The Rights of the Data Subject Regarding the Processing of Their Personal Data

INTRODUCTION

On the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC  REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL  (hereinafter referred to as the “Regulation”) requires that the Data Controller take appropriate measures to ensure that all information provided to the data subject regarding the processing of personal data is provided in a concise, transparent, understandable, and easily accessible form, expressed in clear and plain language, and that the Data Controller facilitates the exercise of the data subject’s rights. 

 The data subject’s obligation to provide advance notice is also stipulated in Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information.

 We are complying with this legal obligation by providing the information below.

 The information must be posted on the company's website or sent to the affected individual upon request.

NAME OF THE DATA CONTROLLER

Company Name: ERON Trading Kft.

Headquarters: 1054 Budapest, Honvéd Street 8, 1st Floor, Unit 2

Company Registration Number: 01-09-376760

Tax ID Number: 28848673-2-41

Representative: Gábor Szántó

Website:                       www.erontrading.hu

(hereinafter referred to as the “Company”)

 

  1. CHAPTER

ENSURING THE LEGALITY OF DATA PROCESSING

 

  1. Data Processing Based on the Data Subject's Consent

(1) If the Company intends to process personal data based on consent, it must obtain the data subject’s consent to the processing of their personal data in accordance with the content and information set forth in the privacy notice.

(2) Consent is also deemed to have been given if the data subject checks a box to that effect while viewing the Company’s website, makes relevant technical settings while using information society services, or makes any other statement or takes any other action that, in the given context, clearly indicates the data subject’s consent to the intended processing of their personal data. Silence, a pre-checked box, or inaction therefore do not constitute consent.

(3) Consent covers all data processing activities carried out for the same purpose or purposes. If data processing serves multiple purposes at the same time, consent must be given for all purposes of data processing.

(4) If the data subject provides consent in a written statement that also covers other matters—e.g., the conclusion of a sales or service contract—the request for consent must be presented in a manner that is clearly distinguishable from those other matters, in an understandable and easily accessible form, using clear and plain language. Any part of such a statement containing the data subject’s consent that violates the Regulation is not legally binding.

(5) The Company may not make the conclusion or performance of a contract contingent upon the provision of consent to the processing of personal data that is not necessary for the performance of the contract.

(6) The data subject may withdraw his or her consent to the processing of personal data at any time.

(7) If personal data was collected with the data subject’s consent, the data controller may, in the absence of any provision to the contrary in the law, process the collected data without further specific consent for the purpose of fulfilling a legal obligation to which it is subject, even after the data subject has withdrawn their consent.

  1. Data Processing Based on Compliance with a Legal Obligation

(1) In the case of data processing based on a legal obligation, the scope of the data that may be processed, the purpose of the data processing, the duration of data storage, and the recipients shall be governed by the provisions of the applicable legislation.

(2) Data processing based on the legal basis of compliance with a legal obligation is independent of the data subject’s consent, as the data processing is prescribed by law. In this case, the data subject must be informed prior to the commencement of data processing that such processing is mandatory; furthermore, the data subject must be provided with clear and detailed information prior to the commencement of data processing regarding all facts related to the processing of their data, including, in particular, the purpose and legal basis of the data processing, the person authorized to process the data, the duration of the data processing, whether the data controller is processing the data subject’s personal data in accordance with a legal obligation applicable to the data controller, and who may have access to the data. The information must also cover the data subject’s rights and remedies regarding the data processing. In cases of mandatory data processing, the information may also be provided by publishing a reference to the statutory provisions containing the aforementioned information.

  1. Promoting the Rights of the Affected Person

In all of its data processing activities, the Company is required to ensure that data subjects can exercise their rights.

 

 

 CHAPTER III

Purpose and Duration of Data Processing

  1. Purpose of Data Processing

 

  • Creating and managing a user account on the Company's website.
  • Processing orders for the service, including order acceptance, fulfillment, and billing.
  • Providing support services, including responding to inquiries from data subjects regarding the services provided by the Company or in connection with a specific order.

 

In most cases, the handling and processing of the data subject’s data for the above purposes is necessary for the conclusion and performance of the contract between the Company and the data subject. In addition, the processing of certain data in this context is required by law, including laws governing taxation and accounting.

