According to the Law of the Kyrgyz Republic "On Personal Information", citizens have the right to know what personal data state, municipal or commercial organizations (owners of personal data arrays) collect, process and store and whether they do it legally.
In what areas is the personal data of citizens processed?
The patient has the right to confidentiality of data relating to his or her state of health, medical condition, diagnosis, prognosis and treatment, as well as of all personal data that must be kept secret.
The Internet is the largest platform where the personal data of each user is processed. In this regard, citizens often face violations of their rights on the Internet, which can lead to:
- online identity theft;
- creating fake profiles;
- email password theft;
- dissemination of compromising video and photographic material;
- posting a photo or video without the consent of a citizen.
In order to prevent cases of loss of control over personal data, one must be careful with his or her personal data and:
- do not go to suspicious sites;
- not to show or tell logins, passwords and banking data to other people;
- not to access Internet banking from other people's computer devices or phones. The browser can save one'spassword automatically, which may result in data loss;
- do not share flash cards if they have passport photos, questionnaires with passport data or other personal data.
The employer's need for information and the employee's right to privacy can be balanced if the collection, storage and processing is for a specific purpose. The protection of personal data of employees is regulated by the “Procedure for maintaining a personal file of a state civil servant and a municipal employee of the Kyrgyz Republic”.
The personal data of an employee is understood as information about the facts, events and circumstances of the employee's life, allowing to identify his or her personality and contained in the employee's personal file or to be included in his personal file.
Personal data entered into the employee's personal files are classified as confidential information.
When receiving, processing, storing and transferring personal data of an employee, the personnel management service must comply with the following requirements:
- the processing of personal data of an employee is carried out in order to ensure compliance with the Constitution, laws and other regulatory legal acts of the Kyrgyz Republic, to assist the employee in the passage of the state civil service and municipal service, in training and career growth, to ensure the personal safety of the employee and members of his or her family, as well as for the purposes of ensuring the safety of the property belonging to him or her and the property of a state body, local self-government body, taking into account the results of the performance of his official duties;
- personal data should be obtained personally from an employee. If it is necessary to obtain personal data of an employee from a third party, one should notify the employee in advance, obtain his written consent and inform the employee about the purposes, alleged sources and methods of obtaining personal data;
- it is prohibited to collect and enter into the personal file of an employee personal data not established by laws about his or her political, religious and other beliefs, private life, membership in public associations, including trade unions;
- when making decisions affecting the interests of an employee, it is prohibited to rely on the employee's personal data obtained solely as a result of automated processing or using electronic media;
- the protection of personal data of an employee from unlawful use or loss is provided at the expense of the state body, local self-government body of the Kyrgyz Republic in the manner prescribed by the laws of the Kyrgyz Republic;
- the transfer of personal data of an employee to a third party is not allowed without the written consent of the employee, except for cases established by the laws of the Kyrgyz Republic.
Special categories of personal data
According to the Law of the Kyrgyz Republic “On Personal Information”, special categories of personal data include racial or ethnic origin, nationality, political views, religious or philosophical beliefs, as well as information relating to health and sexual inclinations.
Collection, accumulation, storage and use of special categories of personal data is permitted only in the following cases:
- if the subject of personal data has given his or her consent to the collection and processing of such data;
- if the processing is necessary to protect the health and safety of the subject of personal data, another person or a relevant group of persons, while it is impossible to obtain the consent of the subject of personal data.