INTRODUCTION OF THE PACK PROJECT

The fundamental goal of the PACK project is to introduce a new solution for a smoother flow of cargo by launching an advanced end-to-end system which will be able to manage every facet of goods transportation. With integrating the existing and future technologies used in customs checks on the borders, PACK aims to deploy a state-of-the-art detection, real-time tracking and recognition system that not only improve efficiency of customs checks but also enhance security. The innovative products developed by the consortium and its members (hereinafter: “project partners” or “partners”) are designed to reduce the risks of illegal activities associated with international road transportation and the delivery of goods. By deploying these products commercially in real-world environments, we expect improvement in the detection of unauthorized cargo bay openings, tampering with goods and potential illicit trafficking, whether involving humans, animals or other contraband. The PACK project also takes into account the environmental impact of inefficient operations used in customs checks as we aim to reduce pollution through the deployment of our products. By minimising the time spent on the borders waiting for the customs inspections, the project contributes to the reduction of CO2 emissions during these extended delays. Altogether, the vision behind the PACK project is built upon a balanced road transportation without unnecessary delays or interruptions in the flow of goods with special consideration paid for illegal and polluting activities which must be – and will be – addressed and solved. 

 

To achieve our goal, the PACK project adopts a collaborative approach. Tight cooperation and steady teamwork between the partners, along with the involvement of stakeholders, external researchers and the general public is the key to avoid working in silos or skimming over the real desires and needs of end-users. By pursuing this path of work, collecting and processing a variety of personal data is inevitable. This Privacy Policy (hereinafter: “privacy notice”) outlines how personal data collected in relation to the PACK project is processed, managed and stored by the partners, who are obligated to comply with the applicable legal framework established by the EU at all times. This obligation specifically includes the European General Data Protection Regulation (hereinafter: “GDPR”), which serves as the foundation of this privacy notice. In addition, partners also evaluated guidelines published by the  European Data Protection Board (hereinafter: “EDPB”) as those soft-law documents introduce a shared direction for all Member States in the field of data protection. 

 

We ensure that all partners are adequately informed about their obligations concerning the processing of personal data. Due to the collaborative nature of the project, collected personal data might be processed by more than one partner to the extent necessary to execute their own work-tasks. All of these aspects and branches of data processing activities will be governed by the provisions detailed in this privacy notice. 

 

Beside laying down the roles and responsibilities project partners will take on in relation to processing activities, another goal of this privacy notice is to inform individuals whose personal data may be collected under the PACK project (hereinafter: “data subject”) about the purposes and legal bases behind and the extent of data processing, the rights of data subjects related to these activities and the legal obligations on the partner’s behalf. Fundamental principles for data security will be defined in this notice as well as imposing a tight guideline on the consortium which aims to draw a proportionate line between the interest of the project and the data subject’s freedom to have control over their personal data. By requiring the partners to adhere to the policy outlined in this notice, we ensure that data collection, management, processing, storage, and deletion are conducted within clearly and transparently defined guidelines. Straightforward and easily comprehensible information will be provided on these topics, presenting the legal framework governing data processing. In case of any uncertainty or disagreement regarding interpretation, our Data Protection Officer (hereinafter: “DPO”) will be available to offer further assistance upon request from data subjects. 

SUMMARY OF DATA PROCESSING ACTIVITIES ACROSS THE PROJECT

To provide data subjects with a comprehensive overview, the following table summarizes the purposes and legal bases on which the consortium of the PACK project intends to collect and process different types of data.

Activity
Categories of personal data collected
Purpose of data processing
Legal bases
Data concerning employees of the project partners
Names, contact information, position, payment informations
Certain personal data collected from employees hired by one of the project partners will be processed in connection with the project either for the purpose of fulfilling obligations arising from the employment contract or to pursue a partner’s legitimate interests. Project partners may also maintain records about data processing activities to monitor which of their employees accessed project-related data and when. Personal data of an employee may be accessed by other partners as well when it is necessary for executing their own work-tasks.
Project partners process the data of their employees on the legal basis of contractual obligations (e.g. salary transfers). Other partners may access these data sets if a legitimate interest (e.g. pursuit of a legal claim) arises or if they need to fulfil their own legal obligations (e.g. reporting to a national or EU authority). [Article 6(1)(b), (c) and (f) of the GDPR]
Internal communication
Names, phone number, email address (other contact details, if necessary)
As project partners must stay in close contact to ensure seamless internal collaboration, their personal contact details may be shared among the project partners (e.g. for organizing meetings or assemblies) based on the consortium’s legitimate interest and contractual obligations.
Generally, internal agreements concluded between the partners regulate this issue. However, data processing may also occur based on the legitimate interests of the consortium (e.g. ad-hoc emergency communication) to the extent necessary. [Article 6(1)(b) and (f) of the GDPR]
Internal events for the consortium members
Name, contact details, recordings at the venue
Project partners (and their associates) may be expected to attend internal events (e.g. conferences) during which occasion a set of personal data may be processed.
Regardless of whether the partners are required to attend an event or do so voluntarily, their data may only be processed if it is necessary for the performance of a contractual obligation, or if the partner has given their informed consent (e.g. being recorded). [Article 6(1)(a) and (b) of the GDPR]
Contact list produced by the involvement of stakeholders, volunteers, potential participants or end-users
Names, contact information (e.g. email address, phone number)
A minimal amount of personal data might be collected from individuals who may potentially become participants in the project. Such data will be deleted upon the individual's request or once it is no longer necessary (e.g. after the project ends).
Contact details will be collected based on the partners’ legitimate interest if they intend to involve an individual in the development, innovation or dissemination phases of the project. [Article 6(1)(f) of the GDPR]
Contract between data subjects (practitioners, stakeholders) and the project partners
Name, contact information, postal address, tax or other unique ID (depending on national law and legislation), birthdate
Data from individuals who have entered into a contract with one of the project partners will be collected in order to comply with contractual obligations.
To fulfil the obligations and counter-obligations arising from the concluded contract, the partners will process certain categories of personal data. [Article 6(1)(b) of the GDPR]
Engagement of stakeholders
Name, contact information, electronic contact (e.g. social media accounts), recordings (e.g. pictures, videos) on workshops, affiliation
By participating in events organized throughout the project’s lifetime, individuals consent to the processing of certain personal data. Detailed information on the extent of such processing will be provided in the invitation or notification of the events.
Regardless of whether the event in question requires registration, the project partners may only process any personal data of a participant based on their informed consent, which must be obtained prior to the collection of the data (e.g. before taking a photo or video). [Article 6(1)(a) of the GDPR]
Dissemination media materials (recordings)
Name, age, recordings (e.g. pictures, videos, podcasts) made at the venues
Mere participation in events, which are also based on freely given consent, must be distinguished from cases where recordings may be made on-site featuring the participants. In such cases, proper information will be provided, and the participants will have the right to decline to appear in any recordings. Participants must also be informed that the recordings may be uploaded to the project website or other social media platforms.
Recordings may be produced and made public on the project website and social media platforms solely with the participant’s explicit and freely given consent. [Article 6(1)(a) of the GDPR]
Cookies (trackers)
IP-address, username, browser type or version, names, electronic contact
Upon visiting the project website essential and non-essential cookies might track certain types of data. Consent of the visitor will be requested before the use of the latter, and the consent can be withdrawn at any time.
The operation of all trackers used by the website, including cookies, is contingent upon the visitor’s prior informed consent. [Article 6(1)(a) of the GDPR].
PACK newsletter
Name, email address, phone number, electronic contact
Visitors may provide their personal data when signing up for the PACK newsletter on the project website, which purpose is to inform people about the progress of the project. A visitor can subscribe or unsubscribe any time, the active subscription list will be deleted after the final report of the project is accepted.
Processing of this set of personal data is based on informed consent given electronically by the visitor when signing up for the newsletter. [Article 6(1)(a) of the GDPR]
Attendance at scientific conferences and workshops
Name, contact information, electronic contact, recordings (e.g. pictures, videos) on workshops
Members of the scientific community are welcome to attend our events and special conferences organized to enhance their engagement. Recordings at the event require the informed consent of the individuals who appear in them.
Participation in scientific events is voluntary, and only individuals who have explicitly given their prior informed consent may appear in recordings made at these events. [Article 6(1)(a) of the GDPR].
Publications
Name of the authors, scientific identifier
The project’s scientific outcomes will be published in research journals, including only the minimal amount of personal data necessary, in accordance with the principle of data minimization and the requirements of Open Science.
The publication of materials related to the project requires either the publisher's consent or a contractual basis. [Article 6(1)(a) and (b) of the GDPR].
Accidental findings of personal data
Names, contact information, etc.
It may happen during the project that members come across data not directly connected to the project, which cannot be legally processed for any purposes. A prompt decision must be made regarding whether this data can be processed on any legal basis, and if not, it must be deleted without delay.
The data can be retained until a decision is made regarding the legal basis for its processing. Meanwhile, it may be processed or handled under the members’ legitimate interests. [Article 6(1)(f) of the GDPR].
Personal data collected while testing or using project products
Name (pseudonyms),
Aggregated or pseudonymized personal data will be collected while participants (e.g. truck drivers) use some of the project products.
Processing of this set of personal data is based on informed consent given by the users when they start to use the product(s). [Article 6(1)(a) of the GDPR]

RESPONSIBILITIES OF PROCESSING

Data controller responsible for data management

 

