Personal Data Processing and Protection Policy
Approved by Order of the Secretary General of the World Peoples Assembly
Policy of the International Union of Non-Governmental Organizations “World Peoples Assembly” on the Processing and Protection of Personal Data on the Websites
1. General provisions
1.1. This Policy on the processing and protection of the personal data of website users (hereinafter referred to as the “Policy”) of the International Union of Non-Governmental Organizations “World Peoples Assembly” (hereinafter referred to as the “Operator”) in the information and telecommunications network Internet at the following addresses https://world-assembly.org, https://worldpublicsummit.org, https://public-diplomacy.org (hereinafter referred to as the “Websites”) has been developed pursuant to the requirements of clause 2 of part 1 of Article 18.1 of Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (hereinafter referred to as the “Personal Data Law”) for the purpose of ensuring the protection of the rights and freedoms of the individual and the citizen in the processing of their personal data, including the protection of the rights to inviolability of private life and to personal and family privacy.
1.2. The Policy applies to all personal data processed by the International Union of Non-Governmental Organizations “World Peoples Assembly” (hereinafter — the Operator, the Assembly).
1.3. The Policy extends to relations in the field of processing of personal data that arose for the Operator both before and after the approval of this Policy.
1.4. Pursuant to the requirements of part 2 of Article 18.1 of the Personal Data Law, this Policy is published with free access in the information and telecommunications network Internet on each of the Operator’s Websites: https://world-assembly.org, https://worldpublicsummit.org, https://public-diplomacy.org.
1.5. Principal terms used in the Policy:
1.5.1. personal data — any information relating to a directly or indirectly identified or identifiable natural person (personal data subject);
1.5.2. personal data operator (operator) is a state authority, a municipal authority, a legal entity or a natural person that, independently or jointly with other persons, organises and (or) carries out the processing of personal data, and also determines the purposes of the processing of personal data, the composition of the personal data to be processed, and the actions (operations) performed with the personal data;
1.5.3. processing of personal data means any action (operation) or set of actions (operations) performed with personal data, with or without the use of automation means. The processing of personal data includes, among other things:
- collection;
- recording;
- systematisation;
- accumulation;
- storage;
- clarification (updating, modification);
- extraction;
- use;
- transfer (dissemination, provision, access);
- depersonalisation;
- blocking;
- deletion;
- destruction.
1.5.4. automated processing of personal data means the processing of personal data by means of computer technology;
1.5.5. dissemination of personal data means actions aimed at disclosing personal data to an unlimited number of persons;
1.5.6. provision of personal data means actions aimed at disclosing personal data to a specific person or a specific number of persons;
1.5.7. blocking of personal data means the temporary suspension of the processing of personal data (except where the processing is necessary for the clarification of the personal data);
1.5.8. destruction of personal data means actions as a result of which it becomes impossible to recover the content of the personal data in the personal data information system and (or) as a result of which the material carriers of the personal data are destroyed;
1.5.9. depersonalisation of personal data means actions as a result of which it becomes impossible, without the use of additional information, to determine that the personal data belong to a particular personal data subject;
1.5.10. personal data information system means the aggregate of personal data contained in databases and of the information technologies and technical means that ensure their processing.
1.5.11. User is any person visiting the Websites and using the information, materials and services of the Websites. The User of the Websites is a personal data subject within the Federal Law No. 152-FZ of 27 July 2006 “On Personal Data”.
1.5.12. Services of the Websites mean interactive (dialogue) software components on the pages of the Websites, used for integration with information systems and providing users of the Websites with certain capabilities to access information, namely: registration and the user’s personal account; submission of an application for admission to the Assembly and tracking its consideration; payment of admission and membership fees; submission of applications for participation in events held by the Operator and making decisions thereon; uploading documents and photographs required for participation in events and for the production of a badge; submission of an application for participation in the “Leader of Public Diplomacy” competition and uploading competition materials; feedback forms and enquiries to the editorial office regarding the website’s materials; subscription to informational mailings; search of the website’s materials; media centre (photo albums, video recordings, presentations) (hereinafter referred to as the “Services, the Services of the Websites”).
1.5.13. cross-border transfer of personal data means the transfer of personal data to the territory of a foreign state to an authority of a foreign state, to a foreign natural person or to a foreign legal entity.
