Privacy notice

 

•  Privacy notice:
Prepared on the basis of the EU General Data Protection Regulation 2016/679 (GDPR)
and its recommendations.

Contents:
CHAPTER 1 – Introduction
1. Legal and regulatory framework
2. Purpose of this notice
3. The Data Controller
4. Data Processors (register)

CHAPTER 2 – INFORMATION ABOUT SPECIFIC PROCESSING ACTIVITIES

5. Processing of health data and medical records

6. Processing based on the data subject’s consent

7. Processing of customer, contractual partner and contact person data

8. Processing necessary to comply with a legal obligation

9. Processing for tax and accounting obligations

10. Processing by the Practice in its capacity as a payer

11. Processing records of permanent value under the Archives Act

CHAPTER 3 – PROCESSING VISITOR DATA ON THE PRACTICE WEBSITE
– INFORMATION ABOUT THE USE OF COOKIES
12. General information about cookies
13. Cookies used on the Practice website and data generated during visits

CHAPTER 4 – INFORMATION ABOUT DATA SUBJECT RIGHTS
14. A summary of your rights
15. Your rights in detail

*

CHAPTER 1 – Introduction

1. Legal and regulatory framework

– REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, “GDPR”)

– Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information

– Act XLVII of 1997 on the Processing and Protection of Health Data and Related Personal Data

– Act CLV of 1997 on Healthcare

– Act XLVII of 2008 on the Prohibition of Unfair Commercial Practices against Consumers

– Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities

2. Purpose of this notice

REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “Regulation”), requires the Data Controller to take appropriate measures to provide data subjects with all information concerning the processing of their personal data in a concise, transparent, intelligible and easily accessible form, using clear and plain language, and to facilitate the exercise of their rights.

The obligation to inform data subjects in advance is also laid down in Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information.

This notice fulfils our obligations under these laws.

3. The Data Controller

The healthcare provider

Name: Dr Dávid Zsila, sole trader

Registered office: 1115 Budapest, Etele út 36/A

ÁNTSZ licence number: 8396-3/2007

Practice address: 1115 Budapest, Etele út 36/A

Person responsible for the processing of personal data

Responsible manager: Dr Dávid Zsila

Telephone: +36 20 472 8035

Email: davident@davident.hu

4. Data Processors (register)

The Practice maintains a register containing the details of the Data Processors involved in its personal data processing activities. This register is available for inspection at the Practice.

CHAPTER 2 – INFORMATION ABOUT SPECIFIC PROCESSING ACTIVITIES

5. Processing of health data and medical records

1. Data subjects may provide their treating dentist with previous and current health data and medical records, including X-rays, reports and examination results, to support the requested service.

During examinations, the Data Controller collects, stores, records and processes health data and medical documentation using its own equipment and methods.

2. Collecting health data and medical documentation forms part of providing the service (treatment). The treating dentist decides which health data must be collected and stored in accordance with professional requirements.

3. Data subjects provide their health data and medical records voluntarily and consent to examinations

of their own free will.

4. The immediate purpose of processing is to determine which of the Data Controller’s services is appropriate for the data subject, provide a quotation, answer questions and maintain contact.

5. Health data necessary for the service may be processed by the dentist and by staff involved in the data subject’s treatment, in accordance with the treating dentist’s instructions and only to the extent required for their duties.

6. Retention period: Under Section 30(1) of Act XLVII of 1997, the Data Controller must retain health data and medical records for at least 30 years, discharge summaries for at least 50 years, diagnostic images for 10 years from their creation, and reports relating to those images for 30 years from the date the images were created.

6. Processing based on the data subject’s consent

1. Where the Practice intends to process personal data on the basis of consent, it must request the data subject’s consent using the content and information specified in the data request form under its data protection policy.

2. Consent may also be given by ticking a box while visiting the Practice website, choosing appropriate technical settings for information society services, or by any other statement or action that clearly indicates agreement to the proposed processing in the circumstances. Silence, pre-ticked boxes and inactivity therefore do not constitute consent.

3. Consent covers all processing activities carried out for the same purpose or purposes. Where processing serves several purposes, consent must be given for all of them.

4. Where consent is given in a written declaration that also concerns other matters, such as entering into a sales or service contract, the request for consent must be clearly distinguishable from those matters and presented in an intelligible, easily accessible form using clear and plain language. Any part of such a declaration that infringes the Regulation is not binding.

