1.1. This Policy regarding the processing of personal data (hereinafter – the Policy) has been developed in accordance with the requirements of Federal Law No. 152 of July 27, 2006 “On Personal Data” (hereinafter – Federal Law No. 152) and defines the procedure for the processing of personal data and measures to ensure the security of personal data in the online publication “Proceedings of the Saratov Military Institute of the National Guard Troops” (hereinafter – the Operator).
1.2. The Operator’s paramount goal and condition for carrying out its activities is the observance of the rights and freedoms of humans and citizens when processing their personal data, including the protection of the rights to privacy, personal, and family secrets.
1.3. This Policy applies to all information that the Operator may obtain about visitors to the website https://svkinio.ru/, as well as about authors of scientific publications published in the online publication.
2.1. Personal data – any information relating directly or indirectly to a specific or identifiable natural person (personal data subject).
2.2. Processing of personal data – any action (operation) or set of actions (operations) performed with or without the use of automation tools with personal data, including the collection, recording, systematization, accumulation, storage, clarification (updating, changing), retrieval, use, transfer (distribution, provision, access), anonymization, blocking, deletion, and destruction of personal data.
3.1. The Operator may process the following personal data of authors of scientific publications:
– surname, first name, middle name (full name);
– academic degrees, academic titles, honorary titles;
– position held;
– place of employment (name of organization, structural unit, country, city);
– email address (e-mail);
– contact phone number;
– postal address (work);
– researcher identifiers (ORCID, SPIN-code, Author ID, ResearcherID, and other similar identifiers).
3.2. The Operator may process the following personal data of website visitors:
– IP address;
– information about the browser (or other software used to access the online publication);
– time of access;
– URL address of the page(s) being accessed;
– cookie files.
3.3. Passport data of authors are processed exclusively for the purpose of concluding and executing license agreements and are not subject to publication in the open metadata of articles.
3.4. Methods of collecting personal data of website visitors:
– automatic collection when visiting the website (IP address, cookie files, browser information);
– voluntary provision through feedback forms;
– use of web analytics systems.
4.1. Purposes of processing authors’ personal data:
– preparation, peer review, and publication of a scientific article;
– identification of the author (co-authors) of the scientific work;
– ensuring authorship and correct attribution of author information in the published material;
– inclusion of article metadata in open scientific databases, abstract and bibliographic systems (eLibrary.ru, Russian Science Citation Index, Russian Center for Scientific Information, Federal State Budgetary Institution Research and Technology Center “Informregistr,” and others);
– communication with the author regarding matters related to the preparation and publication of the article;
– compliance with the requirements of the legislation of the Russian Federation in the fields of science, education, and publishing activities;
– conclusion and execution of license agreements.
4.2. Purposes of processing website visitors’ personal data:
– ensuring the operation of the website;
– improving the quality of the website and its content;
– conducting statistical research.
5.1. Personal data processing is carried out on the basis of:
– consent of the personal data subject (clause 1, part 1, article 6 of Federal Law No. 152);
– a contract to which the personal data subject is a party (clause 5, part 1, article 6 of Federal Law No. 152);
– a contract concluded between the operator and a third party in whose interest the personal data are processed (clause 5, part 1, article 6 of Federal Law No. 152);
– other grounds provided for by the legislation of the Russian Federation.
5.2. The processing of authors’ personal data in respect of information on surname, first name, middle name, affiliation, and researcher identifiers that have become part of a published scientific article is carried out on the basis of Article 1265 of the Civil Code of the Russian Federation (right of authorship) and does not require separate consent of the personal data subject, since such information is an integral element of the work, and its removal would violate the integrity of the work and the author’s right to have their name attributed to the work.
6.1. The Operator ensures the security of personal data and takes all possible measures to prevent unauthorized persons from gaining access to personal data.
6.2. The period for processing authors’ personal data is 5 (five) years from the date of publication of the article, with the exception of information that has become part of the published work and is processed on the basis of Article 1265 of the Civil Code of the Russian Federation for the entire duration of the work’s copyright term.
6.3. The period for processing website visitors’ personal data is 3 (three) years from the date of the last visit to the website.
6.4. Measures to ensure the security of personal data.
6.4.1. General Provisions.
When processing personal data, the Operator takes the necessary legal, organizational, and technical measures to protect personal data from unlawful or accidental access, destruction, alteration, blocking, copying, distribution, as well as from other unlawful actions by third parties, in accordance with Article 19 of Federal Law No. 152 of July 27, 2006 “On Personal Data” and the following regulatory legal acts:
– Decree of the Government of the Russian Federation No. 1119 of November 1, 2012 “On the approval of requirements for the protection of personal data during their processing in personal data information systems”;
– Order of the FSTEC of Russia No. 21 of February 18, 2013 “On the approval of the composition and content of organizational and technical measures to ensure the security of personal data during their processing in personal data information systems”;
– Order of the FSB of Russia No. 378 of July 10, 2014 “On the approval of the composition and content of organizational and technical measures to ensure the security of personal data during their processing in personal data information systems using cryptographic information protection means”;
– Order of Roskomnadzor No. 279 of March 21, 2013 “On the approval of Requirements for notification of personal data processing and changes to previously submitted information.”
6.4.2. Organizational Measures for Personal Data Protection.
To ensure the security of personal data, the Operator implements the following organizational measures:
Appointment of responsible persons:
– a person responsible for organizing the processing of personal data has been appointed (by order of the head);
– a person responsible for ensuring the security of personal data in information systems has been appointed (by order of the head).
Local regulatory acts:
– this Personal Data Processing Policy;
– regulations on the personal data protection regime;
– a list of persons whose access to personal data is necessary for the performance of their official duties;
– instructions on the procedure for identifying facts of unlawful processing of personal data and taking measures to eliminate the consequences of such facts;
– a logbook for recording personal data media;
– a logbook for recording requests from personal data subjects.
