Privacy Notice for Employees

PT Fajar Surya Wisesa Tbk. dan PT Dayasa Aria Prima (hereinafter collectively referred to as “we”) respect the rights to privacy of all individuals. To ensure that your personal data is protected, we have created this privacy notice to provide information on the collection, use, disclosure, deletion, and destruction of your personal data in electronic and other formats under Law No. 27 of 2022 on Personal Data Protection and other applicable laws and regulations pertaining to personal data protection in Indonesia (“PDP Laws”).

1. Definitions.

  • 1.1. “We” means PT Fajar Surya Wisesa Tbk. and/or PT Dayasa Aria Prima.
  • 1.2. “You” means employees and staff of PT Fajar Surya Wisesa Tbk. and/or PT Dayasa Aria Prima.
  • 1.3. “Processing” means collecting, analyzing, storing, correcting, updating, displaying, announcing, transferring, disseminating, using, disclosing, deleting, and/or destroying personal data.
  • 1.4. “Personal data” means any data relating to an identified or identifiable natural person that can be identified on its own or in combination with other information directly or indirectly through an electronic or non-electronic system.

2. Purposes of Processing

  • 2.1. Contractual Necessity: We process your personal data to perform our contractual obligations, including employment contracts, preparation, compliance, and personnel management. This includes adherence to our code of ethics, staff transfers, secondments, training, performance appraisals, position considerations, compensation management, and ensuring the health and safety of our employees.
  • 2.2. Legal Compliance: We process your personal data to comply with legal obligations such as labor protection laws, labor relations laws, social security laws, occupational safety and health laws, and regulations on occupational diseases and contagious disease control.
  • 2.3. Legitimate Interests: We process your personal data to pursue our legitimate interests or those of third parties. This includes human resource management, manpower analysis and allocation, employee development, medical and insurance benefits, staff facilities, financial and budget management, internal communications, third-party interactions, registration and certification processes, document publication, report preparation, information submissions to government or regulatory agencies, employee information verification, database creation for work history, communication, news dissemination, workplace improvement, facilities provision, information security, user account creation, system access, security measures, accident and crime prevention, complaint and fraud investigation, and post-employment management.
  • 2.4. Vital Interests: We process your personal data to protect your vital interests or those of another person. This includes emergency contact and disease control and prevention.
  • 2.5. Public Interest: We process your personal data as it is necessary to perform a task in the public interest or to exercise official authority vested in us.
  • 2.6. Consent: We process your personal data based on your consent for specific purposes, which will be communicated to you when obtaining consent. More information about your consent and its implications can be found in the subsequent sections of this privacy notice.

3. Personal Data We Collect

  • 3.1. Sources of Data Collection: We collect personal data directly from you and indirectly from reliable sources such as public organizations, the companies in the SCG Group, recruitment platforms, business partners, individuals who can legitimately disclose your personal data, and trusted service providers.
  • 3.2. Types of Personal Data Collected: We collect the following types of personal data:
    • (1) Recruitment Information: Resume, CV, job application letters, and comments from recruiters.
    • (2) Contact Information: First name, last name, address, telephone number, email, and social media details.
    • (3) Identification Information: Citizen identification number, passport number, driver’s license number, social security number, national insurance number, taxpayer identification number, and other government-issued identification numbers.
    • (4) Immigration and residency Information: Stay permit, residence permit, work permit, visa, and similar paperwork.
    • (5) Personal Information: Date of birth, age, gender, marital status, interests, and opinions.
    • (6) Family Information: Data about family members or dependents eligible for benefits, such as spouses, children, parents, and beneficiaries. Please inform these individuals about this privacy notice before providing their information.
    • (7) Photos and Videos
    • (8) Educational and Competency Information: Education level, institution, training history, test results, driver license, work rights, professional qualifications, language abilities, and reference information.
    • (9) Work Experience: Positions held, employer details, previous salaries, and compensation.
    • (10) Work Location Information
    • (11) Employee Characteristics: Habits, behaviors, attitudes, skills, leadership, teamwork ability, emotional intelligence, and organizational commitment, derived from observations and analyses.
    • (12) Regulatory Reporting Information: Data required for reporting to regulatory agencies such as the Ministry of Manpower.
    • (13) Financial Data: Bank account information, wages, salaries, income, tax details, provident fund, loans, tax deductions or exemptions, and securities holdings.
    • (14) Social Security and Benefits: Data on social security, labor protection, benefits, welfare, and compensation in accordance with company regulations.
    • (15) Attendance Records: Time attendance, work duration, overtime, absences, and leave.
    • (16) Work History: Positions held, meeting attendance, opinions, and additional information for directors.
    • (17) IT Usage Data: Information about usage and access to company computers, information systems, websites, applications, networks, and electronic devices in compliance with IT policies and laws.
    • (18) Participation Data: Information from your participation in activities, surveys, and assessments.
    • (19) Shared Information: Data you share through applications, tools, questionnaires, assessments, and various documents.
    • (20) Identification Documents: Copies of ID cards, passports, household registrations, driver’s licenses, and other government-issued documents.
    • (21) Emergency Contact Information
    • (22) Vehicle and Driving Information: Data about your ability to drive, your vehicles (for security or parking permits), and driving behavior for company-provided vehicles.
    • (23) Conflict of Interest Information: Data necessary for investigating conflicts of interest, such as stock holdings and relationships with business partners.
    • (24) Accident Information: Data on accidents, whether work-related or not.
    • (25) Employment and Welfare Data: Information necessary to comply with your employment contract, welfare, benefits, analysis, administration, post-retirement care, and applicable laws.
    • (26) Whistleblowing and Disciplinary Data: Information regarding whistleblowing, complaints, and disciplinary investigations.
  • 3.3. Additional Data Collection: If we need to collect additional personal data, we will notify you and process the data in compliance with PDP Laws.
  • 3.4. Specific Personal Data: We may need to collect and process specific personal data, including:
    • (1) Personal financial data for salary and compensation payments.
    • (2) General health data (e.g., food allergies, drug allergies, vaccinations) for event organization, accommodation, and compliance with legal and regulatory requirements.
    • (3) Criminal offense data.
  • 3.5. Third-Party Data Disclosure: If you disclose the personal data of others to us, you must be able to do so lawfully and comply with PDP Laws, including informing the data subjects of this privacy notice and other relevant documents and obtaining necessary consent before or at the time of disclosure.