5. The Practice must not make entering into or performing a contract conditional on consent to processing personal data that is not necessary for performance of that contract.

6. Withdrawing consent must be as easy as giving it.

7. Where personal data was collected with the data subject’s consent, unless the law provides otherwise, the Data Controller may continue processing it to comply with a legal obligation without further consent, including after consent has been withdrawn.

7. Processing of customer, contractual partner and contact person data

1. On the legal basis of performance of a contract, the Practice processes the following data of natural persons contracting with it as customers or suppliers for the purposes of entering into, performing or terminating the contract and granting contractual benefits: name, birth name, date of birth, mother’s name, home address, tax identification number, tax number, business or primary agricultural producer licence number, identity card number, registered office and business address, telephone number, email address, website address, bank account number, customer or order number and online identifier, including customer, supplier and loyalty lists. Processing is also lawful where necessary to take steps at the data subject’s request before entering into a contract.

Recipients of personal data: the Practice’s staff responsible for customer service, accounting and taxation, and its Data Processors. Retention period: five years after termination of the contract.

2. The legal basis for processing the contractual data of natural persons for accounting and tax purposes is compliance with a legal obligation. The retention period for these purposes is eight years.

3. On the basis of legitimate interests, the Practice processes the contractual personal data, home address, email address, telephone number and online identifier of the individual signing a contract on behalf of a legal entity, for communication and the exercise of contractual rights and obligations. These data are retained for five years after termination of the contract. Where processing is based on legitimate interests, the data subject has a particular right to object.

4. On the basis of legitimate interests, the Practice processes the name, address, telephone number, email address and online identifier of a non-signatory individual designated as a contractual contact person, for communication and the exercise of contractual rights and obligations. As the contact person is employed or engaged by the contracting party, this processing does not adversely affect their rights. The contracting party declares that it has informed the contact person of this processing. These data are retained for five years after the person ceases to act as a contact.

5. For all data subjects, recipients of personal data include the head of the Practice, staff responsible for customer service, contact persons, staff responsible for accounting and taxation, and Data Processors.

6. Personal data may be transferred to the Practice’s contracted accounting firm for tax and accounting purposes, to Magyar Posta or a contracted courier for postal and delivery services, and to the Practice’s security contractor for property protection.

7. Processing is lawful where necessary in the context of a contract or the intention to enter into one (Recital 44), or to take steps at the data subject’s request before entering into a contract (Article 6(1)(b)). Personal data collected through contractual offers may therefore also be processed on this basis as described here. When making or receiving an offer, the Practice must inform the offeror or recipient accordingly.

8. Processing necessary to comply with a legal obligation

1. Where processing is based on a legal obligation, the underlying legislation determines the categories of data, purposes, retention period and recipients.

2. Processing necessary to comply with a legal obligation does not depend on the data subject’s consent, because it is required by law. Before processing begins, the data subject must be told that it is mandatory and must receive clear, detailed information about all relevant facts, particularly the purpose and legal basis, persons authorised to process the data, retention period, the Data Controller’s legal obligation and who may access the data.

The information must also cover the data subject’s rights and available remedies. For mandatory processing, this information may be provided by publishing a reference to the legislative provisions containing it.

9. Processing for tax and accounting obligations

1. To comply with a legal obligation, the Practice processes the statutory data of natural persons doing business with it as customers or suppliers for tax and accounting purposes. Under Sections 169 and 202 of Act CXXVII of 2017 on Value Added Tax, these include tax number, name, address and tax status. Under Section 167 of Act C of 2000 on Accounting, they include name, address, identification of the person or organisation authorising the transaction, signatures of the authorising person and the person confirming execution and, where applicable, the auditor; the recipient’s signature on stock movement and cash management documents and the payer’s signature on receipt counterfoils. Under Act CXVII of 1995 on Personal Income Tax, they include business licence number, primary agricultural producer licence number and tax identification number.

2. Personal data are retained for eight years after the legal relationship forming the basis for processing ends.

3. Recipients of personal data: the Practice’s staff and Data Processors responsible for taxation, bookkeeping, payroll and social security administration.

10. Processing by the Practice in its capacity as a payer

1. To comply with statutory tax and contribution obligations, including the calculation of taxes, tax advances and contributions, payroll, social security and pension administration, the Practice processes the personal data prescribed by tax laws of employees, their family members, other workers and benefit recipients with whom it has a payer relationship under Section 7(31) of Act CL of 2017 on the Rules of Taxation.

