The Limassol District Local Government Organisation (the “Organisation” or “we”) respects your privacy and is committed to protecting your personal data. The Organisation is a legal person governed by public law and operates pursuant to the District Local Government Organisations Law (Law 37(I)/2022).
As the “controller” of your personal data, the Organisation determines the purposes and means of collecting and processing the data of municipal residents, consumers and persons liable for fees; owners, consultants and applicants in the context of permitting procedures; its tenderers, suppliers and external collaborators; visitors to its offices and website; as well as any other third party who interacts or conducts transactions with the Organisation in any manner, whether online or in person (the “Data Subjects” or “you”).
The Organisation’s Data Protection and Privacy Policy explains which categories of personal data we collect, when, how and why we process them, and to whom we disclose them, both during and after the end of our transactional or contractual relationship. The retention periods for your data are set out in the Organisation’s Data Retention and Destruction Policy. The security measures we implement are described in the Personal Data Security Policy.
PURPOSE OF THE PROCEDURE
This procedure explains how any Data Subject concerned may exercise their rights under the General Data Protection Regulation (EU) 2016/679 (the “GDPR”) and the Law Providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data of 2018 (Law 125(I)/2018).
This procedure concerns your own personal data. Access by any person to public-sector information and documents is governed separately by the Right of Access to Public Sector Information Law (Law 184(I)/2017) and is not covered by this procedure.
YOUR RIGHTS
Under certain circumstances and subject to the applicable legal requirements, you have the following rights in relation to your personal data:
Please note that the above rights are not absolute. The law provides for certain conditions and exceptions. For instance, the Organisation cannot erase data that is legally required to be retained, such as accounting and tax records; data contained in public records subject to permanent retention, such as town planning and building permitting records; or data necessary for the establishment, exercise or defence of legal claims. In all cases, we will explain the reasons for our response. The Organisation does not make decisions concerning you solely on the basis of automated processing, including profiling.
PROCEDURE
Any Data Subject concerned may exercise their rights by completing the Data Subject Rights Form below and submitting it:
The duties of the Organisation’s DPO are performed by PERICLEOUS MICHAIL LLC, with Mr Christos Pericleous as the designated contact (22 Griva Digeni, 4th Floor, 3106 Limassol, tel. 25000070, email: dpo@eoalemesos.org.cy).
The internal point of contact for personal data matters is the DPO Services Agreement Coordinator, Ms Eleni Nicolaou (email: eleni.nicolaou@eoalemesos.org.cy, tel. 25271000).
Use of the form is recommended, as it helps us process your request promptly. However, it is not mandatory. A request submitted by other means, for example by a simple letter or email, is equally valid. Any member of staff who receives a request to exercise data subject rights will forward it immediately to the DPO, and no later than within 2 working days.
We will respond to your request without delay and no later than 1 (one) month from receipt. If the request is complex or if a large number of requests are pending, this period may be extended by 2 (two) additional months. In such cases, we will inform you of the extension and the reasons for it within the first month after receiving the request. If you submit your request electronically, the response will be provided electronically, unless you request otherwise.
If the Organisation is unable to fulfil your request, in whole or in part, we will inform you, no later than 1 (one) month from receipt of the request, of the reasons for this, as well as of your right to lodge a complaint with the Commissioner for Personal Data Protection and to seek judicial redress.
Please note the limited retention periods applicable to certain data. Closed-circuit television (CCTV) recordings are retained for up to 1 month, and recorded call centre calls for up to 3 months. If your request concerns such data, please submit it as soon as possible and specify the date, time and location or the relevant call number, so that the data can be located before they are deleted.
Providing a copy of your data must not adversely affect the rights and freedoms of others. Before providing access to or copies of the documents or recordings, the Organisation removes or redacts any personal data relating to third parties that may be contained in them, unless disclosure of such data is permitted.
Where a request for rectification, erasure, or restriction is granted, the Organisation will also inform the recipients to whom the data have been disclosed, unless this proves impossible or would involve disproportionate effort. If you so request, we will inform you of those recipients.
The DPO maintains a record of all requests to exercise rights and their outcomes, for accountability purposes.
Usually free of charge
There is no charge for exercising your rights. However, where a request is manifestly unfounded or excessive, particularly due to its repetitive nature, the Organisation may either charge a reasonable fee to cover administrative costs or refuse to act on the request, explaining the reasons. A reasonable fee for administrative costs may also be charged for additional copies of your data.
SECURITY MEASURES
In all cases, the Organisation requests specific information to verify the applicant’s identity so as to ensure that personal data are not disclosed to an unauthorised person. If the request is submitted electronically or by post and there are reasonable doubts as to the applicant’s identity, additional identification information may be requested, such as presentation of an identity card. A request submitted through a representative will only be accepted with the Data Subject's written authorisation and verification of the representative’s identity.
Under no circumstances will the personal data we collect for the purpose of processing a request to exercise rights be disclosed to any person who is not entitled to access them. The forms and related correspondence are handled in accordance with the Organisation’s Personal Data Security Policy. Any personal data breach is handled in accordance with the Organisation’s Personal Data Breach Incident Management Policy.
Version history
| Version | Update |
|---|---|
| v.1.0 | 2026 |