The task of data management in the PACK project is led by Székely Family & Company Non-profit Kft. (hereinafter: “SFC”), who will take on the role of main data controller. However, due to the highly collaborative nature of the project where the factual influence over the processing operations is shared and the purposes and means of processing are jointly determined by the consortium members, a joint controllership will be established in accordance with Article 26 of the GDPR and the guidelines published by the European Data Protection Supervisor. The concept of joint controllership implies that even though SFC takes on the task of managing data processing as a contact point and main data controller between data subjects and other partners (i.e. joint controllers), the identification of the purposes (as in why the data is processed) and the means (as in how it is conducted) is a shared responsibility of the consortium and they all have the right to effectively shape the following essential elements, which are determined in a previously conducted agreement among the partners:

 

  • Types of data to be processed
  • Retention and storage period
  • Identity of data subjects from whom data is collected
  • Rules of data accessibility by the consortium members
  • Involvement of data processors

 

Upholding a joint controllership is a necessity during the PACK project’s lifetime, not only because the essential elements of processing are determined by the consortium members together, but also because forwarding various types of data – including personal data – is unavoidable to facilitate smooth communication. This solution means that alll partners are collectively obligated and jointly accountable to comply with the GDPR, other applicable laws and the precedent of the Court of Justice of the European Union (CJEU). Joint controllership entails specific obligations for the partners involved: clear allocation in a transparent manner of their respective responsibilities to protect the rights and freedoms of data subjects [Article 26 and Recital (79) of the GDPR]. However, it is important to note that defining the respective responsibilities does not mean (nor does the GDPR require) that the joint controllers share their processing-related tasks equally. However, SFC takes on the role of the main data controller and the contact point, other partners (i.e. joint controllers) are expected to be involved at different stages of the project and to varying degrees of the data processing – as long as this information is clearly disclosed to data subjects and not prevent them from exercising their rights outlined in this privacy notice. 

 

Please, keep in mind that this privacy notice provides sufficient information about our structure of joint controllership. In case you, as a data subject, have any further questions, you may contact our DPO via the contact details below. 

 

Not all partners bear the responsibility of interacting directly and/or regularly with data subjects. The limited involvement of some partners in work-tasks related to personal data collection or processing does not prevent data subjects to reach out to them specifically via the contact point (i.e. SFC) or another contact detail presented below.

 

The specific roles and responsibilities assigned to all partners are set forth in an internal agreement (i.e. the Grant Agreement) signed by the consortium. This agreement serves as the standard arrangement, discussed and agreed upon by all partners. Since it contains confidential information and the joint controllers (i.e. all project partners) are not obligated to make its whole content public, only the essence of the arrangement will be made available to data subjects, which key elements cover the aspects of data processing detailed in this privacy notice (e.g. purposes of data collection, types of data being processed or the rights of the data subject). The internal arrangement also assigns the task of informing data subjects [Art. 13 and 14 of the GDPR] at the time when data collection begins and establishing communication channel(s) between them and the project partners. This responsibility falls on SFC and the appointed DPO, both of whom act as primary contact points for data subjects, receive their requests and provide additional information when the right to access further information about data processing is exercised.

 

The preference of the PACK project is to maintain a single-channel communication model under which data subjects are predominantly in contact with the appointed contact points avoiding the ambiguity, overload of contact information and the chance of miscommunication. This model is preferable to establish a clear and unmistakable route for data subjects to follow when seeking additional information about the processing of their personal data. This chosen approach, as stated above, is not intended to prevent data subjects from directly communicating with any project partner, if they wish to do so. In such cases there will be multiple ways to reach out to them: 

 

  • The PACK project is supported and co-funded by the European Union’s Horizon research and innovation programme, hence information about the project partners – including their roles and contact details – is available on the official website of the European Union. Data subjects are encouraged to consult the site and reach out directly to any partner if they have a specific question or issue directed at them. 
  • Information can also be found on the PACK LinkedIn page , where a short introduction to the project and list of project partners is provided. 
  • The PACK project also takes great effort to communicate with the wide public via well-known social media channels such as Facebook. Visitors are welcome to visit our Facebook site any time under this link.
  • Finally, SFC, as the main contact point, or the appointed DPO can be approached at any time in relation to any arising issue or simply to obtain the contact details of another partner. In case of any question, please feel free to reach out using one of the contact information provided under this section of the privacy notice. In addition to this approach, we would like to further inform data subjects that they have the opportunity to exercise their rights in respect of and against all consortium members as the obligation to comply with legal provisions is a shared responsibility. Therefore, SFC acting as the main contact point, neither has the option, nor will refuse to facilitate communication between data subjects and the consortium when such a request is submitted.  

 

Contact details of SFC

 

 

In accordance with the GDPR all joint controllers are jointly responsible for ensuring compliance with the applicable regulations and safeguarding the rights of data subjects, so that these rights can be exercised at any time without undue delay or obstacles. 

 

In greater detail, internal data forwarding among project partners is regulated by the Consortium Agreement, Grant Agreement and this privacy notice.

 

Data Protection Officer (DPO)

 

Bence Juhász
sustainability@szekely.family 

 

Data processors 

 

The PACK consortium intends to delegate certain processing activities to data processors, who will handle personal data on behalf of the joint controllers (i.e. the project partners). These processors primarily provide software and cloud services for corporate administration, including data storage, documentation, payment processing, transactions, and communication with participants. In performing these tasks, the processors act in an implementing capacity by following the instructions of the joint controllers and working in their interest. As a result, the joint controllers bear the primary responsibility for complying with legal requirements. However, this arrangement does not entirely eliminate the processors’ independence, as they maintain some autonomy in determining how to deliver their services or execute specific assigned tasks. Consequently, the consortium considers the possibility that some processors (or their parent companies) may have servers located outside the EU, which entails that data processing may occur outside the EU. For more information about this topic, please refer to the section called “Data transfers outside the European Economic Area”.

 

The following processors and their provided services will be used:

 

  • Google (e.g. using Google Forms for event registration)
  • Microsoft (e.g. using Word to write scientific reports including personal data)

 

The exact list of data processors is expected to expand during the implementation period of the project, as the overall landscape of processors may change. Regardless of the identity of specific processors, a clear description of their categories and the tasks they handle is provided below, in accordance with the principle of transparency. 

 

Categories of the involved processors:

 

  • Cloud hosting providers: Partners may use third-party cloud service providers to store data in larger databases, run backups, or assist with managing the collected data (e.g. Google Cloud Platform).
  • IT support services: Third-party IT support providers will be engaged, who may access personal data when necessary to provide maintenance services, troubleshooting and technical assistance
  • Backup and disaster recovery: Specialized service providers may be used to back up personal data and ensure data recovery in the event of a system failure or data loss.
  • Communication services: External communication service providers may be used to deliver emails, messages, and notifications related to the project’s services (e.g. internal communication, newsletter).
  • Email list services: Processors may help with the management of mailing lists and deliverance of our newsletters and other project updates. They may manage and store the previously shared personal data related to these operations (e.g. email addresses provided by subscribers on the project website).
  • Event platforms: Services offered by these platforms (e.g. Google Meet, Zoom) are focused on planning, managing and hosting in-person, virtual or hybrid events. To provide their services personal data may be processed by them (e.g. name, email address, IP address).
  • Survey tools: Since the project aims to conduct multiple user feedback sessions, it is likely that online platforms that help to create, distribute and analyse surveys, feedback forms and other questionnaires will be used. These tools may process personal data (e.g. contact details) on the controllers’ behalf. 
  • Payment processors: Third-party payment processors (e.g. PayPal) will be used to handle payment transactions securely. These providers process your payment information on our behalf solely for payment processing purposes.

 

If a different type of service provided by data processors is deemed necessary, affected data subjects will be informed and this privacy notice will be updated accordingly.

OVERVIEW OF THE LEGAL BASES AND PURPOSES OF DATA PROCESSING

We would like to provide clear and accurate information to the individuals involved in the PACK project regarding the processing of their personal data, regardless of the purpose for which the processing might take place. Therefore, the privacy notice first outlines the purposes and legal bases for data processing in general, underlining the legal framework within which the project operates. This includes the conditions for accessing such personal data by any partner. Through this data subjects can find out why their data is being collected and how it will be used from the legal basis and obtain information about the specific purpose behind data processing (e.g. ensuring communication between the data subjects and the partners, fulfilling obligations arising from a contract, sending out our newsletter). 

 

You can find an overview of legal bases and purposes of data processing:

 

  • If ‘the data subject has given informed consent to the processing of his or her personal data for one or more specific purposes’ [Article 6(1)(a) of GDPR], data controllers might process that data for various purposes as detailed in the consent form (e.g. business networking, subscription to our newsletter, visiting our website, usage of cookies, to appear in recordings). Project level templates for informed consent will be provided by SFC with the intent to make data management more transparent using unified forms and to prevent project partners from – even by accident – applying different conditions for data processings. Consistency ensures that every partner follows a precise and harmonised procedure around data processing activities. Regardless of this unification, the exact format of the consent form may vary depending on the occasion in which data processing becomes necessary. For example, to subscribe to the newsletter, users must check a tickbox on our website or other (relevant) media channels. To register an event, where a participant’s name, email address, etc. might be collected, the registration form will also include a section for informed consent. The specific purpose of these processing will always be detailed in the consent form, however, the main objective is to create user-friendly communication channels (e.g. newsletters, event invitations, emails about the project’s progress) and ensure the dissemination of the project’s outcomes and milestones, which involves the collection of individual’s personal data (e.g. contact details) to inform them upon the state of the project. This method of data processing also facilitates the proper functioning of the consortium and smooth communication either between the partners or with the external participants.

 

The specific number of consent form an individual is required to fill out in order to access the project’s outcomes or participate in an event depends on the extent of our activities one would like to engage with. For more information about informed consent, please refer to the section called “Informed consent and its withdrawal by the data subject” or contact our DPO.

