I. PREAMBLE
When processing personal data within the entity, the principles set forth in international legal instruments are applied, including the Universal Declaration of Human Rights, the Convention for the Protection of Human Rights and Fundamental Freedoms, the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, Directive 95/46/EC of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data, as well as national legislation, including the Constitution of the Republic of Moldova, the Law on the Protection of Personal Data, the Law on Access to Information, the Requirements for Ensuring the Security of Personal Data when Processing such Data within Personal Data Information Systems, approved by Government Decision No. 1123 of 14 December 2010, the Regulation on the Register of Personal Data Operators, approved by Government Decision No. 296 of 15 May 2012, and other relevant legislative/regulatory acts.
II. INTRODUCTION
“Business Market” LLC has its registered office at 18 Grigore Vieru Street, Ialoveni, Republic of Moldova. At the same time, correspondence is received and the administration is located at 108 Alexandru cel Bun Street, Chisinau, Republic of Moldova.
This Policy is approved by “Business Market” LLC, which operates in accordance with the applicable legislation of the Republic of Moldova.
This Policy is also approved for the purpose of ensuring the compliance of “Business Market” LLC with the provisions of Government Decision No. 1123 of 14 December 2010 of the Republic of Moldova “On the Approval of the Requirements for Ensuring the Security of Personal Data when Processing such Data within Personal Data Information Systems” and Law No. 133 of 8 July 2011 of the Republic of Moldova “On the Protection of Personal Data.”
III. GENERAL DEFINITIONS
The following terms are defined/used in this Security Policy:
- personal data – any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). An identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more specific elements relating to their physical, physiological, genetic, mental, economic, cultural or social identity;
- processing – any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- restriction of processing – the marking of stored personal data with the aim of limiting their future processing;
- profiling – any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning their performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.
- pseudonymization – the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures designed to ensure that the personal data cannot be attributed to an identified or identifiable natural person;
- filing system – any structured set of personal data that is accessible according to specific criteria, whether centralized, decentralized, or distributed according to functional or geographical criteria;
- controller – a natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of processing are determined by legislative or regulatory acts, the controller or the specific criteria for its designation shall be provided for by such acts;
- processor – a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller;
- establishment – the place where an activity is effectively and actually carried out within the framework of stable arrangements;
- recipient – a natural or legal person, public authority, agency, or other body to whom personal data are disclosed, whether or not such person or entity is a third party. However, public authorities which may receive personal data in the framework of a particular investigation in accordance with legislative or regulatory acts shall not be regarded as recipients; the processing of such data by those public authorities shall comply with the applicable data protection rules in accordance with the purposes of the processing
- third party – a natural or legal person, public authority, agency, or body other than the data subject, the controller, the processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data;
- consent – any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them;
- personal data breach – a breach of security that leads, accidentally or unlawfully, to the destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data transmitted, stored, or otherwise processed;
- genetic data – personal data relating to the inherited or acquired genetic characteristics of a natural person which provide unique information about the physiology or health of that person and which result, in particular, from the analysis of a biological sample from the person in question.
- biometric data – personal data resulting from specific technical processing relating to the physical, physiological, or behavioral characteristics of a natural person which allow or confirm the unique identification of that person, such as facial images or fingerprint data;
- data concerning health – personal data related to the physical or mental health of a natural person, including the provision of healthcare services which reveal information about their health status;
- national identification number – a number by which a natural person is identified in certain filing systems and which has general applicability, such as the state identification number, the series and number of the identity card, passport number, or driving license number;
- representative – a natural or legal person established in the Republic of Moldova, designated in writing by the controller or processor pursuant to Article 27, who represents the controller or processor with regard to their obligations under this Law;
- enterprise – a natural or legal person carrying out an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity;
- group of enterprises – an enterprise exercising control and the enterprises controlled by it;
- binding corporate rules – personal data protection policies which must be complied with by a controller or processor established in the territory of the Republic of Moldova with regard to transfers or sets of transfers of personal data to a controller or processor in one or more countries within a group of enterprises or a group of enterprises engaged in a joint economic activity;
- total annual turnover – turnover as defined in Article 4 of Competition Law No. 183/2012;
- information society services – services as defined in Article 4 of Law No. 284/2004 on Information Society Services;
- direct marketing – communication, by telephone, mail, or any other means of direct communication, of advertising or marketing messages (promoting goods or services) addressed to particular individuals.
