In accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – GDPR), users are hereby informed of the processing of their personal data.
Data Controller
Personal data collected through this website will be processed by the Spanish National Research Council (Consejo Superior de Investigaciones Científicas – CSIC), which acts as the data controller.
Purpose of Data Processing
Personal data will be processed and incorporated into the processing activity entitled “General Information Enquiries”, the purpose of which is to manage and respond to the enquiries submitted by users.
The processing of personal data is based on the performance of the public tasks and competences legally assigned to CSIC.
Data Recipients
Personal data may be communicated to other competent departments or services of Public Administrations, where such communication is necessary in order to properly address the user’s enquiry.
No international data transfers are foreseen.
Data Retention
Personal data will be retained for the period strictly necessary to fulfil the purpose for which they were collected and to comply with applicable legal obligations.
Data Protection Officer
In accordance with applicable data protection regulations, CSIC has appointed a Data Protection Officer (DPO) and has notified this appointment to the Spanish Data Protection Agency (AEPD).
The Data Protection Officer of CSIC is José López Calvo.
Data Subject Rights
Users may exercise their rights of access, rectification, erasure, objection, restriction of processing, as well as any other rights recognised under data protection legislation, by contacting the Data Protection Officer through the corresponding contact form provided for this purpose.
Record of Processing Activities
Applicable regulations require that the record of processing activities be made publicly available by electronic means.
Users may access the records corresponding to the central organisation of CSIC as well as those of the CSIC Institutes through the relevant official links.
Security Measures
CSIC has complied with all remaining obligations established under data protection legislation. These include, among others:
the implementation of internal procedures for the notification and management of personal data breaches;
the performance of risk analyses;
the adoption of appropriate technical and organisational security measures based on the identified risks; and
the conduct of Data Protection Impact Assessments (DPIAs) where necessary, particularly in relation to personal data processing carried out within the framework of certain research projects.