 

  • Data will be processed where ‘processing is necessary for the performance of a contract between the data subject and the controller or where it is necessary to take action at the request of either one of the parties prior to the conclusion of the contract’ [Article 6(1)(b) of the GDPR]. For example, when one of the partners drafts a contract or monitors its progress, issues certification of performance or invoices, we use the data to generate documents in this context and for these purposes. During the PACK project, partners may aim to create long-lasting partnerships with external participants (e.g. authorities, research institutions) instead of relying on occasional engagement. In addition, personal data of individuals participating in the project as employees, associates of a project partner or stakeholders will be processed under this legal basis as well, based on their employment contract, direct contract, or any legally binding contract they signed. In brief, if a project partner concludes a legally binding contract that is valid under the applicable national contract laws (or any other legislation that was chosen by the parties) and data processing is objectively necessary for the performance of that particular contract, the partner lawfully processes the personal data collected from the data subject. Since the project complies with the principles of data minimization and transparency, a distinction will be made between processing activities that are necessary for the performance of a contract and clauses making the service conditional on processing activities that are not, in fact, necessary for fulfilling the contract. This means that unilaterally imposed conditions do not constitute a valid legal basis on their own. Contrariwise, data processing may still be necessary even if it is not explicitly mentioned in the contract. For more information about the scope of personal data processed on this legal basis, please contact the project’s Data Protection Officer (DPO) or your contracting party (i.e. project partner). 
  • To manage and operate the PACK project, joint controllers may process data if ‘the processing is necessary to fulfil the legal obligation of the controller’ [Article 6(1)(c) of the GDPR]. This includes, for example, tax returns, payrolls, registers of safety training, employee registration, other documents and protocols required by Member State law. Since data management is a responsibility of SFC, which company is located in Hungary, legal obligations set forth by the Hungarian Law will apply in the first place. However, please note that in cases when the project partner acting as (joint) data controller is not a partner operating under Hungarian Law, the legal obligations of their own jurisdiction should apply to them. Beyond obligations arising from national law, EU legislation may impose additional requirements which must be fulfilled.
  • In order to pursue our legitimate interests, we process the data where ‘processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child’  [Article 6(1)(f) of the GDPR]. In order to rely on this legal basis, the project partners must justify and demonstrate their broader stake or benefit in engaging in a specific processing activity. As a first step, the legitimate nature of the interest must be assessed in accordance with the standards established by the GDPR, CJEU and EDPB. While no conclusive list of legitimate interests exists, such an interest must be lawful, not in conflict with any applicable regulations, clearly defined by the partners, and it must not be speculative. It must be real and present at the time when data collection begins under the legitimate interest basis. For example, a legitimate interest may arise when there is (or will be) a relevant relationship between the data subject and the partner acting as data controller in that situation. In this case, the partner may pursue its legitimate interests to access the contact details of that data subject so they can be contacted later on, inviting them to participate in the project. This legal basis also applies when project partners process personal data for the purpose of pursuing legal and/or financial claims, recording dispute settlement teleconferences or meetings and disclosing information about possible criminal acts or security threats to the competent authorities. The necessity of processing as well as the balance between the fundamental rights and freedoms of the data subject and the legitimate interest will always be analyzed and assessed (i.e. balancing test) by the partner acting as the data controller in the given situation, the DPO or the Ethical Advisory Board.

 

Data processed on the basis of legitimate interest may serve a wide range of purposes, which, without aiming to provide an exhaustive list, may primarily include the following:

 

  • Responding appropriately to a request or inquiry sent by a visitor using the contact details provided (e.g. sending a response email to the sender’s address).
  • Forwarding a visitor’s personal data to a partner in the PACK project to enable them to establish direct communication and provide more detailed and extensive information.
  • Reserving the right to take legal action, defend the project partners in legal proceedings and enforce legal claims.
  • Ensuring the security of our website, social media channels, products, and services against misuse and unlawful activities.
  • Marketing and promoting our products, services, and brands to ensure their successful commercialization.
  • Storing the contact details of certain external participants in order to have the possibility to get in touch with them in the hope of a future collaboration.
  • In rare and exceptional cases, project partners may become aware of personal data (i.e. an accidental finding) that is not related to the project and therefore they are not authorized to process it. Under these circumstances, the data in question may be processed temporarily on the basis of the partner’s legitimate interest, solely to determine whether a valid legal basis or purpose for processing exists. If necessary, the opinion of the DPO or the Ethics Advisory Board will be sought during this assessment. If the final decision confirms that none of the partners has a legitimate interest justifying the processing, the data must be permanently deleted. 

 

When legitimate interest is used as the legal basis for data processing, a three-part Legitimate Interest Assessment (LIA) will be carried out by the partner responsible for data collection and/or by the DPO to ensure full compliance with the obligation to implement appropriate organisation measures, in line with the principle of accountability [Article 5(2) and 24 of the GDPR]. Besides reviewing the purpose (by identifying the legitimate interest for which the data is collected) and the necessity (whether data collection is necessary to achieve the previously identified legitimate interest) of data processing, the main objective of the assessment is to determine whether the pursued legitimate interest is balanced against the fundamental rights and freedoms of the data subject whose personal data the project partners plan to process under this legal basis. If the identified legitimate interest is overridden by the data subject’s rights and freedoms, personal data must not be processed on this legal basis – though this outcome does not prevent the consortium from collecting data if another legal basis applies. For example, the collection of contact information from external individuals cannot be too extensive, however, if participants voluntarily share their information after giving informed consent, the processing of such data is free from any further issues. 

 

While assessing the weight and importance of the legitimate interest, the following core aspects will be examined. The list is not exhaustive, as the relevant factors may change depending on the situation when data collection becomes necessary and no other legal basis applies except the legitimate interest of the partners): 

 

  • How will data processing affect data subjects?
  • What measures can be taken to avoid potential unethical or unlawful use of data (e.g. anonymisation, encryption, pseudonymisation)?
  • What is the goal behind data collection that the partners try to achieve? Whether the importance of the goal is essential to achieve the project overall success, as the partners cannot proceed without the data in question.
  • What benefits come from data processing?
  • What would be the (negative) impact if data processing could not be conducted?
  • May the processing impose a high risk to the fundamental rights and freedoms of data subjects? 

 

Results of the conducted assessment will be documented to demonstrate compliance with the principle of accountability and the GDPR [Article 5(2)].

CATEGORIES OF PERSONAL DATA PROCESSING AND THEIR LEGAL BASES

After outlining a broad overview of the general purposes behind data processing, we would like to present the specific categories of personal data that are likely to be processed during the lifetime of the PACK project. Project partners will collect and process various types of personal data to ensure uninterrupted internal cooperation, the flawless execution of multiple activities and/or work-tasks, collaboration with external participants and compliance with their legal obligations. Regardless of the specific purpose behind a processing activity, it must be justified by at least one of the legal bases listed above and carried out in compliance with the principles of the GDPR. All partners commit to adhere to the obligations and requirements set forth in this privacy notice and avoid violating applicable legislations or the rights of the data subjects. 

 

Data protection during the execution of work tasks 

 

All employees involved in the PACK project under a valid employment contract or other legally binding agreement with any of the project partners, are required to follow the guidelines of this privacy notice, which are designed in accordance with EU and national laws to enhance data security. This applies to any associate, staff member or subordinate, even if the law governing the legally binding contact with a partner does not classify them as ‘employees’. As long as one is working on the project or accessing its products, documents or internal communication channels, adherence to this privacy notice is obligatory. 

 

Employees can keep only work-related documents visible on their desk and screen during working hours, and only when the data is necessary for their tasks. Also, any written documentation (e.g. printed sheets) and electronic devices containing personal data related to the project must be locked away at the end of the workday. All devices (e.g. phones, laptops, tablets) must be secured with strong PINs or passwords, and auto-lock features must be activated when the devices are left unattended. In the absence of the employee, appropriate procedures must be followed so that outsiders cannot access sensitive or restricted data. 

 

Internal meetings within each partner’s organization – especially when project-related personal data is discussed – must not be recorded without an explicit permission from a superior. If such recordings are made, they are subjected to the same principles and requirements outlined in this privacy notice. For example, data may be processed only if it is necessary to complete a specific work task during the meeting (e.g. deciding whether a potential external participant should be contacted). After concluding an online or hybrid meeting, all documents and table contents must be removed from the meeting rooms.

 

It is possible that not all employees of a partner are assigned work-tasks related to the PACK project under their employment contract. In such cases access by these employees to the data processing connected to the project must be explicitly prohibited and prevented through measures the partner deems necessary. Even if an employee is involved in the project, they may only access data to the extent and within the scope necessary for carrying out their previously assigned tasks.

 

The partners may maintain logs of data access by their employees whose activities can be monitored within legal boundaries (e.g. data stored on work-related devices can be checked by a supervisor appointed by the controller). Information from these logs may be retrieved by other partners in cases of unauthorised processing, data breaches or when a legitimate interest arises on the part of a consortium member concerning an employee (e.g. for the purpose of conducting a legal dispute). If a partner would like to follow this practice, they are required to provide proper information to their employees (e.g. which device can be monitored, how often or by whom). 

 

Primarily the personal data of employees involved in the PACK project will be processed by the respective partner employing them under a valid contract. However, if it is deemed necessary, the project coordinator or SFC – who is responsible for data management and protecting personal data – may access employees’ personal data besides the employer partners. The legal basis for this processing includes, on one hand, the fulfilment of contractual obligations (e.g. salary transfers), and on the other, compliance with financial transparency and budgeting requirements. Since the PACK project is funded by the European Union, it is objected to EU law requirements. This data may also be processed by the parties when there is a legal obligation to do so (e.g. reporting to an EU body on the project’s financial status or to submit data to various national authorities).