- international organization – an organization and its subordinate bodies governed by public international law, or any other body established by an agreement concluded between two or more States or pursuant to such an agreement;
- personal data – any information relating to an identified or identifiable natural person (data subject). An identifiable person is a person who can be identified, directly or indirectly, by reference to an identification number or to one or more specific elements of their physical, physiological, psychological, economic, cultural, or social identity;
- special categories of personal data – data revealing a person's racial or ethnic origin, political, religious, or philosophical beliefs, social affiliation, data concerning their health or sex life, as well as data relating to criminal convictions, procedural coercive measures, or administrative-offense sanctions;
- controller – a natural or legal person under public or private law, including a public authority, any other institution or organization that, individually or jointly with others, determines the purposes and means of processing personal data, as expressly provided by the legislation in force;
- processor – a natural or legal person under public or private law, including a public authority and its territorial subdivisions, which processes personal data on behalf of and for the benefit of the controller, based on instructions received from the controller;
- authentication – verification of the identifier assigned to an access subject and confirmation of its authenticity;
- security control – actions undertaken by Business Market LLC to ensure an adequate level of security for personal data processed within information systems and/or maintained registers;
- temporary files – a set of data or information stored on a digital medium and created for a limited period of time, until the tasks for which they were designated are initiated;
- identification – assigning an identifier to access subjects and objects and/or comparing the presented identifier with the list of assigned identifiers;
- integrity – the certainty, consistency, and currency of information containing personal data, as well as its protection against unauthorized destruction and modification;
- cryptographic protection means for information containing personal data – technical, software, and technical-application means, systems, and system complexes that implement cryptographic conversion algorithms for information containing personal data, intended to ensure the integrity and confidentiality of such information during its processing, storage, and transmission through communication channels;
- protection level – a level of security proportionate to the risk posed by the processing of the respective personal data, as well as to the rights and freedoms of individuals, developed and updated in accordance with the level of technological development and the costs of implementing such measures.
- personal data security policy – a document developed by the data controller – Business Market LLC – providing a precise description of the security measures and protection features selected for data security, taking into account the potential threats to the personal data processed and the actual risks to which such data are exposed;
- security perimeter – an area that constitutes a barrier to passage, secured by physical and/or technical access control measures;
- person responsible for the personal data security policy – the person responsible for the proper functioning of the comprehensive protection system for information containing personal data, as well as for developing, implementing, and monitoring compliance with the provisions of the personal data controller's security policy;
- protection of information against unintentional actions – a set of measures aimed at preventing unintentional actions caused by user errors, defects in technical and application means, natural phenomena, or other causes that do not directly aim to modify the information but may result in the distortion, destruction, copying, or blocking of access to information, as well as its loss or destruction or damage to the physical medium containing personal data;
- personal data carrier – a magnetic, optical, laser, paper, or other medium for information on which a document containing personal data is created, recorded, transmitted, received, stored, or otherwise used, and which allows the document to be reproduced;
- data restoration – procedures for reconstructing/restoring personal data to the state in which they existed prior to their loss or destruction;
- information technology – the totality of methods, procedures, and means for processing and transmitting information containing personal data, as well as the rules for their application;
- user – a person acting under the authority of the personal data controller, with an acknowledged right of access to personal data information systems;
- work session – the period from the moment the computer and the application used to access the information resource are started, or from the moment the information resource is started, until the moment they are shut down;
- personal data information system – the totality of interdependent information resources and technologies, methods, and personnel intended for storing, processing, and providing information containing personal data;
- processing of personal data – any operation or set of operations performed on personal data by automated or non-automated means, such as collection, recording, organization, storage, retention, retrieval, adaptation or modification, extraction, consultation, use, disclosure by transmission, dissemination or otherwise, alignment or combination, blocking, erasure, or destruction;
- storage – retaining personal data on any type of medium;
- personal data filing system – any structured set of personal data accessible according to specific criteria, whether centralized, decentralized, or distributed according to functional or geographical criteria;
- consent of the personal data subject – any freely given, specific, informed, and unconditional expression of will, in written or electronic form, in accordance with the requirements applicable to electronic documents, by which the personal data subject agrees to the processing of data relating to them;
- data depersonalization – the modification of personal data in such a way that details concerning personal or material circumstances no longer permit the data to be attributed to an identified or identifiable natural person, or permit such attribution only under conditions requiring disproportionate expenditure of time, resources, and labor for an investigation.
