Slika družine

Personal Data Protection

Personal Data Protection

 

At the Pension and Disability Insurance Institute of Slovenia (hereinafter »ZPIZ«), we are aware of the importance of protecting your privacy and personal data. Pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and of the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), the data controller must provide the data subject with information on the processing of their personal data.

The following information integrates the key information on personal data protection at ZPIZ under Article 13 of the General Data Protection Regulation.

  • Personal data controller
  • Data Protection Officer
  • Rights of the data subject
  • Detailed information on the processing of personal data in applications lodged in person
  • Detailed information on the processing of personal data at ZPIZ website: https://www.zpiz.si
  • Detailed information on the processing of personal data in the records held by ZPIZ

 

 

 

 

Personal data controller

 

Personal data controller is the Pension and Disability Insurance Institute of Slovenia, Kolodvorska 15, 1000 Ljubljana, company registration number: 5156700000.

Contact details of the controller:

telephone number: 01 4745 100

fax number: 01 4321 046

email address: informacije@zpiz.si

 

 

Data Protection Officer

 

Contact details of the DPO:

Jasmina Habulin

email: dpo@zpiz.si

 

 

 

Rights of the data subject

 

Data subject shall have the right:

- to request access to their personal data;

- to request rectification and erasure of their personal data;

- to request restriction of processing of their personal data;

- to object to processing of their personal data, and

- to data portability.

 

The request can be lodged in writing (by post or per email) with the data controller or DPO. You can also use a form prepared for you by the DPO HERE TUKAJ.

ZPIZ can comply with the request of the data subject only if and as soon as the conditions laid down by the General Data Protection Regulation and by the sectoral legislation are met. 

The data subject whose personal data (telephone number and/or email address) are, with their consent, processed for the purpose of the digital delivery of documents can withdraw their consent with the Withdrawal statement HERE: TUKAJ

If you believe that your rights in regard to the protection of personal data have been infringed, you have the right to file a complaint with a personal data supervisory authority – Data Protection Officer (address: Dunajska 22, 1000 Ljubljana, email: gp.ip@ip-rs.si, telephone number: 012309730. website: www.ip-rs.si) .

 

 

Detailed information on the processing of personal data in applications lodged in person

 

What information: In paper applications lodged in person or with an authorized official of the Institute, ZPIZ obtains the personal data that the data subject or an authorized official entered on an individual form. Information on telephone number or email address is optional.

Purpose: Personal information from the form is processed for the purpose of processing an application. 

Telephone number or email is used for the purpose of direct communication with the data subject or for digital delivery of documents, if the data subject explicitly gave their consent for such delivery when lodging an application via eApplications for EVERYONE online service or in a Statement for the granting of consent or amendment of data.

Legal Basis: 6(1)(a) of the General Data Protection Regulation – consent to use information on telephone number and email (if provided).

With regard to personal data provided in individual form, Article 6(1)(c) of the General Data Protection Regulation, the Act Governing the Register of Insured Persons and Beneficiaries of Rights Provided under Pension and Disability Insurance (ZMEPIZ-1), the Act Governing Administrative Procedure (ZUP), and relevant provisions of the act governing compulsory pension and disability insurance (ZPIZ, ZPIZ-1, or ZPIZ-2), shall apply.

Users’ categories: When delivering ZPIZ documents in paper form, personal data from a document will be transferred to the outsourcing partner responsible for delivery of physical documents.

For more information on the transmission of personal data provided in applications to users, see the individual records HERE TUKAJ

Information regarding transmission of personal data to third countries or international organizations: When the processing of your application requires cooperation with foreign providers of pension and disability insurance within a framework of international social security agreements with third countries, personal data can be transferred in accordance with the provisions of such agreements concluded with Argentina, Australia, Bosnia and Herzegovina, Montenegro, South Korea, Canada and Quebec, North Macedonia, Serbia, and the USA.

Retention period: Data provided on the basis of personal consent of the data subject (telephone number and email) shall be processed only for the purposes for which the consent has been given until such consent is withdrawn. ZPIZ shall, for the purpose of proving their validity, keep such data even if the consent has been withdrawn. For more information on the storage of personal data provided in applications, see the individual records HERE TUKAJ

Right to withdraw consent: With regard to personal data processed by ZPIZ on the basis of personal consent of the data subject (telephone number and email), the latter has the right to withdraw their consent at any time, whereby the withdrawal does not affect the lawfulness of data processing carried out on the basis of their consent prior to its withdrawal.

Information on

  • whether provision of personal data is a statutory or contractual requirement: Yes, since the entitlements from pension and disability insurance are established in an administrative proceeding, the data subject is, pursuant to ZPIZ-2, ZMEPIZ-1, and ZUP, obliged to provide all personal data and other information required for the processing of their claim.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data: If, in their formal claim, the data subject fails to provide obligatory personal data and other information required for the processing of their claim, the claim shall be rejected. Other optional data, not provided by the data subject or obtained by ZPIZ ex officio, shall not be taken into account in decision-making.

