Personal Data Protection


The National Bank of Romania (NBR) is constantly preoccupied with ensuring a high level of protection of personal data, which are processed according to the current legal framework.

As personal data controller, the National Bank of Romania processes the data that are either voluntarily provided or are automatically received as a result of visiting the www.bnr.ro website, according to the applicable provisions of the national legislation in force, to the provisions of Regulation (EU) 679/2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter named “GDPR”, and of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector, in a secure manner and for the sole purpose for which they have been collected.

DEFINITIONS

Personal data” means any information that relates to an identified or identifiable natural person (“data subject”).

In relation to the NBR, you are by law the “data subject”, meaning an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

The NBR website is the main means of communication on the Internet of the National Bank of Romania and may be accessed at www.bnr.ro.

↑ Top

COLLECTED PERSONAL DATA

  • Voluntarily Provided Data

    When using forms on the NBR website or when contacting us by e-mail, you are voluntarily providing us with your personal data. Such data may include name and surname, profession, institution/company, home address, telephone number, identification papers (I.D. card/passport), e-mail address.
    The NBR keeps these data secure and confidential and does not disclose or transfer them to third parties, unless expressly laid down by law or when necessary for the purpose of collecting such data.

  • Automated Data Collection

    When navigating the NBR website, data regarding your visit are automatically generated. They include your IP address, your browser, accessing time, accessed page or document and other technical data. The NBR website does not use cookies for tracing your browsing options, tracking your searches or other potentially intrusive elements.

↑ Top

PURPOSE AND LEGAL GROUNDS FOR DATA PROCESSING

Some of the services provided by the NBR website require personal data processing. The NBR, as controller, processes data exclusively for the specific purpose for which they have been collected.