 

Data processing at partners related to the project will be reviewed by SFC with special attention paid to where the data is stored and the adequacy of its protection. 

 

Cooperation among project partners

 

Uninterrupted internal collaboration among the project partners is a key element in ensuring the success of the PACK project. Without seamless coordination and effective project (consortium) management, the project’s outcomes (e.g. products, publications, dissemination materials) will not achieve the broad accessibility and stakeholder engagement that the partners aim to reach. During this frequent communication, partners should expect that their personal data (e.g. email address, phone number, other contact details) may be shared among the consortium members. The legal basis for this data processing is either the fulfilment of obligations arising from a previously conducted contract (e.g. Consortium Agreement) or any other agreements between the partners, or the legitimate interests pursued by a partner. For example, in order to complete a work-task, a partner may be given access to the contact details of an employee of another partner organization if direct interaction is essential for executing that task. Primarily SFC – who is responsible for project coordination and operational management – and additionally any partner intending to communicate with another, reserves the right to collect and process the personal data of the members on the basis of their legitimate interest, limited strictly to what is necessary for effective internal communication. SFC will provide  project management templates (e.g. partner contact list) and offer assistance to the project partners as needed to support efficient collaboration. At the same time, SFC guarantees that personal data collected from the partners are handled securely. 

 

Cooperation between the partners extends far beyond ad-hoc or occasional communication. Semi-annual on-site meetings, as well as hybrid or fully virtual (video)conferences will be organized at various levels throughout the entire course of the project. Partners may be invited to on-site technical testings or field trips to test the project products. Therefore, the scope of the data processed in connection with these occasions, as well as its legal basis, will depend on the nature and purpose of the specific event. The legal basis for each type of data processing will be evaluated separately. This means that a signed agreement between the partners (e.g. Consortium Agreement) does not automatically authorize all forms of data processing by other project partners. For example, personal attendance at a physically conducted meeting or field trip may be required by a contractual obligation, which would justify sending an invitation to a partner’s email address, including their name, organizational role, and other contact details. However, this does not imply consent for recordings or photographs to be taken of those individuals at the venue. The scope of data processing must be interpreted strictly even within internal relations, and partners must be provided with appropriate information accordingly. Also, where necessary, informed consent must be obtained from them before data collecting may begin. 

 

The PACK project entails an ongoing internal quality assurance, during which personal information related to internal documents and external publications may be shared among partners or directly forwarded to those working on related tasks. Since sharing data at this level is essential for the successful implementation of the project (e.g. internal peer reviews, approval from the Management Team or other partners), it will be carried out based on the partners’ legitimate interest.

 

One of the goals of the PACK project is to introduce its products to the market. To achieve this, partners will monitor the status of intellectual property rights (IPR) and any relevant trademarks. Personal data might be processed during such activities as a part of IPR research or (later on) the implementation of IPR protection measures. Such data processing will be carried out on the basis of legitimate interest of the partners and in accordance with the applicable data protection requirements detailed in this privacy notice.

 

Certain project partners and/or their selected employees might be invited to promote the PACK products in interviews or podcasts on television or radio. Participation in such activities will be voluntary. If a partner agrees to participate, their personal data will be processed based on their informed consent.

 

Stakeholders’ engagement

 

With the intention of increasing the visibility and outreach of the PACK project, a separate work-task will be dedicated to identify and engage stakeholders: both individually and as groups or entire organisations. PACK’s communication targets a wide and varied range of stakeholder groups, including logistics companies, customs and border authorities, truck and trailer manufacturers, suppliers, truck drivers, policy makers and environmental agencies as well as the members of the general public. Active and regular engagement of these stakeholders is essential to refine the specific desires and needs PACK intends to address by the end of the project. Also, by recruiting volunteers and other participants for our events, gathering feedback from them and considering the diverse perspectives coming from a broad range of sources, we hope that the project’s results will more accurately represent the real-world needs of the industry.

 

Mapping and engaging the stakeholders will also allow the partners to make significant progress in communicating and disseminating our results with the public. Our outreach to stakeholders will not be limited to the online space (e.g. teleconferences) but their participation in community events, such as workshops, demonstrations or product testings, will also be encouraged. These collaborative events will be organized to connect the partners with diverse end-users and stakeholders, while also showcasing the project’s progress and achievements to them. 

 

To establish contact with potential future stakeholders (e.g. truck drivers, customs officers, transport companies), who may be invited to participate in the project, the partners need to access a small set of their personal data (e.g. name, phone number, email address), limited strictly to what is necessary for making contact. This data will be processed based on the partners’ legitimate interest and will be deleted if the cooperation between the partner and the stakeholder has failed and the personal data is no longer necessary for future collaboration, or if a new legal basis applies (e.g. a contract is concluded between the parties). Data subjects may also exercise their right to erasure by contacting our DPO. After contacting a potential stakeholder, a partner may offer to enter into a contract. From this point forward, the legal basis and scope of data processing will be adjusted accordingly, and different types of data may be collected if necessary for performing the contract. The content of the contract concluded between the data subject and a consortium member may extend beyond participation in the project and could also include a non-disclosure agreement (NDA).

 

Stakeholder engagement is led by SFC – who is mainly responsible for data management in this regard – however, all partners contribute with stakeholder identification and involvement. Hence, all partners (as joint data controllers) are involved in sharing basic contact details of identified stakeholders for outreach purposes. 

 

As it was pointed out, various types of events (e.g. conferences, workshops, tests, demonstrations) will be organised throughout the lifetime of the PACK project to engage a wide-range of stakeholders and other participants while also introducing our products. Regardless of the exact type of these events, fundamental data security standards will apply uniformly. Attendance at any event is always voluntary, no attendee may be compelled or coerced into participating. However, if someone chooses to attend, their personal data may be collected based on the legal basis of informed consent. At events where a prior registration is required, after reading the provided information that will be published on the website where a registration can be submitted participants may voluntarily choose to provide their personal data (e.g. name, contact details). In some cases, participants may also be notified via confirmation emails about the extent of data collection and processing during the event (e.g. that recording may take place). If an individual is previously signed up to our newsletter, this notification may be sent out beside an invitation to the event via emails without the registration process.

 

For public events (e.g. promotional workshops) that do not require registration, appropriate information about data collection will still be provided. This may include notices on the event’s promotional website, cautionary signage at the venue or verbal announcements during the event. These notices inform attendees that recordings may take place. By attending with awareness and understanding of this possibility, individuals are generally considered to have given informed, valid consent to appear in such recordings (e.g. group photos, short videos). However, attendees must retain the right to define the limits regarding their consent, being recorded or photographed must not be a precondition for attending the event. Any attendee who does not wish to be included in such media, must be given a clear opportunity to express their will explicitly and cannot be compelled to appear in recordings solely on the basis of attending the event.

 

At events that require personal invitation (e.g. closed testings or demonstrations), the partners may need to access a limited set of personal data (e.g. email addresses or other contact details) to establish contact with potential participants (e.g. customs authorities, transport companies) whom the partners intend to involve in the project. This data will be processed based on the partners’ legitimate interest and will be deleted if no cooperation is established and the data is no longer necessary for future collaboration, or if a new legal basis applies (e.g. a contract is concluded between the parties, or a tester gives its informed consent to participate). Legitimate interest may justify data collection when such activity is carried out for statistical purposes (e.g. participation numbers or attendance figures). Data collection may sometimes be required by legal obligations during events, such as when an accident occurs and the appropriate authorities need to be notified.

 

The PACK project also intends to invite policymakers to main events. Personal data collected from them during their participation will be managed in the same manner outlined above.

At some events short videos and photographs may be taken and posted of the project website and/or other social media platforms. Being featured in these recordings depends fully on the informed consent of the data subject. In these situations, the scope of this consent is determined by the data subject who gave it, which means that they may agree to certain data processing activities (e.g. participation in a group photograph, interviews) while refusing others (e.g. videos taken while they use our products). 

 

Feedback from the participants will also be gathered at the venue as well as online (e.g. via email). In accordance with the principle of data minimization, it is unlikely that new personal data will be processed alongside the already collected data (e.g. the email address to which the message is sent) by the project during gathering feedback. 

 

During the project, partners may conduct surveys with stakeholders (or other participants). In addition, PACK aims to carry out a dedicated survey targeting customs authorities, truck operators, truck and trailer manufacturers, logistics and transport companies and ITS companies to assess the conditions and intentions for including deployment of PACK products in their future improvement plans. Project partners will also conduct interviews with representatives of ministries and/or other industrial experts. Participation is voluntary in both instances. Personal data from individuals filling out our surveys or participating in interviews can be only processed after obtaining informed consent from them. 

 

Website and dissemination materials

 

A publicly available PACK website will be created and launched under the leadership of SFC to reach the general public and share information on the project’s achievements. The project website will serve as the main dissemination platform, providing access to the latest publications related to PACK, updated project information and a schedule of events (e.g. workshops, conferences) organised by the partners. The project website will also be used to attract participants to the project’s public workshops, including information about such events and offering the option to register for participation. 