 

Submitting a mobile telephone number is obligatory only if the data subject expressed a wish for digital delivery of ZPIZ documents and gave their consent for such delivery when lodging an application via eApplications for EVERYONE online service or in a Statement for the granting of consent or amendment of data. If failing to do so, documents will be delivered by post.

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

 

Detailed information on the processing of personal data via ZPIZ website: https://www.zpiz.si

 

ZPIZ operates the website https://www.zpiz.si/ using its own server infrastructure.

For the purpose of operating the website, none of the personal data shall be transmitted to third countries, international organizations, or other users.

ZPIZ processes collected personal data of the website users for different purposes, such as:

  • Visiting website
  • Cookies
  • Processing of personal data in online services provided by ZPIZ

 

 

Visiting website

 

What information: ZPIZ shall not collect any personal data on any visit to the website https://www.zpiz.si/, used by a website visitor only for the purpose of obtaining information, who does not register or log in to online portals, does not fill in any application, or otherwise provide personal data. The IP address – a unique number that identifies an individual computer or a device on the internet – shall be anonymised with an IP number generated on the firewall used by ZPIZ.

 

 

Cookies

 

ZPIZ website uses different types of computer cookies, the scope and function of which are described HERE TUKAJ

 

 

 

Processing of personal data in online services provided by ZPIZ (My eZPIZ, e-Applications for EVERYONE, Digital document retrieval, and My BiZPIZ)

 

  • My eZPIZ
  • e-Applications for EVERYONE
  • Digital document retrieval
  • My BiZPIZ
  • Online surveys

 

 

 

 

Online service My eZPIZ

 

What information: Registration to the My eZPIZ online portal is possible only with a qualified digital certificate or via the SI-PASS. Upon registration and each time the data subject logs in to the portal, ZPIZ shall acquire data from their digital certificate or identification data from the SI-PASS access control system.

Where lodging an e-Application via My eZPIZ online service, ZPIZ shall (via online e-Application forms) process personal data of the data subject that is (at each registration with a qualified digital certificate or login with the SI-PASS) automatically transferred to the information system, and that provided in the application by the data subject themselves.

Purpose: ZPIZ uses personal data from the digital certificate or identification data from the SI-PASS system for the purpose of unique identification of the registered user. Data from an e-Application provided by the data subject shall be used for the purpose of deciding on the claim. Providing a telephone number is optional.

Legal Basis: With regard to personal data provided in an individual e-Application form, Article 6(1)(c) of the General Data Protection Regulation, Act Governing the Register of Insured Persons and Beneficiaries of Rights Provided under Pension and Disability Insurance (ZMEPIZ-1), Act Governing Administrative Procedure (ZUP), and relevant provisions of the act governing compulsory pension and disability insurance, shall apply.

Users’ categories: Data from the digital certificate shall not be transferred to users. For more information on the transmission of personal data provided in applications to users, see the individual records HERE TUKAJ

Information regarding transmission of personal data to third countries or international organizations: Data from the digital certificate shall not be transferred to third countries or international organizations. For more information on the transmission of personal data provided in applications to users, see the individual records HERE TUKAJ

Retention period: Data on registered users of the My eZPIZ online portal shall be kept indefinitely. For more information on the storage of personal data provided in applications, see the individual records HERE TUKAJ

Right to withdraw consent: Since the processing of personal data is not based on consent of the data subject, the latter cannot prevent the processing of data from their digital certificate by revoking their consent for as long as they hold a registered user account with ZPIZ via the My eZPIZ online service.

Information on

  • whether provision of personal data is a statutory or contractual requirement: No.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data: Yes, personal data shall be processed due to the nature of the operation of the services.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

 

 

e-Applications for EVERYONE online service

 

What information: When applying via e-Applications for EVERYONE online service, ZPIZ shall collect personal data provided by the data subject in an application form. Information on PIN (EMŠO) is mandatory. For a successful submission of an application, information on a mobile telephone number is also required. Providing an email address is optional.

Purpose: ZPIZ shall process information on telephone number and email address (if provided) for the purpose of submission of an application. Mobile telephone number and email address for the purpose of digital document retrieval shall be processed only, if the data subject has signed a consent when applying. Personal data provided in an e-Application are requested for the purpose of processing a claim.

Legal Basis: With regard to telephone number and email address (if provided), Article 6(1)(a) of the General Data Protection Regulation shall apply. With regard to personal data provided in the application form, Article 6(1)(c) of the General Data Protection Regulation shall apply.

