{"id":1859,"date":"2026-05-26T13:03:35","date_gmt":"2026-05-26T10:03:35","guid":{"rendered":"https:\/\/divaplus.org\/?page_id=1859"},"modified":"2026-05-26T13:03:37","modified_gmt":"2026-05-26T10:03:37","slug":"data-protection-policy","status":"publish","type":"page","link":"https:\/\/divaplus.org\/en\/data-protection-policy\/","title":{"rendered":"DATA PROTECTION POLICY"},"content":{"rendered":"\n<p class=\"wp-block-wd-paragraph wd-15895317\"><strong>DIVA PLUS EOOD \u2013 UIC 175013870<\/strong> Sofia, Bakston District, Bl. 19, Entr. A, Apt. 6, Bulgaria | <a href=\"https:\/\/divaplus.org\/\">https:\/\/divaplus.org\/<\/a><\/p>\n\n\n\n<div class=\"wp-block-wd-divider wd-style-line wd-b19cdb2f\"><\/div>\n\n\n\n<h3 class=\"wp-block-wd-title title wd-67ac0554\">1. Purpose, Scope and Users<\/h3>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-690ea004\">DIVA PLUS EOOD (the &#8220;Company&#8221;) strives to comply with all applicable laws and regulations relating to personal data protection in the countries where the Company operates.<\/p>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-50e7b8b6\">This Policy defines the core principles by which the Company processes personal data of consumers, clients, suppliers, business partners, employees and other individuals, and sets out the responsibilities of business departments and employees during personal data processing.<\/p>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-cb336c73\">The Policy applies to all employees, permanent or temporary, as well as all contractors working for or on behalf of the Company.<\/p>\n\n\n\n<div class=\"wp-block-wd-divider wd-style-line wd-2131f6e6\"><\/div>\n\n\n\n<h3 class=\"wp-block-wd-title title wd-7725626f\">2. Reference Documents<\/h3>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-949725f4\">This Policy is based on Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and the applicable national legislation implementing GDPR.<\/p>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-4666d04e\">It is related to: the Employee Data Protection Policy, Data Retention Policy, Data Protection Officer job description, data inventory and processing guidelines, individual access request procedures, data protection impact assessment, information security policies and breach notification procedures.<\/p>\n\n\n\n<div class=\"wp-block-wd-divider wd-style-line wd-8445a9bc\"><\/div>\n\n\n\n<h3 class=\"wp-block-wd-title title wd-d7a96789\">3. Definitions<\/h3>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-743e8211\"><strong>Personal Data<\/strong> \u2013 any information relating to an identified or identifiable natural person via an identifier such as: name, identification number, location data, online identifier or factors specific to physical, physiological, genetic, mental, economic, cultural or social identity.<\/p>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-d4d37219\"><strong>Sensitive Personal Data<\/strong> \u2013 data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, health data, sex life or sexual orientation.<\/p>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-2e319768\"><strong>Data Controller<\/strong> \u2013 the natural or legal person which determines the purposes and means of the processing of personal data.<\/p>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-469370c4\"><strong>Data Processor<\/strong> \u2013 a person or entity that processes personal data on behalf of the Controller.<\/p>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-2e053663\"><strong>Processing<\/strong> \u2013 any operation or set of operations on personal data: collection, recording, storage, use, disclosure, erasure or destruction.<\/p>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-d0d5742b\"><strong>Pseudonymisation<\/strong> \u2013 processing of personal data in such a manner that they can no longer be attributed to a specific data subject without the use of additional information stored separately and protected by technical and organisational measures.<\/p>\n\n\n\n<div class=\"wp-block-wd-divider wd-style-line wd-a6d91f9e\"><\/div>\n\n\n\n<h3 class=\"wp-block-wd-title title wd-bd4d285f\">4. Core Principles for Processing Personal Data<\/h3>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-f3a3fa1e\">DIVA PLUS EOOD is committed to processing personal data in accordance with the following principles:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Lawfulness, fairness and transparency<\/strong> \u2013 data is processed only on a lawful basis.<\/li>\n\n\n\n<li><strong>Purpose limitation<\/strong> \u2013 data is collected for specified and explicit purposes.<\/li>\n\n\n\n<li><strong>Data minimisation<\/strong> \u2013 only data necessary for the stated purposes is collected.<\/li>\n\n\n\n<li><strong>Accuracy<\/strong> \u2013 data is kept accurate and up to date.<\/li>\n\n\n\n<li><strong>Storage limitation<\/strong> \u2013 data is retained no longer than necessary.<\/li>\n\n\n\n<li><strong>Integrity and confidentiality<\/strong> \u2013 data is processed in a manner that ensures appropriate security against unauthorised access, loss or destruction.