Purpose
The purpose of this Guideline is to define and set forth a process ensuring minimal security requirements (hereinafter the “MSR”) of the personal data processing, to be met by INDRC, so as compliance with the requirements of the article 24 of the GDPR to be observed and to be able to be demonstrated.
Breach of this Guideline shall represent misbehavior and shall be subject to corrective and/or disciplinary procedures.
Scope
This Guideline is global in scope and applies to INDRC worldwide, all INDRC employees, subcontractors, statutory body members and member of other bodies, and external service providers of INDRC as well as other persons cooperating with INDRC, including persons cooperating with INDRC on voluntary basis. This Guideline applies also to the aforementioned individuals who are involved with the project Center for Artificial Intelligence and Quantum Computing in System Brain Research (CLARA) (hereinafter as “Responsible persons”).
In case a Responsible person is a data processor within the meaning of article 4, paragraph 8 GDPR, a data protection agreement shall be entered into. For the avoidance of doubt, the principles of this Guideline apply to data processors as well.
Definitions
For the purposes of this Guideline:
Personal data means any information relating to an identified or identifiable natural person (hereinafter as “data subject”), an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processing / Handling means any operation or set of operations which is performed on Personal data or on sets of Personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
INDRC means International Neurodegenerative Disorders Research Center, zapsaný ústav.
INDRC Director means a person who was appointed an executive director of INDRC.
CLARA Director means a person who was appointed a director or interim director of the CLARA by INDRC.
The Director means INDRC Director or CLARA Director.
Principles for Processing Personal data
INDRC commits to Processing Personal data in accordance with the following principles:
a) Lawfulness, Fairness, and Transparency
Personal data shall be processed lawfully, fairly, and transparently.
b) Purpose Limitation
Data shall only be collected for specific, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
c) Data Minimization
Only the data necessary for the intended purposes will be collected and processed.
d) Accuracy
Personal data must be accurate and kept up to date.
e) Storage Limitation
Data will not be retained longer than necessary for the purposes it was collected.
f) Integrity and Confidentiality
Data will be protected against unauthorized access, alteration, or destruction.
Supervision
INDRC Director is authorized and instructed to control compliance with the provisions of this Guideline including MSR measures, unless such responsibilities are related to CLARA Project and therefore assigned to CLARA Director.
CLARA Director is authorized and instructed to control compliance with the provisions of this Guideline including MSR measures in relation to CLARA organizational unit.
The Director especially
a) strictly observes secrecy and confidentiality obligations in relation with performance of his/her role and responsibility.
b) fulfils specific responsibilities in relation with this Guideline, respectively:
c) is obliged to observe GDPR and other applicable laws.
d) fulfils other responsibilities pursuant to this Guideline.
The Director may assign part of his/her responsibilities to a designated employee.
Responsible persons
a) strictly observe secrecy and confidentiality obligations in relation with performance of their role and responsibility.
b) are bound by confidentiality obligation during the performance of their responsibilities related to Personal data protection.
c) are obliged to observe GDPR and other applicable laws.
d) fulfil other responsibilities pursuant to this Guideline.
MSR measures
a) Identification and authentication:
b) Organizational measures
The Responsible persons must always act with due care so as not to breach any provisions of the GDPR or other data protection legislation. This includes:
c) Technical measures
Data handling principles
Should the Responsible person need to share any of the Personal data with third parties (e.g. in order to perform services for INDRC or within the fulfilment of their work tasks), they must follow the following principles:
Updating this Guideline
This Guideline enters into effect as of January 15, 2025 and is issued in accordance with the GDPR. This Guideline may be updated, in which case, the changes contained in the update shall become effective once the relevant update is published on our website.
Exhibit A: List of Prohibited apps