Users’ categories: Information on telephone number and email address (if provided) shall not be transferred to users. For information regarding the transmission of personal data provided in applications to users, see the individual records HERE TUKAJ

Information regarding transmission of personal data to third countries or international organizations: Information on a telephone number and an email address, provided for the purpose of submission of applications via e-Applications for EVERYBODY online service shall not be transferred to third countries or international organizations. For information regarding the transmission of personal data provided in applications to users, see the individual records HERE TUKAJ

Retention period: Personal data provided on the basis of personal consent of the data subject shall be processed for the consented purposes only until revoked. ZPIZ shall keep these data for the demonstration of validity of the consent even after the withdrawal.

For information regarding retention of personal data provided in application forms, see the individual records HERE TUKAJ

Right to withdraw consent: Where processing of personal data (mobile telephone number and email address) by ZPIZ is based on personal consent of the data subject, the latter has the right to withdraw their consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Information on

  • whether provision of personal data is a statutory or contractual requirement: No.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data: If the data subject fails to provide a mobile telephone number, they shall not be able to use e-Applications for EVERYONE online service. Providing information on an email address is optional.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

 

Digital Document Retrieval online service

 

What information: Online service enables access to the Institute's source documents originally issued in electronic form by entering an ID number of the selected document and the mobile telephone number or email address of the data subject. Successfully collected documents can be downloaded via ZPIZ subpage.

Purpose: Provided personal data shall serve for receiving a link to the document a user wishes to retrieve.

Legal Basis: Article 6(1)(a) of the General Data Protection Regulation

Users’ categories: Information collected for the purpose of digital documents retrieval shall not be transferred to users.

Information regarding transmission of personal data to third countries or international organizations: Information collected for the purpose of digital documents retrieval shall not be transferred to third countries or international organizations.

Retention period: Personal data provided on the basis of personal consent of the data subject shall be processed for the consented purposes only until revoked. ZPIZ shall keep these data for the demonstration of validity of the consent even after the withdrawal.

Right to withdraw consent: Where processing of mobile telephone number and email address for the purpose of digital documents retrieval is based on personal consent of the data subject, the latter has the right to withdraw their consent at any time.

Where in order to access the source document by entering the document ID number, the data subject has provided their contact details for one-time retrieval only, this information shall only be used once for each session respectfully, thereby exhausting their right to withdrawal.

Information on

  • whether provision of personal data is a statutory or contractual requirement: No.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data: If the data subject fails to provide personal data when using Digital Document Retrieval online service, downloading of such document shall not be enabled. 

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

 

My BiZPIZ online service

 

What information: Upon registration and each time the data subject logs in to the portal, ZPIZ obtains data from a digital certificate of the data subject.

Where lodging an e-Application via My BiZPIZ online service, ZPIZ shall process (via online e-Application forms) personal data of the data subject that are, at each registration with a qualified digital certificate, automatically transferred to the information system, and those provided in the application by the data subject themselves.

Purpose: ZPIZ shall use personal data from the digital certificate for the purpose of unique identification of the registered user. Data from the e-Application provided by the data subject shall be used for the purposes of processing the claim.

Legal Basis: With regard to personal data provided in an e-Application form, Article 6(1)(c) of the General Data Protection Regulation, Act Governing the Register of Insured Persons and Beneficiaries of Rights Provided under Pension and Disability Insurance (ZMEPIZ-1), Act Governing Administrative Procedure (ZUP), and relevant provisions of the act governing compulsory pension and disability insurance, shall apply.

Users’ categories: Data from the digital certificate shall not be transferred to users. For information regarding the transmission of personal data provided in applications to users, see the individual records HERE TUKAJ

Information regarding transmission of personal data to third countries or international organizations: Data from the digital certificate shall not be transferred to third countries or international organizations. For information, regarding the transmission of personal data provided in applications to users, see the individual records HERE TUKAJ

Retention period: Data on registered users of the My BiZPIZ online portal shall be kept indefinitely. For information, regarding the retention of personal data provided in applications, see the individual records HERE TUKAJ

Right to withdraw consent: Since the processing of personal data is not based on personal consent of the data subject, the latter cannot prevent the processing of data from their digital certificate by revoking their consent for as long as they hold a registered user account with ZPIZ via My BiZPIZ online service.

Information on

  • whether provision of personal data is a statutory or contractual requirement: No

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data: Yes, personal data are processed due to the nature of the operation of the services.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

Online Survey

 

All information provided by the data subject taking part in a survey shall be collected on an anonymous basis only, unless the data subject explicitly decides to reveal any of their personal data publicly. If the data subject decides to reveal any of their personal data or the personal data of any third person, it shall be assumed that they understand the risks and potential consequences of such conduct. When participating in a non-anonymous survey, the data subject shall be informed thereof in advance and shall be given the opportunity to consent to processing of their personal data for the purposes specified in the respective survey.

Where the data subject has been invited to participate in a survey through SMS or/and email, the legal basis for the processing of contact details shall be either the prior consent of the data subject when providing contact details (Article 6(1)(a) of the General Data Protection Regulation), or Article 6(1)(f) of the General Data Protection Regulation allowing the processing of personal data for other purposes, where the legitimate interests pursued by the controller are not overridden by the interests of the data subject.

