Data protection of Tampereen Infra Oy
The Data Protection Regulation applies from 25 May 2018. With that, the rules for processing personal data become more detailed and stricter. The requirements of the Data Protection Regulation must be taken into account in all processing of personal data: processes, information systems and purchases.
The goal of the new legislation is to improve the protection of personal data and the rights of data subjects. Appropriate processing of personal data increases openness and transparency and strengthens the rights of data subjects to control the processing of their personal data.
In the operations of Tampereen Infra Oy, various personal data are processed, e.g. in connection with personnel management, financial management and contract management. Because of this, Tampereen Infra Oy is obliged to demonstrate that data protection matters have been sufficiently taken into account in its operations. In other words, we must ensure that personal data is processed in accordance with the law, appropriately and transparently for the data subject. In addition to this, personal data must be processed in a way that ensures adequate security of personal data, including protection against unauthorized and illegal processing and against accidental loss or destruction.
The law requires Tampereen Infra as a data management unit to prepare a data protection statement for each personal register. The description is used to inform customers, for example, about why their data is collected and what the data is used for.
Personal register information
1. Register name
Customer register of Tampereen Infra Oy
2. Purpose of personal data processing
The register stores the information of Tampere Infra’s customers, partners and other stakeholders. Personal data is processed for purposes related to customer relationship management, administration and service development, as well as conducting customer surveys.
The controller processes the data himself and uses partners acting on behalf of the controller in the processing of personal data. In customer surveys, only necessary information is collected in relation to the various surveys.
Those registered in the register are persons who have a valid connection with the controller, either directly as a customer, contractual partner or stakeholder.
3. Registrar Tampereen Infra Oy
Patamäenkatu 18
33900 Tampere
Business ID 3022425-9
4. Person responsible for the register, job title and contact information
Geospatial Manager Eelis Ylitalo
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
041 730 1313
5. Register contact person and contact information
Communication designer Jyrki Ristilä
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
040 801 6422
6. The processing of the register’s personal data has been outsourced through an assignment agreement
Yes
On the company’s behalf, external service providers can also process personal data in connection with customer satisfaction surveys.
7. Lawfulness of personal data processing
Consent, data is collected from the registered person.
Legitimate interest, personal data is processed in customer relationship management and development of our services.
8. Personal data in the register
Tampereen Infra Oy’s customers, contractual partners and other stakeholders: name, email, phone number, address information.
Personal data received by Tampereen Infra Oy and based on orders from the City of Tampere for the purpose of service performance and customer surveys: name, email, phone number, address information.
The information collected through individual surveys is Tampereen Infra Oy’s internal information, and as a rule, it is not disclosed to third parties.
9. Data sources of the register
Customers, contractual partners and other cooperation parties
Registered yourself, the survey link can also be publicly displayed, e.g. On Tampere Infra’s website and social media channels
10. Register data maintenance systems
Intranet (Infra Oy) intranet protected/access rights limited information system
11. Transfer of personal data in the register? No, except for the purposes of paragraph 2.
12. Transfer of the register outside Tampere Infra Oy? No
13. Transfer of register data to a third country or international organization (outside the EU or the European Economic Area (EEA))? No
14. Is there manual (paper) material in the register? No
15. Principles of data protection
Data storage, archiving, disposal and other processing are governed by archiving instructions and information security and data protection instructions. Only those employees are entitled to use the data of the survey service. who have the right to process customer data for their work. Every user accepts the commitment regarding the use and confidentiality of the Information and information systems upon obtaining the access rights. The information in the customer register is protected by access rights.
The information gathered with Microsoft Forms or similar surveys is collected in databases that are protected by firewalls, passwords and other technical and contractual legal means.
16. Retention periods of personal data/Retention period determination criteria
The registrar does not keep personal data longer than the maximum time allowed by legislation and only as long as is necessary to provide the registrar’s services.
Description of processing operations
Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation) Article 30
1. Register name
Notification channel register of Tampereen Infra Oy
2. Purpose of personal data processing
Tampereen Infra Oy’s (hereinafter “Tampereen Infra”) notification channel register (Tampereen Infra’s First whistle notification channel). Personal data is processed as described in more detail below in order to monitor and ensure compliance with Tampereen Infra’s ethical guidelines and other internal regulations and the legislation and agreements binding on Tampereen Infra, as well as to prevent, investigate and investigate possible crimes, violations or other abuses in Tampereen Infra’s operations, for example bribery, competition law, procurement , in relation to accounting and auditing matters, equality matters and other reprehensible activities that may take place in Tampere Infra. Personal data is also processed for the preparation, presentation and defense of legal claims regarding Tampere Infra, as well as for statistics and internal reporting of cases. The purpose is to ensure that the decision-making and internal control system works properly. The purpose of using personal data and the reason for keeping it is to implement the measures described above.
