Suoma Sámi Nuorat

Privacy Policy

This is the Privacy Policy statement in accordance with the Personal Data Act of Finland (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Prepared on 13.09.2020. Last modified 13.09.2020.

 

1. The controller

Suoma Sámi Nuorat ry, Pulkkatie 19 A 4, 99400 Enontekiö

suomasaminuorat@gmail.com

 

2. Contact person responsible for the register

Petra Laiti
treasurer
petra.laiti@gmail.com

 

3. Name of the register

Association member register

 

4. Legal basis and purpose of the processing of personal data

The legal basis for the processing of personal data under the EU General Data Protection Regulation is – the consent of the person (documented, voluntary, identified, informed and unambiguous) – the Association Act 503/1989 The purpose of the processing of personal data is to maintain a register of members required by the Associations Act.

 

5. Information content of the register

The information to be stored in the register is the member’s full name and domicile as required by the Associations Act. In addition, the member’s Year of Birth and e-mail address are stored. The year of birth is required to establish that a member meets the conditions for membership. The e-mail address is stored so that the board of the association can contact the member if necessary. Member information will be retained until membership expires. Membership is automatically terminated at the annual meeting of the association in the year in which the member reaches the age of 30. A member may also request the termination of his or her membership or the Board may decide to dismiss the member.

 

6. Sources of information

The information stored in the register is obtained by the member himself in connection with the membership application.

 

7. Transfers of data and transfers of data outside the EU or the EEA

The information is not regularly disclosed to other parties.

 

8. Registry Security Principles

The register shall be handled with due care and the data processed by the information systems shall be adequately protected. The controller shall ensure that the stored data is treated confidentially and only by the contact person responsible for the register.

 

9. Right of inspection and right to request correction of information

Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check the data stored about him or her or request a correction, the request must be sent in writing to the data controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the timeframe set out in the EU Data Protection Regulation (generally within one month).

 

10. Other rights related to the processing of personal data

A person in the register has the right to request the removal of his or her personal data from the register (“right to be forgotten”). Data subjects also have other rights under the EU’s general data protection regulation, such as restrictions on the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the member within the timeframe set out in the EU Data Protection Regulation (generally within one month).