  • Browsing the NBR website – When browsing the NBR website, data regarding your visit are automatically generated. They include your IP address, your browser, accessing time, accessed page or document and other technical data. The ground for this processing consists in the legitimate interests of the NBR pursuant to point (f) of Article 6(1) subparagraph 1 of the GDPR. The NBR processes these data in order to ensure the proper functioning and improvement of services provided by the website, to identify users with an abusive behaviour (fend off DoS cyber-attacks), as well as generate traffic stats (total number of hits on the website, unique IP count, most visited pages, IPs with the biggest number of visits, etc.). Access statistics are generated on a daily basis. Detailed data older than 10 days are automatically erased.
  • Subscribing for a newsletter – The NBR website users may receive, upon request, notification e-mails announcing press releases, fresh publications or other news published on the website. The persons who wish to receive such information fill out the online form on our News section > “Subscribe”. The only personal data processed by the NBR during this process are the users’ e-mail addresses. When a data subject decides to unsubscribe, his/her data are automatically erased from the database. The legal ground for this processing is your consent pursuant to point (a) of Article 6(1) of the GDPR.
  • Requesting access to the NBR Library/Archive – The NBR website users may send requests to access the NBR Archive and/or Library via dedicated online forms that may be sent to arhiva [at] bnro.ro and biblioteca [at] bnro.ro, respectively. The personal data processed by the NBR as a result of the above are the following: name and surname, profession, institution/company, home address, telephone number, ID/Passport number, e-mail address and research subject. The legal ground for this processing consists in the provisions of the following laws: National Archives Law No. 16/1996, republished; Law No. 182/2000 regarding the protection of national cultural heritage, recast, as subsequently amended and supplemented; Libraries Law No. 334/2002, republished, as subsequently amended and supplemented; Law No. 333/2003 regarding the protection of sites, goods, values and persons, republished, as subsequently amended and supplemented. The processing of personal data is necessary for compliance with legal obligations of the National Bank of Romania pursuant to point (c) of Article 6(1) of the GDPR. Moreover, the lawfulness of this processing is also based on the legitimate interest of the NBR to ensure the security and preservation of highly-valuable written documents resulting from its activity, as well as on that deriving from the management of goods of material value that belong to it, pursuant to point (f) of Article 6(1) subparagraph 1 of the GDPR.
  • Scheduling a visit to the NBR Museum – The NBR website users may send scheduling requests to visit and access the NBR Museum. The data are sent by users to Muzeul [at] bnro.ro. The personal data processed by the NBR as a result of the above are the following: name and surname, passport number, telephone number, e-mail. The legal ground for this processing is Law No. 333/2003 regarding the protection of sites, goods, values and persons, republished, as subsequently amended and supplemented, pursuant to point (c) of Article 6(1) of the GDPR – namely processing is necessary for compliance with a legal obligation of the NBR.
  • Numismatic monetary reservation - The users of the NBR site have the possibility of submitting requests for numismatic monetary reservation regarding the purchase of numismatic coins. The data will be sent by the user by filling in the reservation forms available on the site www.bnr.ro. The personal data that the NBR processes in this case are the following: surname, first name, social security number, phone number and email address. Pursuant to Art. (1) letter (b) from GPDR, the processing is necessary in order to endorse the requests of the user before signing a contract.
  • Online recruitment (for more information please access Informare - Recrutare – For a quick and effective submission of your application for a vacancy within the NBR, as an NBR website user you can download the necessary forms and subsequently send the documents to HR.Recrutare [at] bnro.ro. All the data and documents (including personal data such as name and surname, signature, photograph, home and/or mailing address, gender, telephone number, date and place of birth, e-mail address, nationality, ID card, identification number, marital status, education, references, data concerning relatives working at the NBR, data about criminal offences, including prior convictions and the initiation of criminal proceedings, data mentioned in the following documents: curriculum vitae, letter of intent/of motivation, affidavit and the supporting documents) which you send in order to apply for a vacancy will be used exclusively for processing your employment request. The ground for this processing consists in taking steps at the request of the data subject prior to entering into a contract pursuant to point (b) of Article 6(1) of the GDPR, as well as in the applicant’s consent to the processing of his/her personal data after the completion of the initial recruitment process that did not end with the entering into a contract pursuant to point (a) of Article 6(1) of the GDPR.
  • Submitting online petitions – The NBR website users may submit petitions by filling out the online form under Contact > Public Information. Petitioners may also send these forms to info [at] bnro.ro. The personal data thus processed by the NBR are the following: name and surname, home address, e-mail address. The ground for this processing is Government Ordinance No. 27/2002 regulating petition solving and Law No. 233/2002 for the approval of Government Ordinance No. 27/2002, pursuant to point (c) of Article 6(1) of the GDPR – namely processing is necessary for compliance with a legal obligation of the NBR.
  • Submitting online requests – The NBR website users may submit online requests via the e-mail address info [at] bnro.ro. The personal data thus processed by the NBR are the following: name and surname, e-mail address/the address where the reply is to be sent. The ground for this processing is Law No. 544/2001 regarding free access to information of public interest, pursuant to point (c) of Article 6(1) of the GDPR – namely processing is necessary for compliance with a legal obligation of the NBR.
  • Submission of the Fintech Innovation Hub form – Information on innovative projects in the area of payment and financial services transmitted so that the NBR can promote and effectively monitor technological progress and market developments in the area of payment services also include the personal data of contact persons, filled in a standard form (in the Fintech Innovation Hub section). These data are collected and processed to facilitate communication in order for the innovative project to be analysed at the NBR level.
    The personal data of the contact persons that the NBR processes for this purpose are the following: first and last name, mailing address, e-mail address, phone number.
    The legal basis for personal data processing is the legitimate interest of the NBR, in accordance with Art. 6 (1) (f) of the General Data Protection Regulation (GDPR).

↑ Top

PERSONAL DATA STORAGE PERIOD

The National Bank of Romania stores the personal data of the NBR website visitors, as well as those comprised in the requests addressed to the NBR by forms available on the Internet page or sent via e-mail only for the period necessary to achieve the purposes for which such data have been collected (this includes the storage period for auditing and legal purposes), as required by the applicable legal provisions and by the rules and regulations on archives respectively.

↑ Top

ACCESS TO PERSONAL DATA AND RECIPIENTS OF THESE DATA

Personal data are accessed only by NBR staff involved in this activity. These data may be disclosed to persons outside the NBR only when necessary for the purpose of processing and/or when required by law.

↑ Top

PERSONAL DATA TRANSFER

We do not transfer your personal data to EU/non-EU countries, unless expressly laid down by law or when necessary for the purpose of data collection. In case any changes occur, you will be duly informed.

↑ Top

CONSEQUENCES OF THE FAILURE TO PROVIDE REQUESTED PERSONAL DATA

If an NBR website visitor refuses to provide certain data that are essential for the purpose of accessing the website, the NBR reserves the right to deny the visitor’s request.