The basis for the processing of personal data is Article 6, Paragraph 1, subparagraph e of the General Data Protection Regulation, i.e. the processing is necessary to perform a task in the public interest as follows:
With regard to the personal data presented in the notifications, it is the processing of personal data in accordance with Section 4, subsection 1, point 2 of the Data Protection Act (1050/2018), as the processing is necessary and proportionate in the operation of the authority in order to perform a task in the public interest.
3. Registrar
Tampereen Infra Oy
Patamäenkatu 18
33900 Tampere
Business ID 3022425-9
4. Person responsible for the register, job title and contact information
Administration and personnel director Sanna-Leena Puntola
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
tel. 040 194 8031
sanna-leena.puntola@tampereeninfra.fi)
5. Register contact person, Infra’s data protection officer
Employee relations manager Tytti Marttila
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
tel. 040 801 6306
tytti.marttila@tampereeninfra.fi
6. The processing of the register’s personal data has been outsourced through an assignment agreement
No
7. Lawfulness of personal data processing
Legitimate interest
8. Data content of the register
The following information can be processed in the register:
Identification information of the parties (such as the object of the notification and the person making the notification):
Name
Personal identification number
Other shared information such as address, phone number
Information related to the employment relationship of the subject of the notice, such as work duties and the name of the supervisor and unit
Suspected crime, violation or misconduct and its content
The manner in which the abuse was committed and revealed, as well as the evidence related to the case
The request of the person making the notification for the anonymous processing of the notification
The register can process the information listed above about the subject of the report as well as those Tampereen Infra employees or persons belonging to its stakeholders who are found to be connected to the suspected abuse based on the report. The data will only be processed by the persons specified by the controller in the settlement process.
9. Data sources of the register
Personal information is obtained through notifications made to the system. After this, other information, such as related documents, can be collected to investigate suspected abuse. Personal data can be collected and updated within the framework of the data protection regulation also from Tampereen Infra’s other personal registers and from authorities and companies providing services regarding personal data or from Tampereen Infra’s partners.
10. Register data maintenance systems
Intranet (Tampereen Infra Oy) intranet protected/access rights restricted information system
11. Transfer of personal data in the register
Information will not be disclosed to parties outside of Tampereen Infra, except for the exceptional situations mentioned below:
Based on the discretion of the data controller, data can be disclosed within the limits allowed and required by the legislation in force at any given time.
Information can be disclosed in a manner required by the requirements of competent authorities or other parties, based on valid legislation. If a related crime appears, the related information, including personal data, can be handed over to the police. It should be remembered that the informant may also be held criminally liable for intentionally reporting false information.
Information can also be handed over to buyers in connection with business arrangements, if Tampereen Infra sells or otherwise organizes its business.
12. Transfer of the register outside Tampereen Infra Oy? No
13. Transfer of register data to a third country or international organization (outside the EU or the European Economic Area (EEA))? No
14. Is there manual (paper) material in the register? No
15. Principles of registry protection
Tampereen Infra’s notification channel is implemented in Juuriharja Consulting Group Oy’s First Whistle system.
The information contained in the register processed electronically is protected by firewalls, passwords and other generally accepted technical means in the field of information security. On websites and other services, data is protected with an SSL-secured connection and other necessary methods.
Technically, every notification made through Tampereen Infra’s notification channel contains:
identifier, a number that only the person making the notification knows
information about the status of the notification in question: received/in process/processed
additional information request and response option without further details
Only identified employees of the registrar have access to the information contained in the register with access rights granted by the registrar. The person making the announcement can only see his own announcement in the service.
16. Personal data retention period
Personal data is stored in the database of the information system for 90 days from the end of system processing of the notification, after which the data is automatically destroyed. The parts of the notification information that are necessary for operation, further processing and reporting are kept.
If it is necessary to store data in order to fulfill statutory obligations, the storage period is 5 years or another period expressly stipulated by law.
If it is necessary to store data due to the further processing of suspicions of abuse, the storage period is defined separately on a case-by-case basis.
