Corporation (“Doosan E&C”) complies with the relevant laws and regulations dealing with personal information protection including the Personal Information Protection Act and the Act on Information Communications Network Use Promotion and Information Protection. Doosan E&C strives to protect the rights and interests of persons providing personal information, such as customers, employees, and Website users through its Privacy and Information Processing Policy and the Privacy and Information Handling Policy. Doosan E&C notifies you of how and for what purposes we may use your information and what measures have been taken to protect your personal information through its policies regarding personal data privacy and information processing. In the event any of the provisions of the relevant policies are amended, we will publicly notify you of such amendments through this Website or individually.
The Company’s policy related to personal information consists of the following: 1) the Privacy and Information Processing Policy regarding the personal information protection of all persons providing their own personal information, 2) the Privacy and Information Handling Policy regarding the personal information protection of this Website’s users, and 3) the Image Information Processing Equipment Operation & Management Policy regarding personal image information protection.
1. Privacy and Information Processing Policy
01. General Rules
Personal information is information regarding a living person. That is, personal information refers to information that through which a person can be identified such as name, resident registration number, and image. This includes information which may not identify a person on its own, but when combined with other information, may identify a person. Personal information provider is a person who can be identified by the processed information. Doosan E&C will disclose the Privacy and Information Processing Policy on the first page of its Website(www.doosanenc.com) so that you can always easily check the policy. When the Policy is amended, we will publically notify you of the amendment through a notice on our Website or individually.
02. Processed Personal Information and Processing Purpose
Without the legitimate provisions or the consent provided by informer, Doosan E&C may handle neither the sensitive information that may significantly compromise the privacy of its provider nor the unique identification information assigned to distinguish the interested-party from others.
A. Processed Information
[Concerning the customer]
- Name, postal address, email, company name, service usage data, access information, cookies, and IP address.
[Concerning employment]
- Name, resident registration number, photo, password, postal address, telephone number, cellphone number, email, education, military service, foreign language competence, computer competence, license/certificate, family, and work experience.
B. Purpose of Processing
[Concerning the customer]
- To support customer service, such as customer inquiries and complaints.
- Online market research or opinion poll.
- A/S related issues after moving in.
[Concerning employment]
- Recruitment screening and contact with applicants,
- Wage/salary payment, fringe benefits, HR management including various job performance supports, and evaluations.
03. Processing and the Retention Period of Personal Information
Once the purpose of collection and the use of personal information are met and completed, as a fundamental rule, the relevant information will be immediately destroyed. However, we will retain the following information during the period specified below and for the reasons specified below, and we will obtain consent from the person who provided his or her own personal information, as necessary.
- Information to be Retained: Name, postal address, email, and company name.
- Retention Period: One year.
- Retention Purpose: User inquiries/requests control, user identification, etc.
- Information to be Retained: Service usage records, log information, cookies, IP address
- Retention Period: Up to three years
- Retention Purpose: To improve service quality by analyzing service usage by users
- Information to be Retained: Name, date of birth, photo, password, home address, home phone number, mobile number, email, education, military service, language ability, computer skills, qualifications, family information, work experience
- Retention Period: Until the termination of the employment relationship
※ Except, the personal information of applicants who are not hired will be retained for five years, with the consent of individuals, for the purpose of recruitment management.
- Retention Purpose: HR management, such as pay information, employee welfare benefits, and support and evaluations for various job assignments
04. How Personal Information is Destroyed
Any personal information saved in an electronic file format will be deleted using a technology that prevents the recovery of the deleted records.
The personal information retained on paper will be shredded or burned.
05. Disclosure of Personal Information to a Third Party
Doosan E&C will collect personal information within the scope of the purpose of the collection, and will not use your personal information beyond the scope of collection purpose or offer or disclose it to a third party. However, the following are the exception to the above rule:
- Consent was received from the person who provided his or her own personal information.
- According to specific provisions in other relevant laws.
