What is data protection?
Data protection refers to rules, practices, and measures established to protect personal data.
What is considered personal data according to the Law on Protection of Personal Data?
Personal data includes information relating to natural persons:
Personal data may also include special categories of personal data or criminal conviction and offences data.
Find more information about the categories of personal data that the Bank processes in Privacy Policy https://procreditbank-kos.com/eng/privacy-policy/.
Which Law regulates data protection in Kosovo?
Law no. 06/L-082 on Protection of Personal Data determines the rights, responsibilities, principles, and punitive measures in regard to protection of personal data and privacy of individuals.
Are the data of legal entities considered personal data?
Data of legal entities such as name and surname, email address, financial data, and others do not classify as personal data according to Law on Protection of Personal Data.
Does Law on Protection of Personal Data apply to personal data of deceased persons?
This Law does not apply to personal data of deceased persons.
What does Law on Protection of Personal Data mean by “processing”?
“Processing” is a broad term that covers just about anything you can do with data: collection, organisation, structuring, storage, alteration, consultation, use, communication, combination, restriction, erasure or destruction of personal data.
Who enforces the implementation of Law on Protection of Personal Data?
Implementation of Law on Protection of Personal Data is enforced by the Information and Privacy Agency (Agency).
Find more information about the Agency in https://aip.rks-gov.net/.
What is the difference between a data controller and a data processor?
The data controller is any natural or legal person, organization, public authority, or other body which determines which personal data is collected and the purposes of the processing. ProCredit Bank is the data controller of the personal data provided by natural persons when they are using the services that the Bank offers.
The data processor is any natural or legal person or organization which processes personal data for and on behalf of data controller. Examples of typical data processor services include third party data storage, data analytics, or software companies.
What are principles of personal data processing?
Law on Protection of Personal Data sets out seven principles for the lawful processing of personal data. These principles should be considered in every data processing activity.
What are the lawful basis for processing?
The lawful basis for processing are set out in Article 5 of Law on Protection of Personal Data. At least one of these must apply whenever the Bank processes your personal data:
What is the role of Data Protection Officer?
Data Protection Officer (DPO) is responsible for understanding the Law and ensuring Bank’s compliance. The DPO is the main point of contact for the Agency.
You can contact Bank’s Data Protection team at kos.dpo@procredit-group.com.
What rights do individuals have according to the Law on Protection of Personal Data?
Law on Protection of Personal Data provides the following rights for individuals:
Do I have absolute rights to protection of personal data?
The right to data protection is not an absolute right. It must always be balanced against other values, fundamental rights, human rights, or public and private interests and there may be circumstances under which the Bank may have grounds to refuse your request to exercise your data protection rights.
What is a personal data breach?
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes breaches that are the result of both accidental and deliberate causes.