1.6. Operator’s Principal rights and obligations.
1.6.1. The Operator is entitled:
- independently to determine the composition and list of measures necessary and sufficient to ensure the fulfilment of the obligations provided for by the Personal Data Law and by the regulatory legal acts adopted in accordance therewith, unless otherwise provided by the Personal Data Law or other federal laws;
- to entrust the processing of personal data to another person with the consent of the personal data subject, unless otherwise provided by federal law, on the basis of a contract concluded with that person. A person carrying out the processing of personal data on the instructions of the Operator is obliged to observe the principles and rules of the processing of personal data provided for by the Personal Data Law, to maintain the confidentiality of the personal data, and to take the necessary measures aimed at ensuring the fulfilment of the obligations provided for by the Personal Data Law;
- in case of withdrawal by the personal data subject of consent to the processing of personal data, the Operator is entitled to continue the processing of the personal data without the consent of the personal data subject where the grounds specified in the Personal Data Law are present.
- to receive from the User accurate information and/or documents containing the User’s personal data for the purposes of processing specified in clause 2.3 of the Policy;
- to require the User to clarify the personal data provided in a timely manner.
1.6.2. The Operator is obliged:
- to organise the processing of personal data in accordance with the requirements of the Personal Data Law;
- to process personal data solely for the purposes specified in the Policy, in the manner established by the applicable legislation of the Russian Federation, and to take the measures necessary and sufficient to ensure the fulfilment of the obligations provided for by Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” and by the regulatory legal acts adopted in accordance therewith;
- not to disseminate personal data without the consent of the User, unless otherwise provided by the applicable legislation of the Russian Federation;
- to carry out the processing of personal data in compliance with the principles and rules provided for by Federal Law No. 152-FZ of 27 July 2006 “On Personal Data”;
- to organise the protection of personal data in accordance with the requirements of the legislation of the Russian Federation;
- to consider enquiries from the User (or the User’s legal representative) on matters of the processing of personal data and to give reasoned replies;
- to provide the User (or the User’s legal representative) with the opportunity of free-of-charge access to their personal data;
- to take measures for the clarification, blocking and destruction of the User’s personal data in the cases established by Federal Law No. 152-FZ of 27 July 2006 “On Personal Data”.
- to respond to enquiries and requests from personal data subjects and their legal representatives in accordance with the requirements of the Personal Data Law;
- to report to the authority empowered to protect the rights of personal data subjects (the Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor)), upon the request of that authority, the necessary information within 10 working days from the date of receipt of such request. This period may be extended, but by no more than five working days. To this end, the Operator must send Roskomnadzor a reasoned notification setting out the grounds for extending the period for providing the requested information;
- in the manner determined by the federal executive authority empowered in the field of security, to ensure interaction with the state system for detecting, preventing and eliminating the consequences of computer attacks on the information resources of the Russian Federation, including informing it of computer incidents that have resulted in the unlawful transfer (provision, dissemination, access) of personal data.
1.7. Principal rights and obligations of the personal data subject.
1.7.1. The personal data subject is entitled to:
- to receive information concerning the processing of their personal data, except in the cases provided for by federal laws. Such information is provided to the personal data subject by the Operator in an accessible form and must not contain personal data relating to other personal data subjects, except where there are lawful grounds for disclosing such personal data. The list of information and the procedure for obtaining it are established by the Personal Data Law;
- to require the operator to clarify their personal data, or to block or destroy them, where the personal data are incomplete, out of date, inaccurate, unlawfully obtained or not necessary for the stated purpose of processing, and also to take the measures provided for by law to protect their rights;
- to give prior consent to the processing of personal data for the purposes of promoting goods, works and services on the market;
- to appeal to Roskomnadzor or to the courts against unlawful acts or omissions of the Operator in the processing of their personal data;
- to withdraw consent to the processing of personal data in the manner provided for in Section 7 of this Policy.
1.7.2. The personal data subject is obliged:
- to ensure the accuracy of the personal data provided to the Operator that are necessary for the purposes of processing provided for in clause 2.3 of the Policy;
- to provide the Operator, where necessary, with information for the clarification (updating, modification) of the personal data provided.
1.8. Control over compliance with the requirements of this Policy is exercised by the authorised person responsible for organising the processing of personal data at the Operator.
1.9. Liability for the breach of the requirements of the legislation of the Russian Federation and of the regulatory acts of the Assembly in the field of the processing and protection of personal data is determined in accordance with the legislation of the Russian Federation.
1.10. The Operator retains all previously effective editions of this Policy with an indication of the periods during which they were in force. Upon the enquiry of a personal data subject, the Operator provides the ediiton that was in force on the date on which that subject gave consent to the processing of personal data.
2. Purposes of the processing of personal data
2.1. The processing of personal data is limited to the achievement of specific, predetermined and lawful purposes. The processing of personal data incompatible with the purposes of the collection of the personal data is not permitted.