 

Upon visiting the website, cookies and similar tracking technologies will be used to enhance functionality and to analyse usage. These trackers might collect certain types of personal data (e.g. IP-address, browsing behaviour). The website clearly distinguishes between different categories of cookies, such as essential (strictly necessary) and non-essential (e.g. preference, marketing) ones. Essential cookies ensure the functionality of the website and cannot be disabled via the cookie consent tool. They are used based on legitimate interest, as the website and its specific services (e.g., logging in) would not function correctly without them. The use of non-essential cookies requires the visitor’s informed consent, which must be obtained prior to the activation of any such cookies. Right after accessing the project website, visitors will be provided with clear information about the types of data each cookie tracks and the purposes of such processing, using plain and easily understandable language. A cookie consent popup will inform visitors of their right to give informed consent, the scope of data processing during their visit, and the option to access more detailed information about the trackers used. Visitors will be able to manage their cookie preferences at any time through the website settings. Non-essential cookies that require consent will stop tracking data if consent is withdrawn.

 

Besides the project website, several social media channels (e.g. YouTube channels, Facebook and X page, LinkedIn account) will be set up to produce, publish and post content following the project’s progress. For example, pictures taken and recordings made at the events, as mentioned above, will be posted on these platforms, if informed consent has been previously obtained from the data subjects. SFC is responsible for both the creation and management of these social media platforms. In addition, partners will post project news on their own media accounts to further promote PACK. These social media platforms will also facilitate a channel of communication where the interested members of the general public can interact with the project partners in a lively manner. Project partners will process the minimal amount of personal data necessary to facilitate this type of communication (e.g. email address, social media account, name) on the basis of informed consent which is considered given when an individual reach out to us voluntarily. 

 

Since SFC is mainly in charge of managing the website and the social media platforms, access to personal data necessary for their smooth operation will be primarily accessed by it (e.g. data tracked by cookies). However, all partners will have the opportunity to provide their own introductions, share posts about their activities, or publish news on the project platforms besides their own accounts, and thereby they may access a limited set of personal data based on their legitimate interest. Partners may also gain access to the acquired data in some cases, for example, a guest who created an account on the website could receive an invitation to an event from any member via the email address provided or get notified through their social media account. 

 

To properly inform the interested public, the PACK project will distribute an electronic newsletter and/or direct social media messages at regular intervals. Subscription to these newsletter or massages will be available online via the project website or on the social media platforms. When a data subject signs up, certain types of data must be provided in order for the project members to establish contact with the individual. The processing of this data is based on informed consent given electronically by the data subjects themselves. Subscribers to the newsletter will have the option to unsubscribe at any time. By unsubscribing, data subjects withdraw their consent, and their data related to the newsletter will be deleted.

 

Scientific community and publications 

 

Among the activities aimed at exploiting the results of the project, particular emphasis will be placed on the scientific community and dissemination focused on them. Multiple research institutions will be approached in order to request their insights and collaboration in advancing the project. To enhance their engagement, several scientific conferences (e.g. ETC, TRB, WCTR, IEEE IV symposium, etc.) and dedicated workshops will be organized. Participation at the events centred around the invitation of members from the scientific community will be fully voluntary by the invited and interested participants. Personal data collected and processed in connection with these occasions will be subjected to the same regulations as previously outlined (e.g. appearing in recordings depends on the informed consent of the individual). The involvement of the research community includes publications in targeted scientific journals, the internal peer review of articles or the presentation of the project at conferences. 

 

Research outcomes will be published in high-impact journals. Since the PACK project is fully committed to Open Science, several steps will be taken to comply with its practices and principles. For example, the outcomes and findings of the PACK project are published in fully open-access venues, open-source software developed during the project is made publicly available through repositories such as GitHub and most results can be accessed via the Horizon Results Platform. Validity is an important aspect to ensure the quality of the project’s process, therefore the methodology relies on a large range of external participants to test the project outputs. However, when individuals are involved in a research-focused part of the project, we ensure that their data is anonymised or pseudonymised before publication whenever possible. For example, co-creation processes and feedback will be documented, although personal data related to their sources will be anonymised. And only participation data that has undergone pseudonymisation will be provided to demonstrate the representativeness and reliability of stakeholder engagement. Participants will be informed about the potential for open publication, and only data necessary to validate or understand the research findings is made publicly available. Research publications will not include personally identifiable information unless explicit and informed consent has been obtained, such consent can be withdrawn at any time for future use. Prior to the release of any external publications, a detailed publication and quality assurance process will be presented to which our research partners will be informed and adhere. This quality assurance process is subjected to internal peer reviews and the approval of the project coordinator. During these quality assessments, it is possible that the project coordinator or other members of the consortium may gain access to a researcher’s personal data. However, even in such cases, these data will not be processed beyond what is necessary for the processors’ legitimate interest (e.g. storing email addresses for future cooperation), for fulfilling contractual obligations (e.g. transferring agreed remuneration to a bank account specified in the contract), or for complying with legal obligations (e.g. submitting data to tax authorities after payment has been made).

SPECIAL TYPES OF PERSONAL DATA

Personal data collected by project products

 

Privacy and data protection will be rigorously safeguarded throughout the lifetime of the PACK project. Products accessing a set of personal data will take safety measures to uphold an expected level of data security in line with the principles of the GDPR. For example, the system developed within the project will pseudonymize participants – both individuals and organisations and ensure that their identities can only be resolved by the owner of the data or through authorised national identification databases. The technical solutions within PACK will thoroughly protect personal data against tampering or unauthorised access from the start. 

 

Personal data of data subjects using our products will be only accessible to the project partners involved in the development and testing phases and – after commercially deployed the products – to themselves and their national authorities. 

 

Sensitive personal data 

 

Article 9 of the GDPR specifies a list of certain types of personal data (hereinafter: “sensitive personal data”). This category includes information such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health data, data concerning sexual orientation as well as the processing of genetic data or biometric data for the purpose of uniquely identifying a natural person. The PACK project is not expected to involve the processing of any data that falls within this special category. 

 

Despite the project’s cautious approach to avoid the processing of sensitive data altogether, there remains a possibility that such information may be collected as PACK gathers data on a larger scale from multiple sources and is designed to manage a rather extensive database. In such cases, any sensitive personal data will be classified as an accidental finding, and the project partners will proceed accordingly. 

 

Accidental finding of data

 

Under the principle of data minimisation, only data that is directly relevant to and necessary for a previously defined purpose will be collected and processed.  However, due to the extensive scope of the project, which involves engaging numerous participants through various online and in-person activities, it is possible that project partners come across with data that is not directly relevant to the project’s goals and cannot be lawfully processed for any purposes. If the presence of such data is identified by a partner or the data subjects themselves, the finding will be documented and a notification will be sent to the DPO who will assess the significance of the found data. The DPO may consult with other relevant partners – particularly SFC or the one who came across the accidental finding. After concluding this assessment a prompt decision will be made regarding whether this data can be processed on any legal basis outlined in this privacy notice. If further processing is justified, the data remains processed on the legal basis of the partners’ legitimate interest. If not, the data will be rectified or terminated. Even if the final decision supports further processing, the data subject has the right to request deletion of their data. In such cases, the DPO will conduct a proportionality assessment weighing the data subject’s fundamental rights and freedoms against the legitimate interests of the partner(s).

 

We would like to reiterate that the occurrence of such situations is highly unlikely, as the PACK project does not collect personal data without the data subject’s knowledge. Regardless of the legal basis for processing, data subjects will always be informed in advance about the scope of the data being collected. 

 

Automated decision-making and profiling 

 

There are no current arrangements within the PACK project to perform automated decision-making and/or profiling regarding personal data collected from data subjects, as referred to in Article 4(4) and 22 of the GDPR.

 

Data of minors 

 

The PACK project does not knowingly collect personal data from children under the age of 16. If such data are discovered during the project’s lifetime, it will be classified as accidental findings and handled accordingly. If the processing can be justified by one of the legal bases and purposes outlined in this privacy notice, the strengthened safeguards set forth in the GDPR will be applied when managing the personal data of minors.

DATA PROCESSING PARTIES

The PACK project’s structure is fundamentally built upon teamwork among partners and task division, where uninterrupted internal collaboration, both ad-hoc and regular communication and the sharing of project-related content are key elements. As a result, the concept of joint controllership has been adopted by PACK partners. Consequently, the identity of the partner in charge of data processing may change depending on the specific activity during which the personal data is processed. For example, since not all events will be organised by SFC, any recordings made during those events will be sent to them in order to be published later on the project’s website, the management of which is primarily SFC’s responsibility.

 

The task of data management has been assigned to SFC, who acts as the leader of the related activities (e.g. collecting, handling, storing personal data). This means that SFC does not only access the data of the partners but has the authorization to manage data from external participants (e.g. stakeholders, invited volunteers) as the task leader. Regardless of which partner collected the data, SFC has permission to access all processed data. Despite this, the duty of data processing does not exclusively fall on SFC, all partners take part in it as they may also access, handle and process incoming data. The framework of internal data transfers is governed by the project’s Consortium Agreement, the Grant Agreement and this privacy notice which sources ensure that all partners act in compliance with EU legal standards and principles. For example, in the case when data is forwarded to a partner, the principle of data minimization will be upheld and only the data necessary for the execution of a work-task will be conducted.

 

By adhering to the legal requirements, SFC itself and all other partners may only access personal data if there is a valid legal basis and purpose that justifies such actions (e.g. legitimate interest in establishing contact or the data subject’s explicit consent). As a general practice, data subjects should expect that their data, processed on any lawful basis, may be managed by any project partners, unless they were explicitly informed otherwise at the beginning of the processing (e.g. due to a contractual restriction). This privacy notice serves as adequate information that warns data subjects about the possibility of their personal data being shared with internal parties (i.e. project partners). Where personal data is being processed based on informed consent, the consent form will explicitly emphasise this possibility and the data subject will be asked to agree that their data can be accessed and processed by all partners (e.g. when participating in an event, being photographed, or subscribing to our newsletter).

