RIGHT TO DATA PORTABILITY
You have the right to receive the personal data concerning you that you have previously provided to the Controller in a structured, commonly used and machine-readable electronic format, and you have the right to transmit those data to another Controller or to have your personal data transmitted directly to another Controller by the Controller to whom those data were previously provided / by our institution, where technically feasible.
This right may not be exercised where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.
We are required to notify all recipients to whom your personal data have been disclosed of any rectification or erasure of personal data or restriction of their processing, unless this proves impossible or involves disproportionate effort.
At your request, we will provide you with information about all possible recipients of your personal data.
To exercise the aforementioned rights, you must submit a written request to us.
TRANSFER OF PERSONAL DATA TO ANOTHER COUNTRY OR INTERNATIONAL ORGANISATION
Personal data may be transferred to another country, a part of its territory, one or more specified sectors within that country, or to an international organisation, with the approval of the Commissioner or without prior approval where it has been established that such other country, part of its territory, one or more specified sectors within that country, or such international organisation ensures an adequate level of personal data protection.
An adequate level of protection shall be considered to exist in countries and international organisations that are parties to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, as well as in countries, parts of their territories, one or more specified sectors within those countries, or international organisations that the European Union has determined provide an adequate level of protection.
The Government of the Republic of Serbia may determine that a country, part of its territory, area of activity or legal regulation, or an international organisation does not provide an adequate level of protection, except in the case of parties to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data.
An adequate level of protection shall also be considered to exist where an international agreement on the transfer of personal data has been concluded with another country or international organisation.
The Controller shall notify all recipients to whom personal data have been disclosed of any rectification or erasure of personal data or restriction of their processing, unless this proves impossible or involves disproportionate effort.
At your request, the Controller shall inform you, as the data subject, of all recipients in the event of a transfer, as well as of the manner in which you may obtain information about the safeguards applied.
TRANSFER OR DISCLOSURE OF PERSONAL DATA ON THE BASIS OF A DECISION OF AN AUTHORITY OF ANOTHER COUNTRY
Decisions of a court or administrative authority of another country requiring the Controller or Processor to transfer or disclose personal data may be recognised or enforced in the Republic of Serbia only if they are based on an international agreement, such as an international legal assistance agreement concluded between the Republic of Serbia and that other country.
Transfer documentation shall contain information on the date and time of the transfer, the recipient of the data, the reasons for the transfer and the personal data transferred.
TRANSFER OF DATA IN SPECIAL SITUATIONS
Your data may be transferred to another country or international organisation only where one of the following conditions applies:
1. You, as the data subject, have explicitly consented to the proposed transfer after having been informed of the possible risks of such transfer due to the absence of an adequacy decision and appropriate safeguards;
2. the transfer is necessary for the performance of a contract between the data subject and the Controller or for the implementation of pre-contractual measures taken at the request of the data subject;
3. the transfer is necessary for the conclusion or performance of a contract concluded in the interests of the data subject between the Controller and another natural or legal person;
4. the transfer is necessary for important reasons of public interest prescribed by the laws of the Republic of Serbia, provided that the transfer of certain categories of personal data is not restricted by such law;
5. the transfer is necessary for the establishment, exercise or defence of a legal claim;
6. the transfer is necessary in order to protect the vital interests of the data subject or another natural person where the data subject is physically or legally incapable of giving consent;
7. the transfer concerns certain personal data contained in a public register that is available to the public or to any person who can demonstrate a legitimate interest, but only to the extent that the statutory conditions for access in that particular case are fulfilled.
If the transfer cannot be carried out in accordance with points 1) to 7) above, personal data may be transferred to another country or international organisation only if all of the following conditions are fulfilled:
1. the transfer is not repetitive;
2. the transfer concerns data relating to a limited number of natural persons;
3. the transfer is necessary for the purposes of compelling legitimate interests pursued by the Controller which are not overridden by the interests, rights or freedoms of the data subject;
4. the Controller has ensured the application of appropriate personal data protection measures on the basis of a prior assessment of all circumstances surrounding the transfer.
