1. General provisions

  1. This Procedure (hereinafter - the Procedure) is designed to ensure the protection of personal data of employees of FSSA LLP (hereinafter - the Company) in accordance with the legislation of the Republic of Kazakhstan, internal documents of the Company and determines the order of storage and transfer of personal data of employees of the Company.
    • The following concepts and terms are used in the Rules:
    • Protection of personal data is a regulated technological process, which prevents violation of availability, integrity, reliability and confidentiality of personal data and ensures reliable security of information in the company's activities;
    • Processing of personal data of the employee - receipt, storage, transfer of personal data of the employee;
    • Thecompany/employerisFSSALLP;
    • Personaldataoftheemployee-informationabouttheemployee,whichisnecessaryatthe initiation, continuation and termination of the employment relationship;
    • Thirdparties/parties -peoplewho arenotdirectlyrelatedtothecompany's activities, visitors, employees of third-party organizations;
    • Employee/s-apersoninanemploymentrelationshipwithacompanywhoperforms work on the terms of an employment contract.
  2. Personal data of an employee cannot be used for the purpose of causing him/her property and moral damage, difficulty in exercising rights and freedoms, unless otherwise provided by the legislation of the Republic of Kazakhstan.
    1. The list of documents and/or information containing the employee's personal data includes:
    2. employment record book or other documents confirming employment activity (employment contract; extracts from the employer's acts confirming the onset and termination of employment based on the conclusion and termination of the employment contract; employment record signed by the employer, certified by the company seal or notarized; an archive reference containing information about the employee's employment activity);
    3. ID card or passport;
    4. residence permit (for foreigners permanently residing in the territory of the Republic of Kazakhstan);
    5. diploma and/or other document of education, qualification, special knowledge or professional training;
    6. a document of military registration;
    7. information about wages and salaries;
    8. personal personnel record sheet;
    9. a certificate of absence of medical contraindications for persons being processed for admission to state secrets, in accordance with the legislation of the Republic of Kazakhstan;
    10. copies of certificates of individual identification number (IIN);
    11. a contract on full individual financial responsibility;
    12. a certificate of the nature and conditions of work at the main place of employment (place of work, position, working conditions) (for part-time employees);
    13. other information containing personal data.
    1. Composition of personal data of the employee:
    2. curriculum vitae and curriculum vitae;
    3. passport information;
    4. education;
    5. specialty;
    6. information about your employment history;
    7. information about the composition of the family;
    8. information about the military registry;
    9. information about wages and salaries;
    10. position held;
    11. criminal record;
    12. address of residence;
    13. homephone;
    14. the place of work or study of family members and/or relatives;
    15. the content of the employment contract;
    16. originals and copies of personnel orders;
    17. Personnel files/records and employment records or other documents/statements confirming the employment activities of employees;
    18. characteristics, lens references, reviews;
    19. grounds for personnel orders;
    20. content of the certificate of absence of medical contraindications for persons being processed for admission to state secrets, in accordance with the legislation of the Republic of Kazakhstan;
    21. certificate of acceptance of individual income tax return, issued by the tax authority (for persons performing managerial functions, in accordance with the legislation of the Republic of Kazakhstan);
    22. files containing materials on professional development and training of employees, official investigations and other information containing personal data;
    23. the content of the agreement on full individual financial responsibility;
    24. content of the certificate on the nature and conditions of work at the main place of employment (place of work, position, working conditions) (for part-time employees);
    25. Test and/or interview results.
  3. Storage of personal data of the employee, both on paper and electronic (automated) media, is provided in accordance with the laws of the Republic of Kazakhstan and this Procedure at the Company's own expense.
  4. Employees who are responsible for maintaining and storing personal data of the Company's employees shall be obliged to provide everyone with an opportunity to familiarize themselves with their documents and information containing personal data, as well as other documents generated in the activities of the Company, unless otherwise provided by the legislation of the Republic of Kazakhstan.
  5. When processing the personal data of employees, the Company complies with the requirements stipulated by the legislation of the Republic of Kazakhstan.

