{"id":374,"date":"2026-03-06T10:00:55","date_gmt":"2026-03-06T09:00:55","guid":{"rendered":"https:\/\/admin.zpkb.eu\/?page_id=374"},"modified":"2026-03-06T22:24:36","modified_gmt":"2026-03-06T21:24:36","slug":"zasady-ochrany-osobnich-udaju","status":"publish","type":"page","link":"https:\/\/admin.zpkb.eu\/en\/personal-data-protection-policy\/","title":{"rendered":"Personal Data Protection Policy"},"content":{"rendered":"\r\n<p data-start=\"53\" data-end=\"103\"><strong data-start=\"53\" data-end=\"101\">Statement on the Processing of Personal Data<\/strong><\/p>\r\n<p data-start=\"105\" data-end=\"486\">Statement on the processing of personal data pursuant to the Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC (hereinafter the \u201cGeneral Regulation\u201d), and information for data subjects.<\/p>\r\n<p data-start=\"488\" data-end=\"509\"><strong data-start=\"488\" data-end=\"507\">Data Controller<\/strong><\/p>\r\n<p data-start=\"511\" data-end=\"813\">Pilsen Region, Regional Office of the Pilsen Region, Company ID: 70890366, with registered office at \u0160kroupova 18, 306 13 Pilsen (hereinafter the \u201cController\u201d), hereby informs data subjects, in accordance with Article 12 of the General Regulation, about the processing of personal data and their rights.<\/p>\r\n<p data-start=\"815\" data-end=\"854\"><strong data-start=\"815\" data-end=\"852\">Scope of Personal Data Processing<\/strong><\/p>\r\n<p data-start=\"856\" data-end=\"1221\">Personal data are processed to the extent provided to the Controller by the relevant data subject, in connection with entering into a contractual or other legal relationship with the Controller, or data which the Controller has otherwise collected and processes in accordance with applicable legal regulations or to fulfill the Controller\u2019s statutory obligations.<\/p>\r\n<p data-start=\"1223\" data-end=\"1253\"><strong data-start=\"1223\" data-end=\"1251\">Sources of Personal Data<\/strong><\/p>\r\n\r\n<ul>\r\n \t<li data-start=\"1257\" data-end=\"1339\">Directly from the data subject (e.g., contact form on the Pilsen\u0148 Region website);<\/li>\r\n \t<li data-start=\"1342\" data-end=\"1383\">From other public or state authorities;<\/li>\r\n \t<li data-start=\"1386\" data-end=\"1421\">Non-public registers (ISEO, ROB);<\/li>\r\n \t<li data-start=\"1424\" data-end=\"1560\">Publicly accessible registers, directories, lists, and records (ROS, R\u00daIAN, commercial register, trade register, land registry, etc.).<\/li>\r\n<\/ul>\r\n<p data-start=\"1562\" data-end=\"1605\"><strong data-start=\"1562\" data-end=\"1603\">Categories of Personal Data Processed<\/strong><\/p>\r\n\r\n<ul>\r\n \t<li data-start=\"1609\" data-end=\"1868\">Address and identification data enabling unambiguous identification of the data subject (e.g., name, surname, title, date of birth, permanent address, Company ID, Tax ID) and contact details (e.g., address, phone number, fax, email, or similar information);<\/li>\r\n \t<li data-start=\"1871\" data-end=\"1919\">Descriptive data (e.g., bank account details);<\/li>\r\n \t<li data-start=\"1922\" data-end=\"1967\">Other data necessary to perform a contract;<\/li>\r\n \t<li data-start=\"1970\" data-end=\"2143\">Data provided beyond legal requirements processed on the basis of consent from the data subject (e.g., processing photographs, use of personal data for HR purposes, etc.).<\/li>\r\n<\/ul>\r\n<p data-start=\"2145\" data-end=\"2178\"><strong data-start=\"2145\" data-end=\"2176\">Categories of Data Subjects<\/strong><\/p>\r\n\r\n<ul>\r\n \t<li data-start=\"2182\" data-end=\"2212\">Employees of the Controller;<\/li>\r\n \t<li data-start=\"2215\" data-end=\"2241\">Supervisory authorities;<\/li>\r\n \t<li data-start=\"2244\" data-end=\"2310\">Other persons in a contractual relationship with the Controller;<\/li>\r\n \t<li data-start=\"2313\" data-end=\"2330\">Job applicants.<\/li>\r\n<\/ul>\r\n<p data-start=\"2332\" data-end=\"2379\"><strong data-start=\"2332\" data-end=\"2377\">Categories of Recipients of Personal Data<\/strong><\/p>\r\n\r\n<ul>\r\n \t<li data-start=\"2383\" data-end=\"2409\">Supervisory authorities;<\/li>\r\n \t<li data-start=\"2412\" data-end=\"2430\">Tax authorities;<\/li>\r\n \t<li data-start=\"2433\" data-end=\"2464\">Public administration bodies;<\/li>\r\n \t<li data-start=\"2467\" data-end=\"2479\">Processor;<\/li>\r\n \t<li data-start=\"2482\" data-end=\"2552\">State and other authorities in the fulfillment of legal obligations;<\/li>\r\n \t<li data-start=\"2555\" data-end=\"2574\">Other recipients.