Personal data register information
1. Name of the register
Tampereen Infra Oy’s Into privacy statement
2. Purpose of processing personal data
The controller (Tampereen Infra Oy) handles human resources and employment matters, in addition, the controller collects, stores, organizes, structures, stores, edits, retrieves and discloses personal data for the purpose of annual tax returns and invoicing.
The persons registered in the register are persons who have a material connection with the controller, either directly as employees, as commissioned workers, as students, trainees, customers or contractual partners. The registered personal data may also be based on the controller’s customer’s assignment or for the implementation of a service provision based on the law.
The register is used to support internal personnel mobility, locate equipment, record personnel work performance, monitor costs, as a tool for employees and as a tool for personnel management.
The data controller uses the data in the register when performing the tasks relating to the data subjects that are incumbent on it by law (GDPR, Article 6, paragraph 1 c), separate decisions, regulations or the need to perform a contract (GDPR, Article 6, paragraph 1 b).
3. Controller Tampereen Infra Oy
Patamäenkatu 18
33900 Tampere
Business ID 3022425-9
4. Person responsible for the register, job title and contact information
Administration and Human Resources Director Sanna-Leena Puntola
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
tel. 040 194 8031
5. Contact person and contact information for the register
Administration and Human Resources Director Sanna-Leena Puntola
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
tel. 040 194 8031
6. The processing of personal data in the register has been outsourced under an assignment agreement
Yes
On behalf of the company, external service providers process personal data, for example in connection with opening data in the invoicing system. In addition, there are assignments related to the maintenance tasks and application expert support of the register’s electronic information systems and their servers.
7. Lawfulness of the processing of personal data
A)
Agreement
Legal obligation. The processing of personal data is partly based on the controller’s statutory obligations, such as the conditions set by employment contract legislation and occupational safety legislation. The controller’s legitimate interest is based on the controller’s right to process employees’ personal data also otherwise than to the extent necessary for the implementation of the employee’s employment contract, taking into account that the controller may only process personal data that is directly necessary for the employee’s employment relationship, which is related to the management of the rights and obligations of the parties to the employment relationship or the benefits offered by the employer to the employees or which result from the specific nature of the work tasks. For customers, the processing of personal data is based on the collection of receivables by law.
The rights and freedoms of the data subjects do not override the controller’s legitimate interest.
Statutory obligation
Legislation governing the operation:
Archives Act (831/1994)
Value Added Tax Act (1501/1993)
EU General Data Protection Regulation (2016/679)
Accounting Act (1336/1997)
Act on Tax Procedure (1558/1995)
Act on the Collection of Debts (513/1999)
Data Protection Act (5.12.2018/1050)
Act on the Protection of Privacy in Working Life (759/2004)
B)
The register is a register of official activities
No
The register is a register of voluntary public administration tasks
No
C)
The data in the register is used for automated individual decisions, including profiling
No
8. Personal data in the register
Tampereen Infra Oy’s employees, customers and contractual partners, in the broadest sense: name, date of birth, tax number, email, telephone number, address information, business ID, vehicle identification number
Personal data received by Tampereen Infra Oy and based on assignments from the City of Tampere for the implementation and invoicing of service provision: Name and address information, Business ID or hetu
9. Data sources in the register
Employees
Customers
Contracting partners
Authority registers
10. Register data maintenance systems
• Dynamics 365 Business Central system
• Kiho
• Intranet (Infra Oy) internal network protected/access-restricted network disk.
11. The register contains manual (paper) material
Yes, Administer Oy’s and Tampereen Infra OY’s paper archive
12. Data protection principles
The storage, archiving, destruction and other processing of data are guided by archiving instructions and information security and data protection instructions. The data stored electronically in the register is protected so that only authorized persons can view it. Each user accepts
the commitment regarding the use and confidentiality of data and information systems when receiving access rights. The data in the customer register is protected by access rights.
Manual archives and operational units have access control and/or locked doors. Documents are stored in controlled premises and/or in lockable cabinets.
13. Disclosure of personal data in the register
Yes, Administer Pirkanmaa Oy, Kiho Oyj and debt collection agency Intrum Oy.
14. Transfer of register data to a third country or international organization (outside the EU or the European Economic Area (EEA))
No
15. Retention periods of personal data/Criteria for determining the retention period
The controller does not retain personal data for longer than the maximum period permitted by law and only for as long as is necessary to provide the controller with services and to fulfil its obligations under the law.
