Personal Data Processing Policy
- General Provisions
- Purpose of This Policy
- Key Rights of i-Harbor
- Key Obligations of i-Harbor
- Key Rights of Personal Data Subjects
- Purposes of Personal Data Collection
- Legal Grounds for Personal Data Processing
- Scope and Categories of Personal Data Processed and Categories of Data Subjects
- Personal Data Processing Procedures and Conditions
- Personal Data Operations Performed by i-Harbor
- Personal Data Processing Methods
- Transfer of Personal Data to Third Parties
- Security Measures for Personal Data Processing
- i-Harbor Personal Data Databases Are Located Entirely Within the Russian Federation
- Personal Data Processing Periods
- Conditions for Personal Data Processing Without Automation
- Procedure for Responding to Requests from Personal Data Subjects and Their Representatives
- Procedure for Responding to Requests from the Authorized Personal Data Protection Authority
Definitions
| automated personal data processing | processing personal data using computing equipment |
| personal data security | the protected state of personal data, characterized by the ability of users, systems, technical equipment, and information technologies to ensure its confidentiality, integrity, and availability when processed in personal data information systems |
| blocking of personal data | temporary suspension of personal data processing, except where processing is necessary to clarify the data |
| personal data information system | the personal data contained in databases together with the information technologies and technical equipment used to process it |
| personal data confidentiality | a requirement binding on the Operator or any other person with access to personal data not to disseminate it without consent from the data subject or another lawful basis |
| unauthorized access (unauthorized actions) | access to or actions involving information that violate established access rights and/or rules governing access to or use of the information, using standard information system tools or tools with similar functions and technical characteristics |
| personal data processing | any action or set of actions performed on personal data, with or without automation, including collection, recording, organization, accumulation, storage, clarification (updating or modification), retrieval, use, transfer (dissemination, provision, or access), anonymization, blocking, deletion, and destruction |
| personal data anonymization | actions that make it impossible to determine which specific data subject personal data relates to without additional information |
| Operator | a state authority, municipal authority, legal entity, or individual that independently or jointly organizes and/or carries out personal data processing and determines its purposes, the personal data to be processed, and the actions or operations performed on it |
| personal data | any information relating to a directly or indirectly identified or identifiable individual (personal data subject) |
| personal data authorized for dissemination by the data subject | personal data that the data subject has made accessible to an unlimited audience by consenting to the processing of personal data authorized for dissemination under Federal Law No. 152-FZ of July 27, 2006, On Personal Data |
| provision of personal data | actions intended to disclose personal data to a specific person or defined group of persons |
| dissemination of personal data | actions intended to disclose personal data to an undefined group of persons |
| technical equipment of a personal data information system | computing equipment, information and computing systems and networks, equipment and systems for transmitting, receiving, and processing personal data (including sound recording, amplification, and playback equipment and systems, intercom and television devices, document production and duplication equipment, and other technical equipment for processing speech, graphics, video, and alphanumeric information), software (including operating systems and database management systems), and information security tools |
| cross-border transfer of personal data | transferring personal data to a foreign country to a foreign government authority, individual, or legal entity |
| personal data security threats | conditions and factors that create a risk of unauthorized, including accidental, access to personal data that may result in destruction, alteration, blocking, copying, or dissemination, or other unauthorized actions during processing in a personal data information system |
| destruction of personal data | actions that make it impossible to restore personal data in a personal data information system and/or destroy physical media containing personal data |
1. General Provisions
1.1. Purpose of This Policy
This document (the Policy) establishes the purposes and general principles of personal data processing and the personal data protection measures implemented by MOYA GAVAN LIMITED LIABILITY COMPANY (the Company).
The Company is a personal data operator. This Policy is a publicly available Company document that anyone may review.
1.2. Key Rights of the Company
Personal data is processed lawfully and fairly, in compliance with the principles and rules established by Federal Law No. 152-FZ of July 27, 2006, On Personal Data (Federal Law No. 152-FZ), based on consent from the data subject, except in cases provided by Federal Law No. 152-FZ.
The Company reserves the right to verify the completeness, accuracy, and adequacy of the personal data provided and, where necessary, whether it is current in relation to the processing purposes. If incorrect or incomplete personal data is identified, the Company may terminate all relations with the data subject.
If consent to personal data processing is obtained from a representative of the data subject, the Company verifies the authority of that representative to consent on behalf of the data subject.