- The person providing their own personal information or his/her legal representative is in a state in which an opinion/intention cannot be expressed, or prior consent cannot be gained due to an invalid address, but disclosure to a third party is urgently needed for the sake of the data provider or a third party’s life, body, and property.
- Necessary for statistical purposes and academic studies, where personal information is provided in a way as not to identify a specific individual.
Doosan E&C currently offers personal information as follows:
- Institutions receiving personal information: DLI_Doosan Leadership Institute, Samil Academy, Samsung SDS
- Usage purpose: Verify qualification.
- Retention and use period: Destroyed immediately.
06. Commissioning of Personal Information Processing
Doosan E&C will not commission personal information processing to an outside agency without your consent. We commission personal information processing as follows, and regulate necessary matters/issues so that personal information can be safely managed upon commission of service as contracted under the relevant laws and regulations:
- Outsourcing Company: Doosan Cuvex
- Outsourcing Information: Pay information, employee welfare benefits, etc.
- Outsourcing Company: Doosan Digital Innovation
- Outsourcing Information: HR system management
- Outsourcing Company: Doosan Dong-A, Samsung SDS
- Outsourcing Information: Website and system management
07. Rights and Obligations of the Person Providing Their Own Personal Information and Method to Exercise the Rights
All the persons providing their personal information may request for the inspection, revision, deletion, and cessation of the processing of their personal information. However, Doosan E&C may reject or restrict such a request in the following cases:
- When specifically required under the law or to comply with obligations under laws and regulations.
- When there is a concern for harm to another person’s life or body, or when there is a concern of unlawfully infringing upon another person’s property and profits.
- In a case where the service contracted with the personal information provider cannot be offered without processing his or her personal information, or when it is difficult to perform the service contracted with the personal information provider, but her or she does not clearly express his/her intention to terminate the contract.
[Method and Procedure to Exercise Rights]
- A person wanting to exercise the above rights regarding their personal information may complete the Read/Inspect, Revise, Delete, and Suspend the Processing Form and sent it by email or fax to the department in charge of personal information.
- (See “09. Customer Request Service on Personal Information” concerning the department) Unless there is a legitimate reason, Doosan E&C will take a proper action within 10 days of receiving such a request. When there is a reason to reject or restrict the request, we will inform you of the reason and a method to appeal the decision within 5 days upon receiving the request.
- When the concerned person or legal representative makes a request as above, we can confirm the identity of the person or legal representatives by checking their identification cards such as a resident registration card or a recognized electronic signature.
08. Technical, Administrative, and Physical Protection Measures for Personal Information
Doosan E&C takes the following safeguards in handling personal information so that it will not be lost, stolen, leaked, modified, or damaged:
[Technical actions]
- Doosan E&C complies with the criteria set forth by laws and regulations for the safe storage and transmission of personal information.
- We protect against computer virus by using a vaccine program. The vaccine program is periodically updated, but if there is a sudden emergence of a new virus, we will implement the appropriate vaccine as soon as it becomes available so that personal information infringement can be prevented.
- To deal with outside infiltration, including hacking, we use an infiltration interruption system and a weakness analysis system.
[Administrative actions]
- Doosan E&C restricts the rights to access personal information to the following cases: a person carrying out sales and marketing activity involving the personal information provider, a person engaging in personal information management, and a person whose task requires the use of personal information.
- We conduct regular in-house training and external commissioned training for those employees that handle personal information, and we thoroughly manage and supervise them to comply with the laws and regulations regarding personal information protection.
[Physical actions]
- To protect personal information, we limit physical access to the information through the use of locks and similar devices.
- We control access to the computer room and archives by designating and operating them as specially protected areas.
09. Customer Request Service for Personal Information
Doosan E&C has appointed the following department and personal information protection administrator to protect personal information and to process complaints related to personal information:
A. Department in Charge of Personal Information
- Department : Management Support Team
- Tel : 02-510-3674
- Fax : 02-510-3598
- Email : doosanprv@doosan.com
- Business hours : (Mon.-Fri.) 09:00–18:00, and closed on Saturday and Sundays.
