Skip to content Skip to footer

DATA PROTECTION POLICY FOR BYRÅ FEMTIOTVÅ AB

Policy for Handling Personal Data

Table of Contents

1 Introduction and Purpose

2 Application and Revision

3 Organization and Responsibility

4 Definitions and Abbreviations

5 Processing of Personal Data

1 Introduction and Purpose

The purpose of this policy is to ensure that Byrå Femtiotvå AB handles personal data in accordance with the EU General Data Protection Regulation (GDPR). The policy applies to all processing activities involving personal data and covers both structured and unstructured data. This policy is embedded among all our employees and close partners.

2 Application and Revision

The CEO is responsible for ensuring that the processing of personal data complies with this policy. The policy shall be adopted by the board at least once a year and updated when necessary.

The CEO is responsible for managing the process of annual updates to the policy due to new or changing regulations.

This policy applies to the company’s board members, CEO, employees, and contractors involved in our operations. 

3 Organization and Responsibility

The CEO has the overall responsibility for the content of this policy and for ensuring that it is implemented and followed across the company. All employees are responsible for acting in accordance with this policy and its objectives.

4 Definitions and Abbreviations

Personal Data:

Any information that directly or indirectly relates to a living individual.

Data Subject:

The individual to whom the personal data relates, i.e., a person who can be directly or indirectly identified through the data in a record.

Processing of Personal Data:

Any operation or set of operations performed on personal data – whether automated or not – such as collection, registration, organization, or structuring.

5 Processing of Personal Data

Each processing activity shall comply with the following principles:

o Lawfulness

o Purpose Limitation

Data Minimization

o Accuracy

o Storage Limitation

o Integrity and Confidentiality

Clients – we only store contact details relevant to fulfilling commissioned assignments. Contact details are deleted if a client has not placed an order within the past five years.

Suppliers – we only store contact details relevant to commissioning specific assignments. Contact details are deleted if a supplier has not been relevant within the past five years.

Clients’ customers or employees – these details are stored only during ongoing projects and deleted thereafter from our data systems. The data stored during a project may include employer, name, address, phone number, email address, and special requirements such as dietary needs or accessibility. Only information relevant to the ongoing project is stored.

Our data processing activities are documented in the GDPR Register: Byrå Femtiotvå AB.xlsx

Follow-up and evaluation of our personal data management are conducted at least annually.

Any incidents regarding personal data that we process must be reported by the CEO without undue delay and no later than 72 hours to the Swedish Data Protection Authority (Datainspektionen), as well as handled with all necessary corrective measures.

Our requirement that personal data is managed in compliance with GDPR must always be ensured in the procurement and development of IT solutions and services. These requirements must be part of specifications and any contractual agreements.

en_USEnglish