Iscriviti alla Newsletter
Scopri in anteprima le nuove collezioni e le offerte speciali.
This document of privacy policy, updated with the EU Regulation (GDPR) 2016/679 concerning the processing of personal data, as well as with the D.Lgs 181/18 which modifies the D.Lgs 196/2003, regulates the manner of data processing collected by a website during the navigation by the user.
It has the express purpose of inform the user about the processing of your personal data in accordance with the law and the recent EU Regulation 679/2016, which profoundly changed the discipline.
A website must have a Data Controller. The data controller is the person who has decision-making and organizational power on the processing, as well as deciding the methods of data processing and is the person responsible towards the privacy guarantor. Two or more joint owners can also be appointed. In this case, it is mandatory for the user to know what the competences of each co-owner are, through a link indicating the agreement between them.
The data controller is supported by Data Processor. This figure is the one who processes the data on behalf of the data controller. This means that it will be a subject close to the owner, from whom it receives directives on how to manage the data. The Data Processor must be a competent figure able to fully satisfy the security put in place by the Data Controller.
These two figures are flanked by the Data Protection Officer DPO, who, despite being appointed directly by the owner, is in any case an independent person from the latter. The DPO, previously only optional, is now a figure at times mandatory under Article 37 of Regulation (EU) 679/2016. This article indicates the obliged subjects and those who are exempt. In any case, the DPO, called RPD in Italian, is an independent subject and processes the data autonomously. Furthermore, it is directly responsible and communicates with the privacy guarantor. Ultimately, the designation of the DPO reflects the new approach of the GDPR, towards a responsibility for data processing, being aimed at facilitating the implementation of the regulation by the owner and manager. The role of the DPO is to protect personal data, not the interests of the data controller.
Therefore, while the Data Processor is a figure close to the Data Controller, the DPO is a much more independent figure, who cannot or must receive orders from the Data Controller on effective data protection.
Returning to the information, the place where the data will be processed, which coincides with the headquarters of the data controller.
It is essential to also insert the purpose of data processing. In fact, according to the new legislation, the data must be kept for a period suitable for achieving the purposes set by the site, and then be deleted. Therefore it is mandatory that the purposes are indicated in a clear and concise manner within the information.
The document must also indicate the types of cookies which are used on the web page. Cookies are short pieces of information that can be saved on the user's computer when the browser calls up a specific website. With them the server sends information that will be re-read and updated every time the user returns to the site.
There are various types of cookies:
The document must also indicate whether the site allows plug-in dei social network and any data transfer to companies located in extra-continental countries.
It is also important to mention what are the new rights of the data subject under the new European legislation, such as the right to deletion of data, l'update of the same or of oppose to a possible transfer of data.
How to use the document?
Through this document you can:
Once you have the document, it must be entered on the website's web page and made available to the user.
Reference legislation
REGULATION (EU) 2016/679 of the European Parliament and Council, of 27 April 2016, concerning the protection of individuals with regard to the processing of personal data, as well as the free circulation of such data and which repeals Directive 95/46 / EC (general regulation on data protection) .
Legislative Decree 181/18, on "Provisions for the adaptation of national legislation to the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of individuals with regard to the processing of personal data, as well as on free movement of such data and repealing Directive 95/46 / EC (General Data Protection Regulation) "which amends the Legislative Decree 196/2003, "Code regarding the protection of personal data."
Provision of the Privacy Guarantor n. 229/2014, relating to the "Identification of simplified procedures for the information and the acquisition of consent for the use of cookies."