According to the Accounting Act (1336/1997), time reports, shift lists and information used for salary payment are retained for 10 years. Upon termination of employment, time reports, shift lists and information used for salary payment are retained for two years. The retention period for driving logs and travel invoices is 6 years from the end of the year in which the accounting period ended.
Personal register information
1. Register name
The personnel register of Tampereen Infra Oy’s personnel administration
2. Purpose of personal data processing
Managing the personnel administration and labor relations matters of the registrar (Tampereen Infra Oy).
Those registered in the register are persons who have a factual connection with the controller either as an employee, former employee, as a person doing work on assignment or as a person who has done work on assignment, as a job seeker, student, intern, or as persons who belong to or have belonged to the company’s institutions.
The company uses the information in the register when performing the tasks concerning the registered persons that belong to it based on laws, collective agreements and separate decisions and regulations.
The register is also used for the procurement of labor, to support the internal mobility of the personnel, to maintain the personnel’s competence information, as a working tool for the employees and as a tool for personnel management.
3. Registrar
Tampereen Infra Oy
Patamäenkatu 18
33900 Tampere
Business ID 3022425-9
4. Person responsible for the register, job title and contact information
Administration and personnel director Sanna-Leena Puntola
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
tel. 040 194 8031
5. Register contact person and contact information
Employment relations manager Tytti Marttila
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
tel. 040 801 6306
6. The processing of the register’s personal data has been outsourced through an assignment agreement
Yes
Service providers outside the company’s mandate process personal data, for example, in connection with recruitment-related interviews and evaluations. In addition, assignments are related to the maintenance tasks of the registry’s electronic information systems and their servers and application expert support.
7. Lawfulness of personal data processing
A)
Legal obligation. The processing of personal data is partly based on the legal obligations of the controller, such as the requirements set by employment contract legislation and occupational safety legislation.
Execution of the contract. The processing of personal data is necessary for the implementation and preparation of the employment contract.
The legitimate interest of the data controller is based on the data controller’s right to process employees’ personal data also other than those necessary for the implementation of the employee’s employment contract, taking into account that the data controller may only process personal data that is immediately necessary for the employee’s employment relationship, which is related to the management of the rights and obligations of the parties to the employment relationship or the benefits offered to employees by the employer or due to the special nature of the work tasks .
The rights and freedoms of the registered do not supersede the legitimate interest of the controller.
B)
The register is a register of official activities
No
The register is a register of voluntary tasks in the public administration
No
C)
The information in the register is used for automated individual decisions, including profiling
No
Personal data in the personal register, data sources and data transfer
8. Personal data in the register, description of groups of registered users
Contact information of employees and other registered persons: name, social security number, address information, e-mail, telephone number, bank contact information and tax card
· Information related to the task
· Information related to the side action
· Salary-related information
· Other information related to the employee, such as Competence Management
· Degrees, details of the development discussion
· Necessary information related to the job applicant
Basic information related to the employment relationship, such as
· Start and end date of the employment relationship
· Employee photo
· The employment contract and the terms it contains, such as monetary salary and other methods of remuneration and benefits
· Job content and title
· Information related to employee benefits
· Information related to taxes and employer contributions
· Information related to the employee’s insurance
· Separate commitments and consents collected from the employee, such as, for example, the right to view e-mails or a separate non-disclosure agreement
· Trade union membership/membership is recorded from special personal data groups, if the ay membership fee is collected from the salary
· Information and work certificates related to the end of the employment relationship
Information related to managing tasks, developing at work and monitoring working hours, such as:
· Work time accounting
· Qualification information and information related to training
· Information related to goals and development discussions
· Information on fiduciary duties and memberships paid by the employer
· Sick leave, annual leave, parental leave and care leave as well as any other agreed absences (e.g. study and rotation leaves)
· Medical certificates or statements or other information about the employee’s state of health or ability to work, to the extent that the legislation allows the processing of such information
Information related to work tools, such as
· Access rights granted to the employee, as well as user IDs and passwords for the employer’s electronic systems and registers
· Identification information of the work tools assigned to the employee, such as computers and mobile devices as well as access cards, keys or other similar
9. Data sources of the register
· You registered yourself
· Supervisor of the registrant
· Job search-related interviews
· Personnel administrative decisions
· Reel
· Occupational health care and other providers of health and medical care services
· Spring
· Insurance companies
· Tax collector
· TE center
10. Maintenance of register data
Personnel and payroll administration systems, such as salary, vacation and financial monitoring, travel and expense invoices, access control, working time monitoring, safety and occupational health and safety observations, development discussions and personnel benefits
City website, Tampereen Infra website/intranet, Infra app
Intranet (Tampereen Infra Oy) intranet protected/access rights limited information system.