What information: When completing the survey, ZPIZ shall collect personal data provided by the data subject in their answers to the questions from the survey. The data so collected shall not be processed separately and shall not be linked to any other data.

Purpose: ZPIZ shall use the collected data exclusively for the purpose of research or for those exclusively defined in the respective survey and not for the purposes of direct marketing.

Legal basis: Article 6(1)(a) of the General Data Protection Regulation

Users’ categories: Information collected shall not be transferred to users.

Information regarding transmission of personal data to third countries or international organizations: Data shall not be transferred to third countries or international organizations.

Retention period: Data shall be stored until the consent given by the data subject has been revoked.

Right to withdraw consent: Consent to processing of personal data provided in the survey can be revoked by a request for withdrawal of consent sent to informacije@zpiz.si in which the data subject must specify the survey they have taken part in. Furthermore, the data subject can object to processing of their contact details (telephone number or/and email address) for the purpose of future online surveys via informacije@zpiz.si.

 

Information on

  • whether provision of personal data is a statutory or contractual requirement: No.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data: Where the data subject decides to participate in an online survey they have to answer all the questions in order to submit the survey successfully (unless otherwise provided in an individual question).

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

Processing of personal data in the individual records kept by ZPIZ

 

For performing its activities, ZPIZ in the role of data controller processes personal data of the data subjects in its various records, such as:

  • Register of beneficiaries of pension and disability benefits
  • Register of insured persons
  • Register of liable persons
  • Payments records
  • Expert medical opinions records
  • Electronic records of the medical examiners
  • Infringers records
  • Records of job applicants responding to job vacancy notices
  • Video surveillance records
  • ZPIZ visitors log
  • Records of applicants under the Public Information Access Act
  • Processing of personal data in records collections concerning physical asset management
  • Records of applicants under the Mass Media Act
  • Register of the members of the Council of the Institute

 

 

 

Register of beneficiaries of pension and disability benefits

 

Purpose: Personal data are processed for the purpose of:

  • processing the claims and deciding on the entitlements and protection of rights from the pension and disability insurance under the act governing compulsory pension and disability insurance;
  • processing the claims and deciding on the entitlements granted by ZPIZ under special provisions and paying out the benefits thereof;
  • acting or cooperating in compensation proceedings where the Institute acts as a party to a case or a participant in the proceedings.

 

Legal Basis: Article 6(1)(c) of the General Data Protection Regulation, ZPIZ-2, ZEPDSV, ZMEPIZ-1.

Users' categories: Legally authorized users (Article 2(3) ZMEPIZ1 and Article 8(3) of ZMEPIZ-1), as well as users providing a legal basis for obtaining personal data pursuant to sectorial legislation.

Information regarding transmission of personal data to third countries or international organizations: With regard to international insurance, data can be transferred to third countries on the basis of concluded and ratified international agreements with Argentina, Australia, Bosnia and Herzegovina, Montenegro, South Korea, Canada and Quebec, North Macedonia, Serbia, and the USA.

Retention period: Indefinitely.

Right to withdraw consent: Since the processing of personal data is not based on consent, the data subject shall not have the right to withdraw their consent.

Information on:

  • whether provision of personal data is a statutory or contractual requirement: Yes, since the entitlements from pension and disability insurance are granted in an administrative proceeding, the data subject is, pursuant to ZPIZ-2, ZMEPIZ-1, and ZUP, obliged to provide all personal data and other information required for the processing of their claim.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data: If, in their formal claim, the data subject fails to provide obligatory personal data and other information required for the processing of their claim, the claim shall be rejected. Other optional data, not provided by the data subject or obtained by ZPIZ ex officio, shall not be taken into account when deciding on a claim.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

Register of insured persons

 

Purpose: Personal data are processed for the purpose of:

  • processing the claims and deciding on the entitlements and protection of rights from the pension and disability insurance under the act governing compulsory pension and disability insurance;
  • processing the claims and deciding on the entitlements granted by ZPIZ under special provisions and paying out the benefits thereof;
  • processing the claims and deciding on the entitlements under provisions of ZMEPIZ-1;
  • acting or cooperating in compensation proceedings where the Institute acts as a party to a case or a participant in the proceedings.

 

Legal Basis: Article 6(1)(c) of the General Data Protection Regulation, ZPIZ-2, ZEPDSV, ZMEPIZ-1. Pursuant to the provisions of ZPIZ-2, a person is covered by the compulsory pension and disability insurance as soon as they meet the statutory insurance requirements, irrespective of their willingness to register for insurance. To implement the insurance, persons liable for registration and other institutions are required to provide relevant data under ZMEPIZ-1.

Users' categories: Legally authorized users (Article 2(3) of ZMEPIZ-1 and Article 8(3) of ZMEPIZ-1) as well as users providing a legal basis for obtaining personal data pursuant to sectorial legislation.

