Privacy disclaimer
How we work
PRIVACY POLICY Abnormal B.V.
- GENERAL
A.1. PURPOSE OF THIS PRIVACY POLICY
This privacy policy is intended to describe a general “framework” for how Abnormal B.V. handles personal data. More specific regulations (such as protocols) may apply to more specific processing of personal data within the organization of Abnormal B.V.
A.2. “SCOPE” OF THIS PRIVACY POLICY
The scope of this privacy policy extends to Abnormal B.V. and the personal data for which Abnormal B.V. is to be regarded as the controller.
This includes, among other things, the following types of personal data:
- Personal data of employees
- Personal data of website visitors of Abnormal B.V.
A.3. TERMS USED
Appendix 1 to this document describes the relevant terms from privacy legislation used in this privacy policy.
- LEGAL FRAMEWORK
B.1. GENERAL DATA PROTECTION REGULATION
As of May 25, 2018, the General Data Protection Regulation applies to the use (“processing”) of personal data by Abnormal B.V. From that day, the GDPR replaces the Dutch Personal Data Protection Act (“Wbp”).
The GDPR applies to:
- the “automated” processing of personal data; in short, “automated” means processing via a computer or other electronic device such as a smartphone, tablet, digital camera, or via a server. Common examples include creating customer databases, sending and receiving emails, collecting data via a website or an app, making camera recordings, and recording employee data; and
- the processing of personal data on paper in a “structured set” (in a searchable file).
An example of the latter is the physical folder administration of personnel files.
Under the GDPR, Abnormal B.V. has certain obligations as a “controller” regarding the processing of personal data. The individuals whose data is concerned (the “data subjects”) have certain rights under the GDPR regarding the processing of their personal data. This policy describes in general terms what those obligations and rights are.
B.2. OTHER SPECIFIC LAWS AND REGULATIONS
In certain specific situations, such as for the use of employee personal data, medical data, or criminal personal data, additional laws and regulations may apply.
- GUIDING PRINCIPLES
C.1. GENERAL
In general, personal data must be handled “carefully.” Employees of Abnormal B.V. must therefore ensure that the privacy rules of the GDPR are observed when using personal data during their daily activities.
C.2. COLLECTION, RECEIPT, AND INTERNAL USE OF PERSONAL DATA
When collecting/creating personal data, receiving personal data from external parties, and further processing it internally within Abnormal B.V., Abnormal B.V. considers whether this is permitted and, if so, how far the use may extend.
In doing so, at least the following questions are taken into account (the terms used are explained in Appendix 1):
- Does it concern “special categories of personal data”? If so, these may only be collected, received, and processed on the basis of a legal exception. If special categories of personal data may be processed, extra care must be taken with this personal data.
- Does it concern personal data of children (persons under the age of 16)? If so, extra care must also be taken with the data and additional rules apply.
- Is there a “legal basis” to collect, receive, and use the personal data? There must be a legal basis for every processing operation (every type of use).
- For what purposes is the personal data collected, received, and processed? The purposes must be clear.
- Is it necessary to collect, receive, and further process the personal data for the established purposes? If it is not necessary for those purposes or for compatible purposes, the data should not be collected, received, or processed.
- Is use being made of “solely automated individual decision-making”, including profiling, which has legal consequences for the individuals concerned or which affects the individuals in another significant way? This is only permitted under certain conditions.
Where necessary, Abnormal B.V. carries out a privacy assessment to answer the above questions.
C.3. OVERVIEW OF PROCESSING OPERATIONS
Abnormal B.V. maintains an internal overview of the various processing operations for which Abnormal B.V. is to be regarded as the controller. If Abnormal B.V. is to be regarded as a “processor” of certain personal data, an overview is also kept of the processing operations for which Abnormal B.V. is to be regarded as a processor.
C.4. CONFIDENTIALITY
Employees of Abnormal B.V. keep personal data confidential and only use it in the context of their work for Abnormal B.V. They commit to this in writing to Abnormal B.V.
C.5. DATA QUALITY
Personal data is kept as accurate, complete, and up-to-date as possible.
