Bank Pekao is both a data controller and a processor within the meaning of the provisions of the GDPR and is fully responsible for compliance with the provisions on the protection of personal data, in particular taking into account the rules on the processing of personal data indicated in the GDPR, such as:
- Information Security Policy along with the Information Security Policy Documents,
- Methodology of managing the risk of infringement of rights or freedoms of natural persons in Bank Pekao S.A. (PIA Methodology),
- Rules of personal data protection and rules of obtaining consents for Bank Polska Kasa Opieki Spółka Akcyjna to undertake activities for direct marketing purposes,
- Register of processing activities and Register of processing activities categories kept by Bank Polska Kasa Opieki Spółka Akcyjna,
- The rules of granting personal data processing authorizations and authorizations of access to the Bank’s information to persons employed in the Bank,
- The procedure for examining the requests of data subjects under the GDPR by Bank Polska Kasa Opieki Spółka Akcyjna,
- Personal Data Retention Policy at Bank Polska Kasa Opieki Spółka Akcyjna,
- Procedure for managing personal data protection violations in Bank Pekao S.A,
- The rules and procedure at Bank Polska Kasa Opieki Spółka Akcyjna in connection with the commissioning of services involving the processing of personal data,
- Application Security Policy at Bank Polska Kasa Opieki Spółka Akcyjna,
- Rules of protection and the manner of proceeding with information in Bank Polska Kasa Opieki Spółka Akcyjna,
- Protection of electronic information in Bank Polska Kasa Opieki S.A.