The information is combined with the information in the user registers of the electronic information systems used by the controller.
The information is also combined with the occupational health care information purchased by the company.
11. Transfer of personal data in the register
Yes, personal data is disclosed within the limits permitted and required by the legislation in force at any given time. Information is regularly disclosed to the tax authorities, Kela, pension institutions, occupational health service providers and trade unions.
Data is transferred to service providers and similar operators who process personal data on behalf of the controller.
In recruitment situations, personal data is disclosed to companies in connection with assignments-related interviews and evaluations.
12. Transfer of the register outside Tampereen Infra Oy?
No
13. Transfer of register data to a third country or international organization (outside the EU or the European Economic Area (EEA))
No
14. The register contains manual (paper) material
Yes, Tampereen Infra Oy’s paper archive
15. Principles of data protection
Data storage, archiving, disposal and other processing are governed by archiving instructions and information security and data protection instructions. The information stored electronically in the register is protected so that only authorized persons can view it. Every user accepts the commitment regarding the use and confidentiality of the Information and information systems upon obtaining the access rights. Manual archives and operating units have access control and/or door locks. The documents are kept in controlled rooms and/or in lockable cabinets.
16. Retention periods of personal data/Retention period determination criteria
The retention period is defined in Tampereen Infra Oy’s archive creation plan.
1. Register name
Location personal register of Tampereen Infra Oy
2. Purpose of processing personal and location data:
The controller (Tampereen Infra Oy) collects, stores, organizes, stores, edits, searches and analyzes the location data of phones, vehicles and machines in its own systems, in order to take care of the following obligations as an employer:
• occupational safety
• improving customer service
More efficient use of vehicle resources
• more detailed monitoring of maintenance programs, usage notifications and reporting
Route optimization and fast vehicle transfers
• producing more accurate emissions calculations
• economical driving style and being rewarded for it
Those registered in the register are persons who have a factual connection with the controller either as an employee, former employee, as a person doing work on assignment or as a person who has done work on assignment, as a job seeker, student, intern, or as persons who belong to or have belonged to the company’s institutions.
The company uses the information in the register when performing the tasks concerning the registered persons that belong to it based on laws, collective agreements and separate decisions and regulations. The register is also used to support the internal mobility of personnel, as a work tool for employees and as a tool for personnel management.
3. Registrar
Tampereen Infra Oy
Patamäenkatu 18
33900 Tampere
Business ID 3022425-9
4. The person responsible for the register:
Administration and personnel director Sanna-Leena Puntola
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
tel. 040 194 8031
5. Contact information of the controller:
Employment relations manager Tytti Marttila
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
tel. 040 801 6306
6. Record keeping outsourced to a third party: No
7. Lawfulness of personal data processing:
• Agreement
• Legitimate interest of the controller
8. Personal data contained in the register:
Contract contact information (name, position, e-mail, phone number)
9. Data source of the register
Location agreement, registered based on contract information
10. Maintenance systems:
• Microsoft Office
• Intranet (Tampereen Infra Oy) intranet protected/access rights limited information system.
• Mobile and other Infra vehicle tracking applications
11. Does the material contain paper material? No
12. Principles of data protection:
Data storage, archiving, disposal and other processing are governed by archiving instructions and information security and data protection instructions. The information stored electronically in the register is protected so that only authorized persons can view it. Every user accepts the commitment regarding the use and confidentiality of the Information and information systems upon obtaining the access rights. Location data is protected by access rights.
13. Disclosure of personal data in the register: No
14. Transfer of the register outside of Tampere Infra Oy? No
15. Personal data retention periods:
The registrar does not keep personal data longer than the maximum time allowed by legislation and only as long as is necessary to provide the registrar’s services.
Personal register information
1. Register name
Tampereen Infra Oy’s contract register
2. Purpose of personal data processing
• Contract management and control
• Maintenance of supplier relations
• Implementation of competitions
• Placing orders
• Renewal and termination of contracts
Infra Oy’s contracts and documents related to tenders are stored in the contract register. With the help of the register, contract documents are available and usable in the company’s daily internal operations. Those registered in the register are persons who have an actual connection with the controller as representatives of contractual partners or as representatives of employers participating in tenders.