2.2. Only personal data that correspond to the purposes of their processing are subject to processing.
2.3. The processing of personal data by the Operator is carried out for the following purposes:
2.3.1. carrying out its activities in accordance with the charter of the Assembly, including the conclusion and performance of contracts with counterparties and the identification of the User registered on the Websites;
2.3.2. compliance with labour legislation within the framework of employment relations and other relations directly connected therewith, including: assisting employees in obtaining employment, education and career advancement, attracting and selecting candidates for employment with the Operator, ensuring the personal safety of employees, monitoring the quantity and quality of the work performed, ensuring the safekeeping of property, maintaining accounting and bookkeeping records, completing and submitting to the authorised authorities the required reporting forms, and organising the individual (personalised) registration of employees in the systems of compulsory pension insurance and compulsory social insurance;
2.3.3. implementation of the access control.
2.3.4. creation and maintenance of the personal data subject’s personal account in the Operator’s information systems, identification upon log-in and recovery of access;
2.3.5. consideration of applications for admission to the Assembly, management of membership records, and accounting for admission and membership fees;
2.3.6. consideration of applications for participation in events held by the Operator and taking decisions on admission to participation;
2.3.7. production of a participant’s personal badge and provision of admission to the venue of the event, including by means of scanning the code printed on the badge;
2.3.8. issuance of invitations and documents required for obtaining a visa, given the data subject's stated need for visa support;
2.3.9. arrangement of the accommodation, transportation and reception of event participants;
2.3.10. mnagement of participant lists and preparation of reporting on the holding of events;
2.3.11. enabling the exchange of messages between users of the Operator’s information systems and with the Operator;
2.3.12. sending informational messages about the Operator's activities and events conducted by them - subject to the separately expressed consent of the personal data subject.
2.3.13. informing about the operation of the Websites (the Services), and monitoring and improving the quality of the Services.
2.3.14. providing the User with access to personalised resources of the Websites.
2.3.15. establishing communication with the User, including sending notifications and enquiries relating to the use of the Websites, the provision of services and the performance of works, and processing requests and applications from the User.
2.3.16. creation of an account to provide the User with access to the personal account and Website Services, provided that the User has given consent to the creation of the account.
2.3.17. providing the User with effective customer and technical support in case of problems relating to the use of the Websites.
2.3.18. sending advertising to the User with the User’s prior consent.
2.4. The processing of employees’ personal data may be carried out solely for the purposes of ensuring compliance with laws and other regulatory legal acts.
3. Legal grounds for the processing of personal data
3.1. The legal ground for the processing of personal data is the body of regulatory legal acts pursuant to and in accordance with which the Operator processes personal data, including:
3.1.1. the Constitution of the Russian Federation;
3.1.2. the Civil Code of the Russian Federation;
3.1.3. the Labour Code of the Russian Federation;
3.1.4. the Tax Code of the Russian Federation;
3.1.5. Federal Law No. 7-FZ of 12 January 1996 “On Non-Profit Organisations”;
3.1.6. Federal Law No. 402-FZ of 6 December 2011 “On Accounting”;
3.1.7. Federal Law No. 167-FZ of 15 December 2001 “On Compulsory Pension Insurance in the Russian Federation”;
3.1.8. Federal Law No. 149-FZ of 27 July 2006 “On Information, Information Technologies and the Protection of Information”;
3.1.9. Federal Law No. 294-FZ of 26 December 2008 “On the Protection of the Rights of Legal Entities and Individual Entrepreneurs in the Exercise of State Control (Supervision) and Municipal Control”;
3.1.10. Decree of the President of the Russian Federation No. 188 of 6 March 1997 “On Approval of the List of Information of a Confidential Nature”;
3.1.11. Resolution of the Government of the Russian Federation No. 1119 of 1 November 2012 “On Approval of the Requirements for the Protection of Personal Data during Their Processing in Personal Data Information Systems”;
3.1.12. Order of the FSTEC of Russia No. 21 of 18 February 2013 “On Approval of the Composition and Content of Organisational and Technical Measures to Ensure the Security of Personal Data during Their Processing in Personal Data Information Systems”;
3.1.13. other regulatory legal acts governing relations connected with the Operator’s activities.
3.2. The legal grounds for the processing of personal data are also:
3.2.1. the charter of the Assembly;
3.2.2. contracts concluded between the Operator and personal data subjects;
3.2.3. the consent of personal data subjects to the processing of their personal data, including consent given upon registration and upon the submission of applications on the Websites.
4. Scope and categories of the personal data processed, categories of personal data subjects
4.1. The content and scope of the processed personal data must correspond to the stated processing purposes provided for in Section 2 of this Policy. The processed personal data must not be excessive in relation to the stated purposes of their processing.
