Orion Corporation's reputation and materiality survey register
General Data Protection Regulation (2016/679), Articles 13 and 14
Date of drafting: September 18th, 2018
We may update or revise this Information Notice at any time, with any notice to you as may be required under applicable law.
1. Controller / Company
Orion Corporation (Company Identification Number: 1999212-6)
Tel. 010 4261
2. The person in charge / contact person
Head of Corporate Responsibility Noora Paronen
Tel. +358 10 426 2258
Contact details of the Data Protection Officer: Heidi Arala
3. Name of the data file
Orion Corporation’s reputation and materiality survey 2018
4. The purpose for processing the personal data / recipients (or categories of recipients) of personal data / the legal basis for processing the personal data
The purpose for use of this data file, which is project specific, is to enable Orion Corporation’s reputation and materiality survey to develop Orion Corporation’s operations and to develop and manage its stakeholder relations. The survey is carried out in cooperation with EllunKanat, GAIA and Norstat. The technical implementation of the survey is carried out by Norstat. Orion Corporation transfers personal data to the service providers of the survey EllunKanat and GAIA. EllunKanat and GAIA transfer personal information to the technical developer of the survey, Norstat, for the implementation of the service.
We may share your information with third parties who assist us by performing technical operations such as data storage and hosting.
If ownership or control of Orion Corporation or all or any part of our products, services or assets changes, we may disclose your personal data to any new owner, successor or assignee.
The legal basis for processing of the personal data is legitimate interests of the controller or a third party/ the development of controller´s operations and the management and development of the controller´s relationship with its stakeholders. We only process personal data based on our legitimate interests, in case we have deemed, based on the balancing of interest test, that the rights and interests of the data subject do not override our legitimate interest.
5. Content of the data file
The register contains information about Orion’s stakeholders, such as policymakers and influencers (authorities or different organisations), partners’ employees as well as investors. The following information regarding stakeholders may be collected: name, email address and the stakeholder group to which the individual belongs.
6. Source of information
Orion Corporation’s employees and contact information about Orion's stakeholder groups available from public sources, such as the internet.
7. Retention period of the personal data
The controller retains personal data for about 60 days after the personal data is no longer needed for the purpose of Orion’s reputation and materiality survey.
The contents of the register are updated during the project to ensure that it contains only relevant and up-to-date information relevant to the intended use.
8. The principles how the data file is secured
Data is technically protected so that no third party has access to the data. Data will be encrypted when the personal data is transferred to controller´s partners in connection with the provision of the services in accordance with section 4.
9. Right of access
The data subject shall have the right of access, after having supplied sufficient search criteria, to the data on himself/herself in the personal data file, or to a notice that the file contains no such data. The controller shall at the same time provide the data subject with information on the sources of the data, on the uses for the data in the file, and the destinations of disclosed data.
The data subject who wishes to have access to the data on himself/herself, as referred to above, shall make a request to this effect to the person in charge at controller by a personally signed or otherwise comparably verified document and by verifying his or her identity by attaching a copy of an official identification document.
Verification requests should be made by contacting the named representative in section 2.
10. Right to object to processing
In case the legal basis for processing the personal data is the legitimate interests of the controller, the data subject has the right to object to processing on grounds relating to his or her particular situation.
In case the data subject wishes to use its above-mentioned right, he or she shall make a request to this effect to the person in charge at the data controller by a personally signed or otherwise comparably verified document in writing to the representative of the data controller named under section 2. hereinabove.
11. Rectification, restriction of processing and erasure
A controller shall, on its own initiative or at the request of the data subject, without undue delay rectify, erase or supplement personal data contained in its personal data file if it is erroneous, unnecessary, incomplete or obsolete as regards the purpose of the processing.
Under specific circumstances, the data subject has the right to obtain from the controller restriction of processing of his or her personal data.
If the controller refuses the request of the data subject of the rectification of an error, a written certificate to this effect shall be issued. The certificate shall also mention the reasons for the refusal. In this event, the data subject may bring the matter to the attention of the Data Protection Ombudsman.
The controller shall undertake reasonable measures to notify the erasure to the controllers to whom the data has been disclosed and who are processing the data. However, there is no duty of notification if this is impossible or unreasonably difficult.
Requests for the above uses of data subject’s rights shall be made by contacting the representative of the controller named under section 2 hereof.