The contracts are available to the company’s employees who need information in their work.
3. Registrar
Tampereen Infra Oy
Patamäenkatu 18
33900 Tampere
Business ID 3022425-9
4. Person responsible for the register, job title and contact information
Procurement and facilities manager Topi Karhu
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
tel. 04o 487 7662
5. Register contact person and contact information
Procurement and facilities manager Topi Karhu
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
tel. 04o 487 7662
6. The processing of the register’s personal data has been outsourced through an assignment agreement
No
7. Lawfulness of personal data processing
A)
• Execution of the contract
• Legitimate interest of the controller
B)
The register is a register of official activities
No
The register is a register of voluntary tasks in the public administration
No
C)
The information in the register is used for automated individual decisions, including profiling
No
8. Personal data in the register
Contract contact information (name, email, phone number, job title)
Information about the contractual partner’s employees (date of birth, education, work experience, qualifications)
Personal data provided for the purpose of contract management, the execution of tenders or the organization of market dialogue, e.g. information about the company’s contact and responsible persons
• In offers, responsibility, contact or other person’s contact information, training, experience or other similar information
• Record of checking the criminal record extract
9. Data sources of the register
Contract partner
Tender documents and procurement contracts
10. Register data maintenance systems
Microsoft Office
Intranet (Infra Oy) intranet protected/access rights limited information system
11. The register contains manual (paper) material
Yes, Tampereen Infra Oy’s paper archive
12. Principles of data protection
Data storage, archiving, disposal and other processing are governed by archiving instructions and information security and data protection instructions. The information stored electronically in the register is protected so that only authorized persons can view it. Every user accepts the commitment regarding the use and confidentiality of the Information and information systems upon obtaining the access rights.
The information in the contract register is protected by access rights. The manual material is in a locked archive.
13. Transfer of personal data in the register
Regular transfer of information
No
14. Transfer of register data to a third country or international organization (outside the EU or the European Economic Area (EEA))
No
15. Retention periods of personal data/Retention period determination criteria
The storage period for contracts is specified in Tampereen Infra Oy’s archive creation plan. Purchase agreements 10 years from the end of the agreement (own needs)
Privacy Policy for the Land and Snow Reception System
1. Name of the register
Tampereen Infra Oy’s Land and Snow Reception System Privacy Policy
2. Purpose of processing personal and vehicle data:
• The vehicle registration number is used to identify the customer registered in the service for billing and reporting.
• The information registered by the customer is used for billing.
• The information in the register is used to monitor, investigate and identify the movement of vehicles moving at snow and land disposal sites.
• The information in the register is used to monitor, investigate and identify problem situations occurring at snow and land disposal sites.
3. Controller:
Tampereen Infra Oy, Business ID 3022425-9
4. Person responsible for the register:
Work Manager Juho Toivonen
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
040 153 5773
firstname.lastname@tampereeninfra.fi
5. Controller’s contact information:
Work Manager Juho Toivonen
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
040 153 5773
firstname.lastname@tampereeninfra.fi
6. Register management outsourced to a third party: yes
Contract partner Loihde Trust Oy, Business ID 0863729-2
7. Lawfulness of the processing of personal data:
• Agreement
• Legitimate interest of the controller
8. Personal data contained in the register:
Contact details of the contract contact persons (name, email, phone number)
Regarding the company:
• Email address
• Company Business ID
• Phone number
• Street address
• Postal code
• City
• Country
Invoicing information:
• Reference
• Online invoicing operator
• OVT ID
• Email address
• Phone number
• Street address
• Postal code
• City
• Country
9. Maintenance systems:
• Soil and snow reception system (Loihde Trust Oy)
• Financial management system for invoicing, internal network protected/access-restricted information system (Tampereen Infra Oy, City of Tampere)
• Video recorders and computer equipment (Loihde Trust Oy)
10. Does the material include paper material?
No
11. Data source of the register
Image material transmitted by video and digital cameras belonging to the recording surveillance system, registered on the basis of contract information. Identification data is obtained from the image material transmitted by the cameras belonging to the system. Video and digital cameras record the entrance to the area and the load, and the vehicle registration number is identified from the image.