IV. Objectives of the Security Policy
The main objectives of the Policy are the availability, integrity, and confidentiality of all information, including personal data processed by Business Market LLC, both in the course of manual processing and within information technology systems and processes. Security represents an essential component of the optimal operation of IT-based processes within Business Market LLC. Compliance with this Policy constitutes the foundation of adequate IT security. It establishes requirements and rules for the protection of all information, including personal data, IT systems, and processes against natural influences, human and technical errors, as well as deliberate actions that may cause material or non-material damage or may result in violations of applicable legislation. Considering that IT security cannot be guaranteed exclusively through technical systems, this Policy also addresses organizational, legal, and other relevant aspects.
Business Market LLC shall protect the personal data of both participants in the process/visitors and its employees.
The provisions of this Policy represent the minimum standard applicable to Business Market LLC, including all employees of Business Market LLC. Based on these provisions, all employees of Business Market LLC shall strictly comply with the requirements of this Policy and the company's internal rules concerning the protection of personal data and IT systems.
V. Provisions on the Hierarchy and Responsibilities of the Person Responsible for the Security Policy
Taking into account the specifics of its activities, the personal data controller, through this Security Policy, establishes the procedures and measures necessary to ensure an adequate level of protection when processing personal data within the managed data filing systems.
The Personal Data Security Policy shall be reviewed at least once a year as a result of changes to or reassessment of the entity's competencies. The management shall be responsible for appointing the person(s) who will directly undertake the adjustment of the provisions of this document.
The Security Policy shall mandatorily be brought to the attention, against signature, of all employees responsible for processing personal data before they are granted access to personal data processing, including when amendments are made as necessary to ensure an adequate level of personal data protection.
A person responsible for implementing and monitoring compliance with the provisions of the Personal Data Security Policy shall be appointed. In accordance with their job description and/or internal order, this person shall have sufficient resources (time, human resources, equipment, and budget) and free access to the information necessary to perform their duties, insofar as such access remains within the scope of this Policy.
The designated responsible person, regardless of their other duties, shall, in the course of monitoring the implementation and compliance with the provisions of the Security Policy, report directly to the management of Business Market LLC or to the person acting in that position.
The person responsible for the Personal Data Security Policy shall ensure the clear definition of the various responsibilities relating to the security of personal data processing (prevention, supervision, detection, and response), as well as the performance of these responsibilities independently of pressure arising from personal interests or other circumstances.
The person responsible for the Personal Data Security Policy shall clearly define the responsibilities and processes for managing the security of personal data and appropriately integrate them into the organizational structure and overall operational framework. They shall ensure the technical and organizational measures necessary for organizing the personal data security management process; develop procedures for classifying information containing personal data so that a nomenclature/register can be established and all processed personal data can be located, regardless of the type of data carrier; and provide training to persons involved in the processing of personal data so that they can perform their functional duties and assume their responsibilities regarding personal data security, including the confidentiality of such data.
VI. Means Subject to the Principles of Personal Data Protection
The protection of personal data within Business Market LLC, in its capacity as a personal data controller, is ensured through a comprehensive set of technical and organizational measures aimed at preventing the unlawful processing of personal data.
All information resources managed by the personal data controller that contain personal data and are stored on the following are subject to protection through specific means and procedures:
magnetic, optical, laser, or other electronic information storage media, information repositories, and databases;
information systems, networks, operating systems, database management systems and other applications, telecommunications systems, including document creation and reproduction equipment and other technical means for processing information.