4.2. The Operator may process the personal data of the following categories of personal data subjects:
4.2.1. Candidates for employment with the Operator — for the purposes of compliance with labour legislation within the framework of employment relations and other relations directly connected therewith, and of the operation of the access control:
- surname, first name, patronymic;
- gender;
- citizenship;
- date and place of birth;
- contact details;
- information on education, work experience and qualifications;
- other personal data communicated by candidates in their CVs and covering letters.
4.2.2. Employees and former employees of the Operator — for the purposes of compliance with labour legislation within the framework of employment relations and other relations directly connected therewith, and of the operation of the access control:
- surname, first name, patronymic;
- gender;
- citizenship;
- date and place of birth;
- image (photograph);
- passport (ID) details;
- registered residential address;
- actual residential address;
- contact details;
- individual taxpayer number;
- insurance number of the individual personal account (SNILS);
- information on education, qualifications, vocational training and further professional training;
- marital status, presence of children, family ties;
- information on employment history, including the presence of incentives, awards and (or) disciplinary sanctions;
- data on the registration of marriage;
- information on military registration;
- information on disability;
- information of alimony withholding;
- information on income from the previous place of employment;
- other personal data provided by employees in accordance with the requirements of labour legislation.
4.2.3. Family members of the Operator’s employees — for the purposes of compliance with labour legislation within the framework of employment relations and other relations directly connected therewith:
- surname, first name, patronymic;
- degree of kinship;
- year of birth;
- other personal data provided by employees in accordance with the requirements of labour legislation.
4.2.4. Clients and counterparties of the Operator (natural persons) — for the purposes of carrying out its activities in accordance with the charter of the Assembly and of the operation of access control:
- surname, first name, patronymic;
- date and place of birth;
- passport (ID) details;
- registered residential address;
- contact details;
- position held;
- individual taxpayer number (INN);
- bank account number;
- other personal data provided by clients and counterparties (natural persons) that are necessary for the conclusion and performance of contracts.
4.2.5. Representatives (employees) of the Operator’s clients and counterparties (legal entities) — for the purposes of carrying out its activities in accordance with the charter of the Assembly and of the operation of the access control:
- surname, first name, patronymic;
- passport (ID) details;
- contact details;
- position held;
- other personal data provided by representatives (employees) of clients and counterparties that are necessary for the conclusion and performance of contracts.
4.2.6. Members of the Assembly and persons who have submitted an application for admission to the Assembly — for the purposes specified in clauses 2.3.4, 2.3.5 and 2.3.11 of this Policy: surname, first name, patronymic, including in Latin script; gender; date of birth; citizenship; email address; telephone number; photograph; registered residential address; actual residential address; information on places of work and positions held; information on knowledge of foreign languages; addresses of personal websites and social media pages; information on membership of the Assembly and on the payment of fees.
4.2.7. Participants of events held by the Operator — for the purposes specified in clauses 2.3.6–2.3.10 of this Policy: surname, first name, patronymic, including in Latin script; gender; date and place of birth; citizenship; email address; telephone number; photograph of the face; details of the identity document: series, number, date of issue, name of the issuing authority, and also an image (scanned copy or photograph) of the page of that document; name of the organisation represented and the position held; format and category of participation in the event; information on the need for visa support; information on the itinerary: mode of transport, flight number, dates of arrival and departure; information on the contact person.
4.2.8. Persons who have submitted an application for participation in an event without creating an account in the Operator’s information systems — in the scope and for the purposes specified in the application they have submitted and in the consent to the processing of personal data they have given.
4.2.9. Users of the Websites — for the purposes of informing about the operation of the Websites and the Services, monitoring and improving the quality of the Services, ensuring the security of the Websites and confirming the fact that consent has been given:
- IP address, date and time of access to the Websites;
- information on the browser and the device from which access was made (type, version, language, screen resolution);
- addresses of the pages of the Websites visited and the address of the referring source;
- data stored in cookie files.
The IP address, the date and time of access and information on the browser are also retained upon registration, the submission of applications and the giving of consents — as confirmation of the fact and moment of the performance of the corresponding action by the User.
4.3. The processing by the Operator of biometric personal data (information that characterises the physiological and biological characteristics of a person, on the basis of which that person’s identity can be established) is carried out in accordance with the legislation of the Russian Federation.
4.4. The Operator does not carry out the processing of special categories of personal data concerning racial or ethnic origin, political views, religious or philosophical beliefs, state of health or intimate life, except in the cases provided for by the legislation of the Russian Federation.
5. Procedure and conditions for the processing of personal data
5.1. The processing of personal data is carried out by the Operator in accordance with the requirements of the legislation of the Russian Federation.
5.2. The processing of personal data is carried out with the consent of personal data subjects to the processing of their personal data, and also without such consent in the cases provided for by the legislation of the Russian Federation.
