English   |   Català   |   Español   |   Français   |   Portuguès
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO COLEGIO OFICIAL DE ENFERMERÍA DE ZAMORA / Lant Abogados (Lant Advisors, S.L.P.)
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO COLEGIO OFICIAL DE ENFERMERÍA DE ZAMORA / Lant Abogados (Lant Advisors, S.L.P.)
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO COLEGIO OFICIAL DE ENFERMERÍA DE ZAMORA / Lant Abogados (Lant Advisors, S.L.P.)
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO COLEGIO OFICIAL DE ENFERMERÍA DE ZAMORA / Lant Abogados (Lant Advisors, S.L.P.)
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity Ethics line
2 - Responsible for the treatment / DPO COLEGIO OFICIAL DE ENFERMERÍA DE ZAMORA / Lant Abogados (Lant Advisors, S.L.P.)
3- Purpose of the processing

Manage employee complaints; Application of preventive and corrective measures; Report to the competent authorities of events in the case of a crime.

4- Legal grounds for the processing Art. 31 b) point 5.4 of the Criminal Code: Companies shall impose an obligation to report possible risks and legal breaches. Art. 48.1 of Organic Law 3/2007 on equality: Companies must implement specific procedures to channel complaints or claims brought by those who have suffered harassment.
5- Categories of data subjects Employees using the ethics line; Persons possibly reported
6- Origin of the data The data subjects themselves
Categories of personal data

Identification and contact data; judicial; employment details. 

7 - Identification data

Identification and contact details. Name, surnames and email. Judicial: judicial record, penalties and judicial procedures. Employment details: job position.

8 - Processing system Mixed (IT systems and hardcopy documents).
9- Data transfers

Labour Authority; Administration of Justice; Security Forces; Others as legally provided.

International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes The data will be stored until termination of the employment relationship and subsequently for the legal periods provided.
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO COLEGIO OFICIAL DE ENFERMERÍA DE ZAMORA / Lant Abogados (Lant Advisors, S.L.P.)
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO COLEGIO OFICIAL DE ENFERMERÍA DE ZAMORA / Lant Abogados (Lant Advisors, S.L.P.)
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity Video-surveillance management
2 - Responsible for the treatment / DPO COLEGIO OFICIAL DE ENFERMERÍA DE ZAMORA / Lant Abogados (Lant Advisors, S.L.P.)
3- Purpose of the processing

Security management of the facilities and persons using video-surveillance systems

4- Legal grounds for the processing GDPR: 6.1. e) and 6.1 f): Legitimate, public interest in protecting the safety of persons and facilities.
5- Categories of data subjects Persons entering the facilities
6- Origin of the data Security system (cameras and/or alarms that capture images)
Categories of personal data

Identification and contact details.

7 - Identification data

Identification and contact data: image (photographs or videos) of persons entering the facilities or registration plates.

8 - Processing system Automated
9- Data transfers

State Security Forces

International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes One month as from personal data collection
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity Supplier management
2 - Responsible for the treatment / DPO COLEGIO OFICIAL DE ENFERMERÍA DE ZAMORA / Lant Abogados (Lant Advisors, S.L.P.)
3- Purpose of the processing

Tax, accounting and administrative management of suppliers 

4- Legal grounds for the processing Provision of the service: GDP 6.1. b) execution of contract
5- Categories of data subjects Suppliers, contact persons and/or legal representatives.
6- Origin of the data The data subjects themselves or their legal representative.
Categories of personal data

Identification and contact data; economic-financial and insurance.

7 - Identification data

Identification and contact details: Name, surnames, identification documents (DNI, NIE or passport), address, telephone no., email. Name, surnames, telephone no. of contact persons. Name, surnames and signature of legal representatives

Economic-financial and insurance: Bank data.

8 - Processing system Mixed (IT systems and hardcopy documents).
9- Data transfers

Organisations or persons directly related to the controller. Competente Public Administrations.. Tax administration. Banking entities. Such cases as legally provided.

International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes Data will be stored for the duration of the relation and, upon termination, will be stored for the legally required periods to address potential liabilities.
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.