  1. Duration of Data Processing

We store the data subject’s personal data for as long as the user account registered on the Company’s website remains active. Regardless of this, you may request that we delete certain data or terminate your user account at any time; however, we ensure compliance with legal requirements regarding certain data—even after the termination of your user account.

  1. CHAPTER

Scope of Processed Data

  1. User's name and address: The purpose of data processing is to identify the individual in question.
  2. Username: This information is essential for identifying users who register on the Company’s website in the database, as well as for maintaining contact with them.
  3. Password: It is designed to ensure secure access to your user account.
  4. Email address: This information is essential for identifying users who register on the Company’s website in the database, as well as for maintaining contact with them.
  5. IP address: The identification number assigned by the Internet service provider to the device of a user logging into the system. The Company processes this information to ensure the system’s IT security.
  1. CHAPTER

INFORMATION ON THE RIGHTS OF THE DATA SUBJECT

  1. A brief summary of the data subject's rights:
  2. Transparent information, communication, and facilitating the exercise of the data subject’s rights.
  3. Right to prior information—when personal data is collected from the data subject.
  4. Notification of the data subject and the information to be provided to him or her if the data controller did not obtain the personal data directly from him or her.
  5. The data subject's right of access.
  6. The right to correction.
  7. The right to erasure (“the right to be forgotten”).
  8. The right to restrict data processing.
  9. The obligation to notify regarding the rectification or erasure of personal data, or the restriction of data processing.
  10. The right to data portability.
  11. The right to protest.
  12. Automated decision-making in individual cases, including profiling.
  13. Restrictions.
  14. Notifying the affected individual of the data breach.
  15. The right to file a complaint with the supervisory authority (the right to administrative redress).
  16. The right to an effective judicial remedy against the supervisory authority.
  17. The right to an effective judicial remedy against the data controller or data processor.
  1. The data subject's rights in detail:
  1. Transparent information, communication, and facilitating the exercise of rights by those affected

1.1. The data controller must provide the data subject with all information and notifications regarding the processing of personal data in a concise, transparent, intelligible, and easily accessible form, using clear and plain language, particularly in the case of any information addressed to children. The information must be provided in writing or by other means, including, where appropriate, by electronic means. At the data subject’s request, information may also be provided orally, provided that the data subject’s identity has been verified by other means.

1.2. The data controller must facilitate the exercise of the data subject's rights.

1.3. The data controller shall inform the data subject, without undue delay and in any event within one month of receiving the request, of the measures taken in response to the data subject’s request to exercise his or her rights. This deadline may be extended by an additional two months under the conditions set forth in the Regulation, of which the data subject must be informed.

1.4. If the data controller does not take action in response to the data subject’s request without delay, but no later than one month from the date of receipt of the request, inform the data subject of the reasons for failing to take action, as well as of the data subject’s right to file a complaint with a supervisory authority and to seek judicial remedy.

1.5. The data controller provides the information and the information and measures regarding the data subject’s rights free of charge; however, a fee may be charged in the cases specified in the Regulation.

The detailed rules can be found in Article 12 of the Regulation.

  1. Right to Prior Information—When Personal Data Is Collected from the Data Subject

2.1. The data subject has the right to be informed of the facts and information related to data processing prior to the commencement of such processing. In this context, the data subject must be informed of the following:

  1. a) the identity and contact information of the data controller and its representative,
  2. b) the contact information for the data protection officer (if any),
  3. (c) the purpose of the intended processing of personal data and the legal basis for the processing,
  4. d) in the case of data processing based on the assertion of a legitimate interest, the legitimate interests of the data controller or a third party,
  5. e) the recipients of the personal data—to whom the personal data is disclosed—and, where applicable, the categories of recipients;
  6. e) where applicable, the fact that the data controller intends to transfer personal data to a third country or to an international organization.

