PRIVACY POLICY – NEWSLETTER SERVICE

Information notice pursuant to Article 13 of the Reg. UE 2016/679 (GDPR)

Asso DPO - Privacy Policy adesione

1.WHO IS THE DATA CONTROLLER? HOW TO CONTACT THEM?

The data controller, pursuant to Articles 4 and 24 of EU Regulation 2016/679, is the Association Data Protection Officer (ASSO DPO), headquartered at Viale Monza, 44- 20127 - Milan, VAT number 08258580961, Tax code 97656960156, represented by its President and legal representative pro-tempore, Dr. Matteo Colombo. To contact the data controller: email info@assodpo.it or toll-free number 800561720.

Asso DPO - Privacy Adesione 07

2. PURPOSE OF PROCESSING, LEGAL BASIS, DATA RETENTION PERIOD, NATURE OF PROVISION

Purpose A)
Newsletter service. The association, in pursuing the fundamental purposes provided for in the Bylaws, including "promoting research and dissemination of knowledge”; "promoting the enhancement of the DPO's role and fostering its professional growth", offers a newsletter service.
This activity is carried out through the email addresses provided directly by the data subject through the free completion of the form on the website. The data subject will receive, through this channel, institutional communications, news about the association, and, more generally, notices regarding events such as the Congress, new webinars, new articles published on the website and on the official channels of the Association. The Data Controller, to compare and possibly improve the results of communications, uses systems for sending newsletters with reports. Thanks to the reports, the Data Controller will be able to know, for example: the number of readers, openings, unique "clickers," and clicks; the devices and operating systems used to read the communication; the details of emails sent, delivered and undelivered. All these data are used to compare and possibly improve the results of communications.

  • LEGAL BASIS: Consent art. 6 par. 1 lett. a) GDPR: the data subject has given consent to the processing of their personal data.
  • DATA RETENTION PERIOD: The data subject can easily and free of charge revoke their consent (by using the automated cancellation systems provided for emails only; each communication will contain the link to exercise the opt-out).
  • NATURE OF PROVISION: The provision of data is optional, and in the absence thereof, the personal data of the data subject will not be processed for the purpose stated. Refusal to provide data will not affect the availability of other services provided by the Association.
Asso DPO - Privacy Adesione 02

3.TO WHOM WILL THE PERSONAL DATA BE DISCLOSED? DATA RECIPIENTS

Personal data will be disclosed to entities acting as independent Data controllers or Data processors (art. 28 GDPR) and processed by individuals (art. 29 GDPR) acting under the authority of the Data Controller and Data Processors based on specific instructions provided regarding the purposes and methods of processing.
The data will be disclosed to the following categories:

  • companies, based in Italy, contractually bound to the Association Data Protection Officer;
  • entities, based in Italy, providing services for the website and communication networks, including email, hosting, website management, and newsletter service;
  • entities, based in Italy, providing services for the management of the information system used by the Association Data Protection Officer and telecommunication networks;
  • freelancers, firms, or companies within the scope of assistance and consultancy relationships;
  • competent Authorities for compliance with legal obligations and/or provisions of public bodies.

The list of Data processors is constantly updated and available by writing to info@assodpo.it or at the Data Controller's registered office.

Asso DPO - Privacy adesione 03

4.DOES ASSO DPO TRANSFER THE DATA TO COUNTRIES OUTSIDE THE EEA?

The personal data provided for the subscription to the newsletter of the Association will not be transferred to countries located outside the European Economic Area (EEA). The provider of the newsletter service commits to “not carry out any transfer of Personal Data and Databases outside the EU and to Countries that do not guarantee an adequate level of protection”.

If it becomes necessary to transfer the personal data of data subjects to Countries located outside the EEA, this will be done in compliance with the limits and conditions set forth in Articles 44 and following of EU Regulation 2016/679. The data subject may obtain information about the safeguards for data transfer by writing an email to info@assodpo.it or to the legal headquarters of the Data Controller.

Asso DPO - Privacy adesione 04

5.IS THERE AN AUTOMATED PROCESS?

The personal data will be subject to traditional manual, electronic, and automated processing. It is specified that no completely automated decision-making processes are carried out.

Asso DPO - Privacy adesione 05

6. WHAT ARE THE RIGHTS OF DATA SUBJECTS? HOW TO EXERCISE THEM?

Data subjects may exercise their rights as expressed in Articles 15 and following of the GDPR by contacting the Data Controller at the email address: info@assodpo.it, or by writing to the contacts indicated above.
The Data Controller ensures data subjects the right to request, at any time, access to their personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), and restriction of processing (Art. 18). The data controller communicates (Art. 19) to each recipient to whom personal data have been disclosed, any rectifications, erasures, or restrictions of processing made. The data controller informs the data subjects who request it about such recipients.

The data controller ensures the right to data portability (Art. 20) and, in the event of requests under Art. 20, will provide data subjects with the data in a structured, commonly used format, readable with an automatic device. In the cases provided for, data subjects have the right to withdraw consent without prejudice to the lawfulness of processing based on consent before its withdrawal. To unsubscribe from the newsletter service (email), data subjects are invited to write an email to the address info@assodpo.it with the subject "erasure from automated" or to use our automated cancellation systems within the communication emails.

If data subjects believe that the processing of personal data carried out by the Data Controller violates the provisions of Regulation (EU) 2016/679, they are free to lodge a complaint with the national supervisory authority, particularly in the Member State where they habitually reside or work, or where the alleged violation of the Regulation occurred (Italian Data Protection Authority https://www.garanteprivacy.it/ ), or to seek judicial remedies.

Asso DPO - Privacy adesione 05

7.AMENDMENTS TO THE PRIVACY POLICY

The Data Controller may change, modify, add, or remove any part of this Privacy Policy. To facilitate the verification of any changes, the policy will contain the indication of the update date.

Date of review: 21/02/2024