Javascript is required
logo-dastralogo-dastra

Modelo de tratamiento de datos RGPDAccess control by biometric authentication in the workplace

Por: Ludwig Karneth
PrivatePublicGeneral options
This processing model relates to access control to premises as well as access control to business IT devices and applications.

Finalidades (2)

La finalidad de un tratamiento es el objetivo principal del uso de los datos personales. Estos datos deben ser recopilados para un propósito bien determinado y legítimo y no deben ser tratados posteriormente de manera incompatible con este objetivo inicial.

1
Access control for professional IT devices and applications
Limitatively identified organization
Intereses legítimos del responsable o de un tercero - art.6.1 f)
2
Premises access control
Limitatively identified by the organization as requiring restricted movement
Intereses legítimos del responsable o de un tercero - art.6.1 f)

Datos (3)

El artículo 30 del RGPD exige el registro de las categorías de datos tratados. Se trata aquí de definir las categorías de datos tratados. Estas pueden ser consideradas comunes o sensibles.

Data generated by the device: logging access to work tools

Detalles de los datos


Authentication number or individual media numberrequerido
Access attempt timestamprequerido
Devices or applications concernedrequerido

Reglas de conservación

Base activa:

The access logging data produced by the biometric device cannot be stored in the active database for more than six months from the date of registration. This does not, however, prevent them from being kept in an intermediate archive separate from the active database, with restricted access, insofar as there are specific legislative or regulatory provisions, or if these data would be of interest in the event of litigation, justifying keeping them for the duration of the applicable prescription/forclusion rules.

Data generated by the device: premises access logging

Detalles de los datos


Authentication number or individual media numberrequerido
Access attempt timestamprequerido
Access usedrequerido

Reglas de conservación

Base activa:

The access logging data produced by the biometric device cannot be stored in the active database for more than six months from the date of registration. This does not, however, prevent them from being kept in an intermediate archive separate from the active database, with restricted access, insofar as there are specific legislative or regulatory provisions, or if these data would be of interest in the event of litigation, justifying keeping them for the duration of the applicable prescription/forclusion rules.

Data entered by the employer or its agents

Detalles de los datos


Authorized access times and conditionsrequerido
Devices or applications concernedrequerido
Authorized access, zones and time slotsrequerido
Identity or company name of the person (natural or legal) acting as employerrequerido
Graderequerido
Corps ou service d'appartenancerequerido
Internal registration numberrequerido
Authentication number or individual media numberrequerido
Raw record of biometric feature and template(s) of one or more biometric features

Definición

Photo, audio recording, etc.

requeridodatos sensibles
Photography

Definición

Photograph including the person's face

requerido
First namerequerido
name

Definición

Name of the person

requerido

Reglas de conservación

Base activa:

Raw recordings (photo, audio recording, etc.) of the biometric feature can only be processed for the time required to calculate the template(s): they cannot therefore be stored.derived biometric data can only be stored in the form of encrypted templates that do not allow the original biometric feature to be recalculated. They may only be kept for as long as the person concerned has been authorized, and must be deleted if authorizations are withdrawn or if the person concerned ceases to work for the employing organization

Orden final

Personas afectadas (1)

Una persona interesada es toda persona cuyos datos son recopilados, retenidos o tratados por el tratamiento de datos en cuestión. Ej: En el marco de un tratamiento de gestión de reclutamiento, cualquier candidato para el puesto en cuestión constituye una persona interesada.

  • Employees

Autor:
Ludwig Karneth
Ludwig Karneth

Creado el:07/08/2023

Actualizado el:00/01/1970

Licencia: © Creative commons :
Attribution / Pas d'utilisation commerciale
CC-BY-NC AttributionPas d'utilisation commerciale

Número de usos:13


Acceda al modelo completo

Pruebe Dastra ahora mismo para acceder a la totalidad de nuestros modelos de tratamiento de datos que podrá adaptar a su organización. Es gratuito y sin compromiso durante los primeros 30 días (no se requiere tarjeta de crédito).

Añadir a mi registro de tratamientos
Suscríbase a nuestro boletín

Le enviaremos algunos correos electrónicos para mantenerlo informado sobre nuestras novedades y las actualizaciones de nuestra solución.

* Siempre podrá darse de baja en cada boletín.