2.2. To ensure fair and transparent data processing, the data controller must provide the data subject with the following additional information:

  1. (a) the period for which personal data will be stored, or, if this is not possible, the criteria used to determine that period;
  2. b) the data subject’s right to request from the data controller access to, rectification of, erasure of, or restriction of the processing of personal data concerning him or her, and to object to the processing of such personal data, as well as the data subject’s right to data portability;
  3. (c) in the case of data processing based on the data subject’s consent, the right to withdraw consent at any time, which does not affect the lawfulness of the data processing carried out on the basis of consent prior to the withdrawal;
  4. d) the right to file a complaint with the supervisory authority;
  5. e) whether the provision of personal data is required by law or a contractual obligation, or whether it is a prerequisite for entering into a contract, and whether the data subject is required to provide the personal data, as well as the possible consequences of failing to provide such data;
  6. (f) the fact that automated decision-making, including profiling, is taking place, as well as—at least in these cases—the logic applied and clear information regarding the significance of such data processing and its likely consequences for the data subject.

2.3. If the data controller intends to process personal data for a purpose other than the purpose for which it was collected, the data controller must inform the data subject of this different purpose and provide all relevant additional information prior to such further processing.

The detailed rules governing the right to prior information are set forth in Article 13 of the Regulation.

  1. Notification of the data subject and the information to be provided to the data subject if the data controller did not obtain the personal data directly from the data subject

3.1. If the data controller did not obtain the personal data from the data subject, the data controller must inform the data subject no later than one month after obtaining the personal data; if the personal data are used for the purpose of communicating with the data subject, at least at the time of the first contact with the data subject; or if the data is expected to be disclosed to other recipients, no later than the first time the personal data is disclosed, the data controller must provide the facts and information described in paragraph 2 above, as well as the categories of personal data concerning the data subject, the source of the personal data, and, where applicable, whether the data are derived from publicly available sources.

3.2. Further rules are governed by the provisions set forth in Section 2 above (Right to Prior Information).

The detailed rules governing this information are set forth in Article 14 of the Regulation.

 

  1. The Data Subject's Right of Access

4.1. The data subject has the right to receive confirmation from the data controller as to whether his or her personal data are being processed, and if such processing is taking place, the data subject has the right to access the personal data and the related information described in paragraphs 2–3 above.

4.2. If personal data is transferred to a third country or to an international organization, the data subject has the right to be informed about the transfer and the appropriate safeguards provided for in Article 46 of the Regulation.

4.3. The data controller must provide the data subject with a copy of the personal data being processed. For any additional copies requested by the data subject, the data controller may charge a reasonable fee based on administrative costs.

Article 15 of the Regulation sets forth the detailed rules regarding the data subject’s right of access.

  1. The Right to Correction

5.1. The data subject has the right to have the Data Controller correct any inaccurate personal data concerning him or her without undue delay upon request.

5.2. Taking into account the purpose of the data processing, the data subject has the right to request that incomplete personal data be supplemented, including, among other things, by means of a supplementary statement.

These rules are set forth in Article 16 of the Regulation.

 

  1. The Right to Erasure (“the Right to Be Forgotten”)

6.1. The data subject has the right to request that the data controller erase personal data concerning him or her without undue delay, and the data controller is obligated to erase personal data concerning the data subject without undue delay if

  1. (a) the personal data are no longer necessary for the purpose for which they were collected or otherwise processed;
  2. (b) the data subject withdraws the consent on which the data processing is based, and there is no other legal basis for the data processing;
  3. (c) the data subject objects to the processing of his or her personal data, and there are no legitimate grounds for the processing that override the data subject’s interests,
  4. (d) the personal data were processed unlawfully;
  5. (e) the personal data must be erased to comply with a legal obligation under Union or Member State law to which the data controller is subject;
  6. (f) the collection of personal data took place in connection with the provision of information society services offered directly to children.

6.2. The right to erasure cannot be exercised if the processing is necessary

  1. (a) for the purpose of exercising the freedom of expression and the right to information;
  2. (b) compliance with a legal obligation under Union or Member State law to which the data controller is subject, or the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
  3. (c) on the basis of the public interest in the field of public health;
  4. d) for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, insofar as the right to erasure is likely to render such processing impossible or seriously impair it; or
  5. e) to assert, enforce, or defend legal claims.

Article 17 of the Regulation sets forth the detailed rules regarding the right to erasure.

