The principles of data protection
LSB Data is obliged to protect your personal data. Personal data is any data which can directly or indirectly identify you as an individual, for example your contractual data, such as your name and surname, postal or email address, telephone number or, should an employment relationship exist, your personnel number or data from your personnel file. Insofar as your data has been collected within the scope of the European General Data Protection Regulation, i.e. you are a European cus-tomer or employee, LSB Data must observe the following basic principles, in particular:
- Your personal data is only processed in the event that a legal basis to do so exists. This legal basis may be derived from a law, a contract or your previous express consent, insofar as the processing of your personal data is required (Principle of legitimating basis).
- LSB Data may only process such personal data required in terms of type and scope for the fulfill-ment of authorized purposes. Such data must be relevant and appropriate (Principle of purpose limitation).
- Your personal data is deleted as soon as it may no longer be retained pursuant to LSB Data storage guidelines or applicable legislation. Where at all possible and economically viable, anonymization and pseudonymization measures are applied to ensure that your actual identity is not discernible or cannot be reestablished without recourse to a disproportionate amount of effort (Principle of data minimization and data avoidance).
- All necessary technical and organizational measures are taken to ensure that your personal data is protected against unauthorized use and publication, and its security and confidentiality guaranteed. All data stored is up to date (Principle of data security and data quality).
Should you, under exceptional circumstances provide LSB Data with personal data which is, accord-ing to some legal standards, classified as particularly sensitive – such as ethnic origin, religion or health issues, LSB Data is obliged to only process such sensitive personal data in compliance with the applicable legislation, which can often first require your express consent.
Your rights as the data subject
LSB Data is obliged to protect and uphold the rights of the person whose data is processed (data subjects’ rights). As a European customer or employee, the following, in particular, fall under such rights in accordance with EU privacy legislation:
- In your capacity as data subject you may, at any time, request to be informed which data pertain-ing to you is stored, and also to whom such personal data has been transferred. LSB Data is howev-er not obliged to comply with your request for information in the event that it affects the interests of a third party in a manner which is not legally permissible, or in the event that, in a specific case, a legitimate interest in protecting business secrets contradicts such a course of action (Right to infor-mation).
- As the data subject, you retain the right of rectification should the saved data pertaining to you be incomplete or incorrect (Right of rectification).
- LSB Data must delete your personal data in the event that data processing was illegal or the re-quirement for data processing no longer exists. Should statutory retention periods apply, or if dele-tion is not possible or unreasonable, data shall be blocked (Right to deletion and blocking).
- You retain the right to object to the use of your data in the event that a contractual or legal right to object exists. In the event you are approached for the purposes of advertising or market/opinion research, LSB Data must, upon first contact, inform you once again of your right to object as regards the use or transfer of data for direct marketing purposes. In the event you have consented to the use of your data, you retain the right to revoke your consent at any time (Right to object and right of revocation).
- The exercising of your rights may not result in discrimination against your person (Prohibition of discrimination).
- You retain the right to approach the data protection officer of LSB Data with questions at any time (Right to express concerns).