Privacy Policy and Whistleblower Scheme

Part 1: Privacy Policy

This privacy policy was drawn up in accordance with the European Regulation on Data Protection (or the “GDPR: General Data Protection Regulation”) – Regulation 2016/679 of 27 April 2016. This Regulation will be directly applicable in Belgium as of 25 May 2018.

1. General

Premed vzw with its registered office at Tiensevest 61 – bus 2, 3010 Leuven, with company number 0410.064.629 respects the privacy of all affiliated employers and their employees, as well as the users of our website, and ensures that the personal information provided by the employer and/or employee is treated confidentially. This data is processed with the aim of guaranteeing optimal service in the areas of health, safety, occupational hygiene, ergonomics and psychosocial aspects.

Within the framework of GDPR legislation, we want to inform, respect, and give our clients and the users of our website as much control as possible over what happens to their data. Below you will find information about what data we collect, why, for how long, and how you have control over it.

This Privacy Policy serves as an appendix to the Main Agreement between Premed and the client. Deviations from this Privacy Policy are only valid if both parties have given their written consent.

In the relationship with the client's employees, Premed should be regarded as a data controller in accordance with COPREV's advice of 26/01/2018. This means that Premed is itself responsible for complying with the obligations of the GDPR (Art. 5, 2° GDPR) in the relationship with its clients' employees.

2. Who is protected by this privacy policy?

This privacy policy applies to all our current and former clients; thus, for all employers, established in the EU, of whom Premed is in possession of a signed affiliation contract and their current, as well as former employees (natural persons).

3. What does 'data processing' mean and who is responsible for it?

By ‘data processing’ we mean the collection, recording, organisation, storage, updating, supplementation, alteration, retrieval, consultation, use, combination, archiving, deletion or eventual destruction of personal data.

Premed vzw is responsible for the processing of personal data of employees of affiliated employers. Our employees are obliged to respect the confidentiality of your data.

Sub-processors:

  • The affiliated employer and their designated staff members have access to general data (i.e. no medical/psychological/personally identifiable confidential information) of their own personnel via the extranet, in compliance with the European Regulation on Data Protection (or the “GDPR; General Data Protection Regulation”) of 27 April 2016.
  • The government
    • FEDRIS: personal data in the context of reporting occupational diseases, reimbursement of medical examinations for trainees, reimbursement of vaccines
    • Vaccinnet: personal data in the context of vaccinations
    • The official responsible for supervision
    • Public prosecutor
    • ...
  • Laboratory analyses
  • Treating physicians and the advisory physician of the health insurance fund in the context of a reintegration file

4. What data do we process?

  • General personal data:
    • as stated on the identity card: name, first name, address, nationality, date of birth, photo, place of birth, national registry number
    • additional personal data: employer, phone number, language, email address, seniority in the company, seniority in the position, work post, race, marital status, if applicable: type of driving licence
  • Medical data in the broadest sense including: data concerning physical and mental health, laboratory analyses, vaccinations, occupational diseases, weight, BMI, lifestyle,...
  • Photos and/or video images of work situations or training moments and personal data of participants in training moments.

5. How long do we store your personal data?

In the interest of the employees, all data is stored for up to 30 years after reaching the normal retirement age. Personal data may be stored longer for statistical purposes or in the context of scientific or historical research, in which case the data will be anonymized as much as possible.

6. What do we use this data for?

6.1. Provision of company services

The sensitive personal data (more explicitly: “Health data”) are lawfully processed by the processor based on Article 9. b) and h) of the GDPR;

b) processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law in so far as it is authorised by Union or Member State law or a collective agreement pursuant to Member State law providing for appropriate safeguards for the fundamental rights and the interests of the data subject.

The service provision is mainly legally determined by the Codex on Well-being at work.

h) processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3. The sensitive personal data processed by the processor relate to Health data; i.e., weight, BMI, work (in)capacity stated on the HAF (Health Assessment Form) or the RAF (Reintegration Assessment Form), medical data, psychological data, injuries after a serious work accident, the lifestyle of the data subject, ....

