Data Protection Policy
DESIGN PRODUCT SEEDL BARCELONA, S.L.U. (the "Company") is an organization in which personal data processing activities take place, which entails significant responsibility in the design and organization of procedures so that they are aligned with legal compliance in this area.
In the exercise of these responsibilities and with the aim of establishing the general principles governing the processing of personal data within the Company, this Personal Data Protection Policy is approved, communicated to its Employees and made available to all its Stakeholders.
1. PURPOSE
The Personal Data Protection Policy is a proactive accountability measure aimed at ensuring compliance with applicable legislation in this field and, in relation thereto, respect for the right to honor and privacy in the processing of personal data of all individuals who interact with the Company.
In implementation of this Policy, the principles governing data processing within the organization are established, as well as the procedures and organizational and security measures that the persons subject to this Policy undertake to implement within their scope of responsibility.
For this purpose, Management will assign responsibilities to personnel involved in data processing operations.
2. SCOPE
This Personal Data Protection Policy applies to the Company, its directors, executives, and employees, as well as to all individuals who interact with it, including explicitly service providers with access to data.
3. PRINCIPLES OF PERSONAL DATA PROCESSING
As a general principle, the Company will strictly comply with personal data protection legislation and must be able to demonstrate such compliance, paying particular attention to processing activities that may pose a higher risk to the rights of data subjects.
In this regard, DESIGN PRODUCT SEEDL BARCELONA, S.L.U. will ensure compliance with the following principles:
– Lawfulness, fairness, transparency, and purpose limitation. Data processing must always be communicated to the data subject through clauses and other procedures; it will only be considered legitimate if consent has been obtained (with special attention to minors), or if another valid legal basis exists, and if the purpose complies with applicable regulations.
– Data minimization. Data processed must be adequate, relevant, and limited to what is necessary in relation to the purposes of processing.
– Accuracy. Data must be accurate and, where necessary, kept up to date. Measures shall be taken to ensure that inaccurate personal data are erased or rectified without delay.
– Storage limitation. Data shall be kept in a form that permits identification of data subjects for no longer than necessary for the purposes of processing.
– Integrity and confidentiality. Data shall be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, through appropriate technical or organizational measures.
– Data transfers. The purchase or acquisition of personal data from illegitimate sources is prohibited, as well as any use of data collected or transferred in breach of the law or without sufficient guarantees of lawful origin.
– Engagement of data-access providers. Providers will only be selected if they offer sufficient guarantees to implement appropriate technical and security measures. A corresponding agreement shall be duly formalized with such third parties.
– International data transfers. Any processing subject to EU regulations that involves transferring data outside the European Economic Area must strictly comply with applicable legal requirements.
– Rights of data subjects. The Company will facilitate the exercise of rights of access, rectification, erasure, restriction of processing, objection, and data portability, establishing appropriate internal procedures and templates that meet applicable legal requirements.
The Company will promote the integration of these principles into the design and implementation of all work procedures, products and services, contractual obligations, and any systems or platforms enabling access to or processing of personal data by employees or third parties.
4. EMPLOYEE COMMITMENT
Employees are informed of this Policy and acknowledge that personal data is an asset of the Company. They undertake to:
– Complete the data protection awareness training provided by the Company.
– Apply user-level security measures relevant to their role, without prejudice to any additional responsibilities assigned based on their position within DESIGN PRODUCT SEEDL BARCELONA, S.L.U.
– Use the established formats for the exercise of data subject rights and promptly inform the Company to ensure timely response.
– Inform the Company, as soon as they become aware, of any deviations from this Policy, particularly personal data breaches, using the designated reporting format.
5. CONTROL AND EVALUATION
An annual verification, evaluation, and assessment will be carried out, or whenever significant changes occur in data processing, to ensure the effectiveness of technical and organizational measures for safeguarding data processing.