12. Data protection principles:
The storage, archiving, destruction and other processing of data is guided by archiving instructions and information security and data protection instructions. The data stored electronically in the register is protected so that only authorized persons can view it. Each user accepts the commitment regarding the use and confidentiality of data and information systems when receiving access rights.
13. Disclosure of personal data in the register:
Regular disclosure of data: No
Basis for disclosure of data
In cases of suspected crime, data may be disclosed to the police if they have grounds to obtain the information.
Data may be transferred and processed between the City of Tampere’s own organizations to promote and implement business and tasks performed jointly by the city’s organizations.
14. Transfer of the register outside Tampereen Infra Oy?
Yes, the system of the system provider Loihde Trust Oy also transfers data on loads to the Ministry of the Environment’s Siirto register through integration.
Data is not transferred outside the EU/EEA area.
15. Retention periods of personal data:
The controller will not retain personal data for longer than the maximum period permitted by law and only for as long as is necessary to provide the controller’s services.
Personal register information
1. Register name
Tampereen Infra Oy’s financial administration personnel register
2. Purpose of personal data processing
The controller (Tampereen Infra Oy) collects, stores, organizes, organizes, stores, edits, searches and discloses personal data in order to handle sales invoicing and purchase invoices.
Those registered in the register are persons who have a valid connection with the controller, either directly as a customer or as a contractual partner. Registered personal data can also be based on the registrar’s client’s order or for the performance of services based on law.
The data in the register is used by the data controller when performing the tasks concerning the registered data that belong to it on the basis of laws (Art 6 section 1 c), separate decisions, regulations or the need related to the implementation of the contract (Art 6 section 1 b).
3. Registrar Tampereen Infra Oy
Patamäenkatu 18
33900 Tampere
Business ID 3022425-9
4. Person responsible for the register, job title and contact information
Financial Manager Katariina Torkkola
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
tel. 040 800 4286
5. Register contact person and contact information
Finance Secretary Kirsi Mäkelä
Tampereen Infra Oy
Patamäenkatu 18, 33900 Tampere
tel. 040 801 6360
6. The processing of the register’s personal data has been outsourced through an assignment agreement
Yes
Service providers outside of the company’s mandate process personal data, for example, when opening data in the SAP system. In addition, assignments are related to the maintenance tasks of the registry’s electronic information systems and their servers and application expert support.
7. Lawfulness of personal data processing
A)
Agreement
Legal obligation
Legislation governing the operation:
Archives Act (831/1994)
Value Added Tax Act (1501/1993)
EU General Data Protection Regulation (2016/679)
Accounting Act (1336/1997)
Act on taxation procedure (1558/1995)
Law on debt collection (513/1999)
Data Protection Act (5 December 2018/1050)
B)
The register is a register of official activities
No
The register is a register of voluntary tasks in the public administration
No
C)
The information in the register is used for automated individual decisions, including profiling
No
8. Personal data in the register
Tampereen Infra Oy’s customers and contractual partners: name, e-mail, phone number, address information, social security number or social security number
Personal data received by Tampereen Infra Oy and based on orders from the City of Tampere for the implementation and invoicing of services: Name and address information, social security number or hetu
9. Data sources of the register
Customers
Contract partners
10. Register data maintenance systems
• SAP system
• Intranet (Infra Oy) intranet protected/privileged network disk.
11. The register contains manual (paper) material
Yes, the paper archive of Monetra Oy and Tampereen Infra OY
12. Principles of data protection
Data storage, archiving, disposal and other processing are governed by archiving instructions and information security and data protection instructions. The information stored electronically in the register is protected so that only authorized persons can view it. Every user accepts the commitment regarding the use and confidentiality of the Information and information systems upon obtaining the access rights. The information in the customer register is protected by access rights.
Manual archives and operating units have access control and/or door locks. The documents are stored in controlled rooms and/or in lockable cabinets.
13. Transfer of personal data in the register
Yes, Monetra Pirkanmaa Oy
14. Transfer of register data to a third country or international organization (outside the EU or the European Economic Area (EEA))
No
15. Retention periods of personal data/Retention period determination criteria
The data controller does not store personal data for longer than the maximum time allowed by legislation and only as long as it is necessary to provide the data controller’s services and fulfill its obligations arising from legislation.