The Company may obtain personal data from someone other than the data subject, provided the Company supplies confirmation of grounds specified in clauses 2–11 of part 1 of Article 6, part 2 of Article 10, and part 2 of Article 11 of Federal Law No. 152-FZ.
If the data subject withdraws consent to personal data processing, the Company may continue processing without consent where grounds specified in clauses 2–11 of part 1 of Article 6, part 2 of Article 10, and part 2 of Article 11 of Federal Law No. 152-FZ apply.
With consent from the data subject, unless otherwise provided by federal law, the Company may entrust personal data processing to third parties under an agreement or contract or by adopting an appropriate instrument (a Company instruction). A person processing personal data under a Company instruction must comply with the principles and rules of Federal Law No. 152-FZ. The instruction must specify the personal data, the actions or operations to be performed, and the processing purposes. It must require the processor to maintain confidentiality, comply with part 5 of Article 18 and Article 18.1 of Federal Law No. 152-FZ, and, at Company request throughout the instruction period, including before processing begins, provide documents and other information confirming measures taken and compliance with requirements established under Federal Law No. 152-FZ to carry out the instruction. It must require secure processing and specify data protection requirements under Article 19 of Federal Law No. 152-FZ, including notification of the Company in the cases provided by part 3.1 of Article 21 of that law.
A person processing personal data under a Company instruction is not required to obtain consent from the data subject.
When the Company entrusts personal data processing to a third party, the Company remains liable to the data subject for the actions of that party. The processor acting under a Company instruction is liable to the Company.
If the Company entrusts personal data processing to a foreign individual or legal entity, both the Company and the processor acting under its instruction are liable to the data subject for the actions of those persons.
1.3. Key Obligations of the Company
The Company does not collect or process personal data or transfer it to third parties without consent from the data subject, unless otherwise provided by Russian law.
If unlawful processing is identified following an inquiry or request from the data subject, their representative, or the authorized personal data protection authority, the Company blocks the personal data concerned, or ensures it is blocked if processed by another person acting on Company instructions, from receipt of the inquiry or request for the duration of the review.
If inaccurate personal data is identified following an inquiry or request from the data subject or their representative, or a request from the authorized personal data protection authority, the Company blocks the personal data concerned, or ensures it is blocked if processed by another person acting on Company instructions, from receipt of the inquiry or request for the duration of the review, provided blocking does not infringe the rights and lawful interests of the data subject or third parties.
If the inaccuracy is confirmed, the Company corrects the personal data, or ensures its correction where processed by another person acting on Company instructions, within 7 business days after receiving information from the data subject, their representative, the authorized personal data protection authority, or other necessary documents, and removes the block.
If unlawful personal data processing by the Company or a person acting on its instructions is identified, the Company stops the unlawful processing, or ensures that the person acting on its instructions stops it, within 3 business days after identification.
If the processing cannot be made lawful, the Company destroys the personal data or ensures its destruction within 10 business days after identifying the unlawful processing. The person responsible for organizing personal data processing at the Company determines whether processing is unlawful and destruction is necessary, and informs management. The Company notifies the data subject or their representative that the violations have been remedied or the data destroyed. If the inquiry from the data subject or representative, or the request from the authorized personal data protection authority, was forwarded by that authority, the Company also notifies the authority.
If an unlawful or accidental transfer of personal data (provision, dissemination, or access) is found to have infringed the rights of one or more data subjects, the Company must notify the authorized personal data protection authority after the incident is identified by the Company, that authority, or another interested person:
within 24 hours, of the incident, its suspected causes and the expected harm to the rights of data subjects, and the measures taken to address its consequences, and provide information about the person authorized by the Company to communicate with the personal data protection authority about the incident;
within 72 hours, of the results of the internal investigation, and provide information about the persons whose actions caused the incident, if known.
When the purpose of personal data processing has been achieved, the Company stops processing and destroys the data, or ensures that a person processing on its instructions does so, within 30 days after the purpose is achieved. This applies unless otherwise provided by a contract to which the data subject is a party, beneficiary, or guarantor, or another agreement between the Company and the data subject, or unless the Company may process the data without consent under Federal Law No. 152-FZ or other federal laws.