<\/li>\r\n<\/ul>\r\n<p data-start=\"2576\" data-end=\"2617\"><strong data-start=\"2576\" data-end=\"2615\">Purpose of Personal Data Processing<\/strong><\/p>\r\n\r\n<ul>\r\n \t<li data-start=\"2621\" data-end=\"2672\">Purposes specified in the data subject\u2019s consent;<\/li>\r\n \t<li data-start=\"2675\" data-end=\"2718\">Negotiation of contractual relationships;<\/li>\r\n \t<li data-start=\"2721\" data-end=\"2749\">Performance of a contract;<\/li>\r\n \t<li data-start=\"2752\" data-end=\"2854\">Protection of rights of the Controller, recipients, or other affected persons (e.g., debt recovery);<\/li>\r\n \t<li data-start=\"2857\" data-end=\"2897\">Archiving based on legal requirements;<\/li>\r\n \t<li data-start=\"2900\" data-end=\"2932\">Recruitment for job vacancies;<\/li>\r\n \t<li data-start=\"2935\" data-end=\"2993\">Compliance with statutory obligations of the Controller;<\/li>\r\n \t<li data-start=\"2996\" data-end=\"3048\">Protection of vital interests of the data subject.<\/li>\r\n \t<li data-start=\"3050\" data-end=\"3108\"><strong data-start=\"3050\" data-end=\"3106\">Method of Processing and Protection of Personal Data<\/strong><\/li>\r\n<\/ul>\r\n<p data-start=\"3110\" data-end=\"3855\">Personal data are processed by the Controller. Processing is carried out at the Controller\u2019s registered office by authorized employees, or, where applicable, by a processor. Processing occurs via IT systems or manually for paper records, ensuring full compliance with security principles for the management and processing of personal data. The Controller has implemented technical and organizational measures to ensure data protection, particularly to prevent unauthorized or accidental access, alteration, destruction, loss, unlawful transfer, or other misuse of personal data. All parties with access to personal data respect the privacy rights of data subjects and are obliged to comply with applicable legal regulations on data protection.<\/p>\r\n<p data-start=\"3857\" data-end=\"4097\">The Controller commits to processing personal data in accordance with applicable laws and to use the data only to the extent necessary to fulfill the purposes for which the data were collected, always ensuring no harm to the data subject.<\/p>\r\n<p data-start=\"4099\" data-end=\"4260\">Where personal data are to be disclosed to third parties and consent is required, the data subject will be asked for consent, e.g., when concluding a contract.<\/p>\r\n<p data-start=\"4262\" data-end=\"4301\"><strong data-start=\"4262\" data-end=\"4299\">Retention Period of Personal Data<\/strong><\/p>\r\n<p data-start=\"4303\" data-end=\"4606\">In accordance with the periods specified in relevant contracts, the Controller\u2019s filing and retention rules, or applicable legal regulations, personal data will be retained only as long as necessary to ensure the rights and obligations arising from contractual relationships or statutory requirements.<\/p>\r\n<p data-start=\"4608\" data-end=\"4642\"><strong data-start=\"4608\" data-end=\"4640\">Information to Data Subjects<\/strong><\/p>\r\n<p data-start=\"4644\" data-end=\"4845\">The Controller processes personal data based on the consent of the data subject (which may be given for one or more specific purposes) except in cases where the law allows processing without consent.<\/p>\r\n<p data-start=\"4847\" data-end=\"4962\">In accordance with Article 6(1) of the General Regulation, the Controller may process data without consent where:<\/p>\r\n\r\n<ul>\r\n \t<li data-start=\"4966\" data-end=\"5123\">Processing is necessary to perform a contract with the data subject, or to take steps prior to entering into a contract at the request of the data subject;<\/li>\r\n \t<li data-start=\"5126\" data-end=\"5204\">Processing is necessary to comply with a legal obligation of the Controller;<\/li>\r\n \t<li data-start=\"5207\" data-end=\"5310\">Processing is necessary to protect the vital interests of the data subject or another natural person;<\/li>\r\n \t<li data-start=\"5313\" data-end=\"5470\">Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;<\/li>\r\n \t<li data-start=\"5473\" data-end=\"5704\">Processing is necessary for the legitimate interests of the Controller or a third party, except where such interests are overridden by the rights and fundamental freedoms of the data subject requiring protection of personal data.