5.3. The Operator processes personal data for each purpose of their processing by the following means:
5.3.1. non-automated processing of personal data;
5.3.2. automated processing of personal data with or without the transmission of the information obtained via information and telecommunications networks;
5.3.3. mixed processing of personal data.
5.4. Employees of the Operator whose job duties include the processing of personal data are admitted to the processing of personal data. In processing personal data, the Operator takes, or ensures the taking of, the necessary legal, organisational and technical measures to protect personal data against unlawful or accidental access thereto, destruction, modification, blocking, copying, provision and dissemination of personal data, and against other unlawful acts in respect of personal data.
5.5. The processing of personal data for each purpose of processing specified in clause 2.3 of the Policy is carried out by means of:
5.5.1. obtaining personal data in verbal and written form directly from the personal data subjects;
5.5.2. entering personal data into the Operator’s registers, records and information systems;
5.5.3. using other means of processing personal data.
5.6. Disclosure to third parties and dissemination of personal data without the consent of the personal data subject is not permitted, unless otherwise provided by federal law. Consent to the processing of personal data permitted by the personal data subject for dissemination is executed separately from the other consents of the personal data subject to the processing of their personal data. The requirements for the content of consent to the processing of personal data permitted by the personal data subject for dissemination are approved by Order of Roskomnadzor No. 18 of 24 February 2021.
5.7. The transfer of personal data to the bodies of inquiry and investigation, to the Federal Tax Service, to the Social Fund of Russia and to other authorised executive authorities and organisations is carried out in accordance with the requirements of the legislation of the Russian Federation.
5.8. The Operator takes the necessary legal, organisational and technical measures to protect personal data against unlawful or accidental access thereto, destruction, modification, blocking, dissemination and other unauthorised actions, including:
5.8.1. determines the threats to the security of personal data during their processing;
5.8.2. adopts local regulatory acts and other documents governing relations in the field of the processing and protection of personal data;
5.8.3. appoints persons responsible for ensuring the security of personal data in the Operator’s structural units and information systems;
5.8.4. creates the necessary conditions for working with personal data;
5.8.5. organises the recording of documents containing personal data;
5.8.6. organises work with the information systems in which personal data are processed;
5.8.7. stores personal data under conditions ensuring their safekeeping and excluding unlawful access thereto;
5.8.8. organises the training of the Operator’s employees who processes personal data.
5.9. The Operator stores personal data in a form permitting the identification of the personal data subject for no longer than required by each purpose of the processing of personal data, unless the period of storage of the personal data is established by federal law or by contract.
5.9.1. Personal data in paper records are stored at the Assembly for the periods of storage of documents for which such periods are provided for by the legislation on archival matters in the Russian Federation (Federal Law No. 125-FZ of 22 October 2004 “On Archival Matters in the Russian Federation”; the List of Standard Administrative Archival Documents Generated in the Course of the Activities of State Authorities, Local Self-Government Authorities and Organisations, with an Indication of Their Storage Periods (approved by Order of Rosarkhiv No. 236 of 20 December 2019)).
5.9.2. The period of storage of personal data processed in personal data information systems corresponds to the period of storage of personal data in paper records.
5.9.3. The personal data of event participants processed in connection with the holding of an event are stored for five years from the day of the completion of the corresponding event or until the day of the withdrawal of the personal data subject’s consent.
5.10. The Operator ceases the processing of personal data in the following cases:
5.10.1. the fact of their unlawful processing has been identified. Period — within three working days from the date of identification;
5.10.2. the purpose of their processing has been achieved;
5.10.3. the personal data subject’s consent to the processing of the said data has expired or has been withdrawn, where under the Personal Data Law the processing of such data is permitted only with consent.
5.11. Upon the achievement of the purposes of the processing of personal data, and also in the event of the withdrawal by the personal data subject of consent to their processing, the Operator ceases the processing of such data, if:
5.11.1. nothing to the contrary is provided by a contract to which the personal data subject is a party, beneficiary or guarantor;
5.11.2. the Operator is not entitled to carry out the processing without the consent of the personal data subject on the grounds provided for by the Personal Data Law or other federal laws;
5.11.3. nothing to the contrary is provided by another agreement between the Operator and the personal data subject.
5.12. Where a personal data subject applies to the Operator with a demand for the cessation of the processing of personal data, the processing of personal data ceases within a period not exceeding 10 working days from the date of the Operator’s receipt of the corresponding request, except in the cases provided for by the Personal Data Law. The said period may be extended, but by no more than five working days. To this end, the Operator must send the personal data subject a reasoned notification setting out the grounds for extending the period.