VII. Personal Data Protection Measures
Personal data protection measures are implemented for the purpose of:
preventing the leakage of information containing personal data by preventing unauthorized access thereto;
preventing the unauthorized destruction, modification, copying, or blocking of personal data within telecommunications networks and information resources;
preventing the disclosure to third parties of information with restricted access;
ensuring the efficient management and use of information resources, both in paper and electronic format.
VIII. Protection of Personal Data Processed in Information Systems
The protection of personal data processed within information systems is carried out through the following methods:
preventing unauthorized connections to telecommunications networks and the interception, by technical means, of personal data transmitted through such networks;
preventing unauthorized access to processed personal data;
preventing specific technical and software actions that may result in the destruction or modification of personal data or malfunctions of the technical and software infrastructure;
preventing intentional and/or unintentional actions by internal and/or external users, as well as by other members of the controller/personal data processors, that may result in the destruction or modification of personal data or malfunctions of the technical and software infrastructure;
preventing the leakage of information containing personal data transmitted through communication channels by using encryption methods for such information, as well as VPN channels;
preventing the destruction or modification of personal data or malfunctions in the operation of software intended for processing personal data through the use of specialized technical and software protection measures, including licensed software and antivirus programs, the implementation of a software security control system, and the regular creation of backup copies;
preventing the leakage of information containing personal data through continuous internal auditing of information systems;
establishing a precise procedure for access to information containing personal data processed within the established information and filing systems, applicable to both internal and external users.
IX. Organizational and Technical Procedures to Be Observed by Business Market LLC in the Processing of Personal Data
1. General Information Security Management Measures
- a) When paper-based or electronic (digital) information carriers containing personal data are temporarily not in use, they shall be stored in safes or lockable metal cabinets.
- b) Computers, access terminals, and printers shall be disconnected upon completion of work sessions.
- c) The security of correspondence receiving and dispatch points shall be ensured, as well as protection against unauthorized access to fax and copying equipment.
- d) Physical security and access control shall be ensured for means used to display information containing personal data, in order to prevent such information from being viewed by unauthorized persons.
- e) Personal data processing equipment, information containing personal data, or software intended for processing personal data may be removed from the security perimeter only on the basis of written authorization from management.
- f) All software used within the information system shall comply with applicable licensing requirements.
- g) The installation of Shareware or freeware software without the approval of the information system administrator is prohibited.
2. Security of the Physical Environment and Information Technologies Used in the Processing of Personal Data
- a) Access to the premises/offices/rooms where personal data information systems are located shall be restricted and permitted only to persons who have the necessary authorization, in accordance with the relevant lists or identification credentials (badges, access cards, identification cards).
- b) Physical access to all access points to personal data information systems shall be managed and monitored, including appropriate action in response to violations of the access-control regime.
- c) The security perimeter of Business Market LLC shall consist of the office premises where personal data are processed/stored.
- d) The perimeter of the building or rooms where personal data processing equipment is located shall be physically secure; the exterior walls of the rooms shall be structurally sound, and entrances shall be equipped with locks and alarm systems.
- e) Personal data processing equipment shall be positioned in a manner that ensures its protection against unauthorized access, theft, fire, flooding, and other potential risks.
- f) Doors and windows shall be locked whenever the rooms are unattended.
- g) Computers, servers, and other access terminals shall be located in areas with restricted access for unauthorized persons.
- h) Access to the security perimeter of the Business Market LLC building where personal data are processed/stored with unauthorized photo/video equipment is prohibited, taking into account the need to ensure the confidentiality and security of personal data processing, as provided for by Articles 29 and 30 of the Law on the Protection of Personal Data, as well as paragraph 26 of the Requirements.
- i) The use of photographic, video, audio, or other recording equipment within the security perimeter shall be permitted only with specific authorization from management.
3. User Identification and Authentication
- a) Users of personal data information systems and the processes executed on their behalf shall be identified and authenticated.
- b) All users (including technical support personnel, network administrators, programmers, and database administrators) shall have a personal identifier (user ID) that does not contain any indication of the user's access level.
- c) To verify the user's ID, passwords, special physical access devices with memory (tokens) or microprocessor cards, and biometric authentication mechanisms based on unique and individual characteristics of the person shall be used.