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-wd-divider wd-style-line wd-1ebdbbaa\"><\/div>\n\n\n\n<h3 class=\"wp-block-wd-title title wd-7f2b227b\">5. Embedding Data Protection in Business Processes<\/h3>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-5b128423\">DIVA PLUS EOOD integrates data protection into all business processes through the following measures:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Collecting the minimum amount of personal data necessary (data minimisation).<\/li>\n\n\n\n<li>Ensuring the lawfulness and accuracy of collected data.<\/li>\n\n\n\n<li>When engaging third parties for data processing, ensuring an adequate level of protection.<\/li>\n\n\n\n<li>Applying appropriate safeguards for any cross-border transfer of personal data.<\/li>\n\n\n\n<li>Data subjects have the right to access, rectify, erase, port their data and to be forgotten.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-wd-divider wd-style-line wd-db9a9bb4\"><\/div>\n\n\n\n<h3 class=\"wp-block-wd-title title wd-29e58e4e\">6. Guidelines for Fair Processing<\/h3>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-a0f9a2e9\">Personal data must be processed only on a lawful basis. Prior to or at the time of collection, data subjects must be properly informed through a privacy notice regarding: the purposes of processing, recipients of the data and any potential transfer to third countries.<\/p>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-98bd120f\">When processing is based on consent, the Company ensures that consent is documented and can be withdrawn at any time. Data may only be processed for the originally specified purposes. If the purpose changes, new consent must be obtained.<\/p>\n\n\n\n<div class=\"wp-block-wd-divider wd-style-line wd-dc8439f0\"><\/div>\n\n\n\n<h3 class=\"wp-block-wd-title title wd-c330a72e\">7. Organisation and Responsibilities<\/h3>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-0c225aa6\">Responsibility for proper processing of personal data rests with all persons who work for or with the Company. The main roles are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Data Controller<\/strong> \u2013 responsible for system security, approval of data protection declarations and interaction with the Data Protection Officer.<\/li>\n\n\n\n<li><strong>Data Protection Officer (DPO)<\/strong> \u2013 responsible for raising awareness, training employees and managing relationships with suppliers and third parties.<\/li>\n\n\n\n<li><strong>Employees<\/strong> \u2013 all employees are personally responsible for processing personal data in accordance with this Policy.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-wd-divider wd-style-line wd-bc98b0c6\"><\/div>\n\n\n\n<h3 class=\"wp-block-wd-title title wd-1cc8fadc\">8. Actions in Case of Personal Data Breach<\/h3>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-90cc12a1\">In the event of a suspected or actual personal data breach, an internal investigation must be immediately conducted and appropriate corrective measures taken.<\/p>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-fd48f9fc\">When there is a risk to the rights and freedoms of data subjects, the competent supervisory authority must be notified without undue delay and, where feasible, within 72 hours of becoming aware of the breach.<\/p>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-4531c15f\">The competent supervisory authority is: <strong>Commission for Personal Data Protection (CPDP)<\/strong> Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd. | Tel: +359 2 9153518 | <a href=\"http:\/\/www.cpdp.bg\" target=\"_blank\" rel=\"noopener\">www.cpdp.bg<\/a><\/p>\n\n\n\n<div class=\"wp-block-wd-divider wd-style-line wd-18272868\"><\/div>\n\n\n\n<h3 class=\"wp-block-wd-title title wd-1825ec49\">9. Audit and Accountability<\/h3>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-d84223d4\">Compliance with this Policy is reviewed periodically by the Data Controller. Violations may result in disciplinary measures and civil or criminal liability.<\/p>\n\n\n\n<p class=\"wp-block-wd-paragraph wd-3064e1af\"><em>This Policy is adopted by the management of DIVA PLUS EOOD and enters into force from the date of its publication on the website <a href=\"https:\/\/divaplus.org\/\">https:\/\/divaplus.org\/<\/a><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1859","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/divaplus.org\/en\/wp-json\/wp\/v2\/pages\/1859","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/divaplus.org\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/divaplus.org\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/divaplus.org\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/divaplus.org\/en\/wp-json\/wp\/v2\/comments?post=1859"}],"version-history":[{"count":1,"href":"https:\/\/divaplus.org\/en\/wp-json\/wp\/v2\/pages\/1859\/revisions"}],"predecessor-version":[{"id":1860,"href":"https:\/\/divaplus.org\/en\/wp-json\/wp\/v2\/pages\/1859\/revisions\/1860"}],"wp:attachment":[{"href":"https:\/\/divaplus.org\/en\/wp-json\/wp\/v2\/media?parent=1859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}