The categories of data are defined in Section 50 of that Act and include personal identification details, previous names and titles, sex, nationality, tax identification number and social security identification number (TAJ). Where tax legislation attaches legal consequences to them, the Practice may also process employee health data under Section 40 of the Personal Income Tax Act and trade union membership data under Section 47(2)(b), to fulfil tax and contribution obligations, including payroll and social security administration.

2. Personal data are retained for eight years after the legal relationship forming the basis for processing ends.

3. Recipients of personal data: the Practice’s staff and Data Processors responsible for taxation, payroll and social security administration in its capacity as a payer.

11. Processing records of permanent value under the Archives Act

1. To comply with a legal obligation, the Practice processes records classified as having permanent value under Act LXVI of 1995 on Public Records, Public Archives and the Protection of Private Archival Material, so that the permanently valuable part of its records remains intact and usable for future generations. Retention period: until transfer to the public archive.

2. Recipients of personal data: the head of the Practice, staff responsible for records management and archiving, and public archive staff.

CHAPTER 3 – PROCESSING VISITOR DATA ON THE PRACTICE WEBSITE –

INFORMATION ABOUT THE USE OF COOKIES

12. General information about cookies

1. Visitors must be informed on the website about the use of cookies, and their consent

must be requested.

2. A cookie is data sent by a website to a visitor’s

browser as a name–value pair, so that the browser stores it and the same website can later

retrieve its contents. A cookie may have an expiry date, remain valid until the browser closes, or

remain valid indefinitely. On subsequent HTTP(S) requests, the browser also sends this data

to the server. In this way, data on the user’s device is modified.

3. Cookies are used because the nature of website services makes it necessary to identify

a user, for example to recognise that they have signed in, and then handle subsequent interactions

accordingly. The risk is that users may not always be aware of this and that cookies may

allow the website operator or another provider to track them,

where that provider’s content is embedded in the site, such as Facebook or Google Analytics. A profile can then be created

about the user, in which case the cookie’s contents may constitute personal data.

4. Types of cookies:

4.1. Strictly necessary session cookies: without these, the website

would not function properly. They identify the user and help manage, for example,

whether the user is signed in or what they have placed in their basket. Typically, only a session ID is stored, while other

data is held on the server for greater security. There is a security risk if a session

cookie value is not generated properly, as this can permit session hijacking. It is therefore

essential that these values are generated correctly. In other terminology,

“session cookie” refers to any cookie deleted when the browser closes. A

session lasts from opening the browser until closing it.

4.2. Functionality cookies: these remember

users’ preferences, such as how they want the site displayed. These

cookies essentially store preference settings.

4.3. Performance cookies: although the name is not directly related to technical performance, it generally

refers to cookies that collect information about users’ behaviour on the

website, including time spent and clicks. These are typically provided by third-party

applications, such as Google Analytics, AdWords or Yandex.ru. They can be used

to create profiles of visitors.

Information about Google Analytics cookies is available here:

https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage

Information about Google AdWords cookies is available here:

https://support.google.com/adwords/answer/2407785?hl=hu

5. You are not obliged to accept or enable cookies. You can change your browser

settings to reject all cookies or notify you when a

cookie is sent. Most browsers accept cookies automatically by default, but

these settings can generally be changed to prevent

automatic acceptance and allow you to choose each time.

6. Information about cookie settings in popular browsers is available at the following links:

• Google Chrome: https://support.google.com/accounts/answer/61416?hl=hu

• Firefox: https://support.mozilla.org/hu/kb/sutik-engedelyezese-es-tiltasa-amit-weboldak-haszn

• Microsoft Internet Explorer 11: http://windows.microsoft.com/hu-hu/internet-explorer/deletemanage-

cookies#ie=ie-11

• Microsoft Internet Explorer 10: http://windows.microsoft.com/hu-hu/internet-explorer/deletemanage-

cookies#ie=ie-10-win-7

• Microsoft Internet Explorer 9: http://windows.microsoft.com/hu-hu/internet-explorer/deletemanage-

cookies#ie=ie-9

• Microsoft Internet Explorer 8: http://windows.microsoft.com/hu-hu/internet-explorer/deletemanage-

cookies#ie=ie-8

• Microsoft Edge: http://windows.microsoft.com/hu-hu/windows-10/edge-privacy-faq

• Safari: https://support.apple.com/hu-hu/HT201265

Please note, however, that certain

website features or services may not work properly without cookies.

