Privacy Policy

Adapted to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC and Organic Law 3/2018, of 5 December, on the protection of personal data and the guarantee of digital rights.)

Introduction                                                                                            

The protection of natural persons in relation to the processing of their personal data is a fundamental right established in Article 8.1 of the Charter of Fundamental Rights of the European Union and Article 16.1 of the Treaty on the Functioning of the European Union, as translated into Article 18.4 of the Spanish Constitution which establishes that "the law shall limit the use of information technology to guarantee the honor and personal and family privacy of citizens and the full exercise of their rights."

EL PARQUE TECNOLÓGICO DE FUERTEVENTURA, SA MP (hereinafter, PTFSA), within the framework of its commitment to regulatory compliance, approves this DATA PROTECTION POLICY, hereinafter, the Policy, which develops the rules and principles of conduct that should serve as a guide to PTFSA professionals, in relation to the protection of personal data in accordance with current legislation.

Object                                                                                                      

This Policy aims to inform PTFSA professionals of the applicable regulations regarding data protection and, in particular, REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free circulation of such data, and repealing Directive 95/46 / EC (hereinafter, GDPR) and ORGANIC LAW 3/2018, of December 5, on the PROTECTION OF PERSONAL DATA AND GUARANTEE OF DIGITAL RIGHTS (hereinafter, LOPDGDD).

The rules of conduct contained in this Policy will be applicable in the context of the work performed by PTFSA professionals and will be aimed at protecting personal data, both of the professionals and of all third parties (suppliers, clients, representatives of Public Administrations, entities and organizations with which they are linked by their performance, etc.) that are related to PTFSA.

The rules set out in this Policy are guidelines that must be complied with by all PTFSA professionals, who must also use their best efforts to ensure that they are respected, both by other professionals and by PTFSA subcontractors who participate in activities that involve the processing of personal data.

The rules contained in this Policy will be supplemented by the provisions of the DATA PROTECTION AND INFORMATION SECURITY USER MANUAL intended for PTFSA staff.

Area of ​​application                                                                                                

This Policy applies to the fully or partially automated or non-automated processing of personal data in the context of the activities carried out by PTFSA.

Furthermore, this Policy applies to all PTFSA professionals, regardless of their hierarchical position within the organisation or their professional qualifications or the type of their relationship with PTFSA.

PTFSA's presence in the international arena is in the field of its activity in the development of R&D and promotion of Technology. PTFSA, whenever it operates outside Spain and the European Union, is committed to respecting and complying with national legislation on data protection if it exists in any country with which it may have a relationship.

Beginning                                                                                                

Chapter II of the GDPR sets out the principles governing data protection and which therefore form the basis of this Policy:

 Principle of “legality, loyalty and transparency”

PTFSA will process personal data in a lawful, fair and transparent manner, that is, the interested party will be informed about the processing of their data and the specific purposes, offering them all the additional information that may be necessary.

Natural persons shall be informed that personal data concerning them are being collected, used, consulted or otherwise processed, as well as the extent to which such data are or will be processed.

Personal data will be processed in a manner that ensures appropriate security and confidentiality, including preventing unauthorized access to or use of such data and the equipment used in the processing.

Personal data will not be processed without the consent of the interested party or in accordance with the general rules of applicable legislation.

PTFSA will not collect or process personal data relating to ethnic or racial origin, political opinions, religious or philosophical beliefs or trade union membership and the processing of genetic data, biometric data aimed at uniquely identifying a natural person, data relating to health or data relating to the sexual life or sexual orientations of a natural person, unless such collection and subsequent processing are necessary, legitimate or obligatory or permitted by applicable law, in which case they will be collected and processed in accordance with the provisions of that law.

Principle of “limitation of purpose”

Personal data processed by PTFSA will always be collected for specific, explicit and legitimate purposes and will not be subsequently processed in a manner incompatible with those purposes; unless they are processed in the future for archiving purposes in the public interest, scientific and historical research purposes or statistical purposes, this will not be considered incompatible with the initial purposes.

Principle of “data minimization”

PTFSA will only process personal data that is strictly necessary for the purposes for which it was collected, that is, it will be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.

Principle of “accuracy”

PTFSA will ensure that the personal data processed are accurate and up-to-date, adopting reasonable measures to ensure that they are deleted or rectified when they are found to be inaccurate with respect to the purposes for which they were collected.

Principle of “limitation of the retention period”

PTFSA will not retain the personal data it processes beyond the time necessary for the purposes for which it was collected, except under legal obligation or if it is kept for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes.

Principle of “integrity and confidentiality”

PTFSA will endeavour to guarantee the integrity and confidentiality of the personal data processed, applying technical or organisational measures to protect them from unauthorised or unlawful processing, and against accidental loss, destruction or damage.