If the data subject withdraws consent, the Company stops processing, or ensures that a person processing on its instructions does so. If retention is no longer necessary for the processing purposes, the Company destroys the data or ensures its destruction within 30 days after receiving the withdrawal. This applies unless otherwise provided by a contract to which the data subject is a party, beneficiary, or guarantor, or another agreement between the Company and the data subject, or unless the Company may process the data without consent under Federal Law No. 152-FZ or other federal laws.
If the data subject requests that the Company stop processing personal data, the Company stops processing or ensures that its processor does so within 10 business days after receiving the request, except in the cases provided by clauses 2–11 of part 1 of Article 6, part 2 of Article 10, and part 2 of Article 11 of Federal Law No. 152-FZ. This period may be extended by no more than 5 business days if the Company sends the data subject a reasoned notice explaining the extension of the period for providing the requested information.
The Company makes the necessary changes within 7 business days after the data subject or their representative provides information confirming that personal data is incomplete, inaccurate, or outdated.
The Company destroys personal data within 7 business days after the data subject or their representative provides information confirming that it was obtained unlawfully or is unnecessary for the stated processing purpose. The Company notifies the data subject or their representative of the changes and measures taken and makes reasonable efforts to notify third parties to whom the data was transferred.
If personal data cannot be destroyed within the periods specified above, the Company blocks the data, or ensures it is blocked where processed by another person acting on its instructions, and ensures destruction within no more than 6 months, unless federal law establishes another period.
Destruction of personal data is confirmed in accordance with requirements established by the authorized personal data protection authority.
Under Order No. 179 of October 28, 2022, of the Federal Service for Supervision of Communications, Information Technology and Mass Media, On Approval of Requirements for Confirmation of Personal Data Destruction (the Requirements), where the Company processes personal data without automation, destruction is confirmed by a personal data destruction report.
Where the Company processes personal data using automation, destruction is confirmed by a destruction report meeting clauses 3 and 4 of the Requirements and an export from the event log of the personal data information system (the log export).
If the log export cannot include certain information required by clause 5 of the Requirements, the missing information is entered in the destruction report.
Where the Company processes personal data both with and without automation, destruction is confirmed by a destruction report meeting clauses 3 and 4 of the Requirements and a log export meeting clause 5 of the Requirements.
The destruction report and log export must be retained for 3 years after personal data destruction.
1.4. Key Rights of Personal Data Subjects
The data subject decides whether to provide personal data and gives consent to processing freely, voluntarily, and in their own interest. Where required by federal law, processing requires written consent from the data subject. Consent in an electronic document signed with an electronic signature in accordance with federal law is equivalent to written consent on paper bearing the handwritten signature of the data subject.
To protect their lawful interests, data subjects or their representatives have the right to:
receive complete information about their personal data and its processing, including automated processing;
access their personal data freely and at no charge, including obtaining copies of any record containing their personal data, except in the cases provided by part 8 of Article 14 of Federal Law No. 152-FZ;
request correction, blocking, or destruction of personal data that is incomplete, outdated, inaccurate, unlawfully obtained, or unnecessary for the stated processing purpose, and take legally available measures to protect their rights. If the Company refuses to remove, correct, block, or destroy the data, the data subject may submit a written objection with appropriate reasons;
require the Company to notify all persons previously provided with incorrect, incomplete, outdated, inaccurate, unlawfully obtained, or unnecessary personal data of all changes or removals, including blocking or destruction by those third parties;
challenge unlawful acts or omissions of the Company in processing and protecting their personal data in court or before the authorized personal data protection authority if the data subject believes the Company is violating Federal Law No. 152-FZ or otherwise infringing their rights and freedoms. The data subject has the right to protect their rights and lawful interests, including seeking damages and/or compensation for moral harm through the courts.
The data subject has the right to obtain information about processing of their personal data, including:
confirmation that the Company processes personal data;
the legal grounds and purposes for processing;
the purposes and methods of processing used by the Company;
the Company name and location, and information about persons other than Company employees who have access to personal data or to whom it may be disclosed under a contract with the Company or federal law;
the personal data being processed relating to the data subject and its source, unless federal law provides a different procedure for supplying that data;
the processing periods, including retention periods;
the procedure for exercising rights under Federal Law No. 152-FZ;
information about completed or planned cross-border data transfers;
the name, or last name, first name, and patronymic, and address of any person entrusted or to be entrusted with processing personal data on Company instructions;
information about how the Company fulfills its obligations under Article 18.1 of Federal Law No. 152-FZ;
other information provided for by Federal Law No. 152-FZ or other federal laws.
