1. Processing of personal data regarding employees in NorSea
Privacy is the right to a private life and the right to decide over one’s own personal data.
Privacy is important for NorSea, and we are committed to integrity, availability and confidentiality to protect your personal data. All our processing of personal data shall comply with the applicable data protection regulations, including GDPR and the Personal Data Act. This privacy policy provides additional information about what personal data are collected, how they are collected and what rights you have related to your personal data.
2. Data controller
NorSea Group AS (NorSea) owns several legal entities (companies) across multiple countries. The company you are employed by will be the data controller for all processing of personal data about you in connection with your employment relationship. NorSea has, however, the overall administrative responsibility for all processing of personal data in NorSea’s subsidiaries where NorSea has more than 50% ownership. The CEO of the company you are employed by has the legal responsibility for processing personal data about you as an employee.
The responsibility for the daily follow-up of our compliance with the data protection regulations is delegated to the data protection coordinator.
3. Collection and purpose
In connection with your employment/engagement, personal data about you are received and collected directly or from third parties for the following purposes:
(i) Processing of personal data as part of personnel administration.
Personal data that are processed in this connection include personal details, contact information, salary information, attendance, evaluations, absence history, information about relatives, education, competence and work history. The legal basis for the processing is the fulfillment of the employment contract. (GDPR Article 6 letter b and c). In addition, NorSea will process health information in the form of health certificates in the situations where a legal basis follows from AML §9-3 and §9-4. Personnel who are involved in work with the Defense Agreement are security cleared.
(ii) Offer and tender work.
Your personal data may be forwarded to customers and subcontractors to the extent necessary in connection with bids and tenders. This will typically be contact information and other business-related information. The recipient of personal data is to be considered as an independent data controller and shall process your personal data in accordance with the data protection regulations. NorSea’s legal basis for the disclosure is legitimate interest.
(iii) Use of images for marketing.
NorSea may use situation and portrait images of employees for marketing and or promotion of the company. When taking portrait pictures, information is given about the area of use, media and the possibility to opt out. Send an email to personvern@norseagroup.com if you want to opt out of the use of existing images or want to withdraw consent for new images.
(iv) Processing of personal data in connection with recruitment/new hires.
By registering and/or subscribing to vacancies at NorSea, as well as by submitting a CV, application and other relevant documents in connection with a job application, personal data are collected. Personal data that are processed in connection with recruitment include personal details, job, education history and personality tests. In cases where NorSea uses a supplier of recruitment services, the processing will be bound by a data processing agreement.
(v) Health, safety and environment
We process personal information to ensure our employees a safe and secure workday. Personal data are used for studies, control mechanisms, internal audits and investigations.
(vi) Protection of business interests and security
We process personal data to protect our business and our customers’ business interests and equipment. This involves access control, video surveillance, information security, logging and other control mechanisms.
4. Information security
We are concerned about information security and have implemented routines to ensure confidentiality and integrity in our employees’ personal data. We have security mechanisms that involve both organizational and technical measures. Material that contains sensitive personal data or social security number and is transferred to or from the company is secured against access by means of encryption. Extended information about our information security is available on request.
The access to your personal data is limited to employees who have a service need for such access. We provide training to employees and third parties where relevant to promote awareness of our policies and procedures for privacy.
5. Your rights
Our processing of personal data is regulated by the Personal Data Act with accompanying regulations. Your rights related to our processing of personal data are set out in GDPR Chapter III. Below are some of the most central rights:
You have the right to access what personal data are processed, as well as information about how they are processed. If the company processes personal data about you that are incorrect, incomplete or that there is no access to process, you can, within the limitations set by the Personal Data Act and other legislation, demand that the personal data be corrected or deleted. Furthermore, you can request deletion if the processing of the personal data is no longer necessary to fulfill the purpose they were collected for, or if the processing is based on your consent and you withdraw it.
We shall respond to inquiries about access or other rights GDPR Article 15, 16, 17 and 20 without undue delay, and no later than 30 days from the day the inquiry came in, unless special circumstances make it impossible to respond to the inquiry within this deadline.
6. Data protection officer
We have a dedicated data protection officer who advises the company and ensures compliance with the regulations through an external partner (BDO Advokater AS). He or she is registered in the Data Inspectorate’s voluntary scheme. Requests for access, correction and deletion, as well as reports of deviations are handled by the data protection officer.
7. Do others have access to your personal data?
To the extent necessary to maintain the daily operation, justified by law or agreement, we may share your personal data with third parties. For example, we may need to share personal data with NorSea Group AS, or other companies in the group to fulfill some of the above-mentioned purposes of the processing. Furthermore, we will share your personal data with public authorities to the extent necessary to fulfill our legal obligations.
Beyond this, we will not share your personal data with other businesses unless you consent to this.
8. Use of data processors
We enter into a data processing agreement with all businesses that process personal data on our behalf. Our data processors cannot process your personal data in any other way than as agreed with us and described in this privacy policy.
9. Where is your personal data stored?
Personal data processed by NorSea is stored on servers in Norway and Europe. We do not store personal data in countries outside the EU/EEA.
10. Contact information
Inquiries about requests for access, correction, deletion, and deviation reports should be directed to personvern@norseagroup.com
If you believe that we process personal data in violation of the law, you can file a complaint with the Data Inspectorate.
Address: Data Inspectorate, Postboks 8177 Dep., 0152 Oslo
E-mail: postkasse@datatilsynet.no
Tel: +47 22 39 69 00