According to Section 2:10.1 of the Accounting Act (1336/1997), the financial statements, activity report, accounts, list of accounts and list of records and materials must be kept for at least 10 years after the end of the accounting period, so that the requirements of Sections 6, 7 and 9 of Chapter Two of the Act are met. In addition, according to Section 2:10.2 of the Accounting Act, vouchers for the accounting period, correspondence regarding business transactions and accounting material other than those mentioned in subsection 1 must be kept for at least six years from the end of the year during which the accounting period has ended so that the requirements of Sections 6, 7 and 9 are met.
The data subject´s rights and their implementation in Tampereen Infra Oy’s personal registers
The EU General Data Protection Regulation (EU) 2016/679 provides those whose data is being processed (=data subjects) with diverse rights. The rights are applied in different ways, depending on the grounds for processing the personal data. For example, a person has the right to know whether their personal data is processed and which personal data is processed, and to request access to their own data. Data subjects also
have the right to demand that incorrect personal data be corrected.
Right to review data (right of access to data, Article 15)
A person has the right to know whether their personal data is processed or not, and which personal data concerning the person has been recorded. Tampereen Infra Oy will provide the data at the data subject’s request as soon as possible, without undue delay. The period for providing the data or submitting additional information relating to the request for information is one month from receiving the request. If the request for information is exceptionally complex and extensive, the period can be extended by two further months.
The data subject’s data will usually be provided free of charge. If several copies are requested, however, Tampereen Infra Oy may charge a reasonable fee based on administrative expenses. If the request for data is manifestly unfounded or excessive, in particular if the requests are excessively repeated, Tampereen Infra Oy may charge the administrative costs incurred due to providing the data or refuse to provide the data. In such a case, Tampereen Infra Oy shall note the manifestly unfounded or excessive character of the request.
If Tampereen Infra Oy will not provide the information, a written certificate of the matter will be issued. At the same time, we will inform the data subject of the right to legal remedies, such as the possibility of lodging a complaint with the supervisory authority.
Right to rectify information (Article 16)
A person has the right to demand that incorrect, inaccurate or incomplete personal data concerning them be corrected or supplemented without undue delay. In addition, a person has the right to demand the erasure of unnecessary personal data. The unnecessariness and incorrectness are assessed based on the time of recording the data.
If Tampereen Infra Oy does not accept the demand for correction, a written certificate of the matter will be provided, mentioning the grounds on which the demand has not been approved. We will similarly inform the data subject of the right to legal remedies, such as the possibility of lodging a complaint with the supervisory authority.
Right to be forgotten (Article 17)
Only in certain special circumstances does a person have the right to have their personal data completely erased from Tampereen Infra’s filing system (right to be forgotten). Furthermore, such a right does not exist in cases when the processing of personal data is necessary for complying with a statutory obligation or for exercising public authority granted to Tampereen Infra. Tampereen Infra’s archiving plans and data retention periods prescribed by legislation are followed with regard to the storage and erasure of data.
Right to restrict processing (Article 18)
In certain situations, a person may have the right to request that the processing of their personal data be restricted until their data has been appropriately reviewed and corrected or supplemented.
Right to data portability (Article 20)
The right does not apply to processing of personal data that is necessary for the performance of a task carried out for reasons of public interest or for exercising public powers granted to the data controller. Therefore, as a rule, the right is not applied in conjunction with the personal data filing system of Tampereen Infra Oy.
Right to object (Article 21)
A person has the right to object at any time, on grounds relating to his or her particular situation, to processing of personal data concerning him or her, even when the processing is based on the performance of a task carried out for reasons of public interest or the exercise of Tampereen Infra’s public powers. In such a case, the data may be processed further only if there are compelling legitimate grounds for the processing which can be
demonstrated.
Right to lodge a complaint with a supervisory authority (Article 77)
A person has the right to lodge a complaint with a supervisory authority of his or her habitual residence or place of work if they consider that the processing of personal data infringes the EU’s General Data Protection Regulation (EU) 2016/679. Moreover, a person has the right to seek other administrative remedies and judicial remedies.
A person also has the right to bring proceedings against the data controller or organisation processing personal data if they believe that their rights have been violated by not complying with the General Data Protection Regulation.
How are the rights exercised?
For additional information about the processing of personal data in the services of Tampereen Infra please contact Tampereen Infra Oy’s data protection officer or the registry’s contact person.
Data Protection Officer:
Tomi Toivonen
IT Manager
040 655 9986
firstname.surname@tampereeninfra.fi
rotvallin molemmin puolin.