PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA
pursuant to Articles 13 and 14 of Regulation (EU) 2016/679
This document, pursuant to EU Regulation 2016/679 – GDPR, aims to provide the necessary information regarding the processing activities carried out on Personal Data collected in the course of its institutional activities.
1. DATA CONTROLLER
The Data Controller is the Parliamentary Budget Office, hereinafter UPB, with registered office at Via del Seminario 76, Rome, reachable at segreteria@upbilancio.it, to whom you may turn to exercise your rights.
2. DATA PROTECTION OFFICER
The administration has appointed a Data Protection Officer (DPO) who may be contacted for further information about the processing of personal data and for the exercise of rights provided under applicable legislation, reachable at dpo@upbilancio.it.
3. PURPOSES AND LEGAL BASIS OF PROCESSING
Personal Data are processed in the context of the institutional activities carried out by the Parliamentary Budget Office, for the purposes of economic analysis. The processing is grounded in the following legal bases: the processing is necessary to comply with a legal obligation to which the controller is subject (Art. 6(1)(c) GDPR); the execution of tasks carried out in the public interest (pursuant to Art. 6(1)(e) GDPR). In the event of processing of special categories of data, the processing is carried out in accordance with Art. 9(2)(j) GDPR, or Art. 89 of the same Regulation, where applicable. Reference is also made to Art. 18(7) of Law No. 243 of 24 December 2012 as a further regulatory basis.
4. CATEGORIES OF DATA PROCESSED
In relation to the specific operations and activities carried out by UPB, Personal Data may be processed. “Special categories of data” may also be processed (i.e. data capable of revealing, for example, health status; cf. Art. 9(1) GDPR). Such data may be provided directly by the data subject, or collected from other bodies and/or extracted from databases (i.e. Istat, INPS, Revenue Agency, etc.).
5. PROCESSING METHODS
All Personal Data processing activities previously indicated will be carried out by UPB in relation to the aforementioned purposes, through automated or manual means. Such data will first be subject, where possible and compatible with the purposes pursued, to anonymisation or pseudonymisation processes. Through anonymisation, input data will not be traceable, even indirectly, to an identified or identifiable data subject. Through pseudonymisation, direct identifiers will be replaced with alternative elements, reducing the risks associated with data processing, while still allowing, through the use of additional information stored separately, the possible re-identification of the data subject if necessary.
6. CATEGORIES OF RECIPIENTS
In pursuit of the purposes and legal bases referred to above, UPB may acquire data from institutional partners, and such data are not transferred to other parties. Data may occasionally be processed by third parties (e.g. IT suppliers, professionals) for technical purposes and/or in the context of professional assignments conferred by the Office, following prior pseudonymisation and/or other equivalent technical measure.
7. TRANSFER OF DATA TO THIRD COUNTRIES
The Parliamentary Budget Office does not envisage any transfer of the Personal Data it processes to third countries and/or International Organisations.
8. RIGHTS OF THE DATA SUBJECT
The data subject may exercise the rights expressly provided for by the GDPR where applicable:
- Right of access, i.e. the right to obtain from the Data Controller confirmation as to whether or not Personal Data concerning them are being processed and, if so, to obtain access to at least the purposes of the processing, the categories of personal data concerned, any recipients or categories of recipients to whom the data have been or will be disclosed, and the retention period (cf. Art. 15 – GDPR);
- Right to rectification, i.e. the right to obtain from the Data Controller the rectification of inaccurate Personal Data concerning them (cf. Art. 16 – GDPR);
- Right to erasure, i.e. the right to obtain from the Data Controller the erasure of Personal Data concerning them, where the purposes underlying the processing have ceased to exist (cf. Art. 17 – GDPR);
- Right to restriction of processing, i.e. the right to obtain from the Data Controller a restriction of the activities carried out on the data, where one or more of the conditions referred to in Art. 18 – GDPR apply;
- Right to object, i.e. the right to object to processing on grounds relating to the data subject’s particular situation, pursuant to Art. 6(1)(e) or (f) (cf. Art. 21 – GDPR);
- Right to data portability, i.e. the right to receive from the Data Controller, in a structured, commonly used and machine-readable format, the personal data concerning the data subject, as well as the right to transmit such data to another Data Controller without hindrance from the first (cf. Art. 20 – GDPR);
- Where the data subject believes that processing concerning them is in violation of the Regulation, they may lodge a formal complaint with a supervisory authority (cf. Art. 13(2)(d), Art. 77 – GDPR).
9. RETENTION PERIOD
Without prejudice to the principle of data minimisation, data subjects’ data will be retained for a period no longer than necessary to achieve the purposes for which they were collected and processed, in accordance with applicable legal obligations.