 

Besides having a valid legal basis, all data processing must also serve a purpose that requires the data to be forwarded or shared among the partners. Mere membership in the consortium does not grant automatic authorization to access personal data, even if all partners are involved in the task of data management. At least one of the purposes previously outlined in this privacy notice must apply to the specific situation in which a partner forward personal data. For example, such purposes may include establishing further contact with a participant, entering into a contract with an external stakeholder, sending their own message through media channels (e.g. via the newsletter, to those who have previously provided their contact information), transferring data to their relevant national authority (e.g. to national statistical institutes) or pursuing a legitimate interest on behalf of any partner (e.g. enforcement of a legal and/or a financial claims). Even when partners comply with data security principles and a valid legal basis and purpose can be identified, only the ones who guarantee adherence to the required data security standards, such as taking technical and organizational measures, are permitted to manage the data (e.g. partners whose employees have received prior training on data security guidelines).

 

The standard data transmission protocols outlined in this privacy notice should apply at all times, including the forwarding of personal data collected from the partners themselves, as data processing activities conducted within the internal network established under the PACK project are not exempt from data security regulations and must fully comply with them. If a partner intends to access personal data of another partner or its employees, a valid purpose and legal basis must be demonstrated. That being stated, a lower level of data protection can be expected around general contact details of the partners, which may be forwarded among the consortium members to enhance smooth communication and teamwork. For example, this allows partners to quickly access the contact details of those who are involved in shared tasks, ensuring effective collaboration in the event of any work-related issues.

 

The framework for internal data transfers is governed by the project’s Consortium Agreement among the partners. This document ensures that all partners and their affiliates act in compliance with EU legal standards, including in matters of data processing and transfers.

 

All project partners operate within the territory of the European Union; therefore, personal data will not be transferred outside of the EU during the lifetime of the PACK project.

 

To summarize the possible reasons for data transfer, it may occur based on the following grounds:

 

  1. Based on the data subject’s explicit, valid and informed consent that specifically covers both the relevant data and its transmission. For example, if the data subject agrees to hand over their email address to another member of the consortium or project partner so that direct personal contact can also be established with them.
  2. Personal data processed on a contractual basis may be transferred if it is necessary for the fulfilment of obligations arising from the contract by either party. For example, an external contractor party may receive instructions from another consortium member, or their remuneration may be processed by a party other than their direct contractor, requiring the disclosure of their bank account details.
  3. Data may be transmitted by the collector to another consortium member acting as the processor when such transfer is legally required under the basis of legal obligations. For example, when the other consortium member is also subject to obligations imposed by its national authority or European Union institution (e.g. financial reporting).
  4. Data may be disclosed to public authorities by the data collector itself as required by its legal obligations (e.g. the tax identification mark of the employee to the tax authority).
  5. In cases where transmission is necessary to protect the legitimate interest of a project partner, third parties or the data subject. This category covers a wide range of data transmission activities, the full extent of which cannot be entirely specified in advance. When data is transferred based on legitimate interest, a proportionality assessment should be conducted by the DPO (involving the Ethical Advisory Board if necessary) to balance the interests of all parties involved. If the legitimate interest clearly outweighs any potential harm to the data subject, the transfer will proceed. However, the data subject will be notified accordingly, if such a transmission is necessary and based on that notification, they will have the opportunity to contact the DPO and/or exercise their right to erasure, in accordance with the terms described in the relevant section below.

 

Regardless of whether the data is shared with internal (e.g. among the consortium members) or external (e.g. authorities) parties, the data subject will be informed about the third-party recipients of personal data at the time when data is collected (see more in „Right to be informed” section).

PRINCIPLES AND PROCESSES OF DATA MANAGEMENT

SFC, as the PACK project’s main data controller and contact point, along with all project partners undertakes the responsibility to comply with legal obligations under the GDPR throughout the implementation of the PACK project and ensures that all project partners granted access to the collected data adhere to the relevant provisions laid down in this privacy notice. The primary purpose of the processing of personal data is to fulfil the collector’s contractual obligations, ensure smooth operations, protect legitimate interests and support the dispersion of the project’s achievements. In exceptional cases, data processing may also take place for the purpose of handling complaints or as required by a legal order or applicable law. Consequently, data processing will occur on the basis of mutual interests of the data subject and the project partner(s) or based on other explicitly stated legitimate grounds mandated by law or legal order, which may also justify data processing. Consistent with the principle of purpose limitation, personal data will not be collected or processed for any purposes other than those specified above. 

 

In accordance with the principles of data minimization and storage limitation stated in GDPR, the partners will refrain from processing any data that is not necessary for the specified purposes. Already processed data will not be retained for longer than it is essential and will be either archived or permanently deleted without delay.

SFC as the main data controller also ensures that personal data is accurate and kept up to date. Inaccurate data will be corrected or erased either on the collector’s own initiative or upon the data subject’s request. If such a request is submitted, the data will be updated (e.g. obtaining a doctorate), corrected (e.g. typing, recording error) or modified to reflect changes in the data subject’s situation (e.g. change of name due to marriage, change of address due to move, new email address). These updates may also be made directly by the data subjects themselves through their user profiles on the web interface where possible. For security reasons, all changes must be logged (the log file will be recorded under the company’s operational registration code), and a notification must be sent to the data subject confirming the change.

 

Duration of data processing

 

The duration of the processing depends on the legal basis on which the data is processed:

 

  • Personal data collected based on informed consent will be processed for the duration of the valid consent but no longer than 5 years after completion of the project. Data subjects have the right to withdraw their consent, in which case the processing will be terminated. For more information about the withdrawal of consent, please refer to the relevant section in the privacy notice below.

 

In some cases, project partners retain the option to further process previously collected personal data even if data subjects withdraw their consent or invoke the right to erasure. This possibility applies to situations in which the violation causes harm or damage to a fellow user, a stakeholder, the consortium or constitutes a legal violation serious enough to warrant legal action or an official investigation by the relevant authorities. If the previously collected data is necessary to pursue legitimate interest or to comply with legal obligations issued by an investigating authority, the withdrawal of consent does not interrupt the duration of data processing. Further processing of personal data in this scenario depends on the judgement of SFC, the DPO and the Ethical Advisory Board. Even in these scenarios the interests or fundamental rights and freedoms of the data subject may be overruled by the legitimate interests listed above in which case a proportional assessment between the two competing interests must be carried out by the DPO. 

 

If data processing can still be justified under an alternative legal basis following the withdrawal of consent, the data may only be processed within the clearly defined scope of that new valid purpose and legal basis. For example, after a user account is deleted, data may be anonymized and further processed for statistical or research purpose(s).

 

  • Data collected for the fulfilment of contractual obligations will be processed until the contract is terminated and will remain stored, under limited processing (archives), until the period of any claims or disputes arising from the contract has expired. In accordance with the limitation of claims rules set out in the Hungarian Civil Code, this period is five years. However, certain legislation or the Grant Agreement may require a longer retention period for specific contracts.
  • Data collected for the purpose of complying with legal obligations will be erased upon the completion of those obligations. This means that the partners will process data for the duration of any applicable legal obligations and for as long as required by relevant legislation. Based on the legal provisions underlying the data collection, data will be retained for five years for taxation purposes and for eight years for accounting purposes, in accordance with the applicable laws. Following these periods, the data will be stored for an additional two years. If new legal obligations related to data retention arise in the future, the partners will handle them in accordance with the applicable regulations. In such cases, affected data subjects will be informed of the changes as outlined in this privacy notice.
  • Project partners will only process personal data on the basis of their legitimate interest as long as it is strictly necessary to fulfill the original purpose or when a clearly justified and specific objective arises from that purpose. Data processing will cease if it is determined that it causes disproportionately greater harm to the data subject than the importance of the legitimate interest. The duration of data retention under this legal basis may vary depending on the purpose behind the collection. Regarding the length of the retention period an estimation will be carried out based on an assessment of the factors laid out below. 

 

While it would be difficult to determine the exact time limit of retention periods in advance, personal data will predictably be stored for a maximum of 5 years after the conclusion of the project (in secure repositories like Zenodo). Where it is impossible to specify the exact timeframe of the retention period, the following criteria determine how long personal data may be stored:

 

  • Personal data will be kept only for as long as necessary to fulfill the purpose for which it was collected. For example, if contact information of stakeholders and external participants was collected to establish a communication channel with them, the data will be deleted once communication is no longer needed. 
  • Personal data may be stored if any legal obligations apply to keep said data for a fixed period of time. 
  • In cases data may be retained for extended periods for additional operations, such as statistical analysis. However, appropriate safeguards (e.g. anonymisation, pseudonymization) will be applied to protect personal data.
  • While determining retention period the type of data will be considered, as differentiation can be made based on this aspect. For example, data provided when subscribing to a newsletter must be processed until the data subject withdraws their consent, which may result in a longer retention period. In contrast, data provided when registering for a one-time event does not need to be retained after the event has taken place.

 

Once the retention period has expired and other legal bases cannot be identified to justify further processing, personal data will be securely deleted or anonymized.

 

Data transfers outside the European Economic Area

 

According to Chapter V (particularly Article 44) of the GDPR any transfer of personal data which are intended for processing after transfer to a third country must take place only if special conditions are met by both the data controller and the processor. Since the GDPR itself does not define these notions in detail, guidelines and criteria established by the EDPB will be applied and followed in such cases by the joint controllers. To provide data subjects with sufficient information regarding international data transfers, this section aims to clarify when such transfers occur and to explain the provisions that will be implemented in order to uphold the level of data protection and security guaranteed by the GDPR in every situation.

