GENERAL INFORMATION ON THE PROCESSING OF PERSONAL DATA

ALTA banka a.d. Beograd (hereinafter: The Bank), as the Data Controller, during the selection of candidates who will potentially be engaged on the basis of employment or outside of employment, collects and processes personal data in accordance with the Law on Personal Data Protection (Official Gazette, No. 87/2018, hereinafter: Law) as well as the General Data Protection Regulation (EU) 2016/679 – GDPR).

For the sake of transparent processing, the Bank hereby provides information on the processing of personal data, data protection, and rights related to processing.


1. IDENTITY AND CONTACT INFORMATION OF THE CONTROLLER AND THE DATA PROTECTION OFFICER

ALTA banka a.d. Beograd
Bulevar Zorana Đinđića 121, 11070 New Belgrade
Company registration number: 07074433
Phone: 011/2205-500
Website: www.altabanka.rs

For questions regarding personal data, you can contact the DPO via:

  • E-mail: dpo@altabanka.rs

  • Post: ALTA banka a.d. Beograd, Bulevar Zorana Đinđića 121, 11070 Belgrade, with the designation „Za Lice za zaštitu podataka o ličnosti“

  • In person: At any Bank branch, indicating „Odeljenje kontrole usklađenosti poslovanja (Compliance Department) – za Lice za zaštitu podataka o ličnosti“.

The DPO will respond within 30 days from receipt, with possible extensions up to 60 days in complex cases.


2. PURPOSES AND LEGAL BASIS OF DATA PROCESSING

The Bank collects and processes personal data for specific purposes:

  • Candidate selection and recruitment: Processing applications, tests, and interviews based on the candidate’s consent.

  • Retention of unsuccessful candidates’ data: To inform them of future vacancies, based on the Bank’s legitimate interest.

Candidates can withdraw consent at any time by contacting hr@altabanka.rs or the DPO.


3. TYPES OF PERSONAL DATA PROCESSED AND METHOD OF COLLECTION

  • Mandatory data: Name and surname, address, phone number, professional qualification, name of educational institution.

  • Optional data: Driver’s license, CV, photo, certificates.


4. CATEGORIES OF RECIPIENTS WHO HAVE ACCESS TO DATA

  • Bank employees involved in recruitment.

  • Contractual partners performing recruitment tasks under agreements.


5. DATA TRANSFER TO OTHER COUNTRIES OR INTERNATIONAL ORGANIZATIONS

Data is processed in Serbia. Transfers to other countries occur only for necessary cloud solutions with adequate protection, per legal standards.


6. RIGHTS OF PERSONS TO WHOM DATA REFERS

You have the right to:

  • Access your data.

  • Correct, amend, limit, or delete your data under certain conditions.

  • Portability of your data.

  • Object to processing.

  • Dispute automated decisions.

  • Lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection.

Exercising your rights is free unless requests are excessive or repetitive.


7. DATA SECURITY

The Bank applies ISO 27001 standards and all necessary organizational, technical, and personnel measures for data security.


8. DATA RETENTION PERIOD

  • Data is stored until the end of the selection process.

  • Data of unsuccessful candidates is stored for up to 2 years after collection unless consent is withdrawn earlier.


Amendments to Privacy Notice

This notice may change; persons concerned should check it regularly.


Personal Data Protection on the Bank’s Website

  1. Protection: Data is processed legally, only for the necessary period.

  2. Purpose: Communicating with website users, statistical processing.

  3. Security: Data is protected and accessed only by authorized persons.

  4. Cookies Policy: Cookies are used to ensure smooth website functionality and user experience. No personal data is transferred to third parties except necessary platforms (e.g., Facebook for targeted ads).


INFORMATION PRIVACY POLICY

ALTA banka is committed to:

  • Processing data legally, honestly, and transparently.

  • Collecting only necessary data.

  • Keeping data accurate and up-to-date.

  • Retaining data only as long as necessary.

  • Ensuring data confidentiality and integrity.

The Privacy Information Management System (PIMS) is continuously reviewed by Bank management.