The Controller shall also provide information concerning such transfer, including information about the legitimate interest pursued by the Controller through the transfer.
Transfer documentation shall contain information on the date and time of the transfer, the recipient of the data, the reasons for the transfer and the personal data transferred.
RIGHT TO OBJECT
Where you consider it justified by your particular situation, you have the right at any time to object to the Controller to the processing of your personal data.
The Controller shall cease processing the personal data of the person who has submitted the objection unless there are compelling legitimate grounds for the processing which override your interests, rights or freedoms as the data subject, or where the processing is related to the establishment, exercise or defence of a legal claim by the Controller.
RIGHT TO OBJECT TO PROCESSING FOR DIRECT MARKETING PURPOSES
You have the right at any time to object to the processing of your personal data for direct marketing purposes, including profiling to the extent that it is related to such direct marketing.
If you object to processing for direct marketing purposes, your personal data may no longer be processed for such purposes.
RIGHT TO OBJECT TO PROCESSING FOR CLINICAL TRIALS, SCIENTIFIC OR HISTORICAL RESEARCH OR STATISTICAL PURPOSES
Where personal data are processed for the purposes of clinical trials, scientific or historical research or for statistical purposes, you have the right, on grounds relating to your particular situation, to object to the processing of your personal data unless the processing is necessary for the performance of a task carried out in the public interest.
Statistical purposes mean that the result of processing for statistical purposes does not consist of personal data, but of aggregated data, and that such result or data are not used to support measures or decisions concerning a specific natural person.
NOTIFICATION OF THE DATA SUBJECT OF A PERSONAL DATA BREACH
Where a personal data breach is likely to result in a high risk to your rights and freedoms, the Controller shall notify you, as the data subject, of the breach without undue delay so that you can take the necessary precautionary measures.
In the notification, the Controller shall:
- describe the nature of the personal data breach;
- provide the name and contact details of the Personal Data Protection Officer or information on another means through which information concerning the breach may be obtained;
- describe the likely consequences of the personal data breach;
- describe the measures taken or proposed to be taken by the Controller to address the breach, including measures taken to mitigate its adverse effects;
- provide recommendations enabling the natural person to mitigate potential adverse consequences.
NOTIFICATION OF THE COMMISSIONER OF A PERSONAL DATA BREACH
The Controller is required to notify the Commissioner of a personal data breach that may result in a risk to the rights and freedoms of natural persons without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.
NO OBLIGATION TO NOTIFY THE DATA SUBJECT OF A PERSONAL DATA BREACH
The Controller is not required to notify you of a personal data breach where:
- the Controller has implemented appropriate technical, organisational and personnel protection measures in relation to the personal data affected by the breach, particularly where cryptographic protection or other measures have rendered the data unintelligible to any person who is not authorised to access them;
- the Controller has subsequently taken measures ensuring that the personal data breach which posed a high risk to the rights and freedoms of the data subject is no longer likely to result in consequences for that person;
- notifying the data subject would involve disproportionate effort.
In such a case, the Controller shall provide the notification to the data subject by means of a public communication or another equally effective method.
INFORMATION ON ACTION TAKEN IN RESPONSE TO A REQUEST
After verifying the identity of the person submitting the request, the Controller is required to provide the data subject with information on action taken on the request without delay and no later than 30 days from the date of receipt of the request.
This period may be extended by an additional 60 days where necessary, taking into account the complexity and number of requests.
The Controller shall inform the data subject of any such extension and the reasons for it within 30 days from the date of receipt of the request.
Where the data subject submits a request electronically, the information shall be provided electronically where possible, unless the data subject has requested that it be provided by other means.
Where the Controller does not act on the request of the data subject, it shall inform that person without delay, and no later than 30 days from the date of receipt of the request, of the reasons for not taking action, as well as of the right to lodge a complaint with the Commissioner or bring legal proceedings before a court.
The Controller shall provide information relating to the exercise of rights free of charge.
Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the Controller may:
- charge a reasonable fee covering the necessary administrative costs of providing the information or taking the requested action; or
- refuse to act on the request.
RIGHT TO LODGE A COMPLAINT WITH THE COMMISSIONER
As the data subject, you have the right to lodge a complaint with the Commissioner if you consider that the processing of your personal data has been carried out contrary to the applicable regulations of the Republic of Serbia.
The Commissioner is required to inform you of the progress and outcome of the proceedings, as well as of your right to initiate judicial proceedings.
The Commissioner shall prescribe the complaint form and enable complaints to be submitted electronically, without excluding other means of communication.
RIGHT TO JUDICIAL PROTECTION
You have the right to judicial protection if you consider that the Controller or Processor, through the processing of your personal data, has infringed a right granted to you under the applicable regulations of the Republic of Serbia.
PROCESSING OF THE UNIQUE CITIZEN IDENTIFICATION NUMBER
The processing of the unique citizen identification number is subject to the provisions of the law governing the unique citizen identification number or another applicable law, together with the provisions of the Law on Personal Data Protection relating to the protection of the rights and freedoms of data subjects.
OBLIGATION OF A FOREIGN NATIONAL
A foreign national / foreigner / non-resident is responsible for independently obtaining information and translating from Serbian into their own language the data and information contained in this “Notice on Personal Data Processing – Privacy Policy”, including information published on the website, regardless of any translation provided.
RESTRICTIONS ON THE EXERCISE OF DATA SUBJECT RIGHTS
The aforementioned rights and obligations may be restricted for the protection of:
1. national security;
2. defence;
3. public security;
4. the prevention, investigation and detection of criminal offences, prosecution of offenders or enforcement of criminal sanctions, including the prevention of and protection against threats to public security;
5. other important objectives of general public interest, particularly important state or financial interests of the Republic of Serbia, including monetary policy, the budget, the tax system, public health and social protection;
6. the independence of the judiciary and judicial proceedings;
7. the prevention, investigation, detection and prosecution of breaches of professional ethics;
8. the data subject or the rights and freedoms of other persons;
9. the establishment, exercise or enforcement of claims in civil matters.
APPLICATION OF THE “NOTICE ON PERSONAL DATA PROCESSING – PRIVACY POLICY” AND OTHER RULES
All matters not governed by the provisions of this “Notice on Personal Data Processing – Privacy Policy” and other Rules shall be governed exclusively by the laws and regulations of the Republic of Serbia.
JURISDICTION IN THE EVENT OF A DISPUTE AND APPLICABLE LAW
In the event of a dispute concerning any matter arising from the initial contact with our institution and/or the institution’s website and thereafter, taking into account the published rules / terms / prorogation agreement – “Jurisdiction in the Event of a Dispute” – the parties to the dispute shall first attempt to resolve the dispute amicably on their own within 90 days from the registration of the dispute with the institution.
If the dispute is not resolved within the specified period, then, taking into account the “Jurisdiction in the Event of a Dispute” and regardless of the state, country, province, region, place, etc., including any existing or future criteria for determining jurisdiction, conditional clauses and/or jurisdiction arising from the use of the Internet/website, the place of use and/or the place from which our website may be accessed and/or jurisdiction determined according to an “in rem” logic based on the location of the registry or authorised Internet domain name registry, the sole and exclusive court having subject-matter, territorial and personal jurisdiction (both general and specific personal jurisdiction) shall be the competent court in Belgrade.
The legal remedies, standards, procedures and regulations of the Republic of Serbia and the rules/internal regulations adopted by our institution in the Serbian language shall apply.
CONTACT
If you have any questions concerning personal data protection, please contact Živka Rangelov, psychologist at the Special Hospital for Addiction Diseases “DR VOROBJEV” Belgrade, verbally or in writing, by telephone at +381114221435 or by email at:
operater@drvorobjev.rs
By signing the written statement “Consent to Personal Data Processing” or by clicking/checking the “I Accept the Rules” box online (“tick-the-box”), you perform a clear affirmative action expressing your freely given, specific, informed and unambiguous consent, as the data subject, to the processing of your personal data.
