Privacy Policy
1. Objective
This Privacy Policy, in the context of the protection of personal data, aims to define the general principles and rules to be applied by Institute of Informatics, I.P. (II,I.P.) to the personal data processed within the information channel of the Interoperability Services Platform.
The II, I.P. establishes, through this policy, a Privacy Policy to the Holders of Personal Data, which complies with the requirements of the legislation in force and guarantees a specific, explicit and informed communication about the processing of your data.
2. Scope
This Privacy Policy applies to all personal data collected and processed belonging to users of the Interoperability Services Platform information channel.
3. Addressees
The Privacy Policy is addressed to users of the information channel of the Interoperability Services Platform and the Holders of personal data, including those of II, I.P.
4. Description
Personal Data is processed in accordance with the principles set out in Article 5(1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 - General Data Protection Regulation (GDPR).
Namely:
– Lawfulness, Loyalty and Transparency
– Purpose limitation
– Data minimisation
– Accuracy
– Conservation limitation
– Integrity and Confidentiality
5. General principles
II, I.P. undertakes to process personal data in accordance with the applicable rules and legislation. It therefore develops tools and implements actions with the aim of ensuring and monitoring the effectiveness of personal data protection. Internal policies and procedures are adopted to increase employees' awareness of the importance of personal data protection by providing them with operational guidance on how to comply with data protection legislation and monitor compliance with personal data protection. Included is the realization of a training/communication program that sensitizes its employees in the theme of information security and privacy of personal data.
Any employee of II, I.P. who, during his work, has access to Personal Data agrees to keep it in the strictest confidentiality within the framework of the confidentiality agreements signed.
6. Collection and Processing of Personal Data
Within the scope of the information channel of the Interoperability Services Platform, II, I.P. may process personal data relating to the fulfilment of its tasks.
The collection will be made by interconnection, communication or with the Data Subject.
Personal Data will be kept in accordance with the periods imposed by the legislation in force, in particular taking into account the mission and attributions of the Child Guarantee.
7. Confidentiality
Within the scope of II, I.P.'s activity, only the data necessary for the provision of the services will be requested and collected, according to the explicit information on the website and the user's options.
The II, I.P. guarantees to all its users that:
– No personal data shall be provided to third parties without the prior consent of the data subject; – None of the data entrusted to us will be made available, free of charge or commercially, to direct marketing companies or other entities that use mailing lists to advertise their products and/or services.
The II, I.P. reserves the right to provide or publish aggregated data for purposes considered to be of public utility, namely in the scope of statistical production. However, personal identification elements, such as the Name, BI Number, Citizen Card or Tax Identification, or information of a private nature will never be made available.
8. Security of processing measures
II, I.P. follows organizational and technological security standards, and effective practices in information security management, to protect the confidentiality, integrity and availability of information and to provide confidence in inter-organizational exchanges, as well as community standards, legislation and specific national recommendations on information security, with a view to protecting the rights, freedoms and guarantees of Data Subjects.
II, I.P also applies the international standard ISO/IEC 27001.
II, I.P. has, within the scope of the information and transactional channels, all the necessary technical and organizational measures to ensure a level of security of Personal Data appropriate to the risk that may occur during its processing and, in particular, to protect Personal Data against destruction, loss, alteration, unauthorized disclosure or accidental or illegal access.
The same level of protection is imposed, contractually, on its suppliers and service providers, and on the Entities with which it relates.
II, I.P. has an internal organization of Protection of Personal Data to ensure compliance with the rules of protection of Personal Data, supported by Data Protection Officers.
9. Privacy Notice
The II, I.P. processes personal data lawfully, in accordance with Articles 6 and 9 of the GDPR, and only treats them if the situations of lawful processing provided for in the same law occur.
The holders of Personal Data have the right to be informed about the processing of their data and may exercise, at any time, the right to information, access, rectification, erasure, updating, restriction of processing, portability, as well as to oppose and not submit to automated individual decisions regarding their personal data, including the revocation of consent, in accordance with the GDPR or applicable law. To do this, they must access the information indicated in the contact point.
Data Subjects have the right to complain to the competent Supervisory Authority in case of violation of the applicable rules regarding the protection of Personal Data.
In the event of a breach of Personal Data, the II, I.P., as data controller, will notify it to the competent Supervisory Authorities and communicate it to the data subject when justified, in accordance with Articles 33 and 34 of the GDPR.
10. Rights of the Data Subject
In accordance with the applicable rules regarding the protection of Personal Data, the Data Subject may exercise, at any time, his or her right to obtain access, rectify, forget and transfer, pursuant to Article 20 of the GDPR, his or her Personal Data, and also to restrict and oppose the Processing of his or her Personal Data.
The exercise of the rights of the Data Subject must be carried out with the II, I.P., using the channels available in "contacts".
When the Treatment is based exclusively on the consent of the Owner, the latter has the right to withdraw it at any time.
In its own interest, the Data Subject should seek to keep his or her data up-to-date and, for this purpose, should contact the competent authority.
11. Changes to the Privacy Policy
This Privacy Policy may be amended whenever there is a need or change in the normative framework, and a notice of such changes is published in a revised version of the current Policy, with entry into force at the time of its publication or on a date set therein.
12. The Data Protection Officer
The Data Protection Officer informs and advises on the applicable personal data protection requirements and monitors compliance with those requirements.
The Data Protection Officer shall cooperate and act as contact point with the competent supervisory authorities and data subjects.
The data subject may submit data protection requests (exercise of rights, requests for clarification or reporting of incidents of personal data breach), using the following contacts, namely through the e-mail addresses:
Data Protection Officer of II, IP
Address:Av. Prof. Dr. Cavaco Silva, nº 17 – Taguspark, 2740-120 Porto Salvo
E-mail address:II-EPD@seg-social.pt