4. Cookies

  • 4.1. We use cookies and similar technologies to collect personal data as specified in our Cookies Notice.

5. Consent, Withdrawal, and Consequences

  • 5.1. Right to Withdraw Consent: If we rely on your consent to process personal data, you can withdraw your consent at any time. Withdrawal will not affect the validity of processing carried out before the withdrawal.
  • 5.2. Consequences of Withdrawal or Refusal: Withdrawing your consent or refusing to provide certain information may result in our inability to fulfill some or all objectives stated in this privacy notice.
  • 5.3. How to Withdraw Consent: You can withdraw your consent by following the instructions provided in the channels where consent was obtained (e.g., changing settings in your user account) or by sending an email to data.privacy@fajarpaper.com or data.privacy@dayasa.co.id.
  • 5.4. Consent for Minors and Incapacitated Persons: If you are a minor, incompetent person, or incapacitated person and wish to give consent, you must obtain authorization from your guardians or conservators before giving consent.
  • 5.5. Giving Consent on Behalf of Others: If you consent on behalf of another person, you must have the legal authority to do so when consent is given.

6. Retention Period

  • 6.1. Data Retention Duration: We will retain your personal data for the period necessary to meet the stated objectives. We may retain certain data for up to 30 years to defend against legal claims. If the retention period is unclear, we will retain the data for a customary period in accordance with retention standards.
  • 6.2. Data Deletion and Destruction: We have established an auditing system to delete or destroy your personal data when the retention period expires or when it becomes irrelevant or unnecessary for the purposes it was collected.
  • 6.3. Retention After Withdrawal of Consent: If your personal data is processed based on consent, we will stop processing it upon your withdrawal of consent. However, we may retain your personal data to record your withdrawal and respond to future requests.

7. Disclosure of Your Personal Data

  • 7.1. Recipients of Personal Data: We disclose and share your personal data with:
    • (1) Companies in the SCG Group, as listed in the most recent annual report available at https://scc.listedcompany.com.
    • (2) Individuals and entities other than the companies in the SCG Group, such as:
      • (a) Dealers
      • (b) Transport and logistics service providers
      • (c) Postal service providers
      • (d) Data processing service providers
      • (e) Marketing service providers (who might send promotional messages)
      • (f) Contractors performing tasks on our behalf
      • (g) Financial service providers (e.g., banks, payment companies, electronic payment service providers, credit providers)
      • (h) IT service providers (e.g., cloud services, blockchain systems, data analytics, SMS, or email providers)
      • (i) IT developers and programmers
      • (j) Auditors, consultants, and advisors
      • (k) Government agencies (e.g., Revenue Department, Anti-Money Laundering Office)
      • (l) Insurers
      • (m) Other relevant persons to enable us to conduct business, provide products and services, and meet the purposes of collecting and processing personal data as described in this privacy notice.
  • 7.2. Separate Privacy Notices: Recipients of your personal data listed in clause 7.1 may have their own privacy notices. Please read their privacy notices to understand how they process your personal data.
  • 7.3. Business Restructuring: If we restructure our business, sell or transfer assets, acquire businesses, or merge with other businesses, we may disclose your personal data to our counterparties and advisors. We will do our best to safeguard your data and require our counterparties and advisors to comply with PDP Laws and this privacy notice.
  • 7.4. Protection Measures: We will require recipients of your personal data to take appropriate measures to protect your personal data, process it properly and only as necessary, and prevent unauthorized use or disclosure.

