Information about protection of personal data

General terms

We, QIWI PLC (hereinafter referred to as the Company), acting as the controller of personal data consider the protection of rights and freedoms of data subjects and the implementation of data protection principles as an important condition for our personal data processing activities while achieving our business purposes.

This Privacy Notice (hereinafter referred to as the Notice) defines our basic principles and terms for the personal data processing, as well as the measures we have taken to ensure the security of personal data.

The Notice is developed in accordance with the requirements of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as GDPR) as well as the applicable local legislation, including The Protection of Physical Persons Against the Processing of Personal Data and Free Movement of such Data Law 125(I)/2018 (hereinafter referred to as Law 125). The meanings of terms used in this document are as specified in laws mentioned above.

The Notice applies to the processing and security of the personal data processed by us, which can be obtained both from a natural or a legal person in the framework of a contractual relationship with us as well as from other data subjects.

If you have any questions regarding the Notice, please, contact the data protection officer or the person responsible for personal data processing by email at ir@qiwi.global

Information about the processing of personal data Categories of data subjects

As part of our business we can process personal data of the following categories of data subjects:

— Candidates for vacant positions: the personal data of individuals (hereinafter referred to as applicants) who are applying for a job opening at QIWI PLC;

— Representatives of prospective counterparties: the personal data of the prospective companies-counterparties staff members, acting in the name of their company;

— Representatives of counterparties: the personal data of the current companies-counterparties staff members, acting in the name of their company;

— Website users: the personal data of individuals who are using the website;

— Marketing newsletter subscribers: the personal data of individuals who receive marketing communications from the Company.

Other categories of data subjects are being informed through different means, ex. Employee Privacy Notice or Privacy Policy.

The purposes and categories of personal data processing
Personal data transfers

When we transfer personal data to third parties, we make sure that they have sufficient guarantees to implement the appropriate technical and organizational measures. We transfer personal data to third parties with whom we have concluded the appropriate types of contracts with the required obligations regarding the protection of personal data at the level defined by us.

When we need to transfer personal data to a third country, we transfer the data to third country which ensures an adequate level of protection. If we transfer the data to third country which does not ensure an adequate level of protection, we implement appropriate safeguards in place (Standard Contractual Clauses approved by the European Commission).

We monitor compliance with the principles of personal data processing and application of the appropriate security measures by third parties. We control that cross-border transfer of personal data is limited by the purposes for which the data was collected.

In addition, in order to transfer personal data to third parties abroad we conduct TIA (Transfer Impact Assessment) to the activities, where necessary.

Information about companies involved in data sharing is provided below.

Bank that the Company uses for conducting payments

United States — country does not guarantee sufficient levels of personal data protection according to Chapter 5 of GDPR.

The legal basis for cross-border transfer: we use Standard Contractual Clauses approved by the European Commission.

Developer of the software that the Company uses to operate the website

Russian Federation— country does not guarantee sufficient levels of personal data protection according to Chapter 5 of GDPR.

The legal basis for cross-border transfer: we use Standard Contractual Clauses approved by the European Commission.

Representatives of counterparties Settlements with counterparties of the Company Controller Contract that includes security measures
IT solution provider whose services the Company uses to analyze cookies (1)

The legal basis for cross-border transfer: we use Standard Contractual Clauses approved by the European Commission.

Website users Cookie analytics for the Company’s purposes Processor Contract that includes security measures
IT solution provider whose services the Company uses to analyze cookies (2)

Switzerland, Luzern

Website users Cookie analytics for the Company’s purposes Processor Contract that includes security measures
IT solution provider whose services the Company uses to analyze cookies (3)

Ireland, Dublin

Website users Cookie analytics for the Company’s purposes Processor Contract that includes security measures
Data subject’s rights

We guarantee free of charge the following rights under the Law 125 and GDPR regarding your personal data:

If we are processing your personal data based on consent that you gave us when we got the data, you may have the right to withdraw your consent at any time Article 7 of the GDPR You can obtain form us confirmation that we process your personal data, access to the personal data and the information about its processing. You can also ask for a copy of your personal data in a machine-readable format.
We cannot exercise this right if it affects the rights and freedoms of others
Article 15 of the GDPR
If you believe that any personal data, we are holding about you is incorrect or incomplete, you can request that we correct or supplement the data. Please contact us as soon as possible if you notice any inaccuracy or incompleteness Article 16 of the GDPR You can request that we erase some or all of your personal data without undue delay Article 17 of the GDPR You can ask us to restrict further processing of your personal data. This just means you can ask us to stop using it for what we have been using it for Article 18 of the GDPR When the processing is based on your consent or on the Contract with you, you can receive your personal data, which you have provided to us, in a structured, commonly used and machine-readable format and can freely transmit those data to another controller. Where technically feasible, you can also ask us to transmit the personal data directly to another controller Article 20 of the GDPR If we processing your personal data based on legitimate interest (see Appendix 1) you can let us know that you object to the collection Article 21 of the GDPR You have the right to lodge a complaint about the Company practices with respect to your personal data with the supervisory authority of the EU Member State of your habitual residence, place of your work or place of the alleged infringement Article 77 of the GDPR

To exercise your rights mentioned in the table above, contact the following email: ir@qiwi.global

Please note, that we can enforce these rights only if you are expressly identified as a personal data subject for which we may ask you for additional information.

We process and respond to the requests for the exercise the rights without undue delay and in any event within one month of receipt of the request. Considering the complexity and the number of requests, the term for the preparation of an answer to the request can be extended by two months. In this case we will notify you about the reasons for the delay within one month.

Cookies and Web Analytics

We use cookies to enhance performance characteristics of our websites, make it more user-friendly, collect information about visits and take measures to improve the websites.

More information on Cookies is provided in our Cookie Policy.

Measures to ensure the security of personal data processed

When processing personal data, we take the necessary organizational and technical measures, selected based on the risk analysis, to protect personal data from unlawful or accidental access to them, destruction, alteration, blocking, copying, provision, dissemination of personal data, as well as from other illegal actions in relation to personal data.

The security of personal data is ensured by the following:

— we have assigned the responsibility for the organization of personal data processing to a specific employee;

— we have implemented data protection policies to ensure that our personal data processing activities comply with the Law 125 and GDPR (internal policies, internal allocation of responsibilities, trainings);

— we have implemented the necessary measures to protect personal data (access control, encryption, antivirus protection);

— we keep up to date the records of processing activities;

— we have organized a process of receiving and controlling the processing of data subjects’ requests;

— we carry out a DPIA for personal data processing activities that resz-listt in a high risk to data subjects due to the nature or scope of the operation (for more information, see Data Protection Impact Assessment);

— we ensure data protection by design and data protection by default (for more information, see Data protection by design and by default);

— we ensure security of third parties (controllers, processors, joint controllers);

— we control the transfers of personal data outside the EU;

— we document personal data breaches (if any) and their consequences, investigating them, notifying the relevant parties about leaks within 72 hours, and taking measures to eliminate the consequences of personal data breaches;

— we carry out planned and unscheduled audits of personal data processing activities.

Contact information

Our contact information is specified below.

QIWI PLC

Postal address: 12 Kennedy Avenue, Kennedy Business Centre, 2nd Floor, 1087-Nicosia, Cyprus

Tel.: +357 22-65-33-90

Contacts of the person responsible for the personal data processing

ir@qiwi.global