-
01. General Rules
Personal information is information regarding a living
person. That is, personal information refers to information
that through which a person can be identified such as name,
resident registration number, and image. This includes
information which may not identify a person on its own, but
when combined with other information, may identify a person.
Personal information provider is a person who can be identified
by the processed information. Doosan E&C will disclose the
Privacy and Information Processing Policy on the first page of
its Website(www.doosanenc.com) so that you can always easily
check the policy. When the Policy is amended, we will
publically notify you of the amendment through a notice on our
Website or individually.
-
02. Processed Personal Information and
Processing Purpose
Without the legitimate provisions or the consent provided
by informer, Doosan E&C may handle neither the sensitive
information that may significantly compromise the privacy of
its provider nor the unique identification information assigned
to distinguish the interested-party from others.
A. Processed Information
[Concerning the customer]
- Name, postal address, email, company name, service
usage data, access information, cookies, and IP address.
[Concerning employment]
- Name, resident registration number, photo, password,
postal address, telephone number, cellphone number, email,
education, military service, foreign language competence,
computer competence, license/certificate, family, and work
experience.
B. Purpose of Processing
[Concerning the customer]
- To support customer service, such as customer
inquiries and complaints.
- Online market research or opinion poll.
- A/S related issues after moving in.
[Concerning employment]
- Recruitment screening and contact with applicants,
- Wage/salary payment, fringe benefits, HR management
including various job performance supports, and evaluations.
-
03. Processing and the Retention Period
of Personal Information
Once the purpose of collection and the use of personal
information are met and completed, as a fundamental rule, the
relevant information will be immediately destroyed. However, we
will retain the following information during the period
specified below and for the reasons specified below, and we
will obtain consent from the person who provided his or her own
personal information, as necessary.
- Information to be Retained: Name, postal address,
email, and company name.
- Retention Period: One year.
- Retention Purpose: User inquiries/requests control,
user identification, etc.
- Information to be Retained: Service usage records, log
information, cookies, IP address
- Retention Period: Up to three years
- Retention Purpose: To improve service quality by
analyzing service usage by users
- Information to be Retained: Name, date of birth,
photo, password, home address, home phone number, mobile
number, email, education, military service, language ability,
computer skills, qualifications, family information, work
experience
- Retention Period: Until the termination of the
employment relationship
※ Except, the personal
information of applicants who are not hired will be retained
for five years, with the consent of individuals, for the
purpose of recruitment management.
- Retention Purpose: HR management, such as pay
information, employee welfare benefits, and support and
evaluations for various job assignments
-
04. How Personal Information is Destroyed
Any personal information saved in an electronic file format
will be deleted using a technology that prevents the recovery
of the deleted records.
The personal information
retained on paper will be shredded or burned.
-
05. Disclosure of Personal Information to
a Third Party
Doosan E&C will collect personal information within the
scope of the purpose of the collection, and will not use your
personal information beyond the scope of collection purpose or
offer or disclose it to a third party. However, the following
are the exception to the above rule:
- Consent was received from the person who provided his
or her own personal information.
- According to specific provisions in other relevant
laws.
- The person providing their own personal information or
his/her legal representative is in a state in which an
opinion/intention cannot be expressed, or prior consent cannot
be gained due to an invalid address, but disclosure to a third
party is urgently needed for the sake of the data provider or
a third party’s life, body, and property.
- Necessary for statistical purposes and academic
studies, where personal information is provided in a way as
not to identify a specific individual.
Doosan E&C currently offers personal information as
follows:
- Institutions receiving personal information:
DLI_Doosan Leadership Institute, Samil Academy, Samsung SDS
- Usage purpose: Verify qualification.
- Retention and use period: Destroyed immediately.
-
06. Commissioning of Personal Information
Processing
Doosan E&C will not commission personal information
processing to an outside agency without your consent. We
commission personal information processing as follows, and
regulate necessary matters/issues so that personal information
can be safely managed upon commission of service as contracted
under the relevant laws and regulations:
- Outsourcing Company: Doosan Cuvex
- Outsourcing Information: Pay information, employee
welfare benefits, etc.
