opera_btsf_privacy

INFORMATION ON THE PROCESSING OF PERSONAL DATA

The General Data Protection Regulation (GDPR) (EU) 2016/679 is a regulation in EU law on data protection and privacy for all individuals within the European Union (EU) and the European Economic Area (EEA), adopted in April 2016, and enforceable starting on 25 May 2018. The mentioned  EU Directive   regulates the processing of personal data regardless of whether such processing is automated or not ( Personal data is :  “any information relating to an identified or identifiable natural person (“data subject”); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity;” (art. 2 a of GDPR).

This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.This Regulation basically comes to establish that the Personal data should not be processed at all, except when certain conditions are met.

These conditions must fall only into three categories: transparency, legitimate purpose and proportionality.

The responsibility for compliance rests on the shoulders of the “controller” or the potential “collector of the data, meaning by controller the natural or artificial person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data.

Since OPERA SRL (hereafter “OPERA”) is a legal entity, is a potential collector of the personal data of employees and experts, therefore OPERA is recipient of observance of that directive GDPR UE 679/2016 and EU Regulation (GDPR) 2016/679 concerning the processing of personal data, as well as with the Legislative Decree 181/18 which amends Legislative Decree 196/2003, regulates the methods of treatment of the data collected from a website while the user is browsing.

The methods for handling personal data by OPERA SRL are described below, also with reference to the data collected through the website. The personal data that OPERA SRL deals with regards its own personnel and collaborators; the Company does not carry out market surveys, nor does it perform services in favor of consumers and uses data and information managed solely for statutory purposes (participation in national and international projects in the areas of competence: agriculture, rural development and the environment). Also for these reasons, the data and information processed are not marketed or communicated to third parties outside legal obligations or collaboration agreements within the projects carried out. This policy is valid as information on the processing of data, pursuant to art. 13 of the European Regulation n. 679/2016 (also “Gdpr”) and is made available on the company’s website through links.

Data controller and the controller.

Pursuant to art. 24 of the Gdpr, Data Controller is OPERA SRL with registered office in Viale Parioli, 96 00197 Rome.

Pursuant to art. 28 of the GDPR, Mrs Orietta Ricci, mail: orietta.ricci@opera-italy-eu Processor. External data controllers have been appointed as persons who, on behalf of Opera, perform professional services involving the processing of personal data.

Place of data processing

The treatments take place at the offices of the owner and of the external treatment manager for relevant areas. No data is communicated by the company to third parties unless the purpose of the processing is strictly relevant or imposed by laws or regulations.

Purpose of the treatment

OPERA receives and manages the data of experts and technical collaborators for participation in national and international tenders in the areas of competence. The information processed exclusively concerns the professional and technical skills of the personnel employed in the projects to which OPERA participates.

The data concerning the personnel are treated in compliance with the laws in force and in compliance with the contractual obligations assumed.

On the company’s website, the personal data provided voluntarily and optionally by users who send requests for information are collected using the appropriate form. These data are used for the sole purpose of providing the requested information and concern the name and email of the person concerned. At the end of use the data are not stored.

In particular, personal data provided voluntarily by data subjects will be collected and processed for the following purposes:

  • receive general, commercial and / or administrative information pertaining to the company’s social activities.

Personal data are protected by technical, IT, organizational, logistic and procedural security measures, against the risk of destruction or loss, even accidental, and unauthorized access or unauthorized processing.

These measures are updated periodically on the basis of technical progress, the nature of the data and the specific characteristics of the treatment, monitored constantly and verified over time. Third parties who carry out support activities of any kind for the provision of services, in relation to which they carry out processing operations of personal data, are from the latter designated Data Processors and are contractually bound to comply with security measures and the confidentiality of the treatments.

Communication and dissemination of data

The personal data acquired may be processed exclusively by personnel officially appointed and instructed in matters of confidentiality and security of personal data. To this end, the Company has appointed the persons in charge of processing, providing the appropriate provisions.

The areas of communication of the personal data of the interested parties may refer to:

  • to public bodies or offices according to legal and / or contractual obligations;
  • external processors in the capacity of companies or consultants who carry out activities of a professional nature on behalf of the owner;
  • to the Postal Police for the determination of any activities harmful to the company’s website.

Personal data will not be disseminated.

Method of treatment

Personal data are processed in paper form and / or with automated tools for the time strictly necessary to achieve the purposes for which they were collected.

Specific security measures are observed to prevent data loss, illicit or incorrect use and unauthorized access.

In the case of a contractual relationship with OPERA, the data are retained for the duration of the relationship and subsequently eliminated, except for specific legal obligations.

Data provided voluntarily by the user The optional, explicit and voluntary sending of e-mails to the addresses indicated on the Company’s website entails the subsequent acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data included in the message.

Rights of the interested parties

The interested party can claim at any time, without formalities, by contacting the data controller, the rights referred to in Chapter III of the European Regulation n. 679/2016 (article 12 and following).

The interested party has the right to obtain confirmation of the existence or not of personal data concerning him, even if not yet registered, and their communication in intelligible form.

It may also request the deletion or correction of data concerning it, and according to Article 18 the limitation of processing when the following hypotheses occur:

  1. the interested party disputes the accuracy of personal data for the period necessary for the data controller to verify the accuracy of such personal data;
  2. the processing is illegal and the interested party opposes the cancellation of personal data and asks instead that its use is limited;
  3. although the data controller no longer needs it for processing purposes, personal data are necessary for the data subject to verify, exercise or defend a right in court;
  4. the interested party has opposed the treatment pursuant to Article 21 (1), pending verification of the possible prevalence of the legitimate reasons of the data controller with respect to those of the interested party.

As required by the European Regulation n. 679/2016, OPERA SRL based in Rome, Viale Parioli 96, 00197, provides users who visit the website with information on treatments.

For requests or information on the data concerning them, interested parties may contact the Data Processor, Mrs Orietta Ricci, at the following e-mail address: orietta.ricci@opera-italy.eu.

Legal notice  BTSF EU  – BTSF Non-EU

Data Protection Notice for Better Training for Safer Food (BTSF) face to face and virtual classroom training courses

BTSF Online (e-learning courses) Data Protection Notice for Better Training for Safer Food (BTSF) Online training-learning activities

Link:BTSF academy info Privacy