Pursuant to art. 4 ad 24 Reg UE the Data Controller is Associazione Data Protection Officer (ASSO DPO), with registered office in 20121 Milano – P.le Principessa Clotilde n. 6, P.IVA 08258580961, C.F. 97656960156, in person of its Legal Representative Dott. Matteo Colombo.
contacts: email email@example.com; telephone number: 800561720.
Registration to the Congress ASSO DPO in webinar mode; management of administrative-accounting activities related to the event; use of the e-mail contact to inform those interested about the Congress and to send communications related to the service. The processing operations carried out for administrative-accounting purposes are those related to the performance of activities of an organizational, administrative, financial and accounting nature, regardless of the nature of the data processed which, in the case of subjects already associated are: name, surname, email address and ASSO DPO card no.; while in the case of subjects not associated are: name, surname, email address, bank details (for the collection of the transfer). In the context of the webinar, no additional information will be collected with respect to the purposes pursued: the tool used, in fact, does not track or monitor in any way the behavior of the participants on the platform.
• LEGAL BASIS: fulfilment of contractual and pre-contractual obligations related to registration to the Congress (art. 6, par. 1 letter b) GDPR); legal obligation (art. 6, par. 1 letter c) GDPR and LAW 14 January 2013, n. 4, art. 2 c. 3 “Professional associations promote, also through specific initiatives, the continuous professional formation of their members […]”).
• DATA RETENTION: 10 years or otherwise stated by law;
• NATURE OF CONFERRAL: Mandatory, tightly essential to give execution to contractual and law obligations. In case of non-conferment, the data Controller won’t be able to proceed with the registration to the Congress.
Newsletter service. The association, in pursuing the fundamental aims of the Statute, including “promoting research and the spread of knowledge”; “promoting the valorization of the role of the DPO and fostering its professional growth”, offers a newsletter service. This activity is carried out through the e-mail coordinates provided directly by the interested party during the registration phase or through the free filling in of forms on the website. The interested party will receive, through this channel, institutional communications, news about the association and, more generally, notifications regarding, for example, events such as the Congress, new webinars, new articles published on the site and on the others official channels of the association.
The data controller, in order to compare and possibly improve the results of communications, uses systems for sending newsletters and communications with reports. Thanks to reports, the Data Controller will be able to discover, for example: the number of readers, single openings, unique “clickers” and clicks; devices and operating systems employed to read the communication; details of email sent, delivered or not. All these data are employed with the purpose of comparing, and possibly improving, the communication results.
• LEGAL BASIS: the processing is necessary for the pursuit of the legitimate interest of the data controller or third parties, as long as the interests or fundamental rights and freedoms of the data subject which require the protection of personal data do not prevail. The legitimate interest of the data controller is to pursue the institutional information purposes pursued by the Association (art. 6 par. 1 letter f) GDPR and recital 47). As required by the Opinion 6/2014 of the Working Group Art. 29 – WP29 – on the concept of legitimate interest, the Data Controller conducted a “LIA” (Legitimate Interests Assessment), balancing the interests of the parties and the rights at stake. The interested party may oppose the legitimate interest of the Data Controller both at the time of joining the Association and afterwards.
• DATA RETENTION: the data subject may object to the processing based on legitimate interest in an easy way and free of charge (each communication made will contain the link to exercise the opt-out).
• NATURE OF CONFERRAL: the provision of data for this purpose is optional and, where lacking, personal data won’t be processed for such purpose; the denial of conferral will not undermine benefits from other purposes.
Provided data will be shared with recipients who will treat them as data Processors (art. 28 Reg. UE 2016/679) and/or as natural person acting under the controller’s or processor’s authority (art. 29 Reg. UE 2016/679) for former purposes.
Namely, data will be shared with:
– companies contractually associated to the Data Protection Officer Association;
– subjects who provide services for the management of the information system used by the Data Protection Officer Association and telecommunications networks;
– professionals, studies or companies in the assistance and consultancy field;
– competent authorities for compliance with legal obligations and / or provisions of public bodies, upon request;
The list of the data Processors is constantly updated and available writing to firstname.lastname@example.org or sending a traditional mail to the Data Controller registered office.
Personal data will not be transferred out of the UE area. If it should be necessary to transfer your data to non-EU countries, this will be done in compliance with the limits and conditions of the articles 44 and s.s. of EU Reg. 2016/679. The data subject may obtain information about the guarantees for data transfer writing an email to the address email@example.com or at the registered office of the Data Controller.
We do not process data by automated mean, profiling included.
You can exercise your rights, as required by art. 15 and subsequent of the General Data Protection Regulation UE 2016/679 (GDPR) contacting the data Controller at the email address: firstname.lastname@example.org. You have the right, at any time, to obtain from the data Controller the access to your personal data, request their rectification, erasure or processing restriction and, if applicable, data portability. Furthermore, you have the right to object anytime to your personal data processing based upon legitimate interest. Where applicable, you have the right to withdraw consent without prejudice to the lawfulness of the processing based on the consent given before the withdrawal.
To unsubscribe from newsletter service (E-Mail), please write to email@example.com (object: “cancellazione da automatizzato”) or use our automated unsubscribing tools.
Without prejudice to any other administrative or judicial remedy, in case you consider the processing conflicting with Reg. UE 2016/679, pursuant to article 15 lett. f) you have the right to lodge a complaint with a supervisory authority
In case of request for data portability, the Data Controller will provide your personal data in a structured format, commonly used and readable by automatic device.
Data controller retains the right to modify, update, add or remove parts of this statement at his own discretion, in any moment.
Date of review: 09/09/2020