f) processed in a manner that ensures appropriate security of the personal data, including
protection against unauthorized or unlawful processing and against accidental loss,
destruction or damage, using appropriate technical or organizational measures (‘integrity and
confidentiality’).
IV. Additional Safeguards for Data Subject
All persons shall have the right to
1. receive information on his/her data and on processing (right of access by the data
subject),
2. The data subject shall have the right to obtain from the controller restriction of
processing where one of the following applies: (a) the accuracy of the personal data is
contested by the data subject, for a period enabling the controller to verify the accuracy
of the personal data; (b) the processing is unlawful and the data subject opposes the
erasure of the personal data and requests the restriction of their use instead; (c) the
controller no longer needs the personal data for the purposes of the processing, but
they are required by the data subject for the establishment, exercise or defense of legal
claims; (d) the data subject has objected to processing pursuant to relevant legislation
pending the verification whether the legitimate grounds of the data controller override
those of the data subject.
3. establish the existence of an automated personal data file, its main purposes, as well
as the identity and habitual residence or principal place of business of the controller of
the file;
4. obtain at reasonable intervals and without excessive delay or expense, confirmation of
whether personal data relating to him are stored in the automated data file as well as
communication to him of such data in an intelligible form;
5. have such data corrected or erased for reasonable cause without delay (‘right to be
forgotten’); The Data Controller shall communicate any rectification or erasure of
personal data or restriction of processing to each recipient to whom the personal data
have been disclosed, unless this proves impossible or involves disproportionate effort.
The data controller shall inform the data subject about those recipients if the data
subject requests it;
6. receive, in the case of automated processing in consent-based processing, the
personal data concerning him or her, which he or she has provided to Ntice Kft, in a
structured, commonly used and machine-readable format and shall have the right to
have Ntice Kft transmit those data to another data controller. This right shall not violate
the right to be forgotten and shall not adversely affect the rights and freedoms of others.
7. object, on grounds relating to his or her particular situation, at any time to processing
of personal data concerning him or her which is based on point (e) or (f) of Article 6 (1)
of the GDPR, including profiling based on those provisions;
8. not to be subject to a decision based solely on automated processing, including
profiling, which produces legal effects concerning him or her or similarly significantly
affects him or her, except in the cases under Article 22 of the GDPR (automated
decision-making);
9. obtain legal remedy if a request for confirmation or, as the case may be, communication,
rectification or erasure as referred to by relevant legislation is not complied with. At data
subject’s request, data controller shall provide information on the data managed by data
controller or processed by data controller’s authorized data processor, on the purpose,
legal grounds, time period of the data processing, on data processor’s name, address
(registered seat) and data processing activities, and on the identity of the person(s)
receiving the data and on the purpose such data were received. Data Controller shall
provide the requested information in writing in intelligible form at the earliest possible
time upon receipt of data subject’s request, but within no later than 30 days. In case of
any violation of its rights, data subject may lodge a formal complaint against the data