B. Personal information Protection Administrator
Should you need to report a personal information infringement or receive consultation regarding infringement, please contact the following agencies:
10. Obligation of Public Notification
When the current Privacy and information Processing Policy is amended or deleted, we will provide notice on our Website 10 days before such amendment or deletion takes place.
Date of Public Notification : November 15, 2013 (Version 3.0)
Date of Enforcement : November 24, 2013 (Version 3.0)
2. Privacy and Information Handling Policy
Doosan Engineering & Construction (“Doosan E&C”) greatly values users’ personal information, and complies with the Act on Information Communications Network Use Promotion and Information Protection. We inform you about how and for what purpose users’ personal information is used, and what actions are taken for the privacy protection of the users. In the event that any of the provisions of the Privacy and Information Handling Policy are amended or updated, we will publicly notify you of such amendments or updates through this Website or individually. The following Privacy and Information Handling Policy applies to this Website(www.doosanenc.com).
01. Collection of Personal Information and Its Purpose
The company, unless authorized by law or the individual’s consent is provided, does not collect sensitive personal information that can invade the privacy of the individual or personally identifiable information that identifies a specific individual.
A. Information to be Collected
- Name, home address, contact number, email, company name, service usage records, log information, cookies, IP address
B. Collection Purpose
- To support customer service, such as customer inquiries and complaints
- A/S related issues after moving in
02. Retention and Destruction of Personal Information
In principle, once the purpose for which an individual’s personal information was collected and used is no longer being served, the personal information is destroyed immediately. Except, the following information may be retained for the period specified, when necessary, with the consent of the individual.
A. Retention and Usage Period
- Information to be Retained: Name, home address, email, company name
- Retention Period: Up to one year
- Retention Purpose: To manage user inquiries and requests, identify users, etc.
- Information to be Retained: Service usage records, log information, cookies, IP address
- Retention Period: Up to three years
- Retention Purpose: To improve service quality by analyzing service usage by users
The destruction procedure and method are as follows.
B. Destruction Method
- Personal information stored in a digital file format is technically deleted so that it cannot be recovered.
- Personal information on paper is shredded or incinerated.
03. Refusal of Consent to Release Personal Information
You have the right to refuse to consent to the collection and usage of your personal information.
Except, when you refuse to consent to the collection and usage of your personal information, your request may be rejected because we cannot collect or use your personal information.
04. Installation, Operation, and Refusal of Automatic Personal Information Collection System
The company uses cookies that frequently save and retrieve your information. Cookies are very small text files sent by the server, which is used to operate the company’s website, to your browser and saved on your system’s hard drive. The company uses cookies for the following purposes:
- To identify users’ preferences and interests and track digital footprints by analyzing connection frequencies, visit time, etc.
You may choose not to install cookies.
As such, you may configure your browser’s cookie settings to enable all, confirm every time, or disable all cookies.
Cookie Settings (e.g. Internet Explorer): Tools on the top of a browser > Internet Options > Privacy
Please note that disabling cookies might block some services.
05. Disclosure of Personal Information to a Third Party
Doosan E&C will collect personal information within the scope of the purpose of the collection, and will not use your personal information beyond the scope of collection purpose or offer or disclose it to a third party. However, the following are the exception to the above rule:
- Consent was received from the person who provided his or her own personal information.
- According to specific provisions in other relevant laws.
- The person providing their own personal information or his/her legal representative is in a state in which an opinion/intention cannot be expressed, or prior consent cannot be gained due to an invalid address, but disclosure to a third party is urgently needed for the sake of the data provider or a third party’s life, body, and property.
- Necessary for statistical purposes and academic studies, where personal information is provided in a way as not to identify a specific individual.
06. Outsourcing the Processing of Personal Information
In the case that the company outsources the processing of personal information to a third party specializing in information processing, the consent of the individual whose information is being provided is required in accordance with the law. The company shall disclose the name of the outsourcing company and information to be outsourced.