<\/li>\r\n<\/ul>\r\n<p data-start=\"5706\" data-end=\"5735\"><strong data-start=\"5706\" data-end=\"5733\">Rights of Data Subjects<\/strong><\/p>\r\n<p data-start=\"5737\" data-end=\"5917\">In accordance with Article 12 of the General Regulation, the Controller informs data subjects, upon request, of their right to access personal data and the following information:<\/p>\r\n\r\n<ul>\r\n \t<li data-start=\"5921\" data-end=\"5945\">Purpose of processing;<\/li>\r\n \t<li data-start=\"5948\" data-end=\"5988\">Categories of personal data concerned;<\/li>\r\n \t<li data-start=\"5991\" data-end=\"6085\">Recipients or categories of recipients to whom personal data have been or will be disclosed;<\/li>\r\n \t<li data-start=\"6088\" data-end=\"6115\">Planned retention period;<\/li>\r\n \t<li data-start=\"6118\" data-end=\"6231\">All available information about the source of the personal data if not obtained directly from the data subject;<\/li>\r\n \t<li data-start=\"6234\" data-end=\"6299\">Whether automated decision-making, including profiling, occurs.<\/li>\r\n<\/ul>\r\n<p data-start=\"6301\" data-end=\"6530\">Any data subject who finds or believes that the Controller or Processor processes their personal data in a way that violates their privacy or the law, particularly if the data are inaccurate for the purposes of processing, may:<\/p>\r\n\r\n<ul>\r\n \t<li data-start=\"6534\" data-end=\"6579\">Request an explanation from the Controller;<\/li>\r\n \t<li data-start=\"6582\" data-end=\"6787\">Request the Controller to rectify the situation, including correction, supplementation, or deletion of personal data. If the request is found justified, the Controller will immediately correct the issue.<\/li>\r\n<\/ul>\r\n<p data-start=\"6789\" data-end=\"7058\">Requests must always be properly assessed. If there is doubt about the identity of the person requesting information, the Controller may request additional information to confirm the data subject\u2019s identity, in accordance with Article 12(6) of the General Regulation.<\/p>\r\n<p data-start=\"7060\" data-end=\"7382\">For requests under Articles 15\u201322 of the General Regulation, information about measures taken must be provided without undue delay, and in any case within one month of receipt. In exceptional cases, the period may be extended by two months, and the data subject must be informed, including the reasons for the extension.<\/p>\r\n<p data-start=\"7384\" data-end=\"7677\">All information and actions under Articles 13, 14, 15\u201322, and 34 of the General Regulation are provided free of charge. Only if requests are manifestly unfounded or excessive, particularly repetitive, may a reasonable fee be charged, or the request may be refused, with proper justification.<\/p>\r\n<p data-start=\"7679\" data-end=\"7941\">If the Controller does not comply with the data subject\u2019s request, the data subject has the right to contact the supervisory authority, i.e., the Office for Personal Data Protection, directly. The data subject may do so without first contacting the Controller.<\/p>\r\n<p data-start=\"7943\" data-end=\"7972\"><strong data-start=\"7943\" data-end=\"7970\">Data Protection Officer<\/strong><\/p>\r\n<p data-start=\"7974\" data-end=\"8196\">Contact for the Data Protection Officer of the Regional Office of the Pilsen Region:<br data-start=\"8057\" data-end=\"8060\" \/>Mgr. Milan \u0160varc, Head of Internal Audit Unit, Data Protection Officer<br data-start=\"8130\" data-end=\"8133\" \/>Tel.: +420 377 195 751<br data-start=\"8155\" data-end=\"8158\" \/>E-mail: <a class=\"decorated-link cursor-pointer\" rel=\"noopener\" data-start=\"8166\" data-end=\"8194\">milan.svarc@plzensky-kraj.cz<\/a><\/p>\r\n \r\n<figure class=\"wp-block-image size-thumbnail\"><img decoding=\"async\" class=\"wp-image-387\" src=\"https:\/\/admin.zpkb.eu\/wp-content\/uploads\/2026\/03\/Aktuality-3-300x300.png\" alt=\"GDPR\" \/><\/figure>\r\n","protected":false},"excerpt":{"rendered":"<p>Statement on the Processing of Personal Data Statement on the processing of personal data pursuant to the Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-374","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/admin.zpkb.eu\/en\/wp-json\/wp\/v2\/pages\/374","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/admin.zpkb.eu\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/admin.zpkb.eu\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/admin.zpkb.eu\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/admin.zpkb.eu\/en\/wp-json\/wp\/v2\/comments?post=374"}],"version-history":[{"count":4,"href":"https:\/\/admin.zpkb.eu\/en\/wp-json\/wp\/v2\/pages\/374\/revisions"}],"predecessor-version":[{"id":392,"href":"https:\/\/admin.zpkb.eu\/en\/wp-json\/wp\/v2\/pages\/374\/revisions\/392"}],"wp:attachment":[{"href":"https:\/\/admin.zpkb.eu\/en\/wp-json\/wp\/v2\/media?parent=374"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}