C.6. PRIVACY BY DESIGN AND BY DEFAULT
When developing (new) products or services, including IT systems, “privacy by design” and “privacy by default” are used as much as possible.
Privacy by design means, in summary, that the protection of personal data is taken into account wherever possible, for example by pseudonymizing data, and that data minimization and compliance with privacy rules are ensured.
Privacy by default means, in summary, ensuring that, by default, only necessary personal data is used, given the amount of personal data, the way it is used, the period within which it is stored, and its accessibility. The measures must ensure that, by default, personal data is not made available to an unlimited audience without the intervention of an employee of Abnormal B.V., for example on the internet.
C.7. PIAs (PRIVACY IMPACT ASSESSMENTS) AND PRIVACY ASSESSMENTS
A privacy impact assessment (PIA) is carried out when using high-risk personal data, such as at least large-scale use of special categories of personal data, automated individual decision-making, including profiling, which has legal consequences for the individuals concerned or which affects the individuals in another significant way, or the systematic monitoring of a public space on a large scale.
For new projects involving the processing of personal data, a privacy assessment is carried out to check whether the privacy rules are met.
The DPO is involved in carrying out the PIA and the privacy assessment.
C.8. EXTERNAL USE OF PERSONAL DATA
As a starting point, Abnormal B.V. only uses personal data for its own purposes.
In certain cases, however, it may be necessary to pass on personal data to external parties. When passing on personal data to external parties, it must be considered whether this is possible and, if so, under what conditions:
- Is the external party to be regarded as a “processor” who acts exclusively on behalf of Abnormal B.V. when receiving and using personal data? If so, agreements are made with such a party in a processing agreement about how they handle the personal data. Such parties may not use the personal data for their own purposes.
- Is the external party itself to be regarded as a “controller” – for example, the insurer of Abnormal B.V.? Then it must be checked whether passing on personal data to this external party is consistent with the established purposes, which personal data is necessary for this, and whether there is a legal basis for passing on the data. Where possible, agreements are recorded regarding the exchange of personal data.
- Is the external party to be regarded as a controller together with Abnormal B.V. for the relevant processing of personal data? Then the agreements regarding the personal data are recorded in an agreement between Abnormal B.V. and the other controller.
- Is the external party a government agency? As a starting point, Abnormal B.V. only passes on personal data to government agencies when it is legally obliged to do so. In certain specific situations, however, Abnormal B.V. may also be forced to pass on personal data to a government agency if there is no legal obligation. An example of this is passing on data about a person to the police if Abnormal B.V. files a report against this person. No more data is passed on than necessary.
C.9. TRANSFER OUTSIDE THE EEA
If personal data is transferred to a country outside the European Economic Area (“EEA”), (the EEA consists of the countries of the European Union, Norway, Iceland, and Liechtenstein), where there is no adequate level of protection for privacy, measures are taken to make that transfer legally possible.
C.10. SECURITY AND DATA BREACHES
Personal data must be secured technically and organizationally in an appropriate manner, taking into account the nature of the personal data, the risks of using the personal data, the costs of security, and the state of the art. Abnormal B.V. uses a security policy for this.
If data breaches occur involving personal data, these are reported, if necessary, to the Dutch Data Protection Authority and the individuals concerned. There may be special circumstances under which reporting does not take place.
C.11. RETENTION OF PERSONAL DATA
Personal data is kept no longer than is necessary for the purposes for which it was collected. Where applicable, a retention policy and/or retention protocol is drawn up.
C.12. RIGHTS OF INDIVIDUALS
The individuals whose personal data is concerned can exercise certain rights regarding their personal data towards Abnormal B.V.
This concerns the following rights:
- To receive an overview of the personal data in an intelligible form.
- To receive information about the use of the personal data by Abnormal B.V.
- To receive a copy of the personal data.
- In certain cases, to obtain the data in a structured, commonly used, and machine-readable form and to have it transmitted to another “controller” upon request.
- Correction of inaccurate data and completion of incomplete data.