07. Rights and Obligations of the Person Providing Their Own Personal Information and Method to Exercise the Rights
All the persons providing their personal information may request for the inspection, revision, deletion, and cessation of the processing of their personal information. However, Doosan E&C may reject or restrict such a request in the following cases:
- When specifically required under the law or to comply with obligations under laws and regulations.
- When there is a concern for harm to another person’s life or body, or when there is a concern of unlawfully infringing upon another person’s property and profits.
- In a case where the service contracted with the personal information provider cannot be offered without processing his or her personal information, or when it is difficult to perform the service contracted with the personal information provider, but her or she does not clearly express his/her intention to terminate the contract.
[Method and Procedure to Exercise Rights]
- A person wanting to exercise the above rights regarding their personal information may complete the Read/Inspect, Revise, Delete, and Suspend the Processing Form and sent it by email or fax to the department in charge of personal information. (See “09. Customer Request Service on Personal Information” concerning the department)
- Unless there is a legitimate reason, Doosan E&C will take a proper action within 10 days of receiving such a request. When there is a reason to reject or restrict the request, we will inform you of the reason and a method to appeal the decision within 5 days upon receiving the request.
- When the concerned person or legal representative makes a request as above, we can confirm the identity of the person or legal representatives by checking their identification cards such as a resident registration card or a recognized electronic signature.
08. Technical, Administrative, and Physical Protection Measures for Personal Information
Doosan E&C takes the following safeguards in handling personal information so that it will not be lost, stolen, leaked, modified, or damaged:
[Technical actions]
- Doosan E&C complies with the criteria set forth by laws and regulations for the safe storage and transmission of personal information.
- We protect against computer virus by using a vaccine program. The vaccine program is periodically updated, but if there is a sudden emergence of a new virus, we will implement the appropriate vaccine as soon as it becomes available so that personal information infringement can be prevented.
- To deal with outside infiltration, including hacking, we use an infiltration interruption system and a weakness analysis system.
[Administrative actions]
- Doosan E&C restricts the rights to access personal information to the following cases: a person carrying out sales and marketing activity involving the personal information provider, a person engaging in personal information management, and a person whose task requires the use of personal information.
- We conduct regular in-house training and external commissioned training for those employees that handle personal information, and we thoroughly manage and supervise them to comply with the laws and regulations regarding personal information protection.
[Physical actions]
- To protect personal information, we limit physical access to the information through the use of locks and similar devices.
- We control access to the computer room and archives by designating and operating them as specially protected areas.
09. Customer Request Service for Personal Information
Doosan E&C has appointed the following department and personal information protection administrator to protect personal information and to process complaints related to personal information:
A. Department in Charge of Personal Information
- Department : PI/IT Team
- Tel : 02-510-3674
- Fax : 02-510-3598
- Email: doosanprv@doosan.com
- Business hours : (Mon.-Fri.) 09:00–18:00, and closed on Saturday and Sundays.
B. Personal information Protection Administrator
10. Obligation of Public Notification
When the current Privacy and information Processing Policy is amended or deleted, we will provide notice on our Website 10 days before such amendment or deletion takes place.
Date of Public Notification : November 15, 2013 (Version 3.0)
Date of Enforcement : November 24, 2013 (Version 3.0)
3. Image Information Processing Equipment Operation & Management Policy
01. Grounds and Purpose of Image Information Processing Equipment Installation
The Image Information Processing Equipment Operation & Management Policy (“the Policy”) sets forth the rules for Doosan Engineering & Construction (“Doosan E&C”) to comply with concerning the installation and operation of the image information processing equipment (IIPE), and personal image information protection requirement under Article 25 of the Personal Information Protection Act. The Policy aims to promote the adequate performance of work and to contribute to the protection of the rights and interests of the persons providing personal information.
02. Protection Principles of Personal Image Information
Doosan E&C will collect personal image information within the narrow scope in line with the purpose of installing the IIPE and will insure that persons providing personal information will be able to clearly recognize the installation purpose, and will not use the information for any purpose other than the aforementioned purpose. Doosan E&C will safely mange the personal image information, disclose the matters related to the processing of such information, and guarantee the rights of those persons on their personal image information.