Information regarding transmission of personal data to third countries or international organizations: With regard to international insurance data can be transferred to third countries on the basis of concluded and ratified international agreements with Argentina, Australia, Bosnia and Herzegovina, Montenegro, South Korea, Canada and Quebec, North Macedonia, Serbia and the USA.

Retention period: Indefinitely.

Right to withdraw consent: Since the processing of personal data is not based on consent, the data subject shall not have the right to withdraw their consent.

Information on:

  • whether provision of personal data is a statutory or contractual requirement: The provision of personal data for the purpose of the Register of Insured Persons is required by law; persons liable for registration are, pursuant to ZPIZ-2, ZMEPIZ-1, and ZUP, obliged to provide personal data on the insured persons. When the status of an insured person is being established in the course of an administrative proceeding, the data subject is, pursuant to ZPIZ-2, ZMEPIZ-1, and ZUP, obliged to provide all personal and other data required for the processing of their claim.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data:
    • The data subject is obliged to provide data if, under the ZMEPIZ-1, they are defined as a person liable for registration, de-registration and reporting of the changes during insurance or data on bases for the calculation and payment of contributions, or as a person liable to pay contributions. 
    • If the data subject as a person liable for registration, de-registration and reporting of the changes during insurance or data on bases for the calculation and payment of contributions, who is not also an insured person, fails to provide data as required by the law, the Institute shall request the data by official order. If the liable person fails to respond to the order, the Institute shall initiate the offense proceeding against them.
    • If a person is both, a person liable for registration and an insured person at the same time, and fails to register for or de-register from insurance, the Institute shall decide upon the status of an insured person ex officio. If, after the decision thereof is issued, the liable person still fails to register for or de-register from insurance, the Institute shall do so on their behalf ex officio.    

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

Register of liable persons

 

Purpose: Personal data are processed for the purpose of:

  • processing the claims and deciding on the entitlements and protection of rights from the pension and disability insurance under the act governing compulsory pension and disability insurance;
  • processing the claims and deciding on the entitlements granted by ZPIZ under special provisions and paying out the benefits thereof;
  • processing the claims and deciding on the entitlements under provisions of ZMEPIZ-1;
  • acting or cooperating in compensation proceedings where the Institute acts as a party to a case or a participant in the proceedings.

 

Legal Basis: Article 6(1)(c) of the General Data Protection Regulation, ZPIZ-2, ZEPDSV, ZMEPIZ-1.

Users' categories: Legally authorized users (Article 8, paragraph 3 of ZMEPIZ-1) and users providing a legal basis for obtaining personal data pursuant to sectorial legislation.

Information regarding transmission of personal data to third countries or international organizations: With regard to international insurance data can be transferred to third countries on the basis of concluded and ratified international agreements with Argentina, Australia, Bosnia and Herzegovina, Montenegro, South Korea, Canada and Quebec, North Macedonia, Serbia and the USA.

Retention period: Indefinitely.

Right to withdraw consent: Since processing of personal data is not based on consent, the data subject shall not have the right to withdraw their consent.

Information on

  • whether provision of personal data is a statutory or contractual requirement: The provision of personal data for the purpose of the Register of Insured Persons is required by law; persons liable for registration are pursuant to ZPIZ-2, ZMEPIZ-1, and ZUP obliged to provide personal data on both, the liable person and the insured persons.
  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data:
    • If the data subject as a person liable for registration, de-registration and reporting of the changes during insurance or data on bases for the calculation and payment of contributions, who is not also an insured person, fails to provide data as required by the law, the Institute shall request the data by official order. If the liable person fails to respond to the order, the Institute shall initiate the offence proceeding against them.
    • Both the data on a liable person and on an insured person are reported upon registration for insurance. If a person is both, a person liable for registration and an insured person at the same time, and fails to register for or de-register from insurance, the Institute shall decide upon the status of an insured person ex officio. If, after the decision thereof is issued, the liable person still fails to register for or de-register from insurance, the Institute shall do so on their behalf ex officio.    

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

Payments records

 

Purpose: Pension and disability insurance implementation and payment of benefits provided by ZPIZ.

Legal Basis: Article 6(1)(c) of the General Data Protection Regulation, ZPIZ, ZPIZ-1, ZPIZ-2, ZMEPIZ-1, ZPIZVZ, ZZSV, ZVarDod, Farmers Old-Age Insurance Act, Order on advance payment of pensions granted by the republics of ex-Yugoslavia to the beneficiaries residing in the Republic of Slovenia, Regulations (EU) No: 140/71, 574/72 and 2560/01, ZIPO, ZRPri, ZUJIK, Regulation on permanent merit-based grants to remedial teachers, ZDVDTP, ZSVarPre, ZUPJS, TEPDSV, ZDoh-2, ZDavP-2, ZZVZZ, ZIZ, ZUTPG; international social security agreements; international double taxation agreements.