 

International data transfers occur when data controllers (i.e. project partners) subject to the GDPR transfer, forward or otherwise make personal data available to data processors located outside the European Economic Area (hereinafter: “EEA”), who subsequently  carry out data processing operations on behalf of the controllers. In addition to this set of criteria, EDPB provided clarification on the scope of “making personal data available”, as it covers multiple actions. For example, remote access from a third country (e.g. displaying personal data for their own administration purposes) and/or storage cloud situated outside the EEA offered by a service provider data processor is also considered to be an international transfer. Even though the PACK consortium intends to engage data processors whose primarily used servers are located inside the EEA, it is possible that personal data processed by them will be accessed from a third country, as the data processors’ central servers and/or parent company may be located in a non-EEA country. Even if personal data itself is processed, hosted and stored physically on servers within the EEA, if the parent company is based in a third country and support, maintenance or access occur from that country, data controllers are required to comply with the conditions of Chapter V of the GDPR and they have to frame the transfer by using one of the instruments that aims to protect personal data after they have been transferred to a third (non-EEA) country.

In the light of these conditions, the GDPR provides a number of instruments that can – and will – be used by the joint controllers to ensure an adequate level of data security and to protect the rights and freedoms of data subjects in accordance with Article 45, 46 and 49 of the GDPR.

 

Under Article 46 of the GDPR, the Standard Contractual Clauses (hereinafter: “SCCs”) are one of the instruments that can govern international data transfers conducted by data processor organizations outside the EEA. In relation to this solution, the European Commission issued a new framework of SCCs in 2021, which serves as the official, GDPR-compliant mechanism for international data transfers under Article 46(2)(c) of the GDPR. Data processors involved in the PACK project have already incorporated these SCCs into their customer agreements (e.g. via their Data Protection Addendum [DPA] or Online Service Terms). By contracting their services, joint controllers agreed on these terms, therefore, the SCCs are valid and ready to enable lawful data transfers to non-EEA countries while upholding the level of data security guaranteed by the GDPR.

 

The table below shows which data processors will be involved in the PACK project and what safeguards they have in place to comply with the GDPR:

Data processor
Appropriate safeguard
Legal basis
Microsoft
Microsoft provides the EU Standard Contractual Clauses (SCCs), which ensures personal data transfers from the EEA comply with GDPR. Data processing and security terms are defined in the Microsoft Online Services Data Protection Addendum (DPA), which serves as the legally binding agreement between the service provider (i.e. Microsoft as data processor) and the joint controllers. Any personal data leaving the EEA will be transferred in compliance with the DPA, therefore with the GDPR as well.
International data transfers are governed by the standard data protection clauses adopted by the Commission in accordance with Article 46(2)(c) of the GDPR.
Google
Google’s SCCs are used by customers (i.e. data controllers) to ensure personal data transfers to Google’s servers located outside the EEA while maintaining compliance with the GDPR. The SCCs provide appropriate safeguards for data subjects and are incorporated into the Google Cloud Data Processing Addendum (DPA) and other Google service agreements, which have been accepted by the joint controllers and can be found via the link below.
Article 46(2)(c) of the GDPR.

An even more detailed description of the SCCs can be found on the data processors’ websites at the following links:

 

 

Since the PACK project is still in its early stages, it is expected that additional processors will be engaged to successfully implement the project. When such a decision is made by the consortium, this privacy notice will be updated accordingly to include information about the new data processors. 

 

It is possible that some of the data processors engaged in the future will be located within the EEA and provide servers hosted strictly domestically, therefore, no additional safeguards will be needed when using their services. However, the overall degree of data security guaranteed by the GDPR remains intact without any question in these situations.

 

Data Subject Information Disclosure

 

Data subjects will be provided with all relevant information regarding data processing before the activity begins. The form of notification depends on the situation in which the data subject encounters the project and data collection becomes necessary. For example, when visitors open the website, a pop-up window will inform them about the cookies and other trackers used by the server. By clicking the “Accept all cookies” button, visitors can give consent to the operation of non-essential identifiers (cookies). Of course, visitors will also have the option to learn more by clicking “Read more” and to change their cookie preferences at any time afterward. Data subjects may receive the necessary information in written form (e.g. by signing a consent form when attending an event or upon entering into a contract) as well as verbally when appropriate. The data subjects also have the right to request additional information about the processing of their personal data on any occasions. 

 

Determination of legal basis

 

Before initiating data processing, it is necessary to examine and identify the legal basis on which the data subject’s personal data will be processed. The data subjects must be informed about the applicable legal basis at the time when their data will be collected. This information will be included in the specific notification relating to the particular case (e.g. cookie pop-up) presented above or may also be provided verbally to the data subject. Even if data processing is based on several legal bases, the amount of data processed in each case must remain within the permitted limits. Upon the termination of a specific legal basis, processing of the data associated to that basis must cease, unless the processing can be continued under a different, valid legal basis. For example, where the legal basis is informed consent, contact information cannot be processed any further if the consent was withdrawn, except in cases where processing is justified on another legal basis, for example, a legal claim related to future contact. If no valid legal basis can be identified for the data processing, the processing must be terminated and the data in question must be deleted.

 

Data recording and classification

 

There are two ways to start data processing: by recording the data submitted by the data subject or by tracking the data subject with its informed consent. An example for the first case is providing data to conclude a contract; example of the second case includes the use of cookies on a website or making recordings during an event. In both cases, a valid legal basis must be identified. For example, if an informed consent was given for the participation in a group photograph or in an interview. 

 

All collected data will be classified according to the framework established in this privacy notice. Only data supported by an identifiable legal basis will be processed.

 

Data storage, management and termination

 

Personal data collected from a data subject will not be stored longer than it is necessary and beyond the retention period specified in the ‘Duration of Data Processing’ section. Data collected based on one of the legal bases will be processed automatically, although manual (human) processing may also take place where necessary. The protection requirements outlined in this privacy notice apply to both processing methods. As a result of processing, it is possible to carry out various transactions involving the data subject. For example: performance of a contract, sending of a newsletter, provision of services, payment of wages, issuing of invoices. Data processors may also be involved in the processing of personal data, storing and handling the data on behalf of the data controller.

 

Data will be deleted or restricted once the applicable retention period has expired.

 

There may be instances where data cannot be permanently deleted due to its necessity for further measures, such as archiving, dispute resolution, legal defence or asserting potential future claims. In such cases, the data will remain stored but will not be used or processed any further for any purposes. Restricted data will be encrypted, anonymized and segregated in our system and automated processing will be blocked. 

 

Anonymization will be applied when identification of a data subject is no longer necessary, but retention and analysis of data is required solely for statistical or archiving purposes. For example, for long-term trend analysis. Anonymized data is no longer subject to the provisions of the GDPR. 

 

Encryption will be used to ensure a level of security appropriate to the risk and implementing suitable technical measures. When assessing the necessary precautionary safeguards, we will take care to prevent accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data stored or processed.

 

Data will be erased once the purpose of processing is fulfilled and the retention period has expired. Additionally, data will be deleted if there is no further legal obligation to retain it (e.g. for taxation or accounting purposes), it cannot be processed based on another legal basis and there is no retention obligation. 

 

Personal data is protected regardless of the technology used for processing (technology-neutral approach). If the data also exists on physical media, it must be securely overwritten or, if it is not possible, physically destroy the carrier (e.g. smashing a DVD) to ensure permanent deletion. Physical destruction must be carried out in an environmentally responsible manner (e.g. plastic media must not be burned outdoors). This process will permanently terminate the processing of the data. The data subject shall be informed of the erasure before it begins.

 

Systematic procedures for data deletion or restriction will be integrated into the processing activities. In the event of a data breach, SFC will contact the relevant authorities within 72 hours and promptly inform all data subjects affected by the data breach. 

 

Data security

 

The consortium will take appropriate measures to ensure data security, protect data against unauthorized access, and comply with GDPR. A dual approach will be implemented. On one hand, technical measures (e.g. encryption) will be taken to safeguard personal data from unauthorized access or other damage. On the other hand, every member of the consortium commits to organizational measures, ensuring that only those who are properly trained in legal compliance will be able to access and handle the data – if these activities are necessary for their specific work tasks. 

 

Data Protection Impact Assessment (DPIA)

 

The PACK project incorporates new technologies (e.g. AI-driven devices), the use of which is likely to result in high risk to the rights and freedoms of data subjects. Consequently, a Data Protection Impact Assessment (DPIA) will be conducted by SFC and the Ethical Advisory Board as a part of the Data Management Plan. Advice received from the DPO will be taken into account while drafting the assessment to enhance its level of safety and data security. The DPIA will pay particular focus to the data collected through the demonstrations and take into account the different environments in which the project products will be used (i.e. testing or real-word environments). The DPIA will adhere to the GDPR [particularly to Article 35] and national regulations.

 

The DPIA will include the following questions, outlining a set of rules regarding data processing by the PACK consortium with which every partner must comply:

 

  • a systematic description of the envisaged processing operations (e.g how and by which controller the data collection, storage, management and deletion will be carried out);
  • a list of project partners who will have the right to access personal data – as well as the scope of said dataset;
  • the purposes of the processing – including, where applicable, the legitimate interest pursued by the (joint) controllers;
  • an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
  • an assessment of the risks to the rights and freedoms of data subjects for which the drafting of the DPIA is required;
  • the measures envisaged to address the risks, including safeguards, security measures and mechanisms (e.g. anonymisation, encryption) to ensure the protection of personal data.

 

The DPIA might be updated if the course of the project or any specific circumstances concerning the segments listed above changes significantly.