- d) If a user's employment contract/service relationship is terminated, suspended, or modified and their new duties no longer require access to personal data, or if the user's access rights have been modified, or if the user has abused the codes assigned to them for the purpose of committing a harmful act, or has been absent for an extended period, the identification and authentication codes shall be revoked or suspended by the IT administrator.
4. Equipment Identification and Authentication
The ability to identify and authenticate equipment used in personal data processing operations shall be ensured, with such information being retained for an extended period of time.
5. Management of User Identifiers
The management of user identifiers shall include:
unique identification of each user;
verification of the authenticity of each user.
6. Use of Passwords in Ensuring Information Security
Information security requirements shall be observed when selecting and using passwords, including:
maintaining the confidentiality of passwords;
prohibiting passwords from being written down on paper unless the security of the paper record can be ensured;
changing passwords whenever there are indications of possible compromise of the system or password;
selecting strong passwords with a minimum length of 8 characters, which are not related to the user's personal information, do not contain consecutive identical characters, and are not composed entirely of groups of numbers or letters;
changing passwords at intervals not exceeding 3 months;
disabling the automatic login process using saved passwords.
7. Access Administration Control
Systematic monitoring of user activities shall be carried out in order to assess the correctness and compliance of operations and actions performed through personal data information systems.
8. Remote Access
- a) All methods of remote access to personal data information systems shall be secured (using VPN, encryption, cryptographic protection, etc.) and shall be documented, monitored, and controlled.
- b) Each method of remote access to personal data information systems shall be authorized by the responsible persons of Business Market LLC and shall be permitted only for users who require such access to perform their assigned duties and objectives.
9. Restriction of the Use of Wireless Technologies
- a) Wireless access to personal data information systems shall be limited to the maximum extent possible, documented, monitored, and controlled.
- b) Wireless access to personal data information systems shall be permitted only when cryptographic information protection measures are used.
- c) The use of wireless technologies shall be authorized by the responsible persons of Business Market LLC.
10. Power Supply Security
- a) Electrical equipment used to maintain the functionality of personal data information systems, as well as electrical cables, shall be protected against damage and unauthorized connections by installing them in dedicated conduits or enclosures.
- b) In the event of emergencies, failures, or force majeure circumstances, the possibility of disconnecting the power supply to personal data information systems shall be ensured, including the ability to disconnect any IT component.
- c) Automated fire detection and alarm systems shall be installed in offices where personal data information systems and personal data processing equipment are located.
11. Control of the Installation and Removal of IT Components
- a) The installation and removal of software, hardware, and technical and software components used within personal data information systems shall be subject to control and record-keeping.
- b) Information containing personal data stored on information carriers shall be physically destroyed or securely overwritten and destroyed using secure methods, avoiding the use of standard deletion functions.
12. Disclosure of Personal Data
- a) When personal data contained in filing systems are disclosed in electronic format through communication networks or other digital storage and retention media, such information shall be encrypted, or the possibility of using a bilateral connection through a secure VPN channel shall be considered. Wireless access to personal data filing systems shall be permitted only to authorized users. Each request for the disclosure and electronic transmission of personal data shall be examined individually, taking into account the technical capabilities available to the recipient and the controller, as well as the organizational and technical measures implemented by the parties. Where communication networks pose risks to the confidentiality and security of personal data, traditional methods of transmission shall be used (registered postal delivery, personal delivery, etc.).
- b) Disclosure by transmission of personal data through communication networks that do not comply with the Requirements (for example, sending information through personal email accounts such as @gmail.com, @mail.ru, @yahoo.com, etc.) is prohibited.
- c) The disclosure of personal data between Business Market LLC and other entities geographically located on the left bank of the Dniester River that refuse to be legally subject to the legislation of the Republic of Moldova is prohibited, given that, at present, effective control cannot be exercised over this territorial area, including with regard to compliance of personal data processing with the provisions of the Law on the Protection of Personal Data.
- d) The procedure for disclosing personal data stored on paper and/or digital media outside the territory of the Republic of Moldova shall be regulated by an institutional normative act and/or bilateral agreement, taking into account the need to ensure an adequate level of personal data protection.
