Personal Data Protection

Personal Data Protection

This document describes Fundació Esade’s data protection policy. The latter is based on the principles detailed in Regulation (EU) 2016/679 of the European Parliament and Council of 27th April, 2016 (General Data Protection Regulation). We fully assume the spirit of this European Regulation because it reinforces the rights of individuals and offers additional guarantees regarding the processing of their data. This objective coincides completely with our aim to continuously improve the services we provide. Below is a summary of the fundamental elements included in this data protection policy:

How do we obtain personal data?

In the previous section we refer to some of the origins of the data we process. In most cases, the affected parties expressly provide us with their data, and we obtain them primarily through forms designed for this purpose. We also obtain data through open-door events, information sessions given on our campuses and fairs in which we inform about our programmes.

In terms of our relation with students, faculty and service providers, we gather other data which we incorporate into Esade systems.

A smaller amount of data may also originate from the competent public administrations in the higher-education area or from other academic institutions.

6. How long do we store data?

The time we store data depends on different factors. The primary criterion is if the data are still necessary to fulfil the purposes for which they were originally gathered. The second criterion is to duly respond to any legal responsibility regarding Esade’s data processing and to comply with any legal requirements from public administrations and judicial bodies.

Consequently, we have to store data the time necessary to preserve their legal or informational value and to accredit our fulfilment of legal obligations. However, this time shall not exceed the time required for the purposes for which they are processed (“storage period” limitation in the General Data Protection Regulation). With respect to data accrediting the educational programmes students complete, we store said data permanently to preserve these students’ rights.

In specific cases, such as data included in accounting records and billing documents, fiscal norms require we store them until no longer legally required. The norms governing foundations require that we store some accounting-related data for ten years (in keeping with Law 10/2010, dated 28th April).

In the case of data processed solely based on the affected parties’ consent, we store said data until the affected parties revoke their consent.

Lastly, in the case of images obtained through our video-surveillance cameras, we store said images a maximum of one month. However, in case of incidents requiring they be stored longer, we shall preserve them the time necessary to facilitate the work of safety and security forces and judicial bodies.

The norms regulating the storage of public documents and the decisions issued by qualifying committees are a reference when deciding to store or eliminate data linked to providing public interest services.

7. What rights do people have in terms of the personal data we process?

As stipulated in the General Data Protection Regulation, people whose data we process have the following rights:

8. How can the affected parties exercise and defend their rights?

The affected parties can exercise the above-mentioned rights fast and easily through the following application form ARCO rights or writing to Esade at the address above or using any of the other means to contact us as indicated.

If the affected parties are not satisfied with this exercise of their rights, they may file a complaint with the Catalan Data Protection Authority by means of the forms or other channels available via its website (https://apdcat.gencat.cat/).

In all cases, whether to present complaints, clarify doubts or make suggestions, the affected parties may send an e-mail to the Data Protection Delegate via the following address: dpo@esade.edu

Specific data protection policies