- In certain cases, to request the deletion of their personal data.
- In certain cases, to request the “restriction” of their personal data.
- In certain cases, to object to the processing of their personal data.
- When personal data is used for direct marketing purposes, the individual may always object and that use will be ceased.
- As a starting point, to withdraw consent once given.
- To lodge a complaint with the Dutch Data Protection Authority.
In certain cases, Abnormal B.V. may refuse a request, for example if the person requests the deletion of certain personal data but it must still be kept for a legal obligation. Abnormal B.V. will then let the person know. Where applicable, a protocol is made for handling requests from individuals.
C.13. INFORMING INDIVIDUALS
Individuals are informed where necessary about the use of their personal data, for example by means of privacy statements.
C.14. PROTOCOLS / GUIDELINES / CODES OF CONDUCT
When using personal data of an intrusive nature or another activity that significantly affects the privacy of individuals, a protocol, guideline, and/or code of conduct is drawn up as a starting point, recording how the data and privacy are handled.
C.15. TRAINING AND “AWARENESS”
Abnormal B.V. tries to create as much “awareness” as possible about how personal data should be handled. Where applicable, training is provided to inform employees.
C.16. DATA PROTECTION OFFICER (“DPO”)
Abnormal B.V. has a “Data Protection Officer” (“DPO”). The DPO serves (at a minimum) as a point of contact for questions about the use of personal data (both for employees of Abnormal B.V. and the data subjects), provides advice on PIAs to be carried out and monitors compliance therewith, supports projects where personal data is used, and internally supervises the use of personal data by Abnormal B.V.
- CHANGES TO THIS PRIVACY POLICY
This privacy policy may be adjusted, for example to (better) align with new laws and regulations or changed circumstances. The DPO is actively involved in changes. Stakeholders are informed about significant changes.
- COMPLAINTS
When an individual whose personal data is concerned has a complaint about the use of his or her personal data, the person can lodge a complaint with Abnormal B.V. A contact point is designated for this, where applicable per category of persons or personal data. The DPO is informed of the complaint.
If the complainant and the contact point (with the help of the DPO) fail to handle the complaint mutually, the person can escalate the complaint to the manager of the contact point or to the DPO. If the manager or the DPO fails to handle a complaint with the complainant, the complaint can be escalated to management.
If management cannot handle the complaint, the person could decide to ask the court to make a decision or ask the Dutch Data Protection Authority for mediation.
Specific complaint regulations, such as for employees or consumers, take precedence over this complaint procedure.
APPENDIX 1 – TERMS
Personal data: this is data (information) relating to an identified or identifiable person.
Solely automated individual decision-making: this is decision-making about the data subject that is established solely automatically, so without a human being involved in that decision-making.
Special categories of personal data: are the following types of personal data:
- about health,
b. about someone’s race or ethnic background,
c. about someone’s religion or belief,
d. about someone’s sexual behavior or orientation,
e. about someone’s political opinions,
f. about someone’s trade union membership,
g. genetic characteristics,
h. biometric characteristics intended to identify someone.
The BSN (Citizen Service Number) and criminal data also count as special personal data that may only be used if an exception mentioned in the GDPR applies.
Controller: the “controller” is the party that determines what happens to the personal data and how that happens (it determines the “purpose and means”).
Data subject: a “data subject” is a person to whom the personal data relates.
Processing: a “processing” is an operation performed on personal data. This includes, among other things: collection, recording, organization, structuring, storage, updating or modification, retrieval, consultation, use, disclosure by transmission, dissemination, combination, restriction, erasure, or destruction.
Legal basis: for every processing of personal data, one of the following bases (also called “legal grounds”) is required:
- informed, free, and specific consent,
b. because it is necessary for the preparation or execution of an agreement with or for the benefit of the data subject,
c. because it is necessary to comply with a legal obligation to which the controller is subject,
d. because it is necessary to protect the vital interests of the data subject (or another person),
e. because it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or
f. because it is necessary for a legitimate interest of the controller or a third party that takes precedence over the interest of the data subject.