Such consent may be expressed in the form of your written statement, electronic statement, oral statement or through conclusive conduct.
ENTRY INTO FORCE OF THE NOTICE ON PERSONAL DATA PROCESSING – PRIVACY POLICY
The Notice on Personal Data Processing – Privacy Policy entered into force on 20 August 2019.
The Notice on Personal Data Processing – Privacy Policy shall be subject to regular review, and each updated version shall be printed and placed at the reception desk or published on our website.
____________________________________
Director of the Clinic
*1 “Personal data” means any information relating to a natural person whose identity is identified or identifiable, directly or indirectly, in particular by reference to an identifier such as a name and identification number, location data, an identifier in electronic communications networks, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.
*2 “Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the wishes of that person by which the person, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to them.
*3 “Controller” means a natural or legal person or public authority which, alone or jointly with others, determines the purposes and means of processing. Where the purposes and means of processing are determined by law, the Controller may also be designated by such law or the criteria for its designation may be prescribed.
*4 “Joint Controllers” means two or more Controllers that jointly determine the purposes and means of processing.
Joint Controllers shall determine their respective responsibilities for compliance with the obligations prescribed by law, particularly obligations relating to the exercise of data subject rights and the fulfilment of their obligations to provide information to the data subject.
Such responsibilities shall be regulated by an arrangement between the Joint Controllers, unless those responsibilities are prescribed by law applicable to the Controllers.
The arrangement shall designate a contact point for the data subject and regulate the relationship of each Joint Controller with the data subject.
The essence of the provisions of the arrangement must be made available to the data subject.
Irrespective of the terms of the arrangement, the data subject may exercise the rights provided by law in respect of and against each of the Joint Controllers individually.
*5 “Data collection” means any structured set of personal data accessible according to specific criteria, regardless of whether the collection is centralised, decentralised or organised according to functional or geographical criteria.
*6 “Processing of personal data” means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, classification, grouping or structuring, storage, adaptation or alteration, disclosure, consultation, use, disclosure by transmission or provision, reproduction, dissemination or otherwise making available, comparison, restriction, erasure or destruction.
*7 “Processor” means a natural or legal person or public authority that processes personal data on behalf of the Controller.
*8 “Recipient” means a natural or legal person or public authority to whom personal data are disclosed, whether or not a third party, except for public authorities that receive personal data in accordance with the law in the context of an investigation of a particular case and process such data in accordance with the personal data protection rules applicable to the purposes of processing.
*9
- Location data may relate to the latitude, longitude and altitude of the user’s terminal equipment, the direction of travel, the degree of accuracy of the location information, identification of the network cell in which the terminal equipment is located at a particular point in time, and the time at which the location information was recorded.
- A communication may include any name, number or address information provided by the sender of a communication or by the user of a connection for the purpose of carrying out the communication. Traffic data may include any translation of this information performed by the network over which the communication is transmitted for the purpose of carrying out the transmission. Traffic data may, inter alia, consist of data relating to the routing, duration, time or volume of a communication, the protocol used, the location of the terminal equipment of the sender or recipient, the network from which the communication originates or on which it terminates, or the beginning, end or duration of a connection. They may also consist of the format in which the communication is conveyed by the network.
- In cases where an individual subscriber or user receiving information can be identified, for example in “video-on-demand” services, the transmitted information falls within the meaning of a communication.
- Consent may be given by any appropriate method enabling a freely given, specific and informed indication of the user’s wishes, including by ticking a box when visiting an Internet website.
- Application of certain requirements relating to the presentation and restriction of calling and connected line identification and to automatic call forwarding to subscriber lines connected to analogue exchanges.
- Service providers offering publicly available electronic communications services over the Internet should inform users and subscribers of measures they can take to protect the security of their communications, for example by using specific types of software or encryption technologies. The obligation to inform subscribers of particular security risks does not relieve a service provider of its obligation to take, at its own expense, appropriate and immediate measures to remedy any new and unforeseen security risks and restore the normal level of security of the service.