13. Information about cookies used on the Practice website and

data generated during visits

1. Data processed during visits: while the website is being used, the Practice may record and process

the following information about the visitor and the device used for browsing:

• the visitor’s IP address,

• browser type,

• characteristics of the device’s operating system, including its language setting,

• time of the visit,

• the page, subpage, feature or service visited,

• clicks.

We retain these data for a maximum of 90 days and may use them primarily to investigate

security incidents.

2. Cookies used on the website

2.1. Strictly necessary session cookies

Purpose of processing: to ensure the website functions properly. These cookies are necessary

to allow visitors to browse the website and make full, uninterrupted use of

its features and services. This includes, in particular,

remembering actions performed on pages and identifying signed-in users during a visit. These cookies are processed only for the visitor’s

current session. When the session ends or the browser closes, this type of cookie is

automatically deleted from the device.

The legal basis for this processing is Section 13/A(3) of Act CVIII of 2001 on Electronic

Commerce Services and Certain Aspects of Information Society Services,

under which a service provider may process personal data

that are technically necessary to provide the service. All other

conditions being equal, the provider must select and always operate

the tools used to deliver information society services

in such a way that personal data are processed only where

strictly necessary to provide the service and fulfil the other purposes specified in that Act,

and even then only to the necessary extent and for the necessary period.

2.2. Functionality cookies:

These remember users’ choices, such as how they would like the

website displayed. These cookies essentially store preference settings.

The legal basis for processing is the visitor’s consent.

Purpose of processing: to improve service efficiency and the user experience, and to make

the website easier to use.

These data are primarily stored on the user’s device; the website accesses them and may use them to recognise the

visitor.

2.3. Performance cookies:

These collect information about users’ behaviour on the website,

including time spent and clicks. They are typically provided by third-party applications, such as Google Analytics

or AdWords.

Legal basis for processing: the data subject’s consent.

Purpose of processing: website analysis and sending advertising offers.

CHAPTER 4 – INFORMATION ABOUT DATA SUBJECT RIGHTS

The Practice is committed to enabling data subjects to exercise their rights

in all its processing activities.

14. A summary of your rights

1. Transparent information and communication, and facilitating the exercise of data subject rights

2. Right to information in advance where personal data are collected from the data subject

3. Information to be provided where the Data Controller has not obtained personal data

from the data subject

4. Right of access

5. Right to rectification

6. Right to erasure (“right to be forgotten”)

7. Right to restriction of processing

8. Notification obligation regarding rectification or erasure of personal data or

restriction of processing

9. Right to data portability

10. Right to object

11. Automated individual decision-making, including profiling

12. Restrictions

13. Informing the data subject about a personal data breach

14. Right to lodge a complaint with a supervisory authority

15. Right to an effective judicial remedy against a supervisory authority

16. Right to an effective judicial remedy against a Data Controller or

Data Processor

15. Your rights in detail

1. Transparent information and communication, and facilitating the exercise of data subject rights

Under the Act on the Processing and Protection of Health Data:

Patients, or their legal representatives, are entitled to information about their personal identification

and health data and may inspect their medical records.

In dental care, the patient is informed of and accepts the completion of a course of treatment. The

dentist is responsible for definitive treatment. If a course of treatment is interrupted or

modified, the treating dentist records the fact and the reasons in the patient’s documentation.

The right to information as a patient, beyond data processing: before care begins, the patient must be informed about the provider’s data protection arrangements. The

treating dentist or their authorised representative is responsible for informing the patient

about the Practice’s data processing procedures. The patient confirms receipt by signing. The signed

notice must be attached to the patient’s medical records. Any statement by the patient

restricting processing must also be attached, where applicable.

Information about treatment is provided by the treating dentist or healthcare professional.

The healthcare professional caring for the patient may also explain nursing aspects

of treatment. Other healthcare or non-clinical staff may not provide information about the patient’s treatment

unless authorised to do so by the treating dentist for that particular patient.

Information is provided in person.

Under Section 11(1) of the Health Data Act, substantive information about treatment may not

be given by telephone or fax. Unless the patient has stated otherwise, the treating dentist or healthcare professional

may confirm that the patient is receiving treatment from the provider.