 

If data subjects wish to obtain more information about the DPIA, they are welcomed to get in touch with the partner acting as contact point (i.e. SFC) or the DPO via one of the contact details provided above.

 

Tools for the processing of personal data

 

We process personal information on laptops and mobile devices with up-to-date operating systems and software that are protected by passwords, biometrics or two-stage authentication, devices also have a drive-level encryption. Storage is encrypted and is stored in a redundant and synchronized cloud that tracks the activity. The network connections used during processing are also encrypted. We do not install unsigned or unlicensed software or connect to open, unencrypted WiFi networks. Paper-based personal information documents are kept in a lockable room, where people are only allowed to stay with our permission and supervision, and in the event of transport, we use a courier or state post office. The destruction of the media is carried out with a shredder.

THE RIGHTS OF DATA SUBJECTS

The consortium of the PACK project will facilitate the exercise of data subject rights as follows. If a submitted request is received, the main data controller acting as the contact point (i.e. SFC) or the DPO will provide further information on the actions taken without undue delay and in any event within one month of receipt of the request.

 

Right to be informed 

 

Data subjects have the right to be adequately informed about the collection and use of their personal data at the time of collection. This information includes the purpose of processing, the retention period for their personal data and the identity of any third parties with whom the data will be shared. As a standard practice, privacy information will be provided uniformly through the web interface upon visiting (e.g. cookie pop-ups), email or social network (e.g. newsletter), enabling data subjects to understand what data is being processed. In the event of a specific issue affecting a particular stakeholder or at the request of a data subject, individual notification will also be provided through one of the data subject’s contact details. In both instances, the information must be transparent, intelligible, easily accessible and using a clear and plain language, all of which the collector must ensure.  In the case of Artificial Intelligence (AI) used for data processing, prior notifications will be provided explaining the purpose behind the application of AI. The data subject will receive a targeted and specific notification, if the collector intends to further process the collected data for a purpose other than that for which it was originally collected.  

 

Special provisions regarding communication must be taken into account when the processing involves a minor. The language used to provide information to minors must be clear, plain and age-appropriate according to the principle of transparency. Where possible, visualization or images may be used beside written messages for easier comprehension.  

 

Project partners must be informed about the processing of their personal data in the same manner as an external individual, even if the data is only shared with internal partners of the project. This means that all project participants must be aware of which consortium member, colleague, supervisor, or employee of another participating entity may access their data, and which specific data are accessible to them. For example, if their name and contact details are shared on the project’s internal communication servers.

 

Right of access and rectification

 

Data subjects have the right to obtain confirmation as to whether their personal data is being processed by the controller, and if so, to access that data. Upon request, SFC as the general contact point – along with any other partners if a data subject get in touch with them directly – provides a copy of the personal data held about the data subject, along with the following set of information:

 

  • The purposes for which your data is being processed
  • The categories of personal data involved
  • The recipients or categories of recipients to whom your data has been or will be disclosed
  • The retention period or criteria used to determine how long your data will be stored
  • Your rights related to your data and how to exercise them

 

If any personal data seems to be inaccurate, incomplete or misleading, the data subjects have the right to request to promptly correct or complete the data in question.  To make a request, please contact the DPO, who will be pleased to assist you.

 

Where processing is based on the data subject’s consent and it is carried out in an automated way, the data subject also has the right to obtain (get a copy of) their personal data in a structured, commonly used, and machine-readable format and to ask for it to be transferred to another controller (right to data portability). This is in addition to their right to access their personal data and receive information about the processing (right of access).

 

Right to erasure and processing limitation

 

Data subjects have the right to request termination of processing, and the deletion of the data held at the time the request is received. In the case when data is processed based on informed consent, this also includes the withdrawal of that consent. Personal data processed in relation to the offer of ISS to a minor serves as a ground for exercising the data subjects’ right to erasure, if the data was collected based on informed consent and in accordance with the conditions of Article 8 of the GDPR. The deletion must be carried out as soon as possible, without undue delay. However, the controller reserves the right to retain data to fulfil further legal obligations or to protect potential legal claims. For example, upon request, data collected based on a contract between an external participant and a member of the consortium will be deleted if neither party has any claims against each other and there are no more legal requirements (e.g. disclosure of data to authorities) to preserve the data. 

 

If no such request is submitted, the data will be processed in accordance with the data processing policy outlined above and will be deleted once there is no longer a legitimate purpose or legal basis for its continued processing.

 

Instead of requesting the termination of processing, the data subjects have the right to request the restriction or suppression of their personal data, in which case the controller will be prohibited from using the data. This option is available in the following cases:

 

  • the accuracy of the data is contested,
  • the request is based on unlawful processing,
  • the data is no longer needed, or
  • the data subject has exercised their right to object and a decision is still pending.

 

For example, the accuracy of a data subject’s email address, used for communication or newsletter delivery, is questioned, until the clarification is made, the controller must not disclose the email address to other partners in the project nor use it for its own advances.

 

Informed consent and its withdrawal by the data subject

 

Throughout the project, there are many points where informed consent must be obtained from data subjects by having them fill out one of the project level consent forms designed by SFC. The number of occasions will depend on the products and services a data subject wishes to sign up for. Regardless of the exact type of informed consent form, they are created based on similar principles in every case, which are as follows:

 

  • Consent must be freely given, without any coercion or undue influence. Data subjects must have a genuine, real choice after receiving all the relevant information necessary to decide whether to give or withhold consent. 
  • Clear and comprehensible information must be provided for data subjects, in a language they can understand. Implications and consequences must be transparently explained beforehand. If the data subject is a minor, information must be age-appropriate, that pays attention to the child’s level of development.
  • The purpose behind collecting and processing data must be well-defined and communicated toward the data subject. 
  • Separate consents must be obtained for different processing operations. For example, if a data subject creates an account on Disastropedia, it does not mean that their personal data beyond their email address can be automatically processed. 
  • Informed consent must be given through a clear and affirmative action that does not leave any doubt about the intent behind it. For example, by ticking in a checkbox, data subjects express their will to give consent. Methods based on opting out (e.g. pre-ticked boxes) are not allowed.
  • No additional personal data should be required for consent beyond what is necessary for the data processing itself.

 

Where data collection is based on individual consent, we should ensure that all data subjects are provided with a practical, easily accessible and low-effort method for withdrawing their consent. A withdrawal initiated voluntarily by the data subjects must not be interrupted, prevented or obstructed in any way (e.g. persuasion, creating unnecessary delays). For example, if visitors of our website subscribe to the newsletter and provide their email address, they must be able to unsubscribe just as easily by a simple one-step procedure (e.g. by clicking on an “unsubscribe” button or link in emails, or by withdrawing consent through one’s account settings on the website). 

 

The withdrawal of consent must not cause any unjustified disadvantage or detriment. For example, an external participant cannot be excluded from all future public events solely because they once refused to appear in a photograph or other recording. However, the legal consequences outlined in a contract, employment agreement or terms of participation, such as the termination of a particular service or the cancellation of registration for an event, shall not be considered unjustified disadvantages. 

 

Following the withdrawal of consent, an assessment will be carried out by the DPO to determine whether any of the data can continue to be processed under an alternative legal basis. After the DPO completes this assessment, it will be shared with the project coordinator who makes the final decision in this regard that must be communicated to the data subjects as well so that they can take appropriate actions to terminate any other applicable legal basis if desired (e.g. by ending a contract). If the data cannot be classified under another valid legal basis, processing must be terminated.

 

Right to object and lodge a complaint

 

If the data subjects’ personal data is processed under the legal basis of legitimate interest, they have the right to object at any time, regardless of which partner’s legitimate interest is at stake. The objection can be specified and limited to defined boundaries. For example, the data subject may identify the particular set of data they do not wish to be processed or request that processing be restricted to a specific purpose only. If the data subject does not wish to receive direct marketing (e.g. product promotions via newsletter), this right may also be exercised.

 

Beyond the specified cases above, project partners strive to proactively address the problems encountered and to ensure seamless cooperation with data subjects and other stakeholders. In case data subjects have a complaint or comment about the processing, they shall contact the DPO first using the contact details provided above. Regardless of this option, data subjects also have the right to lodge a complaint with the supervisory authority. Since SFC – the project partner mainly responsible for data management and acting as the contact point – is established in Hungary, the primary competent authority will be the National Data Protection and Freedom of Information Authority (NAIH). Individuals (i.e. data subjects) whose personal data is being collected and processed by project partners are more than welcome to contact NAIH if they would like to receive more information about data security or submit a formal complaint regarding a specific operation carried out by the partners/data collectors. NAIH can be reached at the following contact details:

 

Address: 1055 Budapest, Falk Miksa utca 9-11.

Website: www.naih.hu 

Email address: ugyfelszolgalat@naih.hu 

 

NAIH serving as the lead supervisory authority does not prevent data subjects from reaching out to other Data Protection Authorities (DPA) who are in charge of enforcing GDPR and protecting data subjects’ rights under the regulation [Article 77 of the GDPR]. In each Member State in the EEA this independent public authority may be contacted by the data subjects to lodge complaints near their habitual residence, place of work or place of the alleged infringement if they consider the processing carried out by the partners unlawful. 

 

By contacting the DPA, the notification to or involvement of NAIH may be inevitable as it serves as the lead supervisory authority under the Article 56 of the GDPR. 

 

Changes to this privacy notice

 

The consortium of the PACK project reserves the right to revise or update its policy at any time. For example, if new features are introduced on our website that require additional data collection and processing. In this event, data subjects will be notified of significant changes, and the updated version of this notice will be posted on this page of the website. 

 

Effective day: 2025.11.30.

©2025 | PACK Project | ALL RIGHTS RESERVED