Users' categories: Legally authorized users (Articles 3(2) and 8(3) of ZMEPIZ-1) and users providing a legal basis for obtaining personal data pursuant to sectorial legislation.

Applications for registration in the compulsory health insurance for the beneficiaries of pension and disability insurance benefits, who meet the requirements for compulsory health insurance, are submitted via eVem to the Health Insurance Institute of Slovenia.

Data on beneficiaries of pension and disability insurance benefits are transmitted to foreign pension and disability insurance providers for the purpose of confirming that a beneficiary is still alive.

Notifications on regular and special payments are transmitted to the contractor EPPS to be printed and dispatched.

Data on pension beneficiaries are transmitted to an external contractor for the purpose of production of Pensioner’s Cards.

Payment orders for the payment of benefits to beneficiaries residing in the Republic of Slovenia are submitted to the Public Payments Administration of the Republic of Slovenia (UJP).

Payment orders for the payment of benefits to beneficiaries residing abroad are submitted to Nova Ljubljanska banka (NLB).

Information on

  • whether provision of personal data is a statutory or contractual requirement: Yes.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data: If data subject fails to provide required data, not already held by ZPIZ, payment of benefits could be terminated.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

Expert medical opinions records

 

Purpose: Pension and disability insurance implementation, claiming of entitlements, and processing of claims with ZPIZ.

Legal Basis: Article 6(1)(c) of the General Data Protection Regulation, ZPIZ-2, Articles 7 and 20 of ZMEPIZ-1

Users' categories: Legally authorized users (Article 8, paragraph 3 of ZMEPIZ-1) and users providing a legal basis for obtaining personal data pursuant to sectorial legislation.

Information regarding transmission of personal data to third countries or international organizations: Data shall not be transferred to third countries.

Retention period: Indefinitely.

Right to withdraw consent: Since processing of personal data is not based on consent, the data subject shall not have the right to withdraw their consent.

Information on

  • whether provision of personal data is a statutory or contractual requirement: Yes, since the entitlements from pension and disability insurance are established in an administrative proceeding, the data subject is, pursuant to ZPIZ-2, ZMEPIZ-1, and ZUP, obliged to provide all personal data and other information required for the processing of their claim.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data: If, in their formal claim, the data subject fails to provide obligatory personal data and other information required for the processing of their claim, the claim shall be rejected. Other optional data, not provided by the data subject or obtained by ZPIZ ex officio, shall not be taken into account in decision-making.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

Electronic records of the medical examiners

 

Purpose: Medical examiners labour costs calculations.

Legal Basis: Article 6(1)(c) and 6(1)(b) of the General Data Protection Regulation

Users' categories: Copyright Agency of Slovenia (ASS) for the purpose of issuing invoices and payment of remunerations; legally authorized users and users providing a legal basis for obtaining personal data pursuant to sectorial legislation.

Information regarding transmission of personal data to third countries or international organizations: Data shall not be transferred to third countries.

Retention period: Indefinitely.

Right to withdraw consent: Since processing of personal data is not based on consent, the data subject shall not have the right to withdraw their consent.

Information on

  • whether provision of personal data is a statutory or contractual requirement: Yes, since the entitlements from pension and disability insurance are established in an administrative proceeding, the data subject is, pursuant to ZPIZ-2, ZMEPIZ-1, and ZUP, obliged to provide all personal data and other information required for the processing of their claim.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data: If, in their formal claim, the data subject fails to provide obligatory personal data and other information required for the processing of their claim, the claim shall be rejected. Other optional data, not provided by the data subject or obtained by ZPIZ ex officio, shall not be taken into account in decision-making.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

 

Infringers records

 

Purpose: detection and proving of infringements under ZMEPIZ-1; documenting activities of ZPIZ with regard to infringements; determining repeat infringers, and statistical monitoring of infringers.

Legal Basis: Article 6(1)(c) of the General Data Protection Regulation, Article 206 ZP-1, ZMEPIZ-1

Users' categories: Legally authorized users (Article 204(a) of ZP-1).

Information regarding transmission of personal data to third countries or international organizations: Data shall not be transferred to third countries.

Retention period: for 5 years after the infringement decision has become final.  Documentary material in the form of registers shall be kept indefinitely, subsidiary registers shall be kept for 5 years.

Right to withdraw consent: Since processing of personal data is not based on consent, the data subject shall not have the right to withdraw their consent.

Information on

  • whether provision of personal data is a statutory or contractual requirement: Yes, a person initiating the infringement proceeding is obliged to provide personal data.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data: If a person initiating the infringement proceeding pursuant to ZP and ZUP fails to provide information required for processing their claim, the claim shall be rejected.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

 

Records of job applicants

 

Purpose: Storing of documentation for the purpose of ensuring the regularity of the selection procedure in line with the legislation governing employment relationships or public employees.

Legal Basis: Article 6(1)(c) of the General Data Protection Regulation, ZJU, ZDR-1.

