D
D
dvachek2015-02-06 20:47:39
Law in IT
dvachek, 2015-02-06 20:47:39

Login and email are personal data?

On my website, a user can specify a login, email, password, phone number, date of birth, WMR wallet (and other wallets), choose their gender, choose their status (student, worker, etc.).
You are not required to enter your full name anywhere on the site.
Is this data considered personal or not?

Answer the question

In order to leave comments, you need to log in

4 answer(s)
E
Eugene, 2015-02-09
@hokop

We open 152-FZ
Article 3. Basic concepts
Based on the wording, your data set can be summed up under PD.
Going further:
Article 5. Principles of personal data processing

1. The processing of personal data must be carried out on a lawful and fair basis.
2. The processing of personal data must be limited to the achievement of specific, predetermined and legitimate purposes . It is not allowed to process personal data that is incompatible with the purposes of collecting personal data.
3. It is not allowed to combine databases containing personal data, the processing of which is carried out for purposes that are incompatible with each other.
4. Only personal data that meet the purposes of their processing are subject to processing.
5. The content and scope of the processed personal data must correspond to the stated purposes of processing. The processed personal data should not be excessive in relation to the stated purposes of their processing.
6. When processing personal data, the accuracy of personal data, their sufficiency, and, if necessary, their relevance in relation to the purposes of processing personal data, must be ensured. The operator must take the necessary measures or ensure that they are taken to remove or clarify incomplete or inaccurate data.
7. Storage of personal data should be carried out in a form that allows to determine the subject of personal data, no longer than required by the purposes of processing personal data, if the period of storage of personal data is not established by federal law, an agreement to which the subject of personal data is a party, beneficiary or guarantor. data. The processed personal data is subject to destruction or depersonalization upon reaching the goals of processing or in case of loss of the need to achieve these goals, unless otherwise provided by federal law.
Now answer the questions:
1. What is the purpose of your personal data processing?
2. Why do you need the date of birth, social status, gender of clients to achieve your purpose of processing?
If you remove the date of birth, social status, gender of clients, then I am sure that this will not harm the functionality of your project, but your project will be cleaner from the point of view of 152-FZ.

D
Denis Nosov, 2015-02-06
@Cat1987

From the listed personal data are the date of birth.

K
ko3a4ok, 2015-02-06
@ko3a4ok

smoke the law "on personal data" and you will be happy

D
Denis, 2016-01-15
@newpdv

It is acceptable to use the following wording in the site rules:

Since the Site Administration processes the User's personal data in order to comply with these Rules, by virtue of the provisions of the legislation on personal data, the User's consent to the processing of his personal data is not required.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question