Back to home
Legal

GDPR Manual

How to exercise your rights under the EU General Data Protection Regulation — access, correction, restriction of processing and erasure of personal information held by nuvoteQ. (ML-GM-02 v00, effective 1 November 2021.)

Last updated

1 November 2021

01

Right of Access to Information

The right of access plays an integral role in the General Data Protection Regulation (GDPR). This allows the Data Subject to act on further rights including, but not limited to, the request to correct Personal Information, to restrict the processing activities thereof, or to request that Personal Information be Erased or “forgotten”.

The Controller of the data should thus make every effort to provide the Data Subject with the requested information as detailed in Article 15 of the GDPR. It is important to note that in some instances, specifically when it comes to Clinical Trial related activities, nuvoteQ will assume the role of the Processor of the data and would thus be obliged to notify the Client of any such Subject access requests before exercising any further duties.

02

Availability of this Manual

This document serves as the nuvoteQ GDPR — Right of Access, Correction, Restriction of Processing and Erasure of Personal Data Manual (the “GDPR Manual”) in accordance with the General Data Protection Regulation to facilitate access to records held by nuvoteQ.

  • The Manual is available for inspection at the offices of nuvoteQ, free of charge.
  • A copy of the Manual is available to any person of the public in a PDF format on request from the Data Protection Officer referred to in this Manual.
  • Note: The Manual may be amended from time to time and, as soon as any amendments have been finalised, the latest version will be made available.
03

Who may request access

The General Data Protection Regulation (GDPR), under Article 15, gives individuals the right to request a copy of any of their Personal Information which is being processed. These requests are often referred to as “Data Subject Access Requests”, or “Access Requests”. Requestors may make a request as:

  • A personal requestor (Data Subject) who requests a record about him/herself.
  • A third-party requestor who requests a record about someone else with that person's consent and where it is required for the protection of that person's legal right.
  • A public body who may request a record if it fulfils procedural compliance, the record is required for the exercise or protection of a right, and no grounds for refusal exist.
04

Contact details of the nuvoteQ Data Protection Officer

The Chief Executive Officer of nuvoteQ has delegated his powers to the Data Protection Officer below in terms of GDPR to handle all requests on nuvoteQ's behalf and ensure that the requirements of GDPR are administered in a fair, objective and unbiased manner.

Data Protection Officer: Marina Lazaridis — marina@nuvoteq.io

Deputy Data Protection Officer: Ricky Haug — ricky@nuvoteq.io

Physical address: 47 Hazelwood Rd, Hazelwood, Pretoria, 0081, South Africa.

Tel: +27 (0) 12 943 5949

05

Confidentiality and access to information

nuvoteQ will protect the confidentiality of information provided to it by third parties (OP-GM-03, PC-HR-01, PC-GM-03), subject to nuvoteQ's obligations to disclose information in terms of any applicable law or a court order.

If access is requested to a record that contains information about a third party, nuvoteQ is obliged to attempt to contact that third party to inform them of the request. This permits the third party the opportunity to consent to the access or provide reasons why access should be denied. Where reasons are furnished, the Data Protection Officer will consider them in determining whether access should be granted.

06

Company structure

This Manual has been prepared in respect of the nuvoteQ organisational structure (as applicable). The scope of the Manual serves to provide a reference regarding the records held by nuvoteQ at its registered office and other applicable business premises.

nuvoteQ is a South African based and registered Company providing global software solution services to CROs (and other companies within the Healthcare industry) as well as other industry organisation(s). Additional information on nuvoteQ is available on the website nuvoteq.io.

07

Key definitions

Key definitions used in this Manual:

  • Data — Information, facts and statistics used for reference or analysis in electronic form.
  • Data Subject — The person to whom the Personal Information relates.
  • Data Protection Officer (DPO) — Someone, either an employee or a professional hired externally, who has responsibility for ensuring that their organisation is compliant with GDPR.
  • Personal Information — Information relating to an identifiable, living natural person or an identifiable, existing juristic person, as detailed in POPIA and GDPR (including race, gender, marital status, nationality, contact details, biometrics, opinions, correspondence and identifiers). Personal Information must always be treated as Confidential Information, even after the individual's death, and includes Pseudonymised or de-identified data that can be re-attributed.
  • Controller (Joint Controller) — The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processor — A natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.
08

Templates

The following prescribed forms accompany this Manual:

  • ML-GM-02 v00 TPL-1.0 — Data Subject Access Request Form.
  • ML-GM-02 v00 TPL-2.0 — Correction, Restriction of Processing or Erasure Request Form.
10

Access procedure and requests

The purpose of this section is to provide requestors with sufficient guidelines and procedures to facilitate a request for access to a record held by nuvoteQ.

It is important to note that an application for access to information can be refused under the conditions specified in Article 12(5) of GDPR. Similarly, the successful completion and submission of an access request form does not automatically allow the requestor access to the requested record. In limited circumstances, the Controller may refuse to act on a request if it is proven to be “manifestly unfounded or excessive” (Article 12(5), GDPR). An application may also be subject to general limitations as detailed in Article 15(4) of the GDPR, where the rights and freedoms of others may be adversely affected.

