LEGAL NOTICE
COMMITMENT TO PERSONAL DATA PROTECTION
The Management / Governing Body of FRANCISCO PINDADO DE LA TORRE (hereinafter, the data controller), assumes the utmost responsibility and commitment to the establishment, implementation and maintenance of this Data Protection Policy, ensuring the continuous improvement of the data controller with the aim of achieving excellence in relation to compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), and Spanish personal data protection legislation. The Data Protection Policy of FRANCISCO PINDADO DE LA TORRE is based on the principle of proactive responsibility, according to which the data controller is responsible for compliance with the regulatory and jurisprudential framework governing said Policy, and is able to demonstrate this to the competent supervisory authorities.
"INFORMED PEOPLE AND PROTECTED DATA" — Guiding principles
- 01
Data protection by design
The data controller shall implement appropriate technical and organisational measures, such as pseudonymisation, designed to implement data protection principles, such as data minimisation, effectively and to integrate the necessary safeguards into the processing, both at the time of determining the means of processing and at the time of the processing itself.
- 02
Data protection by default
The data controller shall implement appropriate technical and organisational measures to ensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed.
- 03
Data protection throughout the information lifecycle
Measures that guarantee the protection of personal data shall be applicable throughout the complete lifecycle of the information.
- 04
Lawfulness, fairness and transparency
Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject.
- 05
Purpose limitation
Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
- 06
Data minimisation
Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
- 07
Accuracy
Personal data shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.
- 08
Storage limitation
Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
- 09
Integrity and confidentiality
Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
- 10
Information and training
One of the keys to ensuring the protection of personal data is the training and information provided to staff involved in their processing. Throughout the information lifecycle, all staff with access to data will be duly trained and informed about their obligations regarding compliance with data protection regulations.
The Data Protection Policy of FRANCISCO PINDADO DE LA TORRE is communicated to all staff of the data controller and made available to all interested parties. Consequently, this Policy involves all staff, who must know and embrace it as their own, with each member being responsible for applying it and verifying the data protection rules applicable to their activity, as well as identifying and contributing improvement opportunities deemed appropriate in order to achieve excellence in compliance. This Policy will be reviewed by the Management of FRANCISCO PINDADO DE LA TORRE as many times as deemed necessary to ensure it remains aligned with the current provisions on personal data protection.