5.13. When collecting personal data, including via the information and telecommunications network Internet, the recording, systematisation, accumulation, storage, clarification (updating, modification) and extraction of the personal data of citizens of the Russian Federation using databases located outside the Russian Federation are not permitted, except in the cases specified in the Personal Data Law.
5.14. The Operator is entitled to entrust the processing of personal data to other persons on the basis of a contract concluded with them. An essential term of such a contract is the obligation of the person carrying out the processing of personal data on the instructions of the Operator to maintain the confidentiality of the personal data and to ensure their security. The processing of personal data on the instructions of the Operator is carried out by the following persons: the cloud infrastructure and data storage operator - JSC “Selectel”; the payment service provider for processing fees and participation payment — LLC NCO “YuMoney” (the YooKassa service).
In addition, when certain functions of the Websites and the Application are used, data are transferred:
- to the Stripe payment system (outside the Russian Federation) — upon payment for participation by foreign bank cards; bank card data are processed by the payment system and are not stored on the Operator’s servers;
- to the CARTO and OpenStreetMap mapping services — when the map of events is displayed, the network address of the device is transferred to them; the servers are located outside the Russian Federation.
The transfer in the cases listed is carried out to the extent necessary for the operation of the corresponding function. If the personal data subject does not use the function (does not make a payment, does not open the map, has disabled notifications), no transfer is made.
5.15. The Operator, jointly with the User, takes all necessary measures to prevent losses or other adverse consequences caused by the unlawful or accidental transfer (provision, dissemination, access) of the User’s personal data.
5.16. Cookie files and web analytics services.
5.16.1. The Operator uses cookie files — small files stored by the User’s browser — in order to ensure the operation of the Websites, to save user settings and to maintain the session in the personal account.
5.16.2. To obtain anonymized website traffic statistics, the web analytics service “Yandex Metrica” (LLC “YANDEX”) is used on the Websites. In doing so, the information specified in clause 4.2.9 of this Policy is processed. The statistics obtained are used solely in aggregated form and are not applied for the purposes of taking decisions in respect of a particular User.
5.16.3. The User is entitled at any time to disable the acceptance of cookie files in the settings of their browser, and also to delete stored cookie files. Where cookie files are disabled, certain capabilities of the Websites, including log-in to the personal account, may become unavailable.
5.17. Access control at an event. In order to admit participants to an offline event, a list of approved participants is transferred to the devices of authorised staff members and volunteers (access control operators): first name and surname, email address, number of the Assembly membership certificate (where available), photograph, the participant’s role at the event, their application number, the list of participation options paid for by them (in particular, catering, transportation and access to designated areas), information on which of those options have already been used, information on equipment issued to the participant and on any active equipment checkouts, an indication of whether the application has been approved, and the public keys of the participant’s devices required to verify their electronic pass. This information is used solely for verifying the participant at the entrance and in the halls and for providing the paid services and issuing equipment, is stored on the operator’s device only for the duration of the event, and is not further transferred or disclosed.
5.18. Business networking. If a personal data subject completes in their profile information about their interests and about what they are “seeking” and “offering” for professional networking, this information is shown to other event participants for the purpose of business networking. The completion of the said fields is voluntary; they may be left blank or cleared at any time.
5.19. Correspondence and attachments. In the mobile application, participants exchange private messages and take part in event chats. The Operator processes the text of messages, attached files (images, videos, documents), voice messages and polls, as well as read receipts. Correspondence is stored on the Operator’s servers and is accessible to the participants of the correspondence; authorised employees of the Operator gain access to individual messages only when handling a report of unacceptable content. Correspondence is retained for as long as the relevant chat exists or until the personal data subject deletes the message.
5.20. Deletion of the account and retention periods. The personal data subject is entitled to delete their account themselves - in the mobile application, in the “Personal account” section, or by contacting the Operator. Upon deletion, profile information is depersonalised immediately: first name, surname, photograph, telephone number, date of birth, identity document details and their scans, citizenship, gender, address, places of work, languages, interests, networking information and other profile information are erased, and the email address is released.
5.20.1. Within 180 (one hundred and eighty) days from the moment of deletion, the account may be recovered at the request of the personal data subject, in case the deletion was made in error. For this purpose the Operator retains a secure copy of the profile information. Upon expiry of that period, the copy and the related files are destroyed and recovery becomes impossible.
5.20.2. Scans of the identity document are destroyed earlier - within 30 (thirty) days from the moment of deletion of the account. The account is recovered in full, but the document will need to be attached again.
5.20.3. Every deletion, recovery and destruction upon expiry of the periods is recorded in the Operator’s internal log: date, time, method of the request and the internal record number. No personal data is entered into the log.
