Leadership questionnaire data protection notice
Download PDFDATA PROTECTION NOTICE
for the Leadership Questionnaire of the research study “Leadership Practices and Organisational Relationships”
jovezeto.hu
1. Introduction
1.1. Purpose of this Data Protection Notice
The purpose of this Data Protection Notice (hereinafter: the “Notice”) is to provide transparent and detailed information on the processing of personal data in connection with the leadership questionnaire of the research study entitled “Leadership Practices and Organisational Relationships”, including the purposes and legal basis of processing, retention periods, data security measures, and the rights of data subjects.
1.2. Legal framework
Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – GDPR).
Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (Hungary).
The primary legal basis for processing is the data subject’s freely given, specific, informed and unambiguous consent pursuant to Article 6(1)(a) GDPR.
2. Data Controller
- Data Controller
- Kollár László János
- Position
- PhD student
- Organisation
- University of Debrecen, Faculty of Economics and Business
- Address
- 4032 Debrecen, Böszörményi út 138., Hungary
- kollar.laszlo@econ.unideb.hu
- Research platform
- jovezeto.hu
3. Definitions
Personal data: any information relating to an identified or identifiable natural person.
Data subject: the natural person to whom the personal data relate; for the purposes of this Notice, primarily the person completing the leadership questionnaire.
Processing: any operation or set of operations performed on personal data.
Data Controller: the person who determines the purposes and means of processing personal data.
Data Processor: a person or organisation that processes personal data on behalf of the Data Controller.
Consent: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them.
Anonymisation: a process after which information can no longer be related to an identified or identifiable natural person.
Personal data breach: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
4. Description of the Research
The research examines how authentic and servant leadership characteristics relate to employees’ job satisfaction, organisational commitment and longer-term retention in Hungarian small and medium-sized enterprises.
The study is based on the Hungarian adaptation of the Authentic Leadership Integrated Questionnaire (AL-IQ) and the Servant Leadership Survey (SLS-18). It uses a 360-degree assessment framework: in addition to the leader’s self-assessment, at least two direct colleagues anonymously evaluate the leader’s practices. Data collection and processing of results are carried out through the jovezeto.hu online platform.
5. Principles of Data Processing
Lawfulness, fairness and transparency.
Purpose limitation: data are processed only for specified research purposes.
Data minimisation: only data necessary for the research are processed.
Accuracy: reasonable steps are taken to keep personal data accurate and, where necessary, up to date.
Storage limitation: personally identifiable data are retained only for as long as necessary.
Integrity and confidentiality: appropriate technical and organisational measures are applied to protect personal data.
6. Purposes and Legal Basis of Processing
6.1. Completion of the leadership questionnaire
Personal data are processed for conducting the research, administering the questionnaire, linking the leader’s self-assessment with anonymous colleague feedback, preparing an anonymous and aggregated feedback report for the leader, and carrying out scientific analyses. The results may be used in a doctoral dissertation, scientific papers, publications and conference presentations.
Legal basis: consent of the data subject pursuant to Article 6(1)(a) GDPR.
6.2. Communication and operation of the research process
The leader’s e-mail address is processed for purposes directly related to the research process, including sending relevant information, notifying the leader when colleague assessments have been received, and providing access to the leadership report. The e-mail address is not used for marketing purposes.
7. Categories of Data Processed
E-mail address.
Leadership background data, including, for example, age, gender, educational background and leadership experience.
Organisational background data, including information on company size, sector, ownership background, HR characteristics and geographical location.
Questionnaire responses provided by the leader.
Anonymous colleague assessments linked to the leader without disclosing the identity of individual colleagues.
System identifiers and technical data necessary for the operation of the system.
The research does not intend to collect or process special categories of personal data.
8. 360-Degree Assessment and Protection of Anonymity
The leader’s self-assessment is complemented by anonymous assessments from at least two direct colleagues. Colleague responses are displayed in the leadership report only in aggregated form. A report containing colleague feedback is generated only after at least two colleague questionnaires have been completed.
The leader has no access to individual colleague responses. Identifying individual evaluators from their responses is not an objective of the research. Anonymity and data minimisation are fundamental principles of the research design.
9. Source of Data and Contacting Participants
The leader provides their contact details voluntarily and may participate following a direct e-mail invitation or through the jovezeto.hu research platform. The leader may generate an anonymous invitation link for their direct colleagues. Colleague assessments are not displayed to the leader in a personally identifiable form.
