COMMITMENT TO THE PROTECTION OF PERSONAL
DATA This information, addressed to all people (users or not of the website), must be provided through a link available on the website, under the name "COMMITMENT TO THE PROTECTION OF PERSONAL DATA". This link should preferably be available at the top of the website, to facilitate its visibility and accessibility.
OUR COMMITMENT TO THE PROTECTION OF PERSONAL DATA: "INFORMED PERSONS AND PROTECTED DATA"
The Management / Governing Body of BRIGIDA RAUSCH SCHUMANN (hereinafter, the data controller), assumes the utmost responsibility and commitment to the establishment, implementation and maintenance of this Data Protection Policy, ensuring the continuous improvement of the data controller with the aim of achieving excellence in relation to compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (OJEU L 119/1, 04-05-2016), and the Spanish regulations on the protection of personal data (Organic Law, sector-specific legislation and its implementing rules).
The Data Protection Policy of BRIGIDA RAUSCH SCHUMANN rests on the principle of proactive responsibility, according to which the controller is responsible for compliance with the regulatory and jurisprudential framework governing said Policy, and is able to demonstrate this to the competent supervisory authorities.
In this sense, the person responsible for the treatment will be governed by the following principles that must serve all its personnel as a guide and frame of reference in the processing of personal data:
- Data protection by design: the data controller shall apply, both at the time of determining the means of processing and at the time of the processing itself, appropriate technical and organisational measures, such as pseudonymisation, designed to effectively apply the principles of data protection, such as data minimisation, and integrate the necessary guarantees into the processing.
- Data protection by default: the controller shall apply appropriate technical and organisational measures with a view to ensuring that, by default, only personal data that are necessary for each of the specific purposes of the processing are processed.
- Data protection in the information lifecycle: measures ensuring the protection of personal data shall apply throughout the entire information lifecycle.
- Legality, loyalty and transparency: personal data will be treated in a lawful, loyal and transparent manner in relation to the interested party.
- Purpose limitation: personal data will be collected for specific, explicit and legitimate purposes, and will not be further processed in a manner incompatible with those purposes.
- Data minimization: personal data will be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
- Accuracy: personal data will be accurate and, if necessary, updated; all reasonable steps shall be taken to ensure that personal data that are inaccurate with respect to the purposes for which they are processed are deleted or rectified without delay.
- Limitation of the conservation period: the personal data will be kept in such a way as to allow the identification of the interested parties for no longer than necessary for the purposes of the processing of the personal data.
- Integrity and confidentiality: personal data will be treated in such a way as to ensure adequate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, through the application of appropriate technical or organisational measures.
- Information and training: one of the keys to ensuring the protection of personal data is the training and information provided to the personnel involved in the processing thereof. During the information lifecycle, all personnel with access to the data will be properly trained and informed about their obligations in relation to compliance with data protection regulations.
The Data Protection Policy of BRIGIDA RAUSCH SCHUMANN is communicated to all staff of the controller and made available to all interested parties.
Consequently, this Data Protection Policy involves all the personnel of the person responsible for the treatment, who must know and assume it, considering it as their own, each member being responsible for applying it and verifying the data protection rules applicable to its activity, as well as identifying and providing the opportunities for improvement that it deems appropriate with the aim of achieving excellence in relation to its compliance.
This Policy will be reviewed by the Management / Governing Body of BRIGIDA RAUSCH SCHUMANN, as many times as deemed necessary, to adapt, at all times, to the provisions in force regarding the protection of personal data.