If the data subject has been given access to the personal data being processed at their request, they may submit a further inquiry or request to the Company for information and access no earlier than 30 days after the original inquiry or request, unless a shorter period is established by federal law, a regulation adopted under it, or a contract to which the data subject is a party, beneficiary, or guarantor.
The data subject may submit a further inquiry or request before the 30-day period expires if the information and/or personal data being processed was not provided in full in response to the original inquiry. The repeat request must explain why it is being submitted.
The Company may refuse a repeat request that does not meet the conditions in parts 4 and 5 of Article 14 of Federal Law No. 152-FZ. The refusal must be reasoned. The Company bears the burden of proving that its refusal is justified.
The right of a data subject to access their personal data may be restricted under federal laws, including where:
personal data, including data obtained through operational investigative, counterintelligence, and intelligence activities, is processed for national defense, state security, and law enforcement;
personal data is processed by authorities that detained the data subject on suspicion of a crime, charged them in criminal proceedings, or imposed a preventive measure before charges were filed, except where Russian criminal procedure law allows a suspect or accused person to review that data;
personal data is processed under laws combating money laundering and terrorist financing;
access by the data subject would infringe the rights and lawful interests of third parties;
personal data is processed in cases provided by Russian transportation security law to ensure stable and safe operation of the transportation system and protect individuals, society, and the state from unlawful interference in that system.
2. Purposes of Personal Data Collection
Personal data processing is limited to specific, predetermined, and lawful purposes. Only data relevant to those purposes may be processed. The content and amount of data must correspond to the stated purposes and must not be excessive. Processing that is incompatible with the purposes of collection is prohibited. Databases containing personal data processed for incompatible purposes may not be combined.
The Company ensures that the personal data it processes is accurate, adequate, and, where necessary, current in relation to the processing purposes. It takes or ensures the necessary measures to delete or correct incomplete or inaccurate data.
The Company processes personal data for the following purposes:
complying with Russian labor law;
establishing and performing contractual relationships.
3. Legal Grounds for Personal Data Processing
The Company processes personal data on the following grounds:
internal personal data protection documents;
performance of a contract to which the data subject is a party, beneficiary, or guarantor, or entering into a contract at the initiative of the data subject or under which they will be a beneficiary or guarantor;
consent from the data subject;
consent from the personal data subject;
Articles 86–90 of the Labor Code of the Russian Federation;
the founding document of the Organization;
Federal Law No. 152-FZ of July 27, 2006, On Personal Data.
4. Scope and Categories of Personal Data Processed and Categories of Data Subjects
The Company lawfully and fairly processes personal data of the following individuals (data subjects):
For the purpose of compliance with Russian labor law, the following categories of personal data are processed for the following data subjects:
1) employees:
Other personal data categories: residential address, citizenship, employment record book details, income, job title, taxpayer identification number (INN), employment history, qualifications, contact details (phone number and email address), passport details, sex, profession, personal/bank account details, certification information, retraining and continuing education information, professional retraining information, individual insurance account number (SNILS), social benefits, specialty, academic degree and title, last name, first name, patronymic, and photograph.
2) applicants who submitted a resume:
Other personal data categories: residential address, citizenship, employment record book details, date of birth, job title, foreign language proficiency, employment history, qualifications, contact details (phone number and email address), education, profession, certification information, retraining and continuing education information, professional retraining information, specialty, last name, first name, and patronymic.
3) former employees:
Other personal data categories: residential address, registered address, citizenship, employment record book details, date of birth, income, job title, foreign language proficiency, taxpayer identification number (INN), employment history, qualifications, contact details (phone number and email address), place of employment, education, passport details, sex, profession, personal/bank account details, certification information, retraining and continuing education information, professional retraining information, individual insurance account number (SNILS), specialty, academic degree and title, last name, first name, patronymic, and photograph.
Processing method: combined automated and nonautomated processing, including blocking, recording, retrieval, use, accumulation, transfer (access), transfer (provision), collection, organization, deletion, destruction, clarification (updating or modification), and storage.
Processing period: until the processing purposes are achieved. Retention period: from 30 days to 50 years.
For the purpose of establishing and performing contractual relationships, the following categories of personal data are processed for the following data subjects:
1) individuals, including foreign nationals, who request services:
Publicly available personal data: contact details (phone number and email address), last name, first name, patronymic, and photograph.