- e) Cross-border transfers of personal data shall be carried out in strict compliance with the provisions of Article 32 of the Law on the Protection of Personal Data, particularly in cases where the international treaty on the basis of which the transfer is carried out does not contain safeguards for protecting the rights of the data subject.
- f) The volume and categories of personal data collected for record-keeping purposes by Business Market LLC shall be limited strictly to what is necessary to achieve the stated purposes.
- g) Access to information systems managed by Business Market LLC by the General Prosecutor's Office (and, where applicable, territorial/specialized prosecutor's offices), the Ministry of Internal Affairs, the National Anticorruption Center, etc., shall be permitted only where the request complies with the provisions of Articles 15 and 212 of the Criminal Procedure Code.
It is explained that, pursuant to Article 157 of the Criminal Procedure Code, documents in any form (written, audio, video, electronic, etc.) originating from natural or legal persons, where they set out or certify circumstances relevant to a case (including information stored in the audit logs of information and filing systems), may be requested by an official request from the criminal investigation body during criminal proceedings or during the trial of a case. In such cases, however, the provisions of Article 214 of the Criminal Procedure Code must be observed, which stipulate that, during criminal proceedings, official information with restricted access may not be collected, used, or disseminated without necessity. Persons from whom the criminal investigation body or court requests the disclosure or submission of official information with restricted access (including personal data controllers) have the right to ascertain that such data are being collected for the respective criminal proceedings and, otherwise, to refuse to disclose or submit the data. Such persons have the right to receive in advance from the person requesting the information a written explanation confirming the necessity of providing the specified data.
It should be taken into account that, pursuant to Article 8 of the Law on Access to Information, personal data constitute a category of official information with restricted access, access to which is governed by the legislation on personal data protection.
Where a lawyer or an authorized person requests access to a client's personal file, they shall be informed in writing of their obligations under Article 15 of the Criminal Procedure Code, Articles 29 and 30 of the Law on the Protection of Personal Data, including the liability provided for under Article 74¹ of the Contravention Code.
13. Rights of Personal Data Subjects
- a) Where personal data are collected directly from the data subject, in accordance with Article 12 of the Law on the Protection of Personal Data, the following information shall be provided to the person, unless they already possess such information:
- the identity of the controller or, where applicable, the processor (name, registered office/address, IDNO, registration number in the Register of Personal Data Controllers);
- the specific purpose for which the collected personal data are processed;
- the recipients or categories of recipients of the personal data;
- the existence of the rights to information and access to the collected data; the right to intervene with respect to the data (in particular, to rectify, update, block, or erase personal data whose processing is contrary to the law due to their incomplete or inaccurate nature); and the right to object, as well as the conditions under which these rights may be exercised;
- whether answers to the questions through which the data are collected are mandatory or voluntary, including the possible consequences of refusing to answer questions through which the information is collected.
- b) Personal data subjects shall be guaranteed the right of access and the possibility to review documents prepared for the purpose of verifying their accuracy, challenging the omission or incorrect inclusion of certain data, as well as challenging other errors made when recording data concerning them. In this regard, persons responsible for processing personal data shall ensure that an individual has access only to the personal data directly concerning them, excluding the possibility of reviewing personal data relating to other subjects contained in personal files or other materials, except where the applicants are pursuing a legitimate interest that does not prejudice the interests or fundamental rights and freedoms of the personal data subject.
- c) The right to information shall be ensured by the personal data controller (or by entities providing system maintenance and/or outsourced services to the controller) to all persons whose data are subject to processing.
- d) Where a personal data subject exercises their right to intervene, inaccurate data shall be updated through rectification or erasure, based exclusively on lawful sources (identity documents, civil status documents, primary state information resources, etc.), and the amendment shall be made in all managed information and filing systems.
14. Storage, Retention, and Destruction of Processed Personal Data
- a) Access to the premises/security perimeter where personal data information and filing systems are located shall be restricted and permitted only to persons who have the necessary authorization in accordance with the institutional security policy and/or approved departmental regulations.