- Outsourcing Company: Doosan Digital Innovation
- Outsourcing Information: HR system management
- Outsourcing Company: Doosan Dong-A, Samsung SDS
- Outsourcing Information: Website and system management
-
07. Rights and Obligations of the Person
Providing Their Own Personal Information and Method to Exercise
the Rights
All the persons providing their personal information may
request for the inspection, revision, deletion, and cessation
of the processing of their personal information. However,
Doosan E&C may reject or restrict such a request in the
following cases:
- When specifically required under the law or to comply
with obligations under laws and regulations.
- When there is a concern for harm to another person’s
life or body, or when there is a concern of unlawfully
infringing upon another person’s property and profits.
- In a case where the service contracted with the
personal information provider cannot be offered without
processing his or her personal information, or when it is
difficult to perform the service contracted with the personal
information provider, but her or she does not clearly express
his/her intention to terminate the contract.
[Method and Procedure to Exercise Rights]
- A person wanting to exercise the above rights
regarding their personal information may complete the
Read/Inspect, Revise, Delete, and Suspend the Processing Form
and sent it by email or fax to the department in charge of
personal information.
- (See “09. Customer Request Service on Personal
Information” concerning the department) Unless there is a
legitimate reason, Doosan E&C will take a proper action within
10 days of receiving such a request. When there is a reason to
reject or restrict the request, we will inform you of the
reason and a method to appeal the decision within 5 days upon
receiving the request.
- When the concerned person or legal representative
makes a request as above, we can confirm the identity of the
person or legal representatives by checking their
identification cards such as a resident registration card or a
recognized electronic signature.
-
08. Technical, Administrative, and
Physical Protection Measures for Personal Information
Doosan E&C takes the following safeguards in handling
personal information so that it will not be lost, stolen,
leaked, modified, or damaged:
[Technical actions]
- Doosan E&C complies with the criteria set forth by
laws and regulations for the safe storage and transmission of
personal information.
- We protect against computer virus by using a vaccine
program. The vaccine program is periodically updated, but if
there is a sudden emergence of a new virus, we will implement
the appropriate vaccine as soon as it becomes available so
that personal information infringement can be prevented.
- To deal with outside infiltration, including hacking,
we use an infiltration interruption system and a weakness
analysis system.
[Administrative actions]
- Doosan E&C restricts the rights to access personal
information to the following cases: a person carrying out
sales and marketing activity involving the personal
information provider, a person engaging in personal
information management, and a person whose task requires the
use of personal information.
- We conduct regular in-house training and external
commissioned training for those employees that handle personal
information, and we thoroughly manage and supervise them to
comply with the laws and regulations regarding personal
information protection.
[Physical actions]
- To protect personal information, we limit physical
access to the information through the use of locks and similar
devices.
- We control access to the computer room and archives by
designating and operating them as specially protected areas.
-
09. Customer Request Service for Personal
Information
Doosan E&C has appointed the following department and
personal information protection administrator to protect
personal information and to process complaints related to
personal information:
A. Department in Charge of Personal
Information
- Department : IT Planning Team
- Tel : +82 02-510-3262
- Fax : +82 02-510-3598
- Email : dsenc.prv@doosanenc.co.kr
- Business hours : Mon-Fri. 09:00–18:00 (closed on Saturday and Sundays)
B. Personal information Protection
Administrator
- Name : SANGSEON KIM
- Tel : +82 02-510-3262
- Email : dsenc.prv@doosanenc.co.kr
Should you need to report a personal information
infringement or receive consultation regarding infringement,
please contact the following agencies:
- Personal Information Infringement Reporting Center : +82 118 (http://privacy.kisa.or.kr)
- Personal Information Dispute Mediation Committee : +82 1833-6972 (http://www.kopico.go.kr)
- Korea Online Privacy Association : +82 02-550-9531 (http://www.eprivacy.or.kr)
- Supreme Prosecutors’ Office Cybercrime Investigation Department : +82 1301 (http://www.spo.go.kr)
- National Police Agency Cyber Crime Reporting System : +82 1566-0112 (http://ecrm.police.go.kr)
-
10. Obligation of Public Notification
When the current Privacy and information Processing Policy is
amended or deleted, we will provide notice on our Website 10
days before such amendment or deletion takes place.
Date of Public Notification : January 2, 2024
(Version 3.1)
Date of Enforcement : January 2, 2024
(Version 3.1)