8. International Transfer of Your Personal Data

  • 8.1. Purposes of Transfer: We may send or transfer your personal data to the companies of SCG Group or other entities located outside of Indonesia for the following purposes:
    • (1) You have explicitly consented to the proposed transfer after being informed of the possible risks due to the absence of an adequacy decision and appropriate safeguards;
    • (2) The transfer is necessary for the performance of a contract between you and us or the implementation of pre-contractual measures taken at your request;
    • (3) The transfer is necessary for the conclusion or performance of a contract concluded in your interest between us and another natural or legal person;
    • (4) The transfer is necessary for important reasons of public interest;
    • (5) The transfer is necessary for the establishment, exercise, or defense of legal claims;
    • (6) The transfer is necessary to protect your vital interests or those of other persons when you are physically or legally incapable of consent.
  • 8.2. Data Storage and Processing: We may store your personal data on servers or clouds outside Indonesia and use software or applications from service providers outside Indonesia. We ensure that unrelated parties do not access your personal data and require service providers to implement appropriate security measures.
  • 8.3. Compliance and Protection Measures: When transferring your personal data to a foreign country, we comply with PDP Laws and take measures to protect your data. We require recipients to implement protection measures, process the data only as necessary, and prevent unauthorized use or disclosure.

9. Security Measures

  • 9.1. Technical and Organizational Measures: We have implemented technical and organizational measures to protect your personal data from loss, misuse, unauthorized access, disclosure, or destruction. The measures include encryption and access restrictions to ensure only authorized personnel have access to your data and are trained on the importance of data protection.
  • 9.2. Comprehensive Security Measures: We maintain comprehensive security measures, including administrative, technical, and physical safeguards (such as access control and user access management), to prevent unlawful loss, access, use, alteration, or disclosure of personal data. We review and update these measures as necessary or when technology changes to ensure effective security.
  • 9.3. Protection of Specific Personal Data: If we process specific personal data, we will use our best efforts to impose appropriate security measures to protect the data.

10. Your Rights as Data Subjects

  • 10.1. Summary of Your Rights under PDP Laws: You have the following rights:
    • (1) Right to Information: To receive clear information about our identity, accountability, data processing purposes, and data processing basis.
    • (2) Right to Withdraw Consent: To withdraw consent you have given us at any time.
    • (3) Right to Access: To request to view and copy your personal data or disclose the source from which we obtained your personal data.
    • (4) Right to Data Portability: To request us to send or transfer personal data in electronic form to other data controllers as required by PDP Laws.
    • (5) Right to Object: To object to our collection, use, or disclosure of your personal data.
    • (6) Right to Erasure: To request us to delete, destroy, or anonymize your personal data.
    • (7) Right to Restriction: To request us to suspend the use of your personal data.
    • (8) Right to Object to Automated Decision-Making: To object to decisions based solely on automated processing that have legal consequences or significantly affect you.
    • (9) Right to Rectification: To request us to correct your personal information to ensure it is current, complete, and accurate.
    • (10) Right to Lodge Complaints: To file complaints with the Personal Data Protection Authority if we, our data processors, employees, or contractors violate or do not comply with PDP Laws.
  • 10.2. Processing of Rights Requests: We will consider your request, notify you of the result, and execute it (if appropriate) within the period set by PDP Laws from the date we receive the request. Your rights will be processed following PDP Laws.
  • 10.3. How to Exercise Your Rights: You can contact us that handle your personal data to exercise your rights by sending an email to the email address as provided in the item 11.3 (Contact Information).

11. Information about the Data Controller and Data Protection Officer

  • 11.1. Data Controllers: We are the data controllers of this privacy notice.
  • 11.2. Business Address: Jl. Abdul Muis No.32, Jakarta 10160, Indonesia.
  • 11.3. Contact Information: You can contact the data controllers or inquire about this privacy notice by emailing to:
    • – For inquiries related to PT Fajar Surya Wisesa Tbk.: data.privacy@fajarpaper.com;
    • – For inquiries related to PT Dayasa Aria Prima: data.privacy@dayasa.co.id.

12. Miscellaneous

  • 12.1. Amendments to the Privacy Notice: If this privacy notice is amended, we will announce the new privacy notice on our website or through other channels. The new privacy notice will be effective immediately on the date of announcement.