Users' categories: Data is not transmitted to third parties, provided that no appeal has been lodged or no supervision has been carried out.

Information regarding transmission of personal data to third countries or international organizations: Data shall not be transferred to third countries.

Retention period: Selected job applicant – indefinitely, declined job applicant – for 2 years after the recruitment procedure has been concluded.

Right to withdraw consent: Since processing of personal data is not based on consent, the data subject shall not have the right to withdraw their consent.

Information on

  • whether provision of personal data is a statutory or contractual requirement: Yes.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failing to provide such data: If the selecting commission cannot verify whether the job applicant meets the eligibility and selection criteria specified in the vacancy notice, the application of the job applicant shall not be processed.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

Video surveillance records

 

Purpose: Protection of data subject's life, protection of movable and immovable property, maintaining order in ZPIZ premises, and supervision of entries and exits in and from business premises and parking lots at the following addresses:

  • Ljubljana Central Office (Kolodvorska 15, Ljubljana): Lobby – ground floor (pass the security guard); Trg OF – entrance; ground floor – left hall, basement 1 - IT entrance, basement 2 – Records Office entrance, basement 1 – draught lobby, passage, garage entrance, ground floor – staircase, main entrance;
  • Ljubljana Medical Examiners Board (Ob železnici 30, Ljubljana): halls by the elevator: basement, ground floor, 1st and 2nd floor, entrance, basement – service elevator;
  • Regional Unit Celje (Opekarniška cesta 15 c, Celje) – entrance, Customer Service Office;
  • Regional Unit Kranj (Ulica Mirka Vadnova 13a, Kranj) – main entrance, basement entrance, parking lots by the premises, basement slope;
  • Regional Unit Nova Gorica (Delpinova ulica 18b, Nova Gorica): entrance to elevator, lobby, left hall, right hall;
  • Regional Unit Maribor (Zagrebška c. 84, Maribor): halls by the entrance to the elevator: basement, ground floor, 1st and 2nd floor, entrance, basement – IT entrance, basement – Records Office entrance, parking lots – 6x;
  • Regional Unit Novo mesto (Rozmanova 38, Novo mesto): parking lots 5x, entrance – outside and inside, first floor lobby at the entrance.

 

Legal Basis: Article 6(1)(c) of the General Data Protection Regulation in connection with Article 74 ZVOP-1.

Users' categories: Staff providing security services employed with the security service provider can view CCTV cameras live for the purpose of protecting ZPIZ premises.

Only a security service maintenance contractor can have access to security cameras’ footage. Security camera footage can be provided only by request of ZPIZ or police.

Information regarding transmission of personal data to third countries or international organizations: Data shall not be transferred to third countries.

Retention period: The data is deleted automatically and is stored for maximum of three months.

Right to withdraw consent: Since processing of personal data is not based on consent, the data subject shall not have the right to withdraw their consent.

Information on

  • whether provision of personal data is a statutory or contractual requirement: No.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failure to provide such data: No, however; the data subject cannot enter ZPIZ premises without being under video surveillance.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

For more information regarding the video surveillance or your rights concerning the protection of personal data of the data subject, please contact our Data Protection Officer via email: dpo@zpiz.si or call: 01 47 45 559.

 

 

Visitors log

 

Purpose: Protection of property, protection of the data subject's life or limb, and maintaining order in ZPIZ premises as well as supervision of entries to the restricted area.

Legal Basis: Article 6(1)(c) of the General Data Protection Regulation, Article 85 ZVOP-2.

Users' categories: Legally authorized users and users providing a legal basis for obtaining personal data pursuant to sectorial legislation.

Information regarding transmission of personal data to third countries or international organizations: Data shall not be transferred to third countries.

Retention period: The data is deleted automatically.  Access to personal data of 15 most recent visitors is possible.

Right to withdraw consent: Since processing of personal data is not based on consent, the data subject shall not have the right to withdraw their consent.

Information on

  • whether provision of personal data is a statutory or contractual requirement: Yes.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failure to provide such data: The data subject (visitor) is obliged to provide personal data specified by ZVOP-1. If failing to do so, access to ZPIZ premises shall be rejected.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

 

Records of applicants under the Public Information Access Act (ZDIJZ)

 

Purpose: Processing of applications under ZDIJZ.

Legal Basis: Article 6(1)(c) of the General Data Protection Regulation and ZDIJZ.

Users' categories: Data shall be transferred to the DPO only within the framework of an appeal against the decision refusing the applicant’s request to access public information.

Information regarding transmission of personal data to third countries or international organizations: Data shall not be transferred to third countries.

Retention period: Indefinitely.

Right to withdraw consent: Since processing of personal data is not based on consent, the data subject shall not have the right to withdraw their consent.

Information on

  • whether provision of personal data is a statutory or contractual requirement: Yes.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failure to provide such data: If data subject applying to access public information under ZDIJZ and ZUP fails to provide personal data required for the processing of their application, the application shall be rejected.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

 

Processing of personal data in records collections concerning physical asset management

 

Purpose: ZPIZ physical assets management procedures and conclusion of sale contracts and other contracts relating to physical assets of ZPIZ.