- b) The electronic storage and retention of personal data structured in filing systems on computers connected to the Internet that are not equipped with specialized technical and software protection measures and do not have licensed software, antivirus programs, software security control systems, mechanisms for ensuring the regular creation of backup copies, and auditing mechanisms installed is prohibited.
- c) Bringing personal computers or information carriers into the institutional security perimeter and using them for work-related purposes is prohibited. Furthermore, access to company-provided computers shall be protected/restricted through the creation of user profiles, while administrator rights shall be granted exclusively to the person designated by Business Market LLC as responsible for implementing the Security Policy.
- d) Personal data stored on magnetic, optical, laser, paper, or other information media on which a document is created, recorded, transmitted, received, stored, or otherwise used and which allow its reproduction shall be secured by placing such media in safes or lockable metal cabinets. The unauthorized removal of personal data carriers from the controller's security perimeter is prohibited.
15. Audit of Managed Information Systems
- a) Attempts by users to log into or out of the system shall be recorded according to the following parameters:
- date and time of the login/logout attempt;
- user ID;
- result of the login/logout attempt — successful or unsuccessful.
- b) Attempts to obtain access to applications and processes intended for processing personal data, including attempts to execute operations, shall be recorded according to the following parameters:
- date and time of the access attempt/operation execution;
- name (identifier) of the application or process;
- user ID;
- details of the protected resource (identifier, logical name, file name, number, etc.);
- type of requested operation (reading, recording, deletion, etc.);
- result of the access attempt/operation execution — successful or unsuccessful.
- c) Changes to user access rights (authorizations) and the status of access objects shall be recorded according to the following parameters:
- date and time of the change to the authorizations;
- ID of the administrator who made the changes;
- user ID and their authorizations, or identification of the access objects and their new status.
- d) The disclosure/output from the system of information containing personal data (electronic documents, data, etc.), changes to the access rights of subjects, and the status of access objects shall be recorded according to the following parameters:
- date and time of release/output;
- name of the information and the access paths thereto;
- identification of the equipment (device) that released/output the information (logical name);
- user ID of the user who requested the information.
16. Protection Against Malicious Software (Viruses)
Protection against the infiltration of malicious software into software intended for processing personal data shall be ensured through the use of licensed antivirus programs.
17. Testing the Functional Capabilities for Ensuring the Security of Personal Data Information Systems
The proper functioning of the security functions of personal data information systems shall be tested automatically upon system startup and monthly at the request of the user authorized for this purpose.
18. Security Incident Management
- a) Personnel responsible for operating personal data information systems shall undergo training at least once a year regarding their responsibilities and obligations when carrying out actions for managing and responding to security incidents.
- b) The personnel of Business Market LLC shall immediately inform management of incidents that compromise the security of personal data information systems.
- c) Incident management shall include their detection, analysis, prevention of escalation, remediation, and restoration of security.
- d) By January 31 of each year, the personal data controller shall inform the National Center for Personal Data Protection in writing of the security incidents identified.
- e) In the event of security incidents occurring within Business Market LLC, the responsible person shall take the necessary measures to identify the source of the incident, analyze it, and eliminate the causes of the security incident, while notifying the National Center for Personal Data Protection of the Republic of Moldova within 72 hours from the occurrence of the security incident.
- f) During inspections carried out by the National Center for Personal Data Protection of the Republic of Moldova, the necessary support shall be provided and access to information relevant to the subject matter of the inspection shall be ensured.
19. Document Marking
All information intended for disclosure that contains personal data shall be marked by including the registration number from the Register of Personal Data Controllers.
Model:
Attention! This document contains personal data processed within filing system No. 000000X-00X, registered in the Register of Personal Data Controllers at www.registru.datepersonale.md. Further processing of these data may be carried out only under the conditions provided by Law No. 133 of July 8, 2011, on the Protection of Personal Data.
20. Liability for Ensuring the Security of Personal Data and Information with Restricted Access
The personal data controller, the processor, and, where applicable, third parties who have signed Annex No. 1 shall be liable for failure to comply with the provisions of the Security Policy under civil law (Civil Code), administrative-offense law (Article 741 of the Contravention Code), and criminal law (Articles 177, 178, and 180 of the Criminal Code).