HZMO work during COVID-19 epidemic
Preskočite na glavni sadržaj
Personal Data Protection

Personal Data Protection

Personal Data Protection

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data on the free movement of such data and repealing Directive 95/46 / EC (General Data Protection Regulation) OJ L 119 / I, 4.5.2016 - hereinafter: Regulation) directly applies from 25 May 2018 in all EU Member States and is fully binding.
The Regulation was adopted to enable exercising of the right to personal data protection of individuals relating to the processing of their data. The adoption and implementation of this Regulation ensure better supervision and equal treatment in the processing and transfer of personal data throughout the EU, as well as towards third countries.

As a data controller, HZMO also processes personal data of the data subjects; namely, of the natural persons whose data are processed on the legal basis prescribed by the Regulation (insured persons, beneficiaries, workers and similar).

The purpose of the processing of personal data in HZMO is exercising of the rights from the pension insurance, child allowance scheme and the employment-based rights of HZMO employees.
Personal data are processed only to the extent necessary to achieve the lawful purpose of processing.
 

Principles of Personal Data Processing


Lawfulness, Fairness and Transparency
Personal data of a data subject will be processed in a lawful, fair and transparent manner so that the data subject is acquainted with the aim and legal basis of data processing, with the data recipients and storage period.
 
Purpose Limitation
Personal data collected for specific, explicit and lawful purposes may not be further processed if inconsistent with those purposes. Further processing of data for archiving in the public interest, for scientific or historical research or statistical purposes shall not be considered incompatible with the original purpose.

Accuracy
Personal information must be accurate and complete. The data controller should take steps to correct inaccurate personal data, taking into account the purpose of the processing.

Storage Limitation
The storage form of personal data should enable identification of data subjects only for as long as necessary for the processing. Personal data may be retained for longer if processed for archiving strictly in the public interest, for scientific or historical research or statistical purposes.


Integrity and Confidentiality
Personal data processing should ensure the security of personal data, including protection against unauthorized or unlawful processing and accidental loss and destruction, by applying appropriate technical or organizational measures.

Reliability
The controller is responsible for the processing of personal data in accordance with the stated principles, with the possibility to prove them.
 
Processing of Personal Data
  • HZMO processes (collects, records, stores, discloses, transfers and similar) personal data of data subjects based on applicable legislation (Pension Insurance Act, Act on the Rights of the Croatian Homeland War Veterans and Their Family Members, Child Benefit Act, Labour Act, Rules on Maintenance of the Central Database of the Croatian Pension Insurance Institute, and similar)
  • Personal data are also processed based on the agreements (international social security agreements, EU regulations on the coordination of social security systems, business cooperation agreements for data exchange between HZMO and other bodies and state institutions).
  • HZMO collects and processes personal data through video surveillance based on the legitimate interest of HZMO to protect persons and property.
 
Recipients of Personal Data in the Republic of Croatia and the EU
Transfer or disclosure of personal data to recipients (a natural or legal person, public authority) is possible only if based on the law. HZMO exchanges, transfers or discloses personal data, most often to public authorities, to perform their legal and official obligations and powers (Tax Administration, REGOS, Croatian Health Insurance Institute, and others).
HZMO exchanges personal data with the EU Member States for the data subjects to exercise their entitlements to pension and child benefit, based on legal regulations on the coordination of the social security system.
 
Recipients of Personal Data in Third Countries  
HZMO transfers personal data of data subjects to third countries (which are not members of the European Union) exclusively based on international social security agreements. These agreements are part of the internal legal order, and by legal force supersede the law and take precedence over domestic law.
 
Personal Data Storage Period
As the creator of archival and registry (documentary) material, HZMO retains personal data of data subjects for long periods. Deadlines for personal data storage are regulated by the Rules on the Protection and Processing of Archival and Registry Material of the Croatian Pension Insurance Institute.
 

Data Subject Rights


Right of Access to Personal Data
A data subject has the right of access to his data. Also, the data subject may obtain from the controller the information on the processing of his data (the data purpose, types of personal data, recipients to whom personal data are or will be disclosed, especially if those are in the third countries, data storage period and similar).
HZMO, as a data controller, provides this information in a concise, transparent, understandable and easily accessible form, using clear and simple language.
 
Right to Correction and Amendments
The data subject has the right to request the correction of inaccurate personal data relating to him and the right to amend the incomplete personal data.

Right to Erasure
The data subject has the right to erase personal data, except in the case of restrictions on the erasure of personal data, which is prescribed by the Regulation.
The right of the data subject to have data erased is possible only after the expiration of the period prescribed by the Rules on the Protection and Processing of Archival and Registry Material of the Croatian Pension Insurance Institute.

Right to Restriction of Processing
The data subject has the right to obtain from the controller restriction of processing if he considers that the data is inaccurate or that the processing is unlawful.

Right to Complain to the Supervisory Authority
When data subject considers that the processing of his data opposes the Regulation, the data subject may complain to the competent supervisory authority. The competent supervisory authority in the Republic of Croatia is the Agency for Personal Data Protection.

Cookies
For a better user experience on the website (www.mirovinsko.hr) HZMO uses so-called cookies. Cookies make web pages work optimally and enable the best possible browsing and use of web pages. By selecting "I agree", the user confirms that he agrees with the cookie settings on the HZMO website. More on cookies.

Security of Personal Data
HZMO takes appropriate technical and organizational measures to ensure the protection of personal data of data subjects. The measures include access control to all data and documents, monitoring of access and activities in the information system and software solutions to ensure the security of IT equipment and data.
Access to personal data of data subjects by HZMO employees is allowed exclusively for business purposes, to perform work tasks.
HZMO conducts training of its employees about the necessity of the continuous protection of data subjects' privacy. All employees are aware that they may not use the personal data of the data subjects without authorization.
 
Filing of Application
For exercising the rights prescribed by the Regulation, the data subject may file an entitlement application to HZMO in the following way:
  • by applying to the Regional Service/Regional Office of HZMO directly,
upon presentation of ID card
  • by sending the application in writing, to the address:
 
Hrvatski zavod za mirovinsko osiguranje
            Središnja služba
            službenik za zaštitu podataka
            A. Mihanovića 3, 10 000 Zagreb
  • by filing the application electronically (by e-mail), to the e-mail
address: zastita_osobnih_podataka@mirovinsko.hr


For protecting personal data when applying electronically, the data subject will receive the reply strictly to his home address.  It is because it is not possible to establish the identity of the contacted person electronically. 
 
HZMO will respond in writing to the clearly defined and complete applications filed by the data subjects within 30 days from the day of application. Incomplete and unclear applications will be subject to the collection of additional information.  In the case of a rejected application, HZMO will provide the reasons in writing.
HZMO will not process any unfounded and excessive requests and will inform the data subject in writing about the reasons.
 

DATA CONTROLLER
Hrvatski zavod za mirovinsko osiguranje
A. Mihanovića 3
10000 Zagreb     


DATA PROTECTION OFFICER
E-mail: zastita_osobnih_podataka@mirovinsko.hr
T:  01/ 4595-06401/ 4595-293
Address:
Hrvatski zavod za mirovinsko osiguranje
Središnja služba
A. Mihanovića 3
10000 Zagreb
Share feedback
Thank you for your feedback!
Please fill in all required fields.
Did you find what you were looking for?
How would you rate the website?
1
2
3
4
5
Your comment
Please share your opinion on this site and help us improve. Do not leave personal information.
Save