Proactive responsibility

PTFSA is committed to compliance with the principles listed above by applying due diligence and must be able to demonstrate such compliance by applying a “proactive responsibility” which translates into:

Risk assessment or analysis

The controller is obliged to implement appropriate and effective measures and must be able to demonstrate the compliance of the processing activities with applicable law, including the effectiveness of the measures. Such measures must take into account the nature, scope, context and purposes of the processing, as well as the risk to the rights and freedoms of natural persons. To do so, PTFSA will carry out an assessment or analysis of the risk of the processing it carries out, in order to weigh up on the basis of an objective assessment by which it determines whether the measures are in compliance with the applicable law.

data processing operations involve a risk and if this is high, thus determining that the measures applied comply with legal obligations.

Impact evaluation

PTFSA will carry out impact assessments in those cases provided for in the applicable legislation, that is, when there is a likelihood that a certain treatment, and in particular if new technologies are used, entails a high risk for the rights and freedoms of natural persons. The likelihood that the type of treatment entails risks will be assessed taking into account the following criteria: its nature, its scope and the context or the purposes of the type of treatment. The impact assessment will include, in particular, the measures, guarantees and mechanisms envisaged to mitigate the risk, guarantee the protection of personal data and demonstrate compliance with the applicable legislation.

To do so, the guidelines and instructions established in the corresponding internal procedure must be followed.

Record of treatment activities

PTFSA, both when acting as data controller and when acting as data processor for some of its clients, entities, organizations and Public Administrations with which it has relationships, will keep records of the processing activities under its responsibility.

Security breaches

In the event of an incident in the processing of personal data for which PTFSA is responsible and which may result in physical, material or immaterial damage or harm to natural persons, such as loss of control over their personal data or restriction of their rights, discrimination, identity theft, financial losses, unauthorised reversal of pseudonymisation, damage to reputation, loss of confidentiality of data subject to professional secrecy or any other significant economic or social harm to the natural person who is the owner of the personal data, the internal guidelines and rules established by PTFSA for the management of so-called Security Violations or Breaches will be followed.

The functions of monitoring, controlling and implementing the regulations will fall to the PTFSA Management Office.

Rights of the interested parties

Any person has the right to obtain information as to whether or not their personal data is being processed by this PTFSA.

PTFSA undertakes to facilitate the exercise of the rights recognized by the applicable legislation by the interested party:

  • Right of access, retention periods, including obtaining a copy of the same;
  • Right to rectify your data if they are inaccurate;
  • Right Interested parties may exercise the right to deletion (right to be forgotten) whenever the circumstances listed in the GDPR occur;
  • Right to limit processing, for which they must request it from the person responsible, who must suspend the processing of the data when citizens request the rectification or deletion of their data, until their request is resolved;
  • Right to portability, to obtain data in a structured, commonly used and machine-readable format, and to transmit them to another data controller when the processing is based on consent or is carried out by automated means.
  • Right to object and not be subject to automated individual decisions.

To do so, the guidelines and rules established in the internal procedures that regulate the exercise of rights of interested parties will be followed. In any case, interested parties may exercise the rights listed in the previous paragraphs, through the forms available on the PTFSA electronic site or by sending a letter to it by post.

Processors

PTFSA has internal contracting procedures that regulate and establish the specific measures to be taken regarding the contracting of services from providers who access data as data processors, as well as regarding those providers who, without being data processors, could accidentally or incidentally access personal data for which PTFSA is responsible. The provision of these services will be regulated in the corresponding data processing contracts or by including ad hoc clauses in the main service contract.

International data transfers               

PTFSA does not currently have a large international presence and it is not common to need to make international data transfers to States that do not offer the same security as the Member States of the European Union or those recognised by the Commission as safe destinations. However, PTFSA uses information systems to process your data that may occasionally involve international data transfers. PTFSA enters into agreements with its service providers with the appropriate guarantees and decisions.

PTFSA will ensure that any processing involving a transfer of data outside the Union or to countries that do not have an adequate level of data protection is carried out in compliance with the requirements established in the applicable legislation.

Implementation: the Data Protection Management System    

In accordance with the principles and standards included in this Policy, PTFSA will develop the appropriate internal procedures, or any other internal support documents, that allow the implementation of the applicable legislation, thus forming a Data Protection Management System. These procedures or support documents will be mandatory for all PTFSA professionals.

Control and evaluation                                         

The Data Protection Management System must be monitored and evaluated periodically. To this end, a periodic audit of compliance with the provisions of this Policy and applicable legislation in general will be carried out under the direction and supervision of the PTFSA Management Office.

Furthermore, Internal Audit, within the framework of its annual planning for the review of all PTFSA systems, will include a specific section on data protection in order to monitor compliance with the regulations applicable in the subsidiaries and branches it visits.

The results obtained from the various audits and other controls will be reported to the governing body, specifically, to the Board of Directors.

Advertising

The Data Protection Policy will be available as documented information and will be communicated to all interested parties and PTFSA professionals who must comply with and implement it.

It will also be available through the Transparency portal on the PTFSA Electronic Office at https://ptfue.sedelectronica.es/dossier.3. And on the website at https://sede.ptfue.com/

Download the data protection policy

Last updated: March 28, 2019

Go to content