5.21. What is retained after deletion of the account and on what grounds.
5.21.1. Depersonalised participation information - the internal record number, the fact of participation in an event, the fact of payment of a fee, and the record of admission to the venue - is retained indefinitely. Such information does not permit identification of the personal data subject and does not constitute personal data.
5.21.2. Payment information is retained for the period established by accounting legislation, as its retention is an obligation of the Operator.
5.21.3. Messages in shared event chats remain available to the other participants of the correspondence; the author is depersonalised. Deletion of another person’s correspondence is technically impossible and would infringe the rights of its other participants.
5.21.4. A participant’s first name and surname are retained in the event archive indefinitely provided that the personal data subject gave separate consent to this when submitting the application. Such consent is given voluntarily by a separate checkbox, does not affect the ability to submit the application, and may be withdrawn by contacting the Operator. If no such consent was given, the first name and surname are erased upon deletion of the account.
5.21.5. Information about persons who have appeared publicly - speakers, moderators and competition award winners - is published in the Operator’s event programmes, news, reports and photographic materials. Such publications are standalone materials and are retained irrespective of whether the person has an account or whether it has been deleted.
6. Cross-border transfer of personal data
6.1. The Operator carries out the cross-border transfer of the personal data of event participants to the territory of the state in which the corresponding event is held.
6.2. The cross-border transfer is carried out only with the consent of the personal data subject, to the extent necessary for the admission of the participant to the venue, the preparation of visa documents, accommodation and transportation, and only to the following categories of recipients:
- the host party and the organisers of the event;
- the administration and the security service of the venue;
- diplomatic missions and consular offices;
- organisations providing accommodation and transportation services.
6.3. The state in which the event is held is indicated in the application form for participation in the corresponding event.
6.4. Prior to the commencement of the cross-border transfer of personal data, the Operator verifies that the foreign state concerned ensures adequate protection of the rights of personal data subjects and, in the cases provided for by the legislation of the Russian Federation, sends a notification to the authority empowered to protect the rights of personal data subjects.
6.5. The dissemination of personal data, that is, disclosure to an indefinite range of persons, is not carried out in the course of the cross-border transfer, except for the inclusion of the surname, first name and name of the organisation represented in the published lists of participants in the event — where the personal data subject has given separately expressed consent.
7. Procedure for withdrawal consent to the personal data processing
7.1. The personal data subject is entitled to withdraw consent to the processing of personal data at any time.
7.2. The withdrawal of consent is effected by one of the following means:
- in the personal account in the Operator’s information system;
- by sending a written request to the Operator’s registered address;
- by sending an enquiry to the email address info@world-assembly.org.
7.3. In the event of the consent withdrawal, the Operator ceases the processing of the personal data and ensures their destruction within a period not exceeding thirty days from the day of receipt of the withdrawal request, except where the processing continues on another lawful ground provided for by the legislation of the Russian Federation.
7.4. The withdrawal of consent to the receipt of informational messages is additionally effected by following the unsubscribe link contained in each message received, or in the settings of the personal account.
8. Updating, correction, deletion and destruction of personal data, responding to data subjects’ requests for access to personal data
8.1. Confirmation of the fact of personal data processing by the Operator, the legal grounds and purposes of the processing of personal data, and also the other information specified in part 7 of Article 14 of the Personal Data Law, are provided by the Operator to the personal data subject or to their representative within 10 working days from the moment of the enquiry or of the receipt of the request of the personal data subject or of their representative. This period may be extended, but by no more than five working days. To this end, the Operator should send the personal data subject a reasoned notification setting out the grounds for extending the period for providing the requested information.
8.2. The information provided does not include personal data relating to other personal data subjects, except where there are lawful grounds for disclosing such personal data.
8.3. The request must contain:
8.3.1. the number of the principal identity document of the personal data subject or of their representative, information on the date of issue of the said document and on the authority that issued it;
8.3.2. information confirming the participation of the personal data subject in relations with the Operator (the contract number, the date of conclusion of the contract, a conditional verbal designation and (or) other information), or information otherwise confirming the fact of the processing of personal data by the Operator;
8.3.3. the signature of the personal data subject or of their representative.
8.4. The request may be sent in the form of an electronic document and signed with an electronic signature in accordance with the legislation of the Russian Federation.
8.5. The Operator provides the information specified in part 7 of Article 14 of the Personal Data Law to the personal data subject or to their representative in the form in which the corresponding enquiry or request was sent, unless otherwise indicated in the enquiry or request.
8.6. If the enquiry (request) of the personal data subject does not set out all the necessary information in accordance with the requirements of the Personal Data Law, or if the subject does not have rights to access the requested information, a reasoned refusal is sent to that subject.