Premed guarantees that your personal data:

  1. are processed in a lawful, fair and transparent manner
  2. are collected for specified, explicit and legitimate purposes
  3. are sufficient and relevant and are limited to what is necessary for the purposes for which they are processed
  4. are correct and, if necessary, updated
  5. in the case of scientific research: are stored in a form that makes it impossible to identify the data subject

6.2. Marketing purposes

Regarding the processing of Personal Data for marketing purposes, the data controller can rely on a legal basis (recital 47 GDPR). At the bottom of every mailing, you will find the option to unsubscribe.

6.3. Scientific research

Premed guarantees that group reporting, including scientific, historical or statistical research, is carried out anonymously through pseudonymization and encryption of personal data (Art. 89 GDPR).

7. How do we secure your data?

Premed guarantees to have implemented appropriate technical or organisational measures to ensure adequate security of personal data. Personal data are protected, among other things, against unauthorized or unlawful processing and against accidental loss, destruction or damage.

8. What are your rights and how can you exercise them?

8.1. Right of access

Every natural person has the right to view their personal data. You can contact Premed for this.

Please note! Access to medical files is not given directly to the employee, but to his/her treating physician. This is in accordance with the advice of the Order of Physicians dated 07/09/1996.

8.2. Right to rectification

Every natural person has the right to have their data adjusted in our systems.

8.3. Right to erasure

The right to erasure cannot be exercised in most cases, as the processing is based on a legal basis.

8.4. Right to object to the processing of your data for direct marketing

At the bottom of every mailing, you will find the option to adjust your data or to unsubscribe.

8.5. How can you contact Premed to exercise these rights?

  • Tel: 016308111
  • Fax: 016308110
  • Email: info@premed.be
  • Address: Tiensevest 61-bus 2, 3010 LEUVEN

9. Portability of personal data if the client changes External Service

9.1. Medical Surveillance Department

The transfer of health files is regulated in the Codex on Well-being at Work, Book I, Title 4, Section 4.

The health file consists of four different parts:

  • the social-administrative data concerning the identification of the employee and their employer
  • the occupational history and the objective medical personal data, which have been established based on the mandatory actions performed during preventive medical examinations. This personal data relates to the employee's work post or activity
  • the specific personal data established by the occupational physician during preventive medical examinations and reserved for the latter physician
  • the exposure data of every employee working at a work post or performing an activity where they are exposed to biological, physical or chemical agents.

The health file does not contain information about participation in public health programs unrelated to the profession.

The transfer of medical data takes place under the responsibility of the physician who leads the department responsible for medical surveillance (director of medical surveillance).

For the transfer of medical files, the director of medical surveillance of the new external service must send a letter to the director of medical surveillance of the data controller, requesting data transfer. Only after receiving the request will the requested files actually be transferred.

9.2. Psychosocial Risks Department (Risk Management)

The transfer of this personal data is regulated in Article 34 of the Codex on Well-being at Work, Book I Title 3 Prevention of psychosocial risks at work.

When the client changes external service for prevention and protection at work, the transfer of the individual file is regulated as follows:

When the request for formal psychosocial intervention is being processed at the time of the change:

  • the prevention adviser for psychosocial aspects informs the applicant and the other directly involved person as soon as possible that the external service for which they carry out their assignments will no longer be competent for processing the request
  • the client communicates to the prevention adviser for psychosocial aspects with whom the request was submitted, upon their request, the contact details of the new external service
  • the prevention adviser for psychosocial aspects with whom the request was submitted, transfers the individual file to the prevention adviser for psychosocial aspects of the new external service
  • the prevention adviser for psychosocial aspects of the new external service informs the applicant and the other directly involved person that they are taking over the processing of the request.

When the processing of the request for formal psychosocial intervention is concluded at the time of the change of external service for prevention and protection at work:

The prevention adviser for psychosocial aspects of the new external service can, when necessary for the performance of his duties, obtain a copy of the individual file of the prevention adviser for psychosocial aspects to whom the request was submitted.