Legal Basis: Article 6(1)(c) and 6 (1)(b) of the General Data Protection Regulation and the Physical Assets of the State and Local Government Act.

Users' categories: Personal data can be transferred to notary publics, the Financial Administration of the Republic of Slovenia, the Council of the Institute, building managers and associations of property owners, distributors and suppliers, supervisory bodies of the Institute (upon request), and other users providing a legal basis for obtaining personal data pursuant to legislation or contracts.

Information regarding transmission of personal data to third countries or international organizations: Data shall not be transferred to third countries or international organizations.

Retention period: Indefinitely.

Right to withdraw consent: Since processing of personal data is not based on consent, the data subject shall not have the right to withdraw their consent.

Information on

  • whether provision of personal data is a statutory or contractual requirement: Yes.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failure to provide such data: If data subject fails to provide information required for the adjudication of their bids, their tender shall be considered incomplete, or a contract with the selected data subject shall not be concluded.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

Q&A Records under the Mass Media Act and Q&A Records of clients

 

Purpose: Documenting answers to the questions raised by the media and clients.

Legal Basis: Article 6(1)(e) of the General Data Protection Regulation and the Mass Media Act.

Users' categories: Users providing a legal basis for obtaining personal data pursuant to sectorial legislation.

Information regarding transmission of personal data to third countries or international organizations: Data shall not be transferred to third countries or international organizations.

Retention period: Personal data of journalists are kept indefinitely, personal data of clients are kept for 5 years.

Right to withdraw consent: Since processing of personal data is not based on consent, the data subject shall not have the right to withdraw their consent.

Information on

  • whether provision of personal data is a statutory or contractual requirement: Yes

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failure to provide such data: If data subject fails to provide contact details, the answer to their question could not be provided.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

 

Register of the members of the Council of the Institute

 

Purpose: Convening of the Council of the Institute meetings and communicating with the members of the Council.

Legal Basis: Articles 6(1)(c) and 6(1)(a) of the General Data Protection Regulation, ZPIZ-2.

Users' categories: Users providing a legal basis for obtaining personal data pursuant to sectorial legislation.

Information regarding transmission of personal data to third countries or international organizations: Data shall not be transferred to third countries or international organizations.

Retention period: Name, surname, DOB, and tax number are kept indefinitely. An email address and a telephone number are kept until the end of the mandate.

Right to withdraw consent: The members of the Council of the Institute providing their telephone number or email address in order to facilitate the communication with the Institute have the right to withdraw their consent to the use of these data.

Information on

  • whether provision of personal data is a statutory or contractual requirement: Yes, except from email address and telephone number.

 

  • whether the data subject is obliged to provide personal data and of the possible consequences of failure to provide such data: If data subject fails to provide the required data, exercising of the statutory powers of the Council of the Institute will be obstructed.

 

The existence of automated decision-making, including profiling: Automated decision-making and/or profiling shall not be implemented.

 

 

Updated on 5 July 2023

 

 

 

Opening hours, service hours and contacts

 

Institute's OPENING HOURS:

 

  • Mondays from 8 am to 12 pm and from 1 pm to 3 pm
  • Wednesdays from 8 am to 12 pm and from 1 pm to 5 pm
  • Fridays from 8 am to 1 pm

Opening hours of Customer Service in Krško :

  • Mondays from 8 am to 12 pm and from 1 pm to 3 pm
  • Wednesdays from 8 am to 12 pm and from 1 pm to 3 pm

General information on entitlements and obligations from pension insurance are offered per telephone during the following SERVICE HOURS: 

  • Mondays, Tuesdays and Thursdays from 8 am to 3 pm
  • Wednesdays from 8 am to 5 pm
  • Fridays from 8 am to 1 pm

 

 

 

 

Regional Offices:

 

 

Contact Centre 

 

  • Information on deductions from payments provided by the Institute
    01 4745 901
  • Other information on payments provided by the Institute
    01 4745 902
  • Information on pension insurance entitlements
    01 4745 903
  • Information on disability insurance entitlements
    01 4745 904
  • Information on international insurance entitlements
    01 4745 905
  • Information on providing data on i-REK and M4 forms and outstanding contributions notices
    01 4745 906
  • Information on insurance records, pension bases and contributions
    01 4745 908
  • Customer support for E-ZPIZ and BiZPIZ online services
    01 4745 909
  • Other information
    01 4745 910
  • E-service: information on the status of your claim
    01 4745 999
  • E-service: information on current payments provided by the Institute
    01 4745 998
  • Help

 

 

  •  

 

 

Pension and Disability Insurance Institute of Slovenia, Kolodvorska 15, Ljubljana
General terms | Accessibility statement | Personal Data Protection
Created by: MMstudio