↑ Top

YOUR RIGHTS

Insofar as conditions stipulated by the applicable legislation are fulfilled, the NBR website visitors whose personal data are processed have the following rights:

  • Right of access (Article 15 of the GDPR)
    You have the right to obtain from the NBR confirmation as to whether or not your personal data are being processed, and, where that is the case, access to the personal data.
  • Right to rectification (Article 16 of the GDPR)
    You have the right to obtain from the NBR the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed.
  • Right to erasure (“right to be forgotten”) (Article 17 of the GDPR)
    Where (1) personal data are no longer necessary in relation to the purposes for which they were collected, (2) you withdraw consent on which the processing is based and there is no other legal ground for the processing, (3) you object to the processing and there are no overriding legitimate grounds for the processing or (4) the personal data have been unlawfully processed, you have the right to obtain the erasure of personal data concerning you.
  • Right to restriction of processing (Article 18 of the GDPR)
    You have the right to obtain the restriction of personal data processing by the NBR where one of the following applies:
    1. accuracy of the personal data is contested by you, for a period enabling the controller to verify their accuracy;
    2. processing is unlawful and you oppose the erasure of the personal data, requesting the restriction of their use instead;
    3. the NBR no longer needs your personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims;
    4. you have objected to processing pursuant to Article 21(1) of the GDPR, pending the verification whether the legitimate grounds of the NBR override yours.
  • Right to data portability (Article 20 of the GDPR)
    You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the NBR, where:
    1. the processing is based on your consent pursuant to point (a) of Article 6(1) or point (a) of Article 9(2) of the GDPR or on a contract pursuant to point (b) of Article 6(1);
    2. the processing is carried out by automated means.
  • The right to object (Article 21 of the GDPR)

    You shall have the right to object, at any given time, to the processing of your personal data on grounds relating to your particular situation, to the operations of processing of personal data, necessary for the performance of a task carried out in the public interest, or which results from the exercise of an official authority invested in the National Bank of Romania (NBR) and/or to the processing carried out for the purposes of the legitimate interests pursued by the NBR or by a third party, including profiling based on these provisions. If you have already exercised your right to objection, The National Bank of Romania (NBR) cannot process your personal data, but for the case when NBR proves that there are legitimate and imperative reasons which justify the processing and which prevail over the public interest, rights and liberties of the data subject or that the purpose of the processing is establishing, exerting or defending a right in the court of justice.

  • The right not to be subject to a decision based solely on automated processing (Article 22 of the GDPR)
    You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, such as your performance at work.
    This right does not apply if the decision:
    1. is necessary for entering into, or performance of, a contract between you and the National Bank of Romania;
    2. is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or
    3. is based on your explicit consent.
  • Right to withdraw your consent (Article 7(3) of the GDPR)
    Where processing is based on consent, you have the right to withdraw your consent at any time by submitting an express request. If you consider that your rights regarding personal data processing have been infringed, you have:
    1. The right to lodge a complaint with the National Supervisory Authority for Personal Data Processing;
    2. The right to bring the matter before a competent court.
  • ↑ Top

SECURING PERSONAL DATA

In the personal data processing operations, the NBR makes use of technical and organisational measures in order to ensure an adequate level of protection and security against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

↑ Top

PROTECTION OF MINORS

The NBR does not request personal data from minors. People aged under 16 should not provide us with their personal data without the consent of their parents or tutors. Such data are not intentionally collected and are not disclosed to third parties.

↑ Top

EXTERNAL LINKS

The NBR website contains links to other websites, which are not the responsibility of the National Bank of Romania.

↑ Top

HOW TO EXERCISE YOUR RIGHTS

In case you have any questions or doubts about the processing of your personal data or you wish to exercise your legal rights regarding the personal data in our possession, you may contact the NBR’s data protection officer at datepersonale [at] bnro.ro and/or in writing at The National Bank of Romania, Lipscani Street no. 25, sector 3, Bucharest, postal code 030031.

The legal deadline for replying to these requests is 30 days, with the possibility of extension.

↑ Top

UPDATING

The present information may be subject to subsequent changes. All updates and changes to this information are valid starting on the date they are made known, which will be done by publication on the National Bank of Romania website.

↑ Top

CONTACT DETAILS OF THE DATA PROTECTION OFFICER

The data protection officer appointed at the National Bank of Romania may be contacted at datepersonale [at] bnro.ro and/or in writing at The National Bank of Romania, Lipscani Street no. 25, sector 3, Bucharest, postal code 030031.

↑ Top