  1. The Right to Restrict Data Processing

7.1. In the event of a restriction on data processing, such personal data may be processed—other than for storage purposes—only with the data subject’s consent, or for the purpose of asserting, enforce or defend legal claims, or to protect the rights of another natural or legal person, or for reasons of substantial public interest of the Union or of a Member State.

7.2. The data subject has the right to request that the Data Controller restrict data processing if any of the following conditions are met:

  1. a) the data subject disputes the accuracy of the personal data; in this case, the restriction applies for a period that allows the Data Controller to verify the accuracy of the personal data;
  2. (b) the processing is unlawful, and the data subject objects to the erasure of the data and requests, instead, that its use be restricted;
  3. (c) the Data Controller no longer needs the personal data for the purposes of data processing, but the data subject requires it to assert, exercise, or defend legal claims; or
  4. (d) the data subject has objected to the processing; in this case, the restriction shall apply for as long as it has not been determined whether the data controller’s legitimate grounds override those of the data subject.

7.3. The data subject must be notified in advance of the lifting of the restriction on data processing.

The relevant rules are set forth in Article 18 of the Regulation.

 

  1. The obligation to notify regarding the rectification or erasure of personal data, or the restriction of data processing

The data controller shall inform all recipients to whom the personal data has been disclosed of any rectification, erasure, or restriction of processing, unless this proves impossible or involves a disproportionate effort. At the data subject’s request, the data controller shall provide information about these recipients.

These rules are set forth in Article 19 of the Regulation.

  1. The Right to Data Portability

9.1. Subject to the conditions set forth in the Regulation, the data subject has the right to receive the personal data concerning him or her that he or she has provided to a data controller in a structured, commonly used, and machine-readable format, and is also entitled to transmit that data to another data controller without hindrance from the data controller to whom the personal data was provided, provided that

  1. (a) the processing is based on consent or a contract; and
  2. (b) the data processing is carried out by automated means.

9.2. The data subject may also request that their personal data be transferred directly from one data controller to another.

 

9.3. The exercise of the right to data portability shall not infringe upon Article 17 of the Regulation [Right to erasure (“right to be forgotten”)]. The right to data portability does not apply where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This right shall not adversely affect the rights and freedoms of others.

The detailed rules are set forth in Article 20 of the Regulation.

  1. The Right to Protest

10.1. The data subject has the right to object at any time, on grounds relating to his or her particular situation, to the processing of his or her personal data carried out in the public interest, for the performance of a public task (Article 6(1)(e)), or on the basis of a legitimate interest (Article 6 (1)(f)), including profiling based on those provisions. In such a case, the data controller may no longer process the personal data unless the data controller demonstrates that the processing is justified by compelling legitimate grounds that override the data subject’s interests, rights, and freedoms, or that are related to the establishment, exercise, or defense of legal claims.

10.2. If personal data is processed for the purpose of direct marketing, the data subject has the right to object at any time to the processing of personal data concerning him or her for this purpose, including profiling, to the extent that it is related to direct marketing.  If the data subject objects to the processing of personal data for direct marketing purposes, the personal data may no longer be processed for that purpose.

10.3. The data subject must be expressly informed of these rights no later than at the time of the first contact with him or her, and the relevant information must be presented clearly and separately from all other information.

10.4. The data subject may exercise the right to object using automated means based on technical specifications.

10.5. If personal data are processed for scientific or historical research purposes or for statistical purposes, the data subject has the right to object, on grounds relating to his or her particular situation, to the processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

The relevant rules are set forth in Article 21 of the Regulation.

  1. Automated decision-making in individual cases, including profiling

11.1. The data subject has the right not to be subject to a decision based solely on automated processing—including profiling—that would produce legal effects concerning him or her or similarly significantly affect him or her.

11.2. This right does not apply if the decision:

  1. (a) is necessary for the conclusion or performance of a contract between the data subject and the data controller;
  2. (b) the processing is permitted by Union or Member State law applicable to the data controller, which also provides for appropriate measures to safeguard the rights, freedoms, and legitimate interests of the data subject; or
  3. (c) is based on the data subject's explicit consent.