- Measures should be taken to prevent unauthorised access to communications in order to protect the confidentiality of communications, including their content and any data relating to such communications, through public communications networks and publicly available electronic communications services.
- The prohibition on storing communications and related traffic data by persons other than users or without their consent is not intended to prohibit automatic, intermediate and transient storage of such information insofar as it takes place for the sole purpose of carrying out transmission in an electronic communications network, provided that the information is not stored for any period longer than necessary for transmission and traffic management purposes and that confidentiality remains guaranteed throughout the storage period.
- Confidentiality of communications should also be ensured in the course of lawful business practice. Where necessary and legally authorised, communications may be recorded for the purpose of providing evidence of a business transaction/communication. Parties to communications should be informed, before the recording is created, of the recording, its purpose and the duration of its storage. Recorded communications should be erased as soon as possible and in any event no later than the end of the period during which the transaction/communication may lawfully be challenged.
- The terminal equipment of users of electronic communications networks and any information stored on such equipment form part of the users’ private sphere and require protection under the European Convention for the Protection of Human Rights and Fundamental Freedoms. So-called “spyware”, “web bugs”, hidden identifiers and other similar devices may enter a user’s terminal without their knowledge in order to gain access to information, store hidden information or track the user’s activities, and may seriously infringe the privacy of such users. The use of such devices should be permitted only for legitimate purposes and provided that the users concerned are informed accordingly.
- Such devices, for example so-called “cookies”, may, however, constitute legitimate and useful tools, for example in analysing the effectiveness of website design and advertising and in verifying the identity of users engaged in online transactions. Where such devices, such as cookies, are intended for a legitimate purpose, such as facilitating the provision of information society services, their use should be permitted provided that users are given clear and precise information about the purpose of cookies or similar devices so that they are aware of the information being placed on the terminal equipment they use.
Users should have the opportunity to refuse the storage of cookies or similar devices on their terminal equipment. This is particularly important where users other than the original user have access to the terminal equipment and therefore to any privacy-sensitive information stored on it.
Information and the right to refuse may be offered once for the use of various devices to be installed on the user’s terminal equipment during the same connection, also covering any further use of those devices during subsequent connections.
Methods of providing information, offering the right to refuse or requesting consent should be made as user-friendly as possible.
Access to specific website content may still be made conditional upon informed acceptance of a cookie or similar device where it is used for a legitimate purpose.
- Data relating to subscribers are processed within electronic communications networks for the purposes of establishing connections and transmitting information containing details concerning the private lives of natural persons and their right to respect for their correspondence, or concerning the legitimate interests of legal persons.
Such data may be stored only to the extent necessary for the provision of the service, for billing and interconnection payments, and only for a limited period.
Any further processing of such data that a provider of publicly available electronic communications services may wish to carry out for the marketing of electronic communications services or for the provision of value-added services may be permitted only where the subscriber has consented to it on the basis of accurate and complete information provided by the service provider concerning the types of further processing it intends to carry out and the subscriber’s right not to give or to withdraw consent to such processing.
Traffic data used for marketing communications services or for the provision of value-added services should also be erased or made anonymous after the provision of the service.
Service providers should always keep subscribers informed of the types of data they process, the purposes of processing and the period for which such processing is carried out.
- The exact point at which the transmission of a communication is completed, after which traffic data should be erased except for billing purposes, may depend on the type of electronic communications service provided.
For example, in the case of a voice telephony call, transmission is completed as soon as either user terminates the connection.
For electronic mail, transmission is completed as soon as the addressee retrieves the message, typically from the server of their service provider.
- The obligation to erase traffic data or render such data anonymous when they are no longer required for the purpose of transmitting a communication is not inconsistent with Internet procedures such as caching IP addresses in the domain name system, caching IP addresses for the purpose of linking physical addresses, or using log-in information to control access rights to networks or services.
