Information regarding the processing of personal data
(In accordance with the General Data Protection Regulation – GDPR)
1. Introduction
The National Institute of Public Health (hereinafter referred to as „INSP” or the "Operator") places particular importance on the protection of personal data and the respect of the right to privacy of data subjects, in accordance with Regulation (EU) 2016/679„GDPR”).
This notice aims to inform you about how INSP collects, processes, uses, stores, and protects your personal data through the web platform and institutional portal.
2. Legal framework
The processing of personal data by INSP is carried out in compliance with the following legal acts:
Regulation (EU) 2016/679 (GDPR)
Law no. 190/2018
specific public health legislation
other applicable legal provisions
3. Identity of the Operator
National Institute of Public Health
Str. Dr. Leonte Anastasievici no. 1–3, sector 5, Bucharest
Phone: +4 021 318 36 20
E-mail: directie.generala@insp.gov.ro
4. Data protection officer (DPO)
E-mail DPO: dpo@insp.gov.ro
5. Purposes of processing
The data is processed for:
registration and administration of providers
verification of eligibility and compliance
management of contractual relationships
administrative communication
record-keeping of departments and laboratories
fulfillment of legal obligations
platform security
service improvement
6. Legal basis
Processing is based on:
a) performance of a contract
b) legal obligation
c) public interest
d) legitimate interest
7. Categories of data processed
7.1 Organization data
name
CUI / TVA
CAEN codes
contact details
registered office address
7.2 Departments / laboratories
name
contact details
address
mobile status
7.3 Person of contact
full name
phone / e-mail
position
7.4 Technical data
IP address
browser
operating system
date and time of access
pages visited
cookies
Note: INSP does not process special categories of data unless required by law.
8. Mandatory nature of data provision
Mandatory data is necessary for registration. Refusal to provide such data may result in:
inability to process the request
inability to enter into a contract
restricted access
Optional data is voluntary.
9. Data recipients
Data may be disclosed to:
authorized INSP personnel
competent public authorities
IT service providers / processors
legal advisors / auditors
10. International transfers
Data is not transferred outside the EU/EEA, except in legally permitted cases and with appropriate safeguards.
11. Storage period
Data is retained:
for the duration of the contractual relationship
in accordance with statutory archiving periods
technical data: in accordance with the cookie policy
Upon expiration, data is deleted or anonymized.
12. Security measures
Technical measures:
HTTPS/TLS encryption
secure authentication
automatic logout
firewall / anti-malware
backup
monitoring
Organizational measures:
internal GDPR policies
staff training
confidentiality obligations
data protection impact assessments (DPIA)
incident management
13. Rights of data subjects
You have the right to:
access
rectification
erasure
restriction
data portability
objection
not be subject to automated decision-making
lodge a complaint with ANSPDCP
withdraw consent
Supervisory authority (ANSPDCP)
Bucharest – www.dataprotection.ro
anspdcp@dataprotection.ro
14. Exercising your rights
Requests may be sent to:
dpo@insp.gov.ro
directie.generala@insp.gov.ro
Str. Dr. Leonte Anastasievici no. 1–3, Bucharest
Response within a maximum of 1 month..
15. Automated decisions
INSP does not use automated profiling..
17. Amendments
This notice may be updated. The current version is published on the portal.
17. Final provisions
INSP fully complies with the GDPR and national legislation.
For questions: dpo@insp.gov.ro