10224 Vilnius |
| Administration of occupational safety and health data of employees | Collection and processing of employees’ occupational safety and health data in order to comply with the requirements of applicable occupational safety and health legislation. |
| Data subject | A natural person who can be identified directly or indirectly. |
| Consent of the data subject | A freely given, specific and unambiguous indication of the properly informed data subject’s wishes, given by a statement, by which he or she agrees to the processing of personal data relating to him or her. |
| Data processor | A natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller, i.e. performs any operations on personal data – collects, processes, stores, manages, corrects, organises, changes, deletes, etc. |
| Data controller | A natural or legal person who, alone or jointly with others, determines the purposes and means of processing. In this case – the Company. |
| External communication | Collection and processing of the business contact information of officials, officers and employees of public authorities in order to maintain current and accurate information required for recording visits, inspections and other actions carried out by public authorities in relation to the Company. It also includes informing public authorities (the State Tax Inspectorate, Sodra) about employees’ income, taxes paid and social benefits, processing personal data of guests and representatives of public authorities for recording visits to the Company, and providing employee personal data to public and law-enforcement authorities for the performance of their statutory functions. |
| Customers | Natural and legal persons who purchase goods, services or works from the Company (e.g. buyers, customers, tenants, etc.). |
| Partners | Natural and legal persons who sell goods, services or works to the Company or otherwise cooperate with the Company (e.g. contractors, subcontractors, sellers, lessors, service providers, etc.). |
| Public authorities | Public authorities that perform supervisory, control or other public-authority functions established by law in relation to the Company. |
| Business communication | Collection and processing of the business contact information of partners and customers’ employees in order to maintain current and accurate information necessary for business relations; provision of the Company employees’ business contact information to the Company’s partners and customers (as defined in the Company’s Personal Data Processing Rules) where necessary to maintain business relations and perform contracts with partners and customers, including the production and distribution of business cards. |
| Internal administration | Creation and management of employees’ personnel files, recording employees’ working time, transferring salaries to employees’ personal bank accounts, payment of employment-related taxes to public authorities and payments under enforcement documents to law-enforcement authorities. |
| Internal communication | Organisation of the work process (preparation of orders and documents governing work organisation). Administration of employees’ work telephone numbers and work e-mail address lists, preparation of the monthly newsletter and publication on the intranet portal in electronic form and on the notice board in paper form. |
CHAPTER II
PURPOSES AND PRINCIPLES OF PERSONAL DATA PROCESSING
Personal data are processed for the following purposes:
- Recruitment;
- Internal administration
- Internal communication;
- Occupational safety administration;
- Customer service
- Registration of warranty obligations;
- Claims settlement services;
- Insurance intermediation services;
- Leasing intermediation services;
- Direct marketing;
- Targeted marketing and convenient browsing by website visitors (use of cookies);
- Administration of test drives;
- Registration of potential customers;
- Protection of ownership rights and ensuring the security and integrity of property (video surveillance);
- ICT administration;
- Publicising the Company’s activities;
- Performance of functions relating to an employee’s next of kin.
The personal data processed by the Company for each specific purpose are specified in the Company’s Personal Data Processing Rules. Personal data are stored only to the extent and for as long as necessary to achieve the established purposes.
Personal data processed for direct marketing purposes are subject to profiling.
Principles of personal data processing:
Personal data shall be:
- processed lawfully, fairly and transparently in relation to the data subject (lawfulness, fairness and transparency);
- collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes (purpose limitation);
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimisation);
- accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (accuracy);
- kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods where they are processed solely for archiving purposes in the public interest, subject to appropriate technical and organisational measures (storage limitation);
- processed in a manner that ensures appropriate security of personal data through appropriate technical or organisational measures, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage (integrity and confidentiality).
The Data Controller is responsible for compliance with these principles within the Company and has the necessary means to demonstrate such compliance (accountability).
Taking into account the nature of the personal data to be protected and the risks arising from their processing, the Company implements organisational and technical measures appropriate to the established level of security of the personal data processed.