03. Appointment of an Administrator
Doosan E&C has appointed the following administrator to manage the installation and operation of the personal IIPE
- Administrator : Byun Woong-sub
- Phone: 02-510-3058
- Department-In-Charge: Management Support Team
- Outsourcing Company: Doosan FM Business Department Corp.
04. Installation of Image Information Processing Equipment Installation
The number of the installed IIPE and their locations and viewing distances are as follows:
- Number of the IIPE : 29 (26 secured-type and 3 rotating-type)
- Locations of the IIPE : Outside the building, underground parking, and lobby
- Viewing distances of the IIPE : Outside the building, underground parking, and lobby
05. Information Sign Posting
Doosan E&C will take a necessary action such as posting an information sign containing the following so that the persons providing their own person information can easily notice the installation and operation of the IIPE:
- The purpose, location, shooting scope and time, controller’s name, position, and contact number.
- In the case the installation and control is outsourced, the outsourced person/company’s name and contact number.
The information sign shall be posted in a place where those who provide their own personal information can easily see it within the shooting scope. The size of the information sign shall be 40x30cm. However, the size is subject to change, according to the circumstances of the installation location.
06. Request of the Persons Providing Their Own Personal Information, Such As Requesting to View/Inspect Their Personal Information
A person providing their own personal information (“a person”) can request Doosan E&C to view/inspect and confirm the identification (”Viewing/Inspection”) regarding their own personal image information.
Doosan E&C will take a necessary action upon receiving a request for veiwing/inspection. In doing so, Doosan E&C may check through a submitted ID including resident registration card or driver’s license to confirm whether the requesting person is the person concerned or a legitimate representative.
Doosan E&C may reject such a request in the following cases and in such cases, Doosan E&C will give notice, in writing, to the requesting person or the representative of the reason for rejection or the method for appealing within 10 days of receiving the request:
- When the personal image information was destroyed because of the expiration of the retention period.
- When other legitimate reasons exist to reject such a viewing/inspection request.
07. Image Information Control
When the personal image information is used for the purpose other the intended purpose of the collection or when it is transferred to a third party pursuant to your consent or according to the provisions of laws and regulations, the following will be recorded in the Personal Image Information Log:
- Name of the personal image information file
- Name of the user or person to whom the transfer was made
- Purpose of use or transfer
- In the event it exists, the legal grounds of use or transfer
- If it exists, period when the use or transfer occurred
- Type of use or transfer
When destroying personal image information, the following shall be recorded in the Personal Image Information Log:
- Destroyed personal image information (items)
- Date of destruction (destruction frequency, etc., when automatic deletion takes place preset destruction period)
- Person in charge of personal image information destruction
08. Retention and Destruction
Doosan E&C will immediately destroy the collected personal image information upon the expiration of the retention period specified in the Policy. However, it will not do so if required by specific provisions in relevant laws and regulations. The methods of destroying personal image information are as follows:
The methods of destroying personal image information are as follows:
The hardcopy recordings (photo, etc.) of personal image information will be shredded or incinerated. Electronic file format information will be permanently deleted in the technical manner through which the deleted personal image information cannot be retrieved.
09. Administrative, Technical, and Physical Actions
The right to access personal image information collected and processed by the IIPE is limited to a minimum number of people, including the controller and the person in charge of the work. The place where the personal image information transmitted by the IIPE is viewed/inspected and retrieved is designated as being a restricted area, and only the authorized people are allowed to access and view/inspect the information.
Doosan E&C immediately changes or withdraws the access rights of a person, whose access right changes, due to HR changes such as job transfer or retirement.
We take necessary safeguards to ensure the safety of personal image information, including setting a password in the event that we process personal image information or send and receive such a file so that it cannot be lost, stolen, leaked, modified, or damaged.
We regularly inspect the status of the operation of the IIPE to prevent the forgery or modification of personal image information.
Date of Public Notification: September 26, 2013 (Version 2.0)
Date of Enforcement: September 27, 2013 (Version 2.0)