- A service provider may process traffic data relating to subscribers and users where necessary in individual cases in order to detect a technical fault or errors in transmission.
Traffic data for billing purposes may also be processed by a provider in order to detect and stop fraud involving unpaid use of electronic communications services.
- Where a provider of electronic communications services or a value-added service subcontracts to another entity the processing of personal data necessary for the provision of those services, such subcontracting and subsequent processing of data should fully comply with the requirements relating to Controllers and Processors of personal data.
Where the provision of a value-added service requires traffic or location data to be forwarded from an electronic communications service provider to a value-added service provider, the subscribers or users to whom such data relate should also be fully informed of such forwarding before giving their consent to the processing of the data.
- The introduction of itemised billing has improved subscribers’ ability to verify the accuracy of charges imposed by service providers, but at the same time it may jeopardise the privacy of users of electronic communications services.
- With regard to calling-line identification, it is necessary to protect the right of the calling party to prevent the presentation of the identification of the line from which the call is made, and the right of the called party to reject calls from unidentified lines.
There are grounds for overriding the elimination of calling-line identification presentation in specific cases.
Certain subscribers, particularly helplines and similar organisations, have an interest in guaranteeing the anonymity of callers.
With regard to connected-line identification, it is necessary to protect the right and legitimate interest of the called party to prevent presentation of the identification of the line to which the calling party is actually connected, particularly in the case of forwarded calls.
Providers of publicly available electronic communications services should inform their subscribers of the existence of calling and connected-line identification within the network, of all services offered on the basis of calling and connected-line identification, and of the available privacy options.
This enables subscribers to make an informed choice regarding the privacy facilities they may wish to use.
- In digital mobile networks, location data providing the geographical position of a mobile user’s terminal equipment are processed in order to enable the transmission of communications.
In addition, digital mobile networks may have the capacity to process location data that are more precise than necessary for the transmission of communications and that are used to provide value-added services, such as services providing individualised traffic information and guidance to drivers.
Processing of such data for value-added services should be permitted only where subscribers have given their consent.
Even where subscribers have given their consent, they should have a simple means of temporarily refusing the processing of location data free of charge.
- States may restrict users’ and subscribers’ privacy rights with regard to calling-line identification where necessary for tracing nuisance calls and, with regard to calling-line identification and location data, where necessary to enable emergency services to perform their tasks as effectively as possible.
For these purposes, States may adopt specific provisions authorising electronic communications service providers to provide access to calling-line identification and location data without the prior consent of the user or subscriber concerned.
- Subscribers should be provided with safeguards against nuisance that may be caused by automatic forwarding of calls by others.
Furthermore, in such cases, subscribers must be able to stop forwarded calls from being passed to their terminal by making a simple request to the provider of the publicly available electronic communications service.
- Safeguards should be provided for subscribers against intrusion into their privacy through unsolicited communications for direct marketing purposes, particularly through automated telephone calls, fax and electronic mail, including SMS messages.
Such forms of unsolicited commercial communications may, on the one hand, be relatively easy and inexpensive to send while, on the other hand, imposing a burden and/or cost on the recipient.
Moreover, in some cases their volume may also cause difficulties for electronic communications networks and terminal equipment.
For such forms of unsolicited communications for direct marketing purposes, it is justified to require the recipients’ explicit prior consent before such communications are sent to them.
*10 List of domains:
https://cellulestaminali-clinica.com/“Electronic communications identifier” includes, without limitation, other types and forms of identifying individuals on the basis of their devices, applications, tools and protocols, such as Internet Protocol addresses, cookie identifiers or other identifiers such as radio-frequency tags, biometric data obtained from “smart cameras”, etc.
*11 Information on the purposes of processing contains a description of the purpose for which personal data are collected in a particular data collection, together with an indication of whether the purpose of processing is prescribed by law or determined by the Controller with the consent of the data subject or another authorised person.
*12 Decision appointing a person responsible for maintaining documentation, entering data and handling data.
*13 Statement of the person from whom the data entered into health documentation are obtained.