1.1. The Data Controller must provide the data subject with all information and communications

concerning the processing of personal data in a concise, transparent, intelligible and easily accessible

form, using clear and plain language, particularly where information is addressed

to a child. Information must be provided in writing or by other means, including, where

appropriate, electronically. If requested, it may be provided orally,

provided the data subject’s identity has been established by other means.

1.2. The Data Controller must facilitate the exercise of data subject rights.

1.3. The Data Controller must inform the data subject of action taken in response to a request

to exercise their rights without undue delay and in any event within one month

of receiving the request. This period may be extended by a further two months under the conditions

set out in the Regulation, and the data subject must be informed of the extension.

1.4. If the Data Controller does not act on a request, it must inform the data subject without delay and

at the latest within one month of receiving the request of the

reasons for not taking action and the possibility of lodging a complaint with a

supervisory authority and seeking a judicial remedy.

1.5. The Data Controller provides information, communications and action relating to data subject rights

free of charge, although a fee may be charged in the circumstances specified in the Regulation.

Detailed rules are set out in Article 12 of the Regulation.

2. Right to information in advance where personal data are collected from the data subject

2.1. Data subjects are entitled to information about the facts and circumstances of processing

before it begins. They must therefore

be informed of:

a) the identity and contact details of the Data Controller and its representative;

b) the contact details of the data protection officer, where applicable;

c) the purposes of the intended processing and its legal basis;

d) the legitimate interests pursued by the Data Controller or a third party where processing

is based on legitimate interests;

e) the recipients to whom personal data will be disclosed, or the categories

of recipients, where applicable;

f) where applicable, whether the Data Controller intends to transfer personal data to a third country or

an international organisation.

2.2. To ensure fair and transparent processing, the Data Controller must also provide the data subject

with the following information:

a) the retention period for the personal data or, if this cannot be specified, the criteria

used to determine that period;

b) the right to request access to personal data concerning them,

rectification, erasure or restriction of processing, to object to such processing,

and the right to data portability;

c) where processing is based on consent, the right to withdraw that consent

at any time, without affecting the lawfulness of processing carried out on the basis of consent

before its withdrawal;

d) the right to lodge a complaint with a supervisory authority;

e) whether providing personal data is a statutory or contractual requirement

or a prerequisite for entering into a contract, whether the data subject is required to provide

the data, and the possible consequences of

not doing so;

f) the existence of automated decision-making, including profiling, and, at least in such

cases, meaningful information about the logic involved and the significance

and expected consequences of that processing for the data subject.

2.3. If the Data Controller intends to process personal data further for a purpose other than

the one for which it was collected, it must inform the data subject of that new

purpose and provide all relevant additional information before further processing begins.

Detailed rules on the right to prior information are set out in Article 13 of the Regulation.

3. Information to be provided where the Data Controller has not obtained personal

data from the data subject

3.1. Where personal data have not been obtained from the data subject, the Data Controller must

provide the required information within one month of obtaining them at the latest; if the

data are used to communicate with the data subject, at the latest at the time of the

first communication; or, if disclosure to another recipient is envisaged, at the latest

when the personal data are first disclosed. The information must cover the matters described

in section 2 above, the categories of personal data concerned, and

the source of the data, including, where applicable, whether they came from publicly accessible

sources.

3.2. The further rules set out in section 2 above on the right to prior information also apply.

Detailed rules are set out in Article 14 of the Regulation.

4. Right of access

4.1. Data subjects have the right to obtain confirmation from the Data Controller as to whether

their personal data are being processed and, where that is the case,

to access those data and the related information described in sections 2 and 3 above

(Article 15 of the Regulation).

4.2. Where personal data are transferred to a third country or an international organisation,

the data subject has the right to information about the appropriate safeguards

under Article 46 of the Regulation relating to that transfer.

4.3. The Data Controller must provide the data subject with a copy of the personal data

being processed. For any further copies requested, it may charge

a reasonable fee based on administrative costs.

Detailed rules on the right of access are set out in Article 15 of the Regulation.

5. Right to rectification

5.1. At the data subject’s request, the Data Controller must rectify inaccurate personal data

concerning them without undue delay.

5.2. Taking account of the purposes of processing, the data subject also has the right to have incomplete personal

data completed, including by providing a supplementary statement.

These rules are set out in Article 16 of the Regulation.