Processing method: automated processing, including blocking, recording, retrieval, use, accumulation, transfer (access), transfer (provision), transfer (dissemination), collection, organization, deletion, destruction, clarification (updating or modification), and storage.
Processing period: until the organization ceases operations. Retention period: 3 years.
5. Personal Data Processing Procedures and Conditions
5.1. Personal Data Operations Performed by the Company
The Company performs the following personal data operations:
For compliance with Russian labor law: transfer (access), recording, blocking, organization, transfer (provision), use, deletion, anonymization, accumulation, collection, storage, clarification (updating or modification), destruction, and retrieval;
For establishing and performing contractual relationships: transfer (dissemination), transfer (access), recording, blocking, organization, transfer (provision), use, deletion, anonymization, accumulation, collection, storage, clarification (updating or modification), destruction, and retrieval.
5.2. Personal Data Processing Methods
The Company uses the following personal data processing methods:
For compliance with Russian labor law, combined automated and nonautomated processing is used, without transmission over an internal network but with transmission over the Internet;
For establishing and performing contractual relationships, automated processing is used, with transmission over both the internal network and the Internet.
5.3. Transfer of Personal Data to Third Parties
Third party: Domain Name Registrar REG.RU LLC, taxpayer identification number (INN) 7733568767.
Third-party location: 72 Leningradsky Avenue, Building 3, Moscow, Moscow Region, 125315, Russia.
Transfer conditions: instructions from the Operator.
Cross-border personal data transfers: none.
Method of transfer to the third party: automated transmission over the Internet.
Purpose of transfer: outsourcing information processing in the system.
Data subjects and personal data transferred:
1) individuals, including foreign nationals, who request services:
Publicly available personal data: contact details (phone number and email address), last name, first name, patronymic, and photograph.
Third-party processing methods: automated processing with transmission over the internal network and without transmission over the Internet.
Operations permitted for the third party: blocking, recording, retrieval, use, accumulation, transfer (access), transfer (provision), transfer (dissemination), collection, organization, deletion, destruction, clarification (updating or modification), and storage.
5.4. Security Measures for Personal Data Processing
When processing personal data, the Company takes and ensures the necessary legal, organizational, and technical measures to protect it against unlawful or accidental access, destruction, alteration, blocking, copying, provision, dissemination, and other unlawful actions.
The Company ensures personal data security through measures including:
assessing potential harm to data subjects from violations of the Law On Personal Data, in accordance with requirements of the authorized personal data protection authority, and comparing that harm with protective measures intended to fulfill obligations under that law;
conducting internal monitoring and/or audits of compliance with the Law On Personal Data and internal Company documents governing personal data processing;
familiarizing employees directly involved in processing with Russian personal data law, the Company personal data processing policy, and internal processing regulations, and/or training those employees;
issuing a Company personal data processing policy and internal regulations specifying, for each processing purpose, the categories and list of personal data, categories of data subjects, processing methods and processing and retention periods, and procedures for destroying data once the purposes are achieved or other lawful grounds arise; and issuing internal regulations establishing procedures to prevent and detect violations of Russian law and address their consequences;
maintaining an inventory of electronic media containing personal data;
appointing a person responsible for organizing personal data processing;
restoring personal data altered or destroyed through unauthorized access;
using information security tools that have passed the prescribed conformity assessment procedure;
identifying personal data security threats during processing in personal data information systems;
assessing the effectiveness of personal data security measures before a personal data information system is put into operation;
establishing access rules for personal data processed in an information system and ensuring that all operations involving that data are recorded and tracked;
detecting unauthorized access to personal data and taking action, including detecting and preventing computer attacks on personal data information systems, addressing their consequences, and responding to computer security incidents;
monitoring personal data security measures and the protection level of personal data information systems;
implementing organizational and technical security measures necessary to meet personal data protection requirements and achieve the protection levels established by the Government of the Russian Federation;
cooperating with the state system for detecting, preventing, and addressing the consequences of computer attacks on information resources of the Russian Federation, including reporting computer security incidents that result in unlawful access, provision, dissemination, or transfer of personal data.
5.5. Company Personal Data Databases Are Located Entirely Within the Russian Federation.
5.6. Personal Data Processing Periods
Personal data processed by the Company must be destroyed or anonymized if:
the processing purposes have been achieved or are no longer necessary;
the data subject withdraws consent to processing;
consent to processing expires;
lawful processing cannot be ensured;
the Company ceases operations.
