top of page

  POLICY   for the protection of personal data   of "MC DORIS" OOD

Dear patients,
When carrying out its activities as a medical facility, registered and functioning in accordance with the requirements of the Law on Medical Facilities, daily "Doris Clinics Medical Center" Ltd., with its headquarters and management address p.k. 1618 Vitosha Blvd. MONASTIRSKI LIVADI quarter, BYALO POLE street № 33 Telephone: 02 820 38 55, Fax: 02 820 38 55 uses, processes and stores information of different types, volume and nature, including personal data and health information, unconditionally necessary for the full and quality performance of our assigned tasks for the protection of public health. Our responsibility to you requires us not only to process, store and protect your personal data in accordance with the requirements of legislation and good faith, but also to provide you with the information necessary to exercise your rights as data subjects, which for your convenience we also publish on the page of the medical facility:

Basis and categories of personal data processed in the medical facility:
The processing of patients' personal data is carried out on the basis of Art. 6, para. 1, b.  "c" and "e", as well as Art. 9, item 2, b. "a", "c", "h" and "i" of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation) solely for the purposes of public health activities , which we carry out as a medical facility registered under the Law on Medical Facilities and to protect the vital interests of the subjects of personal data, and in some cases – also of other natural persons.  The categories of personal data for patients are provided compulsorily and may include: Basic information about patients, entered in the medical documentation approved by the competent authorities and necessary for their identification - names, uniform civil number, address, date of birth, as well as provided by the patients' contact data, necessary to establish contact with them - telephone number, e-mail address; Health information - personal data related to the state of health, physical and mental development of individuals, as well as any other information contained in medical prescriptions, prescriptions, protocols, certificates and other medical documentation issued for the patient in connection with his diagnosis and treatment .

Purposes for which personal data is processed:  
1. To carry out the activities of diagnosis, treatment and follow-up of the patients' condition on the basis of complete, reliable and objective information about their state of health and in accordance with the legal requirements for performing medical activities;
2. For the implementation of effective coordination between the specialists of the medical facility, performing diagnosis and treatment of the patients and medical specialists outside the medical facility;
3. For the purposes of exercising internal and external control over the activities of the medical facility by the authorized persons and state bodies, including the expenditure of own and public funds. Providing health information to third parties: Health information is provided to third parties on the basis of Art. 28 of the Health Act, when:
- the person's treatment continues in another medical facility;
- there is a threat to the health or life of other persons (after notification to the relevant person);
- is necessary for the identification of a human corpse or for establishing the causes of death;
- is necessary for the needs of state health control to prevent epidemics and the spread of infectious diseases;
- is necessary for the needs of medical expertise and public insurance;
- is necessary for the needs of medical statistics or for medical scientific research, after the data identifying the patient has been deleted;
- is necessary for the needs of the Ministry of Health, the National Center for Health Information, the NHIF, the regional health inspectorates and the National Statistical Institute.
- is necessary for the needs of an insurer licensed under Section I of Appendix No. 1 or Item 2 or under Items 1 and 2 of Section II, Letter "A" of Appendix No. 1 to the Insurance Code.
The medical facility does not provide and does not plan to provide personal data to recipients in third countries outside the EU. In case of change, this information will be updated.

Method and term of storage of information including personal data:
The data are stored on material / paper / and electronic media, with access to them only by employees of the medical facility, directly or indirectly related to the activities of diagnosis and treatment of the specific patient and their organization and accountability, subject to a legally established obligation to comply of professional secrecy, including for non-medical specialists. The medical documentation containing health information kept in the medical facility is stored for various legally established or approved by the medical facility periods from 2 /two/ to 30 /thirty/ years depending on the nature of the information and the assigned its value from the legislator. When the term of storage of health information contained in the medical documentation is not legally established, its determination is based on the nature, scope and purposes of the processing, when applying organizational and technical measures to protect it from unauthorized access and destruction Storage of the information aims to: provide effective and reliable follow-up of the history of each medical case; subsequent use by interested persons /patients or their relatives/ to exercise the rights granted to them by law; use for the exercise or defense of legal claims; use for the needs of subsequent diagnosis and treatment by other medical specialists or for scientific and statistical purposes under the limitations and rules provided for by law.

‍Rights of the subjects of personal data and procedure for their exercise: Every natural person has the right to access, correct (supplement), object to processing, as well as limit processing and delete (in case of illegal processing or invalid basis) the personal data processed by the medical facility and related to it, unless the request contradicts of other relevant provisions, including Art. 17, § 3, b. "c" of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016. In the event of correction, limitation or deletion of personal data, the data subject has the right to require the administrator to notify all third parties thereof -recipients.

To exercise any of the above rights or to obtain more information,the subject of personal data should contact the employees of the medical facility at tel.:0879 851 557 e-mail:  or on site in the building of the medical facility: Sofia, Preobrazhenie Square 1 / Ivan Hadjienev St. 135. Any natural person whose personal data is processed can submit a complaint toThe Commission for the Protection of Personal Data, which is the Supervisory Authority in the field of personal data protection. Commission for the Protection of Personal Data: Address: Sofia 1592, Prof. Tsvetan Lazarov" No. 2
Phone: 02/91-53-518
Dr. Stamen Chupetlovski

Sofia, date 26.04.2019

bottom of page