6. Right to erasure (“right to be forgotten”)

6.1. Data subjects have the right to request erasure of their personal data without undue delay,

and the Data Controller must erase personal data concerning them

without undue delay where:

a) the data are no longer necessary for the purposes for which they were collected or otherwise

processed;

b) the data subject withdraws the consent on which processing is based and there is no

other legal basis;

c) the data subject objects to processing and there are no overriding legitimate grounds

for continuing it;

d) the personal data have been processed unlawfully;

e) erasure is necessary to comply with a legal obligation under Union or Member State law

applicable to the Data Controller;

f) the data were collected in connection with information society services

offered directly to a child.

6.2. The right to erasure does not apply where processing is necessary:

a) to exercise the right to freedom of expression and information;

b) to comply with an obligation under Union or Member State law applicable to the Data Controller, or

to perform a task in the public interest or in the exercise of official authority

vested in the Data Controller;

c) for reasons of public interest in the area of public health;

d) for archiving in the public interest, scientific or historical research, or statistical

purposes, where erasure would be likely to make such processing impossible or seriously

impair its objectives; or

e) to establish, exercise or defend legal claims.

Detailed rules on the right to erasure are set out in Article 17 of the Regulation.

7. Right to restriction of processing

7.1. Where processing is restricted, personal data may, apart from storage, only be processed with

the data subject’s consent, to establish, exercise or defend legal claims,

to protect the rights of another natural or legal person, or for reasons of important public interest of the Union or

a Member State.

7.2. Data subjects may request restriction of processing where any of the following

conditions applies:

a) the accuracy of the personal data is contested, in which case restriction lasts for a period

enabling the Data Controller to verify their accuracy;

b) processing is unlawful and the data subject opposes erasure, requesting restriction

of use instead;

c) the Data Controller no longer needs the data for processing, but the data subject

requires them to establish, exercise or defend legal claims; or

d) the data subject has objected to processing, in which case restriction applies until

it is determined whether the Data Controller’s legitimate grounds override those

of the data subject.

7.3. The data subject must be informed before a restriction on processing is lifted.

The relevant rules are set out in Article 18 of the Regulation.

8. Notification obligation regarding rectification or erasure of personal data or

restriction of processing

The Data Controller must communicate any rectification, erasure or restriction

of processing to every recipient to whom the personal data have been disclosed, unless this

is impossible or involves disproportionate effort. At the data subject’s request,

the Data Controller must inform them about these recipients.

These rules are set out in Article 19 of the Regulation.

9. Right to data portability

9.1. Under the conditions set out in the Regulation, data subjects have the right to receive

the personal data they have provided to a Data Controller in a structured, commonly used and machine-

readable format, and to transmit those data to another

Data Controller without hindrance from the controller to which the data

were originally provided, where:

a) processing is based on consent or a contract; and

b) processing is carried out by automated means.

9.2. Data subjects may also request direct transfer of their personal data between Data Controllers.

9.3. Exercising the right to data portability must not prejudice Article 17 of the Regulation on

erasure (“the right to be forgotten”). The right to data portability does not apply

where processing is necessary to perform a task in the public interest or in the exercise of official

authority vested in the Data Controller. This right must not

adversely affect the rights and freedoms of others.

Detailed rules are set out in Article 20 of the Regulation.

10. Right to object

10.1. Data subjects may object at any time, on grounds relating to their particular situation,

to processing based on the public interest or performance of a public task under Article 6(1)(e), or legitimate interests

under Article 6(1)(f), including profiling based on those provisions. In that

case, the Data Controller must stop processing the personal data unless it

demonstrates compelling legitimate grounds for processing that

override the data subject’s interests, rights and freedoms, or grounds connected with establishing,

exercising or defending legal claims.

10.2. Where personal data are processed for direct marketing, the data subject has the right

to object at any time to the processing of their data for that purpose,

including profiling related to direct marketing. Where the data subject

objects to processing for direct marketing, the

personal data must no longer be processed for that purpose.

10.3. These rights must be explicitly brought to the data subject’s attention at the latest

at the first communication, and the information must be presented clearly and separately

from any other information.

10.4. Data subjects may also exercise their right to object by automated means using technical

specifications.

10.5. Where personal data are processed for scientific or historical research or statistical

purposes, data subjects may object, on grounds relating to their particular situation,

to the processing of their data, unless the processing is

necessary to perform a task carried out in the public interest.

The relevant rules are contained in the Regulation.

11. Automated individual decision-making, including profiling

11.1. Data subjects have the right not to be subject to a decision based solely on automated processing,

including profiling, which produces legal effects concerning them or

similarly significantly affects them.