5.7. Conditions for Personal Data Processing Without Automation
When processing personal data without automation, the Company complies with Government of the Russian Federation Resolution No. 687 of September 15, 2008, On Approval of the Regulation on Specific Features of Personal Data Processing Without Automation.
In such processing, personal data is separated from other information, including by recording it on separate physical media or in designated sections or fields of forms.
Personal data is retained in a form that allows identification of the data subject for no longer than the processing purposes require.
6. Procedure for Responding to Requests from Personal Data Subjects and Their Representatives
When a data subject or their representative makes an oral inquiry or written request for access to personal data, the Company follows Articles 14, 18, and 20 of Federal Law No. 152-FZ.
The data subject or their representative may use the request forms or consent withdrawal form provided in the appendices to this Policy.
The Company provides information on the existence and processing of personal data upon an inquiry or request from the data subject or their representative. The request must include the number of the principal identity document of the data subject or representative, its issue date and issuing authority, information confirming the relationship between the data subject and the Company (contract number, contract date, agreed verbal identifier, and/or other information), or other information confirming that the Company processes the data, and the signature of the data subject or representative. The request may be submitted as an electronic document signed with an electronic signature in accordance with Russian law.
The Company grants access to personal data to the data subject or their representative only under the supervision of the person responsible for organizing personal data processing at the Company (the Responsible Person).
The Responsible Person decides whether to grant the data subject or their representative access to the personal data concerned.
If information provided by the data subject or representative is insufficient to establish identity, or disclosure would infringe the constitutional rights and freedoms of others, the Responsible Person prepares a reasoned response citing part 8 of Article 14 of Federal Law No. 152-FZ or another federal law as grounds for refusal within 10 business days after the inquiry or receipt of the request. This period may be extended by no more than 5 business days if the Company sends the data subject a reasoned notice explaining the extension. Information is provided in the same form as the inquiry or request, unless otherwise specified in it.
To provide access to personal data, the Responsible Person involves employees of the department processing that data, with the approval of the department head.
The Company allows the data subject or their representative to review personal data relating to that subject at no charge.
The Company provides information about the existence of personal data in an accessible form. The information must not contain personal data of other subjects unless lawful grounds for disclosure exist. The Responsible Person oversees provision of information to the data subject or their representative.
Information about the existence of personal data must be provided to the data subject or their representative within 10 business days after receipt of the request or inquiry. This period may be extended by no more than 5 business days if the Company sends the data subject a reasoned notice explaining the extension. Information is provided in the same form as the inquiry or request, unless otherwise specified in it.
If the Company refuses to provide information about the existence of personal data or the data itself in response to an inquiry or request from the data subject or their representative, it provides a written, reasoned response citing part 8 of Article 14 of Federal Law No. 152-FZ or another federal law as grounds for refusal within 10 business days after the inquiry or receipt of the request. This period may be extended by no more than 5 business days if the Company sends the data subject a reasoned notice explaining the extension.
The right of a data subject to access their personal data may be restricted under federal laws, including where:
personal data, including data obtained through operational investigative, counterintelligence, and intelligence activities, is processed for national defense, state security, and law enforcement;
personal data is processed by authorities that detained the data subject on suspicion of a crime, charged them in criminal proceedings, or imposed a preventive measure before charges were filed, except where Russian criminal procedure law allows a suspect or accused person to review that data;
personal data is processed under laws combating money laundering and terrorist financing;
access by the data subject would infringe the rights and lawful interests of third parties;
personal data is processed in cases provided by Russian transportation security law to ensure stable and safe operation of the transportation system and protect individuals, society, and the state from unlawful interference in that system.
7. Procedure for Responding to Requests from the Authorized Personal Data Protection Authority
Under part 4 of Article 20 of Federal Law No. 152-FZ, the Company provides the authorized personal data protection authority, at its request, with information necessary for its activities within 10 days after receipt of the request. This period may be extended by no more than 5 business days if the Company sends the authority a reasoned notice explaining the extension.
The Responsible Person collects information to prepare a reasoned response to a supervisory authority request, involving Company employees as needed.
Within the prescribed period, the Responsible Person prepares and sends a reasoned response and other necessary documents to the authorized personal data protection authority.