10. Storage, Access and Retention
10.1. Storage and access
Data are stored electronically in password-protected digital systems. Processing takes place partly in the LimeSurvey questionnaire system and partly in the backend system of the jovezeto.hu platform.
Access to research data is restricted to authorised persons involved in the research, in particular Kollár László János and Dr. Anita Pierog. Access is limited to the extent necessary for the performance of research tasks.
10.2. Retention period
Personally identifiable data are retained for five years after the completion of the research. After this period, such data will be deleted or anonymised. Anonymous and aggregated research datasets may be retained for scientific purposes thereafter.
11. Data Processors and Technical Service Providers
Technical service providers may be involved in the research, particularly in hosting and operating the jovezeto.hu platform and in providing the LimeSurvey questionnaire system. Such service providers may process personal data only to the extent necessary to provide their services and in accordance with applicable data protection requirements.
The exact identity and contact details of the hosting provider and any additional data processors should be specified in the current privacy information published on jovezeto.hu. No service-provider details that cannot be reliably established from the available research documentation are stated in this Notice.
12. Data Security
Electronic datasets are stored in password-protected systems.
Only authorised persons may access the data.
Leader and colleague data are linked through system identifiers.
Aggregated presentation of colleague responses and separate handling of identifiers reduce the risk of re-identification.
The Data Controller applies technical and organisational measures proportionate to the risks in order to prevent unauthorised access, alteration, loss or disclosure.
13. Use and Publication of Research Results
Research results are used and published only in anonymous and aggregated form in scientific papers, doctoral dissertations, professional or scientific presentations, and conference materials. Individual questionnaire responses and personally identifiable data will not be disclosed in such outputs.
The personalised feedback prepared for the leader may include the leader’s own self-assessment and, where the required number of colleague responses has been received, anonymous and aggregated colleague assessments.
14. Rights of Data Subjects
14.1. Right to information and access
You have the right to obtain confirmation as to whether personal data concerning you are being processed and, where this is the case, to access those personal data and the relevant information concerning the processing.
14.2. Right to rectification
You may request the correction of inaccurate personal data concerning you and the completion of incomplete personal data.
14.3. Right to erasure
Where the conditions laid down in the GDPR are met, you may request the erasure of your personal data, in particular where the data are no longer necessary for the purposes for which they were collected, you withdraw your consent and there is no other legal ground for processing, or the processing is unlawful.
Rights relating to personal data cannot be exercised in respect of data that have already been irreversibly anonymised and can no longer be linked to you, because such data no longer constitute personal data.
14.4. Right to restriction of processing
You may request restriction of the processing of your personal data in the cases specified by the GDPR.
14.5. Right to data portability
Where the conditions under the GDPR are met, you have the right to receive the personal data that you have provided to the Data Controller in a structured, commonly used and machine-readable format.
14.6. Withdrawal of consent
Participation in the research is voluntary. You may withdraw your consent at any time without giving reasons. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
14.7. Exercising your rights
Requests concerning data-subject rights may be submitted to kollar.laszlo@econ.unideb.hu. The Data Controller will respond within the period prescribed by the GDPR, as a rule within one month.
15. Personal Data Breaches
The Data Controller handles personal data breaches in accordance with the GDPR. Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, it will be reported to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it. Where the breach is likely to result in a high risk, affected data subjects will also be informed in accordance with the GDPR.
16. Legal Remedies
If you consider that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address: 1363 Budapest, P.O. Box 9., Hungary
Telephone: +36 (1) 391-1400
E-mail: ugyfelszolgalat@naih.hu
Website: www.naih.hu
You also have the right to seek judicial remedy in the event of unlawful processing of your personal data. Under Hungarian law, proceedings may also be initiated before the regional court having jurisdiction over your place of residence or habitual residence.
17. Cookies and Technical Processing on jovezeto.hu
Technical cookies and other technical identifiers necessary for the operation of jovezeto.hu may be used. If the website uses cookies or similar technologies that are not strictly necessary for its operation, such technologies may be used only on an appropriate legal basis in accordance with applicable law. The cookies actually used and the detailed rules governing them should be described in the current cookie and privacy information published on jovezeto.hu.
18. Final Provisions
This Notice applies to the processing of personal data in connection with the leadership questionnaire. The Data Controller may amend the Notice where necessary, particularly following changes in legislation, the research process or the technical solutions used. The current version may be published on jovezeto.hu.
Debrecen, 9th September 2026
Kollár László János
PhD student
University of Debrecen, Faculty of Economics and Business