CHAPTER III
STORAGE AND PROCESSING OF PERSONAL DATA
Within the Company, the protection and processing of personal data is organised, ensured and carried out by the head of the Data Controller or by a person or persons appointed by his/her order, who shall:
- keep employees’ personal data confidential and comply with the requirements of personal data protection legislation;
- process personal data in accordance with the laws of the Republic of Lithuania, other legislation of the Republic of Lithuania and the European Union governing personal data protection, and this Policy;
- ensure compliance with the “Need to know” principle, i.e. not disclose, transfer or otherwise make personal data accessible by any means to any person who is not authorised to process personal data;
- in order to prevent accidental or unlawful destruction, alteration or disclosure of personal data, as well as any other unlawful processing, store documents and data files properly and securely and avoid making unnecessary copies. Copies of documents containing employees’ personal data must be destroyed in such a way that the documents cannot be restored and their contents cannot be identified;
- ensure that employees of the Data Controller immediately report to the head of the Data Controller or a person appointed by him/her any suspicious situation that may pose a threat to personal data security or any personal data breach, and take measures to prevent such a situation or to reduce or avoid damage that may arise or has arisen from a personal data breach.
Only persons who need personal data to perform their functions are entitled to process them, and only where this is necessary to achieve the relevant purposes.
Employees who, in the performance of their assigned functions, process personal data of employees or other persons shall observe the principle of confidentiality and keep secret any information related to personal data that they become aware of in the performance of their duties, unless such information is public under applicable laws or other legislation. The obligation to maintain the confidentiality of personal data continues after transfer to other duties and after termination of employment or contractual relations.
Employees’ personal data contained in relevant documents (contracts, orders, requests, etc.) are stored for the periods specified in the General Index of Document Retention Periods approved by order of the Chief Archivist of Lithuania.
To ensure the security of personal data, the Company has implemented organisational and technical personal data security measures detailed in the Company’s Personal Data Processing Rules.
CHAPTER IV
RIGHTS OF DATA SUBJECTS
Data subjects have the right to:
- be informed about the collection of their personal data – a person must be informed what personal data must be provided, for what purpose they are collected, to whom and for what purpose they may be provided, and the consequences of failing to provide personal data;
- access their collected personal data and information on how they are processed – they have the right to request information about what personal data are processed and for what purpose;
- request the rectification, clarification or completion of incorrect or incomplete personal data, the erasure of their personal data, or restriction/suspension of the processing of their personal data;
- object to the processing of certain optional personal data of an employee;
- lodge a complaint with the supervisory authority;
- independently opt out of the use of cookies.
CHAPTER V
POLICY COMPLIANCE RULES
Compliance with the Policy is audited during the analysis of the Company’s operational risks by analysing documents related to personal data processing and obtaining feedback from persons directly processing personal data.
Failure to comply with this Policy may, depending on the severity of the violation, be regarded as a breach of employment duties for which employees may be held liable in accordance with applicable legislation.
The Company provides employee education in the field of personal data security.
CHAPTER VI
RELATED DOCUMENTS
Law on Legal Protection of Personal Data of the Republic of Lithuania and other legislation governing personal data protection.
General requirements for organisational and technical personal data security measures.
General Data Protection Regulation of the European Union (EU 2016/679).
Company Personal Data Processing Rules.
Company Information Security Policy.
Company Information Security Incident Management Plan.
Company Video Surveillance Procedure.
CHAPTER VII
FINAL PROVISIONS
The Policy applies to all employees of the Data Controller, data processors and external parties, i.e. persons who have been granted access to personal data managed and processed by the Data Controller and to the means used to process such data.
The Policy applies to all personal data controlled and processed by the Data Controller.
The Policy is approved and amended by decision of the head of the Company after completing the consultation procedure with the works council, if one has been elected in the Company. The Policy is reviewed and updated when legislation governing personal data processing changes and when an existing purpose of personal data processing changes or a new purpose arises.
The Company’s employees are introduced to the Policy in accordance with the procedure in force within the Company for familiarisation with the Company’s internal legal acts, and the Policy is also published on the Company’s intranet website.