Personnel management:
– all employees of the Operator who directly process personal data have been acquainted with the provisions of the legislation of the Russian Federation in the field of personal data, as well as with the local regulatory acts of the Operator, against personal signature;
– periodic professional development (training) is conducted for employees responsible for ensuring the security of personal data;
– employees of the Operator have been warned of criminal, administrative, and disciplinary liability for violations of legislation in the field of personal data.
Organizational and technical measures:
– an access control system has been organized for premises where personal data information systems are located;
– accounting and storage of machine-readable media containing personal data are carried out;
– backup of personal data is organized with a frequency of at least once every 24 hours;
– a logbook for recording requests from personal data subjects is maintained.
6.4.3. Technical Measures for Personal Data Protection.
To ensure the security of personal data, the Operator implements the following technical measures:
Information security tools:
– certified information security tools that have passed the conformity assessment procedure in accordance with the requirements of legislation in the field of personal data are used;
– cryptographic information protection tools are applied (when processing personal data using cryptographic protection);
– antivirus protection tools with automatic updating of antivirus databases are installed;
– firewall tools are used to protect information systems from unauthorized access from external networks.
Access management:
– access rights of users of personal data information systems are differentiated;
– user authentication is performed using unique identifiers and passwords;
– a log of registration and recording of user actions in information systems is maintained;
– physical access to servers hosting personal data information systems is restricted.
Incident detection and response:
– tools for detecting unauthorized access to personal data are used;
– monitoring of the security status of information systems is organized;
– an action plan for responding to personal data security incidents has been developed;
– a procedure for notifying personal data subjects and Roskomnadzor (the Federal Service for Supervision of Communications, Information Technology and Mass Media) about personal data leakage incidents is provided.
Backup and recovery:
– regular backup of personal data is performed;
– backup copies are stored in a secure location that prevents unauthorized access;
– a plan for the recovery of personal data in the event of loss or damage has been developed;
– test restorations from backup copies are carried out periodically.
6.4.4. Category of the Personal Data Information System.
Personal data are processed in a personal data information system classified as the third category in accordance with the requirements of Resolution No. 1119 of the Russian Federation Government of November 1, 2012.
Justification for the category:
– the information system processes personal data of the Russian Federation citizens;
– the personal data do not fall into the special categories or biometric personal data;
– the personal data are processed with the consent of the data subjects;
– the number of data subjects does not exceed 100,000 individuals.
6.4.5. Control and Audit.
The Operator exercises ongoing control over the security of personal data:
– an internal audit of compliance with the requirements of personal data legislation is conducted at least once a year;
– control is exercised over the compliance of the Operator’s employees with the personal data protection regime;
– assessment of the effectiveness of the adopted personal data protection measures is carried out;
– based on the results of control and audit, measures are developed to eliminate identified deficiencies.
7.1. The Operator does not transfer personal data cross-border. No transmission of personal data to the territory of foreign states, to foreign scientific databases, or to servers located beyond the territory of the Russian Federation is carried out by the Operator.
7.2. In strict compliance with Part 5 of Article 18 of the Federal Law No. 152‑FZ of July 27, 2006 “On Personal Data”, the Operator ensures that the recording, systematization, accumulation, storage, updating, and retrieval of personal data pertaining to citizens of the Russian Federation are performed exclusively through databases physically hosted on the territory of the Russian Federation.
7.3. All the scientific databases, repositories, aggregators, and library systems to which the Operator transfers article metadata and authors’ personal data — including, but not limited to, the Scientific Electronic Library eLIBRARY.RU, the Russian Research Citation Index (RRCI / RINTS), the Scientific Electronic Library “CyberLeninka”, and the Federal State Budgetary Institution Research and Technology Center “Informregistr” — are Russian legal entities and process the mentioned above data on servers physically located on the territory of the Russian Federation.
7.4. Should an Author or a Site User initiate the transmission of their personal data or access the Site while being physically present outside the territory of the Russian Federation, such actions shall be construed as an expression of the data subject’s own will and, as such, shall not be regarded as cross-border transfer exercised on the Operator’s own initiative.
8.1. The personal data subject has the right to withdraw their consent to the processing of personal data at any time by submitting a written application to the Operator, signed with an enhanced qualified electronic signature and sent either to the Operator’s email address (svki.izvestiya@bk.ru) or by recorded delivery with acknowledgement of receipt to the Operator’s legal address: 158 Moskovskaya Street, Saratov, 410012, Russian Federation.
8.2. The Operator is obliged to cease processing personal data and to destroy them within a period not exceeding thirty (30) days from the date of receipt of the withdrawal of consent, except in cases where the processing of personal data may be carried out without the consent of the subject on the grounds provided for by Law No. 152‑FZ.
8.3. Withdrawal of consent to the processing of personal data shall not entail:
– the removal of authorship information (surname, first name, patronymic, affiliation, researcher identifiers) from an already published scientific article, since such information, by virtue of Article 1265 of the Civil Code of the Russian Federation, constitutes an integral element of the work and is not subject to removal after its publication;
– the removal of article metadata from abstracting and scientometric databases in which the publication has already been indexed, except in cases where such removal is technically feasible and has been requested by the subject directly from the relevant database operator;
– the termination of licences previously granted to third parties with respect to already published works.
9.1. The User may obtain any clarifications regarding issues of interest pertaining to the processing of their personal data by contacting the Operator via email at svki.izvestiya@bk.ru or at the Operator’s legal address.
9.2. In case of changes in the legislation in the field of the personal data, this Policy shall be subject to revision and updating.
9.3. This Policy shall remain in force indefinitely until replaced by a new version.

