{"id":3060,"date":"2020-03-05T14:34:59","date_gmt":"2020-03-05T13:34:59","guid":{"rendered":"https:\/\/www.recruto.se\/gdpr\/"},"modified":"2020-03-05T14:35:00","modified_gmt":"2020-03-05T13:35:00","slug":"gdpr","status":"publish","type":"page","link":"https:\/\/www.recruto.se\/en\/gdpr\/","title":{"rendered":"GDPR"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"3060\" class=\"elementor elementor-3060 elementor-1484\" data-elementor-post-type=\"page\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-700bc65 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"700bc65\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2308f02\" data-id=\"2308f02\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1d9081b elementor-widget elementor-widget-heading\" data-id=\"1d9081b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">GDPR - The Act on the Processing of Personal Data<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-38d3483 elementor-widget elementor-widget-text-editor\" data-id=\"38d3483\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>GDPR stands for General Data Protection Regulation and is a new EU data protection regulation that will become a law in all EU member states from May 25, 2018. GDPR will replace the current Personal Data Protection Act (PuL). The law is designed to protect the privacy of individuals and intends to modernize, harmonize and strengthen protection within the EU.<\/p>\n<p>Within each EU Member State there is a regulatory authority that will control this. In Sweden, this authority is called the Integrity Protection Authority, formerly the Data Inspectorate. On their website there is more information and help that you can find out to find out what you need to do.<\/p>\n<p>Processing of personal data<br \/>\nThe law is about how you should process personal data, which are two important concepts to understand. Personal data may be explained as any information relating to an identified or identifiable individual (also known as a registered person), whereby an identifiable natural person is a person who can be directly or indirectly identified, in particular with reference to an identifier such as a name, identification number, location information or online identifiers, or to one or more factors specific to the physical person\u2019s physical, physiological, genetic, psychological, economic, cultural or social identity. Processing of this information means that you carry out a measure or combination of measures regarding personal data or sets of personal data, regardless of whether they are automated or not. Examples of such processing are collection, structuring, storage, processing, dissemination or deletion.<\/p>\n<p>Sensitive personal data<br \/>\nThere is a special category of personal data that the law takes up and that you as personal data manager need to pay extra attention to, that is sensitive personal data. Examples of sensitive personal data are information that reveals ethnic origin, political opinions, religious or philosophical beliefs or information about health and sexual life. The starting point is that it is prohibited to process these personal data, but there are a number of exceptions. In Sweden, an investigation is underway on these tasks and they are looking into developing supplementary Swedish legislation.<\/p>\n<p>Responsible for personal data and personal data assistant<br \/>\nIn the processing of personal data there are mainly two roles that you should know about and depending on your role there are different responsibilities. The person responsible for personal data (PuA) is the one who, according to the law, has the ultimate responsibility for the treatment and determines the purpose and the means. The person responsible for personal data shall ensure compliance with the law, shall inform the persons whose personal data is being processed and shall ensure compliance with the personal data officer. The Personal Data Assistant (PuB) processes the personal data on behalf of the data controller and is responsible for the technical and organizational security measures.<\/p>\n<p>Responsible and assistant for tasks in Recruto\u2019s services<br \/>\nYou as a customer are responsible for all personal data processing in the tools. Recruto is a personal data assistant and takes technical and organizational security measures to ensure that your collected personal data is processed securely and in accordance with the law. We therefore also update our User Agreement and incorporate a Personal Data Access Agreement as an accompanying appendix.<\/p>\n<p>Recruto as personal data manager<br \/>\nAll processing of personal data about you as a customer, user we are responsible for personal data when you order Recruto\u2019s services or in various ways contact us. What we do or do not do with your personal information is described in our Privacy Policy.<\/p>\n<p>Basic principles of GDPR<br \/>\nThe law is based on 7 basic principles:<\/p>\n<p>Legality, correctness and transparency<br \/>\nPurpose limitation<br \/>\nData Minimization<br \/>\ncorrectness<br \/>\nstorage Minimization<br \/>\nPrivacy and confidentiality<br \/>\nAccountability<br \/>\nYou can read about the basic principles on the Integrity Protection Authority\u2019s website.<\/p>\n<p>Legal grounds<br \/>\nIn compliance with the principle of legality, regularity and transparency, you need support in the Data Protection Regulation for the processing of personal data to be allowed. These legal bases are about having a consent, agreement, legal obligation, basic interests, public interest, exercise of authority or balancing of interests to process personal data.<\/p>\n<p>Legal basis for information in Recruto\u2019s services<br \/>\nWhat legal bases exist for the processing of personal data in Recruto\u2019s services, as a personal data controller, you must find out and document. It can vary from case to case depending on the activity, what laws you need to follow, whether you collect information that is required or which can be good to have.<\/p>\n<p>Unstructured material<br \/>\nIn PuL, in Sweden we have had an exception where we did not have to think about how personal data is processed, this exception is called the \u201cAbuse Rule\u201d. This has meant that we have been able to have personal data in so-called unstructured material, which is running text and free text such as documents, e-mails, websites or note fields in systems. The abuse rule now disappears with GDPR and means that you need to map out what personal data is in all unstructured material and need to start handling it in the same way as with structured material.<\/p>\n<p>Do you have questions?<\/p>\n<p>Do you have as responsible questions about GDPR and Recruto\u2019s work on the new regulation. Then you are welcome to contact us via info@recruto.co.uk or by calling 031-799 90 65.<\/p>\n<p>You can also update yourself by reading Recruto\u2019s latest mailing (sent 180511 to all our customers) regarding GDPR and what Recruto is doing in the system to customize its tools. Click on the link below:<\/p>\n<p>\u201cUpdated contract terms and new features related to GDPR\u201d<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>GDPR &#8211; The Act on the Processing of Personal Data GDPR stands for General Data Protection Regulation and is a new EU data protection regulation that will become a law in all EU member states from May 25, 2018. GDPR will replace the current Personal Data Protection Act (PuL). The law is designed to protect [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"elementor_header_footer","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-3060","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.recruto.se\/en\/wp-json\/wp\/v2\/pages\/3060","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.recruto.se\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.recruto.se\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.recruto.se\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.recruto.se\/en\/wp-json\/wp\/v2\/comments?post=3060"}],"version-history":[{"count":0,"href":"https:\/\/www.recruto.se\/en\/wp-json\/wp\/v2\/pages\/3060\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.recruto.se\/en\/wp-json\/wp\/v2\/media?parent=3060"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}