11.3. In the cases referred to in subparagraphs (a) and (c) above, the data controller is required to take appropriate measures to protect the data subject’s rights, freedoms, and legitimate interests, including, at a minimum, the data subject’s right to request human intervention by the data controller, express their point of view, and lodge an objection to the decision.

Further rules are set forth in Article 22 of the Regulation.

  1. Restrictions

EU or Member State law applicable to the data controller or data processor may, through legislative measures, limit the scope of rights and obligations (Regulation, Article 5, Articles 12–22, and Article 34) if the restriction respects the essence of fundamental rights and freedoms.

The conditions for this restriction are set forth in Article 23 of the Regulation.

  1. Notifying the Data Subject of a Data Breach

13.1. If the data breach is likely to result in a high risk to the rights and freedoms of natural persons, the data controller must inform the data subject of the data breach without undue delay. This notification must describe the nature of the data breach in a clear and plain language and must include at least the following:

  1. a) the name and contact information of the data protection officer or any other contact person who can provide further information;
  2. (c) the likely consequences of the data breach must be described;
  3. (d) The measures taken or planned by the data controller to address the data breach must be described, including, where appropriate, measures aimed at mitigating any adverse consequences resulting from the data breach.

13.2. The data subject does not need to be informed if any of the following conditions are met:

  1. (a) the data controller has implemented appropriate technical and organizational security measures, and these measures were applied to the data affected by the data breach, in particular those measures—such as encryption—that render the data unintelligible to any person who is not authorized to access the personal data;
  2. (b) following the data breach, the data controller has taken further measures to ensure that the high risk to the data subject’s rights and freedoms is unlikely to materialize in the future;
  3. (c) providing such information would require a disproportionate effort. In such cases, the data subjects must be informed through publicly available information, or a similar measure must be taken to ensure that the data subjects are informed in an equally effective manner.

Further rules are set forth in Article 34 of the Regulation.

  1. The right to file a complaint with the supervisory authority (the right to administrative redress)

The data subject has the right to lodge a complaint with a supervisory authority—in particular, in the Member State of his or her habitual residence, their place of work, or the Member State where the alleged infringement occurred—if the data subject believes that the processing of their personal data violates the Regulation.  The supervisory authority to which the complaint was submitted is required to inform the data subject of the progress of the proceedings and the outcome of the complaint, including the fact that the data subject has the right to seek judicial remedy.

These rules are set forth in Article 77 of the Regulation.

Contact information for the supervisory authority:

Name: National Data Protection Authority

Address: 1055 Budapest, Falk Miksa Street 9–11.

Email: uygfelszolgalat@naih.hu

Phone: +36 (1) 391 1400

 

  1. The right to an effective judicial remedy against the supervisory authority

 

15.1. Without prejudice to other administrative or non-judicial remedies, every natural and legal person is entitled to an effective judicial remedy against a legally binding decision of the supervisory authority concerning that person.

15.2. Without prejudice to other administrative or non-judicial remedies, every data subject has the right to an effective judicial remedy if the competent supervisory authority fails to address the complaint or fails to inform the data subject within three months of the progress or outcome of the proceedings regarding the complaint submitted.

15.3. Proceedings against the supervisory authority must be brought before the courts of the Member State in which the supervisory authority has its seat.

15.4. If proceedings are initiated against a decision by a supervisory authority on a matter regarding which the Board has previously issued an opinion or made a decision within the framework of the Single Supervisory Mechanism, the supervisory authority is required to forward that opinion or decision to the court.

 

These rules are set forth in Article 78 of the Regulation.

 

  1. The right to an effective judicial remedy against the data controller or data processor

16.1. Without prejudice to any available administrative or non-judicial remedies—including the right to lodge a complaint with the supervisory authority— any data subject shall have the right to an effective judicial remedy if he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.

 

16.2. Proceedings against the data controller or the data processor must be brought before the courts of the Member State in which the data controller or the data processor has its place of business. Such proceedings may also be brought before the courts of the Member State in which the data subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.

These rules are set forth in Article 79 of the Regulation.

Dated: Budapest, June 16, 2021

en_USEnglish