Privacy Notice for User Management and Log Registers

Privacy Notice for the VAV Group’s user management and log registers.

1. Contact details of the data controller for data protection matters

Data controllers

The data controllers are the landlords of the properties owned by the VAV Group companies listed below, each in respect of their own tenants; hereinafter referred to as “VAV” or “Data Controller”.

VAV Yhtymä Oy (business ID 0640915-7) and its subsidiaries listed below

  • VAV Asunnot Oy
  • VAV Palvelukodit
  • VAV Hoiva-asunnot Oy

Contact details for data protection matters

email: tietosuoja@vav.fi

Address: VAV Yhtymä Oy, Data Protection, Veturikuja 7, 01300 Vantaa

2. Data subjects and the content of the register

The Data Controller’s information and communication systems utilise access rights management to control access to and use of the systems. The register stores data on data subjects, i.e. system users, who include the Data Controller’s employees, as well as employees of customers, subcontractors and other organisations to whom the Data Controller has granted access rights to the Data Controller’s systems.

The user management register contains information on the access rights granted to the systems, their duration and their scope. It contains the following personal data:

  • first name and surname, user ID, employee ID number
  • contact details
  • organisational unit, place of work, job category
  • in the case of an external person, the contract on the basis of which the access rights have been granted
  • information on who or which unit grants access rights
  • any information regarding the provision of a user and confidentiality agreement to the data controller
  • access rights, their validity period, user ID

Log files contain event data from the systems: time, event, author, access rights used to perform the event, source of the event (where it was performed, where the change data originated), target of the event (which data or system the action was directed at), status of the event. For example:

  • The maintenance log contains information on changes to access rights, deletions and additions, the management of error situations relating to the use of registers, and changes made to the system
  • The access control log contains information on logins and logouts at user, group and application levels, failed login attempts and changes to access rights
  • The change log contains information on changes to the data content of systems: deletions and additions, as well as changes to system parameters and configuration files
  • The error log contains information on errors detected in the monitored system or event, as well as errors and inconsistencies detected in the register.

In addition, the user management and logging system processes and collects personal data of users of the access rights and log register, e.g. the level of access to the logging system (how the user in question can view, edit and/or delete logs), the log data viewed, edited and deleted by the user, as well as the timestamps and identification data relating to these actions.

3. Legal bases and purposes of the processing of personal data

The purpose of the Register is to ensure the continuity and information security of the Data Controller’s services and operations, as well as to prevent and minimise any damage or harm caused to the Data Controller, users and other parties, and

  • to prevent and investigate errors and faults occurring in our information systems
  • to protect personal data and other confidential information
  • analysing information security incidents and preventing and investigating information security breaches
  • to intervene in the unauthorised use, disclosure and other processing of data
  • compiling statistics on system usage.

With regard to information systems containing personal data, the basis for processing is the data controller’s statutory obligation to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32 of the EU General Data Protection Regulation and Section 6 of the Data Protection Act).

With regard to user management and the processing of log data in electronic communications information systems, the maintenance of the register is based on Chapters 17 and 33 of the Act on Electronic Communications Services.

With regard to information systems concerning the selection of tenants for state-subsidised rental housing, the processing is based on the statutory obligation of a private entity performing a public administrative task to manage access rights to information systems and to collect log data (Sections 16–17 of the Act on Information Management in Public Administration).

With regard to other information systems, the basis for processing is a legitimate interest based on the ownership, control and use of the data and information systems (Article 6(1)(f) of the EU General Data Protection Regulation).

4. Where data is collected from

Data for the user management register is routinely collected from the data subject themselves when they apply for access rights and in connection with the creation of access rights, from the controller’s human resources management system or from the data subject’s employer. The primary source of data stored in the log register is the data subject themselves, as well as the information systems whose events are recorded in the logs.

5. To whom is data disclosed or transferred

The data controller shall not disclose data to external parties without the data subject’s consent, unless this is necessary for the prevention and investigation of misconduct by the police and other investigative authorities, for the handling of legal claims (e.g. to legal advisers and courts), or to fulfil the data controller’s statutory obligations.

The Data Controller uses subcontractors for the processing of personal data in accordance with this policy. In such cases, personal data may be transferred to subcontractors to the extent necessary for the subcontractor to perform its services. Subcontractors process personal data on behalf of and for the account of the Data Controller in accordance with its instructions. Subcontractors are bound by agreements entered into with the Data Controller regarding the processing of personal data, including provisions on confidentiality and data security. An up-to-date list of the subcontractors used by the Data Controller in the processing of stored data.

If, in exceptional circumstances, personal data is processed in other countries, VAV ensures an adequate level of data protection by agreeing to the transfer using standard contractual clauses approved by the European Commission.

6. Principles of data protection and data retention periods

Only those persons who require the data to carry out their work duties are authorised to access it.

The data is protected by personal usernames and passwords. Access to and processing rights for the data are granted on the basis of work duties. Staff and subcontractors processing the data are bound by confidentiality and data security obligations. The protection of electronically stored data is based on access control, technical protection of databases and servers, monitoring of their use through the collection of log data, physical security of premises, access control, firewalls and other data communication security measures, as well as data backups.

Staff are briefed and trained on the processing of personal data through regularly organised data protection and information security training sessions.

Personal data is retained for as long as is necessary for the purpose for which it was collected.  As a general rule, data is retained for as long as the data subject has access rights to the information system and for a reasonable period after such access rights have expired.

In practice, the majority of personal data may be required, for example, to investigate data protection breaches or data leaks; for this reason, the data is retained at least until the limitation periods for criminal and civil claims, as well as any related legal proceedings, have expired. The limitation periods for bringing legal actions and prosecutions vary between two and five years for data protection offences and infringements, as well as for any resulting claims for damages. According to Section 145 of the Act on Electronic Communications Services, event data must be retained for two years from the date of recording.

7. Rights of the data subject to access, rectify and other rights

Data subjects have the following rights under the General Data Protection Regulation:

  • The customer has the right to access their personal data held in the register.
  • The data subject has the right to request the rectification or erasure of data that is inaccurate, out of date, unnecessary or unlawful.
  • The data subject also has the right to withdraw their previously given consent to the processing of their personal data at any time. The withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal of consent.

If the data subject has provided their personal data to the data controller and the processing is based on consent or a contract, they have the right to receive this data in a structured, commonly used and machine-readable format and the right to transfer the data to another controller in accordance with applicable legislation.

Where the processing of personal data is based on a legitimate interest, the data subject has the right to object to the processing of their data on grounds relating to their particular personal situation. When making such a request, the data subject must specify the particular situation on which their objection is based.

In situations specified by law, the data subject may request that the processing of their personal data be restricted, for example by suspending it in whole or in part, where the data subject considers that there is uncertainty regarding the accuracy of the data or its processing.

A request to access or restrict data may be made via the data request form available on the VAV website. A request to rectify data may be made the OmaVAV service or via the data request form on the website.

Data subjects have the right to lodge a complaint regarding the processing of personal data with the Data Protection Commissioner.