8.7. The right of the personal data subject to access their personal data may be restricted in accordance with part 8 of Article 14 of the Personal Data Law, including where the access of the personal data subject to their personal data infringes the rights and lawful interests of third parties.
8.8. In the event that inaccurate personal data are identified upon the enquiry of the personal data subject or of their representative, or upon their request or upon the request of Roskomnadzor, the Operator carries out the blocking of the personal data relating to that personal data subject, from the moment of such enquiry or of the receipt of the said request and for the period of verification, provided that the blocking of the personal data does not infringe the rights and lawful interests of the personal data subject or of third parties.
8.9. In case of confirmation of the fact of the inaccuracy of the personal data, the Operator, on the basis of the information submitted by the personal data subject or by their representative or by Roskomnadzor, or of other necessary documents, clarifies the personal data within seven working days from the day of the submission of such information and lifts the blocking of the personal data.
8.10. In case that unlawful processing of personal data is identified upon the enquiry (request) of the personal data subject or of their representative or of Roskomnadzor, the Operator carries out the blocking of the unlawfully processed personal data relating to that personal data subject from the moment of such enquiry or of the receipt of the request.
8.11. Upon detection by the Operator, Roskomnadzor or another interested party of the fact of an unlawful or accidental transfer (provision, dissemination) of personal data (access to personal data) that has resulted in an infringement of the rights of personal data subjects, the Operator shall:
8.11.1. notify Roskomnadzor within 24 hours of the incident that has occurred, of the presumed causes that resulted in the infringement of the rights of personal data subjects, of the presumed harm caused to the rights of personal data subjects and of the measures taken to eliminate the consequences of the incident, and also provide information on the person authorised by the Operator to interact with Roskomnadzor on matters connected with the incident;
8.11.2. notifiy Roskomnadzor within 72 hours of the results of the internal investigation of the incident identified and provide information on the persons whose actions caused it (whether such persons exist).
8.12. Procedure for the destruction of personal data by the Operator.
8.12.1. Conditions and periods for the destruction of personal data by the Operator:
- achievement of the purpose of the processing of personal data or the loss of the need to achieve that purpose — within 30 days;
- attainment of the maximum periods of storage of documents containing personal data — within 30 days;
- submission by the personal data subject (or their representative) of confirmation that the personal data were obtained unlawfully or are not necessary for the stated purpose of processing — within seven working days;
- withdrawal by the personal data subject of consent to the processing of their personal data, where their retention for the purpose of their processing is no longer required — within 30 days.
8.12.2. Upon achievement of the personal data processing purpose, as well as in the event of withdrawal by the personal data subject of consent to their processing, the personal data shall be subject to destruction, if:
- nothing to the contrary is provided by a contract to which the personal data subject is a party, beneficiary or guarantor;
- the operator is not entitled to carry out the processing without the consent of the personal data subject on the grounds provided for by the Personal Data Law or other federal laws;
- nothing to the contrary is provided by another agreement between the Operator and the personal data subject.
8.12.3. The destruction of personal data is carried out by a commission established by Order of the Secretary General of the Assembly.
8.12.4. The methods of destruction of personal data are established in the Operator’s local regulatory acts.
9. Liability of the parties
9.1. The Operator bears liability for the breach of the requirements of Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” in accordance with the legislation of the Russian Federation.
9.2. The User is entitled to claim compensation for losses and (or) compensation for non-pecuniary (moral) harm through the courts.
Non-pecuniary (moral) harm caused to the User as a result of the infringement of their rights, the breach of the rules of the processing of personal data, and also of the requirements for the protection of personal data established in accordance with Federal Law No. 152-FZ of 27 July 2006 “On Personal Data”, as well as of the provisions of the Policy, is subject to compensation in accordance with the legislation of the Russian Federation. Compensation for non-pecuniary (moral) harm is effected irrespective of compensation for property damage and of the losses incurred by the User.
10. Resolution of disputes
10.1. In case of disputes and/or disagreements arising out of the relations between the User and the Operator, such matters are resolved in accordance with the applicable legislation of the Russian Federation.
10.2. The applicable legislation of the Russian Federation applies to the Policy and to the relations between the User and the Operator.
11. Final provisions
11.1. The Operator is entitled to make amendments to the Policy without the consent of the User.
11.2. A new edition of the Policy enters into force from the moment of its posting on the Websites, unless otherwise provided by the new edition of the Policy.
The new edition of the Policy applies to relations that arise after its entry into force.
11.3. All proposals or questions concerning the Policy should be communicated to the email address info@world-assembly.org or via post to the address: 4A Uspensky Lane, Moscow, 127006.
This is a translation of the Russian-language Policy. In the event of any discrepancy between the Russian and English texts, the Russian text shall prevail.