Data protection


Introduction

Elanders has adopted Binding Corporate Rules, approved by the Swedish Authority for Privacy Protection (IMY) on 28 January 2021 under Article 47 of the GDPR, following an opinion of the European Data Protection Board. They govern how personal data is transferred between Elanders companies, including to companies outside the EU and EEA, and they are binding on every Elanders company listed below.

The rules give you rights that you can enforce directly against Elanders. To exercise them, or if you have any question about how we handle personal data, please contact dataprotection@elanders.com.

The Binding Corporate Rules are published in English, the language in which they were approved.

Your rights under these rules

The Binding Corporate Rules give you rights that you can enforce directly against Elanders. These include the right to be told how we use your personal data, to receive a copy of it, to have it corrected or erased, to have its use restricted, to object to it, and not to be subject to decisions taken solely by automated means. Our Privacy Notice explains each of them in full.

Elanders AB accepts liability for breaches of the rules by Elanders companies outside the European Economic Area.

To exercise your rights, or to complain about how we have handled your personal data, write to dataprotection@elanders.com. You may use our complaint form if you find it convenient, but you do not have to, and no particular form is required. We will reply within one month.

You can also lodge a complaint with a data protection supervisory authority, in particular in the country where you live, where you work, or where you believe the infringement took place. Elanders lead supervisory authority is the Swedish Authority for Privacy Protection: Integritetsskyddsmyndigheten (IMY), Box 8114, SE-104 20 Stockholm, imy@imy.se, www.imy.se.

You also have the right to an effective judicial remedy and may claim compensation for material or non-material damage. You may be represented by a not-for-profit body or association under the conditions set out in Article 80(1) of the GDPR.