Information about Personal Data Processing
Declaration on Personal Data Processing
National Electronic Tool (NEN) | |
---|---|
Administrator of personal data | Ministry of Regional Development Staroměstské náměstí 932/6, Staré Město, 110 00 Praha Organization ID Number: 66002222 Data Box: 26iaava Email: gdpr@mmr.cz |
Scope of data processing | In the NEN system, so-called structured data are processed. Unstructured data in procurement documents, invitations to tender, participants' submissions, etc. are no longer processed in the NEN system to the extent defined by the GDPR Regulation. These unstructured data are used exclusively for contracting authorities, they are only stored in the NEN system. The NEN system shall ensure the security of these documents. No content processing is performed on them. The following structured data about the data subject (self-employed individual, private individual, any system user) are stored in the information system:
|
Purpose of data processing | Fulfillment of legislative requirements regarding public procurement according to Act 134/2016 Coll. on public procurement and related decrees to the Fulfillment of requirements for ensuring cyber security according to relevant legislation. |
Lawful grounds for personal data processing |
|
Recipient of personal data | Contracting authorities
Registration of Data Subjects into the NEN SystemRegistration to IS NEN is carried out in the name of a legal entity or Registration into the NEN system is performed by legal entities or self-employed individuals..
Administration of User AccountsThe accounts are managed by a natural person.
|
Intention to transfer personal data to a third county or international organization | The administrator of personal data does not intend to transfer personal data to a third country or international organization. |
Storage duration of personal data | The storage duration of personal data is governed by Act No. 134/2016 Coll. - Act on Public Procurement and subsequently by the filing and shredding rules of each contracting authority. |
Right of access to personal data | The data subject can view their own processed personal data in the user account details. |
Right to rectification of personal data | The data subject may correct their personal data independently. |
Right to erasure of personal data | The right of data erasure does not apply to those data subjects who have have performed or are performing public contract administration or have worked with a specific public contract in any logged manner within the NEN system. |
Right to restriction of processing of personal data | This right is not valid because the processing of personal data is based on a legal requirement. |
Right to object to the processing of personal data | This right is not valid because the processing of personal data is based on a legal requirement. |
Right to personal data portability | This right is not valid because the processing of personal data is based on a legal requirement. |
Right to withdraw consent to the processing of personal data | Consent to the processing of personal data cannot be withdrawn. Personal data is processed on the basis of a legal requirement, not on the basis of consent given by the data subject. |
Right to lodge a complaint with a supervisory authority | The data subject has the right to file a complaint with the Personal Data Protection Office. |
Obligation to provide personal data and consequences of failure to provide | The processing of personal data results from the legal requirement mentioned above, and is not subject to consent of the data subject. However, the data subject must provide some personal data himself in the context of his identification. In the event of failure to provide the relevant data and the resulting failure to identify the data subject, the data subject will not be allowed to log in as a NEN System User. |
Automated decision-making and profiling of personal data | There is no automated individual decision-making or profiling of personal data. |
Other purposes for processing of personal data | Personal data are not processed for purposes other than the above-mentioned purpose of processing personal data. |
Cookies
In order for the site to function properly, it is sometimes necessary to place small data files, known as cookies, on your device.
What are cookies?
Cookies are small text files that websites store on your computer or mobile device when you start using these sites. This way, the website remember your preferences and actions you have taken on them for a certain period (e.g., login details, language, font size, and other display preferences), so you do not have to enter this data again and skip from one page to another.
Title | Recommendations | Expiration | Who has access to the information (us or a third party) | Description | Category |
---|---|---|---|---|---|
NEN.client.Session | Do not block, the page would not be functional | Session | NEN | Designed to store the session when working on the public part of the NEN system. | Essential functional |
BIGipServer* | Do not block, the page would not be functional | 8 hours | NEN | Specifies to which web server the communication will be routed. | Essential functional |
XSRF-TOKEN | Do not block, the page would not be functional | Session | NEN | Cookie to prevent XSRF attack (cross site request forgery) | Essential functional |
XSRF-TOKEN-Client | Do not block, the page would not be functional | Session | NEN | Cookie to prevent XSRF attack (cross site request forgery) | Essential functional |
*MW-FARM* | Do not block, the page would not be functional | Session | NEN | Specifies to which web server the communication will be routed when working with the authorized part of the NEN system. | Essential functional |
PRODMW* | Do not block, the page would not be functional | Session | NEN | Designed to save the session when logging in and working in the authorized part of the NEN system. | Essential functional |
tSW.spu.NEN | Do not block, the page would not be functional | Session | NEN | Technical cookie enabling working with links to download documents. | Essential functional |
ai_session | Blocking is possible | 30 minutes | Microsoft Azure | It is used to collect statistical data about the use of the website. The cookie stores a unique anonymous identifier to recognize users on repeated visits. | Statistical and performance |
ai_user | Blocking is possible | 1 year | Microsoft Azure | It is used to collect statistical data about the use of the website. The cookie stores a unique anonymous identifier to recognize users on repeated visits. | Statistical and performance |
tSW.lang.NEN | Blocking is not recommended | NEN | It is used to store the preferred language in the authorized part of the NEN system. | Preferences | |
Language | Blocking is not recommended | 1 year | NEN | Automatically sets the language of the website according to the browser language settings, with the possibility to change it. | Preferences |
UserCookiesSettings | Blocking is not recommended | 1 year | NEN | It is used to save the settings for the use of cookies. | Preferences |
glide_session_store | Blocking is not recommended | 1 Hour | ServiceNow | To preserve the session when moving customers from one node to another, 'glide_session_store' has been added. Enabling this will ensure that its users will not be logged out when they are transfered from one datacenter to another. | Essential functional |
glide_user_activity | Blocking is not recommended | Session | ServiceNow | This cookie prevents an active user, who has not opted for the 'Remember Me' option, from being logged out. It refreshes periodically when the user is active during the session. This cookie is not part of any authentication or login mechanism. Its presence is solely to detect if there is any activity on the user's side so that the session does not lock the user out during an active session. This helps the server to recover the session. This item does not pose any security issues. | Essential functional |
JSESSIONID | Blocking is not recommended | Session | ServiceNow | The 'JSESSIONID' cookie is a session created by the application when the user first logs into the application, and is created by the underlying server to preserve the attributes of the user session. | Essential functional |
BIGipServerpool_mmrprod | Blocking is not recommended | Session | ServiceNow | The security attribute for this cookie has been implemented on the ServiceNow BigIP load balancing tools. The BigIP cookie is used for load balancing decisions and absolutely no customer data is published. | Essential functional |
glide_user_route | Blocking is not recommended | 1 year | ServiceNow | The glide_user_route cookie defines which application server (or node) in the cluster you are going to so it remains consistent unless otherwise routed/redirected from the load balancer. In short, it controls the persistence of nodes. | Essential functional |
We use third party cookies to help us improve or promote the National Electronic Tool. At the same time, we do not send the content of the viewed pages to these parties in any way. Similarly, it is not technically possible to identify a specific user of the National Electronic Tool system through any third-party cookies.
Application insights (cookie name: ai_user, ai_session) are used to collect statistical data about the use of the website. The cookie stores a unique identifier to recognize users on repeated visits (description of how Application insights works).
The NIPEZ Central ServiceDesk is used to display operational information and news content, FAQs, operating rules, manuals, the NEN chatbot, tutorial, registrations and the operational information subscription function.
Cookie settings
During your visits to our website, we use the following types of cookies. You can grant us consent to use all or only selected types. You can adjust your previously granted consents here.