If it is reasonably suspected that the requestor has obtained access to nuvoteQ's records through the submission of materially false or misleading information, legal proceedings may be instituted against such requestor.

In the event that nuvoteQ is not the Controller of the Personal Information, the company is obliged to inform the Controller (Client) in writing of:

  • Any legally binding request for the disclosure of Personal Information by a law enforcement authority unless otherwise prohibited (to preserve the confidentiality of a law enforcement investigation).
  • Any accidental or unauthorised access to Personal Information.
  • Any request received directly from the Data Subject, without responding to that request.
11

Data Subject Access Request Form

For nuvoteQ to facilitate any access to a record, the attached prescribed “Data Subject Access Request Form” (ML-GM-02 v00 TPL-1.0) should be completed by the Data Subject themselves or the Requestor. The prescribed form must be completed in full — failure to do so will delay processing.

Due cognisance should be taken of the following instructions when completing the form because the Data Protection Officer shall not process any request until satisfied that all requirements have been met:

  • The nuvoteQ “Data Subject Access Request Form” has been submitted in writing.
  • Proof of identity has been provided to authenticate the requestor's identity. If the requestor is the Controller of the data, they shall provide proof of the identity of the person on whose behalf the request is made and authorisation (consent) from the Data Subject.
  • Type or print in BLOCK LETTERS an answer to every question.
  • If a question does not apply, state “N/A” in response to that question.
  • If there is nothing to disclose in reply to a particular question, state “nil”.
  • If there is insufficient space, additional information may be provided on an additional attached folio. Precede each answer thereon with the title applicable to that question.
  • Any other supporting documents or justification have been attached (where applicable).
  • The completed form must be submitted via email addressed to the designated nuvoteQ Data Protection Officer.
12

Notification and timeline

nuvoteQ will within one month of receipt of the request decide whether to grant or decline the request and give notice with reasons (if required) to that effect. The one-month period may be extended for a further period of not more than two months, taking into consideration the number and complexity of requests received. nuvoteQ will notify the requestor in writing should an extension be sought.

If the request for access is successful, the requestor will be notified of the form in which access will be granted. If the request is not successful, the requestor will be notified of the reasons for the refusal and their right to lodge a complaint with the supervisory authority.

Note: If nuvoteQ is not the Controller of the data, every effort should be made to respond to the Controller well in advance of the one-month period to assist with the fulfilment of their timed obligation to respond to requests from the Data Subject.

13

Correction, restriction of processing or erasure

To request the correction, restriction of processing or erasure of a Personal Information record held by nuvoteQ, complete the “Correction, Restriction of Processing or Erasure Request Form” (ML-GM-02 v00 TPL-2.0) fully. Failure to complete the form in full will delay processing.

Due cognisance should be taken of the following instructions when completing the form because the Data Protection Officer shall not process any such request until satisfied that all requirements have been met:

  • The nuvoteQ “Correction, Restriction of Processing or Erasure Request Form” has been submitted in writing.
  • Proof of identity has been provided to authenticate the requestor's identity. If the requestor is the Controller of the data, they shall provide proof of the identity of the person on whose behalf the request is made and authorisation (consent) from the Data Subject.
  • Type or print in BLOCK LETTERS an answer to every question.
  • If a question does not apply, state “N/A”. If there is nothing to disclose, state “nil”.
  • If there is insufficient space, additional information may be provided on an additional attached folio, preceding each answer with the applicable question title.
  • Any other supporting documents or justification have been attached (where applicable).
  • The completed form must be submitted via email addressed to the designated nuvoteQ Data Protection Officer.
14

Notification for correction, restriction or erasure

nuvoteQ will within one month of receipt of the request action the request accordingly. The one-month period may be extended for a further period of not more than two months, taking into consideration the number and complexity of requests received. nuvoteQ will notify the requestor in writing should an extension be sought.

If the request to correct, restrict processing or erase records is successful, the requestor will be notified accordingly. If the request is unsuccessful, the requestor will be notified of the reasons for the refusal and their right to lodge a complaint with the supervisory authority.

Note: If nuvoteQ is not the Controller of the data, every effort should be made to respond to the Controller well in advance of the one-month period to assist with the fulfilment of their timed obligation to respond to requests from the Data Subject.

15

Ensuring correct records are shared, corrected, restricted or erased

It is the responsibility of the nuvoteQ Data Protection Officer (DPO) to ensure that every effort is made to confirm the identity of the Data Subject and match that with the particulars of the Personal Information record(s) being provided, corrected, restricted or erased.

There should be no cross-contamination of records shared with or evidence provided to the Data Subject or Requestor upon execution of any request. It is thus mandated that the Deputy DPO perform a documented quality review prior to any notice of request decision or outcome being issued.

16

Records that cannot be found or do not exist

If nuvoteQ has searched for a record and it is believed the record either does not exist or cannot be found, the requestor will be notified by way of an affidavit or affirmation. This should include the steps that were taken to try to locate the record.

nuvoteQ

For questions about this document, contact our Information Officer at hello@nuvoteq.io — we respond within 30 days as required.