11.2. This right does not apply where the decision:

a) is necessary to enter into or perform a contract between the data subject and the Data Controller;

b) is authorised by Union or Member State law applicable to the Data Controller that

also provides suitable measures to safeguard the data subject’s rights, freedoms

and legitimate interests; or

c) is based on the data subject’s explicit consent.

11.3. In the cases described in points (a) and (c), the Data Controller must implement suitable

measures to safeguard the data subject’s rights, freedoms and legitimate interests,

including at least the right to obtain human intervention from the Data Controller,

express their point of view and challenge the decision.

Further rules are set out in Article 22 of the Regulation.

12. Restrictions

Union or Member State law applicable to the Data Controller or Data Processor may, through legislative

measures, restrict the scope of rights and obligations under Articles 12–22, 34 and 5 of the Regulation,

provided the restriction respects the essence of fundamental rights and freedoms.

The conditions for such restrictions are set out in Article 23 of the Regulation.

13. Informing the data subject about a personal data breach

13.1. Where a personal data breach is likely to result in a high risk to the rights

and freedoms of natural persons, the Data Controller must inform

the data subject without undue delay. The notification must describe, in clear and plain language,

the nature of the breach and include at least:

a) the name and contact details of the data protection officer or another contact point

where further information can be obtained;

c) a description of the likely consequences of the breach;

d) a description of measures taken or proposed by the Data Controller to address the breach,

including, where appropriate, measures to reduce its possible adverse

effects.

13.2. The data subject need not be informed where any of the following conditions applies:

a) the Data Controller has implemented appropriate technical and organisational safeguards and

applied them to the affected personal data, particularly

measures such as encryption that make the data unintelligible

to persons not authorised to access them;

b) the Data Controller has taken subsequent measures ensuring that the high risk

to the data subject’s rights and freedoms is no longer

likely to materialise;

c) notification would involve disproportionate effort. In such cases, data subjects must

be informed by a public announcement or an equivalent measure

that informs them just as effectively.

Further rules are set out in Article 34 of the Regulation.

14. Right to lodge a complaint with a supervisory authority

Data subjects may lodge a complaint with a supervisory authority, particularly in the Member State of their habitual

residence, place of work or the alleged infringement, if they

consider that the processing of their personal data infringes the Regulation. The

supervisory authority receiving the complaint must inform the complainant of the

progress and outcome of the complaint, including their right

to seek a judicial remedy.

These rules are set out in Article 77 of the Regulation.

You may seek a remedy by submitting a report or complaint to the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information

Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c

Telephone: +36 (1) 391-1400

Fax: +36 (1) 391-1410

Website: http://www.naih.hu

e-mail: ugyfelszolgalat@naih.hu

15. Right to an effective judicial remedy against a supervisory authority

15.1. Without prejudice to other administrative or non-judicial remedies, every

natural or legal person has the right to an effective judicial remedy against a legally binding decision

of a supervisory authority concerning them.

15.2. Without prejudice to other administrative or non-judicial remedies, every

data subject has the right to an effective judicial remedy where the competent supervisory authority does not

handle a complaint or does not inform them within three months of the

progress or outcome of the complaint they have lodged.

15.3. Proceedings against a supervisory authority must be brought before the courts of the Member State

in which that authority is established.

15.4. Where proceedings concern a supervisory authority’s decision on which the

Board has previously issued an opinion or decision under the consistency mechanism,

the supervisory authority must forward that opinion or decision to the court.

These rules are set out in Article 78 of the Regulation.

16. Right to an effective judicial remedy against a Data Controller or

Data Processor

16.1. Without prejudice to available administrative or non-judicial remedies, including the

right to lodge a complaint with a supervisory authority, every data subject has the right to an effective

judicial remedy if they consider that their rights under the Regulation have been infringed

through processing of their personal data that does not comply with it.

16.2. Proceedings against a Data Controller or Data Processor must be brought before the courts

of the Member State in which that controller or processor has an establishment. Such proceedings

may also be brought before the courts of the Member State where the data subject habitually resides, unless the

Data Controller or Data Processor is a public authority of a Member State acting

in the exercise of public powers.

These rules are set out in Article 79 of the Regulation.

24 May 2018

Dr Dávid Zsila

Practice director, specialist dentist

DaviDent dental practice • Address:36/A Etele út, ground floor, door 5, Budapest, District XI • Telephone: (+36)-20/472-8035 • Email: davident@davident.hu