2. Access to personal data of the employee

  1. Access inside the Company to work with documents containing employees' personal data shall be granted to persons within their authority: Head of the Company; Head of HR structural subdivision; heads of structural subdivisions by area of activity (access to personal data of their subdivision employees only); when transferring from one structural subdivision to another, access to personal data of the employee may have the head of the new subdivision; the employee himself - the data carrier. Other employees of the Company have access to the personal data of the employee only with the written consent of the employee - data carrier.
  2. The following employees may have access to the processing of an employee's personal data within their competence: employees of the human resources management department; the financial department (accounting department); and the state secrets protection service.
  3. Within the limits of their powers established by the legislation of the Republic of Kazakhstan and/or upon written request, access outside the Company may be granted to authorized persons of state bodies of the Republic of Kazakhstan: Administration of the President of the Republic of Kazakhstan, Office of the Prime Minister of the Republic of Kazakhstan, financial control, tax, oversight and law enforcement authorities, military registration and enlistment offices, migration service, employment authorities;

3. Storageand transfer of personal data

  1. The room where the personal data of the Company's employees is stored must be separate (if there are rooms), and equipped with lockable cabinets/safe, ensuring the complete safety of documents, secure locks and, if necessary, an alarm for the opening of the room.
  2. All electronic folders containing employees' personal data must be password protected.
  3. ДDocuments and/or information containing personal data of employees are formed into personal files, which are stored in a locked cabinet/safe.
  4. Personal files of the Company's employees are included in the file list of the structural subdivision for human resources management.
  5. The room should be closed and the computer should be turned off or locked during working hours when there are no employees of the human resource management unit (HR department) in the room.
  6. The cleaning of the room in which the personal data of employees is stored must be carried out in the presence of employees of the structural subdivision for human resources management (HR Department).
  7. The company ensures the safety and submission to the state archive of documents confirming the employment of employees and information about withholding and deductions for their pensions.
  8. Employees of the structural subdivision for human resource management (HR Department) must: comply with the requirements to ensure the safety of documents, their protection from the harmful effects of the environment (dust, exposure to solar heat), mechanical and other damages; comply with procedures for working with documents and databases containing personal data onemployees; ensure storage of information obtained during testing and/or interviews; not to leave documents at workplace in the open and unattended; access to personal
  9. The Company must comply with the following requirements when transferring an employee's personal data:
    1. Not to disclose the employee's personal data to any third party without the employee's written consent;
    2. Allow access to the employees' personal data to the persons listed in the section of this 2Procedure. At the same time, these persons shall have the right to obtain only those personal data of the employee that are necessary to perform specific functions, and to comply with the confidentiality regime;
    3. to transfer the employee's personal data within the Company in accordance with this Procedure.
  10. Persons to whom the personal data of an employee must use it only for the purpose for which it was communicated, and may not share it with third parties, except as required by the laws of the Republic of Kazakhstan.
  11. Personal files/documents or information containing personal data of employees may only be issued to the head of the company, the head of the structural subdivision for human resource management and in exceptional cases, upon written permission of an authorized person, the head of a structural subdivision for a period not exceeding seven calendar days with a note by a responsible employee of the structural subdivision for human resource management (personnel department) in the documents for recording/transferring of personal data
  12. Company employees who receive documents containing personal data for work, whether on paper or electronic (automated) media, shall be solely responsible for the safekeeping of documents and the confidentiality of information.
  13. The Company's transfer of an employee's personal data to consumers outside the Company in the prescribed manner may be allowed in the minimum amount and only for the purpose of performing tasks that correspond to the objective reason for collecting this data.
  14. The employee's personal data may only be shared with another organization in the prescribed manner with a written request on the organization's letterhead, accompanied by a copy of the employee's application.
  15. Personal data of an employee may be disclosed to his/her family members or relatives only with the written permission of the employee himself/herself or in accordance with the laws of the Republic of Kazakhstan.
  16. Third parties/unauthorized persons shall not know the work processes, storage and transfer of documents/tasks and other work materials available in the human resources management unit.

4. Liability for violation of requirements for storage of personal data of the employee

  1. Persons guilty of violating the rules governing the processing of personal data of an employee shall be liable in accordance with the laws of the Republic of Kazakhstan.
  2. Matters not regulated by this Procedure shall be governed by the laws of the Republic of Kazakhstan and the Company's internal documents.

5. Concluding Provisions

  1. This Procedure shall be put into effect from the date of approval by order of the first Head of the Partnership.
  2. This Procedure shall remain in force until the introduction of the new Procedure for the storage and transfer of personal data of employees
  3. Other issues of regulation of labor relations between the Employer and Employees of the Partnership, not reflected in this Procedure, are regulated by the Labor Code of the Republic of Kazakhstan and other normative legal acts of the Republic of Kazakhstan, the labor contract and acts of the Employer.
  4. This Procedure shall be binding upon the Employer and the Employees of the Partnership.
  5. Any changes and/or additions to this procedure shall be made on the basis of the Employer's order, provided that these changes and/or additions comply with the applicable laws of the Republic of Kazakhstan.
  6. At the time of hiring, the employer must familiarize the employee with this Procedure