On 25 May 2018 acquired force the EU Regulation of the European Parliament and of the Council (EC) No.: 2016/679 as of April, 27 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as “GDPR”) and Act No.: 18/2018 Coll. Z. z. on personal data protection as amended.
Slovenské elektrárne respects protection of your privacy and appreciates your trust, that you put into us when we process your personal data. We have implemented all appropriate security measures in order to protect your personal data (of technical, organisational and other type) and processes for the control of their continuous compliance and sufficiency. We also regularly update security measures and perform inspections, so that we prevent unpermitted access to personal data or unauthorized manipulation with the data.
Personal data shall mean any information related to the identified or identifiable natural person; the identifiable person is a person, who can be identified directly or indirectly, in particular by reference to identifier - name, identification number, location data, on-line identifier, or reference to one or more elements, which are specific for physical, physiological, genetic, mental, economic, cultural or social identity of this natural person.
processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness, and transparency”)
collected for specified, explicit and legitimate purposes (“limiting the purpose”);
adequate, relevant and limited to what is necessary in relation to the purposes, for which they are processed (‘data minimisation’);
accurate and, where necessary, kept up to date (‘accuracy’);
kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (“storage minimisation”);
processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’)
a contract with a data subject – data processing is necessary for performance of a contract, where a contracting parties is the data subject, or in order to take measures before concluding a contract based on a data subject’s request;
performance of a legal obligation of the controller – processing is necessary for performance of a controller’s obligation defined by special law (SR or EU legislation);
legitimate interests of the controller – processing is necessary for the purposes of controller’s legitimate interests;
data subject’s consent – if a data subject expressed their consent with processing their personal data for one or more specific purposes.