The transfer of the individual file takes place under conditions that guarantee professional secrecy.

10. What about our website & cookies?

To make our website work properly, we sometimes have to place small files on your computer, so-called cookies. Most large websites do this.

A cookie is a small text file that a website stores on your computer or mobile device when you visit the site. This way, the website remembers the pages you visited and your preferences so that you don't have to re-enter them every time you visit the site.

What we store in cookies:

  • display preferences, such as contrast colour and font size
  • whether you have answered a survey about our site (so we don't ask again)
  • whether or not you agree to the use of cookies on our site
  • to keep statistics on the use of the website
  • whether or not you agree to our privacy policy

The cookies on our site also use components to compile anonymous statistics about how you found our website and which pages you viewed.

This website also works without cookies, but is then less user-friendly. You can therefore delete or block cookies, but some parts of the site will then not work (properly).

The information collected by the cookies is not used to identify you and we do not share the statistical data with third parties. These cookies are also not used for purposes other than those described above.

How can you learn more and what can you do with cookies?

You can always control and/or delete cookies. You can find more about this on aboutcookies.org. You can delete all cookies on your computer and you can set your browser to block cookies. However, this means that you will then have to reset your preferences with each visit and that some parts of the website will not work (properly).

11. Measures in case of a personal data breach

The data controller (Premed) has the obligation to report personal data security breaches to the competent Belgian supervisory authority within 72 hours. This is unless it is unlikely that the personal data breach poses a risk to the rights and freedoms of the data subject(s).

The above obligation also applies if the data controller, e.g. by means of a complaint submitted by a data subject, has effectively become aware of a personal data breach with an appointed processor or a third party.

If the personal data breach is likely to pose a high risk to the rights and freedoms of natural persons, the client shall notify the data subject(s) of the personal data breach without undue delay in accordance with Article 34 of the GDPR.
Both the client and the data controller cooperate with the competent Belgian supervisory authority to provide the necessary information and limit the consequences of the breach.

For more information about our privacy policy or for complaints regarding your privacy, including exercising your right of access, you can contact our Data Protection Officer (DPO) via dpo@premed.be.

 

Part 2: Whistleblower scheme


In accordance with the Belgian whistleblower scheme, Premed has set up the necessary reporting channels to bring misconduct to light within the (former) organisation. This way, these can be detected and addressed at an early stage. 
At the same time, effective protection is offered to whistleblowers.

Who can submit a report


Any person who obtained information about misconduct in the context of a working relationship can make a report. The whistleblower can be a (former) employee, applicant, volunteer, intern or self-employed person working in the company, shareholder, director, but also someone working under the supervision and direction of (sub)contractors and suppliers, etc.
Persons who do not have a working relationship with Premed cannot make a report. They can, however, submit a complaint, which is not the same as a report. Clients of Premed or their employees can therefore not make a report via this whistleblower scheme. They can submit their complaint about Premed's services via the general email address info@premed.be Premed is ISO-certified (ISO 9001) and will handle this complaint appropriately.

Procedure at Premed VZW


If a whistleblower wishes to make use of the whistleblower scheme, they can express their concern in one of the following ways:  
•    Formal or anonymous letter to: 
Premed Whistleblower
Tiensevest 61 / 2 
3010 Leuven;
•    Via email to klokkenluider@premed.be;
•    Via the external reporting channel set up by the government, directly or parallel to the report to Premed: www.federaalombudsman.be/nl/klokkenluiders.

The concerns are best presented with the necessary background of the concerns, the reason(s) why the whistleblower is concerned and with appropriate data or evidence if available. 
The Whistleblower receives proof of the report within seven days in accordance with the legal obligation.

Protection for whistleblower


Premed VZW has the duty to adequately protect the whistleblower. Therefore, reprisals against an employee who reports a breach in good faith are not tolerated.
Premed VZW also commits to maintaining confidentiality as much as possible and offers the assurance that all reports will be subjected to appropriate investigation and a suitable conclusion through an efficient process.