English   |   Català   |   Español   |   Français   |   Portuguès
Field Content
1 - Name of the activity Telephone call recording management (quality)
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing

Management of the recording of telephone calls for quality reasons.

4- Legal grounds for the processing RGPD 6.1. f): legitimate interest of the Controller.
5- Categories of data subjects Company telephone callers.
6- Origin of the data The interested party himself or his legal representative.
Categories of personal data

Identification and contact details.

7 - Identification data

Identification and contact details: voice (recording of the call).

8 - Processing system Automated.
9- Data transfers

Not expected unless legally provided.

International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes The voice recording shall be retained for 1 month from the time of capture, unless there is a longer legal period.
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing
4- Legal grounds for the processing
5- Categories of data subjects
6- Origin of the data
Categories of personal data
7 - Identification data
8 - Processing system
9- Data transfers
International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity Video-surveillance management
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing

Security management of the facilities and persons using video-surveillance systems

4- Legal grounds for the processing GDPR: 6.1. e) and 6.1 f): Legitimate, public interest in protecting the safety of persons and facilities.
5- Categories of data subjects Persons entering the facilities
6- Origin of the data Security system (cameras and/or alarms that capture images)
Categories of personal data

Identification and contact details.

7 - Identification data

Identification and contact data: image (photographs or videos) of persons entering the facilities or registration plates.

8 - Processing system Automated
9- Data transfers

State Security Forces

International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes One month as from personal data collection
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity RH management
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing
Employees (corporate structure): Management of the employment relationship and employee records; processing registrations and terminations with Social Security, payroll issuance and payment; assessment, monitoring and supervision of professional activities; access and attendance control and working time/schedule recording (including, where applicable, through geolocation-enabled applications or identification cards); promotion and provision of training activities, including subsidized training; occupational risk prevention; promotions, advancements and/or changes in professional category. Processing workplace accident reports (including a description of the accident and its consequences, which may involve access to and processing of health data). Maintenance of a historical record of permanent employees.
Outsourced workers (company employees assigned to client facilities): Management of the employment relationship and personnel records of company employees providing outsourced services at client company facilities; processing registrations and deregistrations with Social Security, payroll issuance and payment; assessment, monitoring and supervision of professional activities at the client's premises; access and attendance control and working time/schedule recording (including, where applicable, through geolocation-enabled applications or identification cards); occupational health and safety management and compliance with business activity coordination obligations with the client company (provision of health surveillance fitness certificates, occupational risk prevention training certificates, ID documents, social security contribution records, and any other required documentation); training activities, including subsidized training; promotions, advancements and/or changes in professional category; employee identification before the client company.
Interns: Management of the relationship with the intern and, where applicable, payment of compensation; occupational risk prevention; training activities; assessment, monitoring and supervision of internship performance; access and attendance controls and working time/schedule recording.
Equivalent self-employed professionals: Management of the commercial relationship with the professional; payment of compensation; assessment, monitoring and supervision of professional activities; access and attendance control; promotion and provision of training activities; occupational risk prevention.
Temporary workers (Temporary Employment Agencies): Management of the employment relationship with the worker; occupational risk prevention; training; assessment, monitoring and supervision of professional activities; access and attendance controls.
External workers: Control and identification of external workers operating at the facilities; collection of health surveillance fitness certificates, occupational risk prevention training certificates, identification documents, social security contribution records and other documentation required for compliance with social security, business coordination and occupational health and safety obligations; training; monitoring of activities performed; access and attendance controls.
Additional processing activities: Collection, use and publication of image and/or voice in photographs or videos for promotional purposes. Use and publication of personal data for social purposes. Use of private mobile phone numbers and/or email addresses for work-related communications, payroll delivery and/or corporate newsletters. Sending notifications and/or creating groups in messaging applications for relationship and communication management. Workplace monitoring through video surveillance cameras, which may be used to impose disciplinary sanctions for labour-related misconduct. Use of geolocation systems in company vehicles or devices to monitor compliance with obligations, optimise routes, ensure safety and manage claims. Subscription to group insurance policies. Deduction of union membership fees. Representation and defence of employees through employee representatives or Works Councils. Disclosure of data to group companies for employment and business coordination purposes.
Candidates: Participation in current and future recruitment processes; verification of provided references. Where applicable, conducting tests and assessments necessary to evaluate candidacies and develop employment profiles.
4- Legal grounds for the processing Employees (Corporate Structure): GDPR 6.1(b) Performance of the employment contract, GDPR 6.1(c) Compliance with a legal obligation (Workers' Statute and applicable Collective Bargaining Agreement), and GDPR 6.1(f) Legitimate interest in retaining the employee’s name, surname, job position, and dates as a historical employee record. Outsourced Workers: GDPR 6.1(b) Performance of the employment contract with the employee, GDPR 6.1(c) Compliance with a legal obligation (Workers' Statute, applicable Collective Bargaining Agreement, Occupational Risk Prevention Law, and Royal Decree 171/2004 on the coordination of business activities), and GDPR 6.1(f) Legitimate interest in retaining the employee’s name, surname, job position, and dates as a historical employee record. Internships: GDPR 6.1(b) Performance of the internship agreement. Equivalent Self-Employed Professionals: GDPR 6.1(b) Performance of a commercial contract. Temporary Agency Workers: GDPR 6.1(b) Performance of the temporary assignment agreement between the temporary employment agency and the user company, and GDPR 6.1(c) Compliance with a legal obligation (temporary employment agency regulations). External Workers: GDPR 6.1(b) Performance of a commercial contract with the employer. GDPR 6.1(c) Compliance with a legal obligation (Occupational Risk Prevention Law and Royal Decree regarding the coordination of business activities). Candidates: GDPR 6.1(a) Consent of the data subject. Additional Processing Activities: GDPR 6.1(a) Consent of the data subject and/or GDPR 6.1(b) Performance of a contract to which the data subject is a party or in order to take pre-contractual measures at the request of the data subject, and/or GDPR 6.1(c) Compliance with a legal obligation.
5- Categories of data subjects Employees (general employment scheme/corporate structure, outsourced workers, equivalent self-employed professionals, interns); temporary agency workers; external workers; candidates; former employees.
6- Origin of the data Corporate Structure/Outsourced Workers/Equivalent Self-Employed Professionals: the data subject themselves or their legal representative. Internships: the data subject themselves or their legal representative and/or the educational institution or training entity to which they belong. Temporary Agency Workers: temporary employment agencies. External Workers: external company responsible for the worker (employer). Candidates: the data subject themselves, employment portals, and recruitment agencies. Where applicable: parent company and/or entities belonging to the corporate group.
Categories of personal data

Identification and contact data; personal characteristics; social and family circumstances; personality-related; academic and professional; employment details; union; economic-financial and insurance; medical or health data; administrative; judicial; social; infrastructure; other special categories of data. 

7 - Identification data

Identification and contact details: Name, surnames; DNI/NIE or Passport, Social Security number, address, email, telephone no., signature, images and/or voice, IP address/MAC of devices. Personal characteristics: Date and place of birth, age, marital status, gender, nationality, mother tongue, physical or anthropometric characteristics. Social and family circumstances: Family situation, family responsibilities, licenses, permits, authorisations, hobbies and lifestyle. Personality: Assessment of profiles, behaviour and attitudes. Academic and professional: Education, qualifications, profession and professional experience, membership of professional associations, email, identification number, hierarchic data. Employment details: Job category, non-economic salary data, professional and employee record, experience in professional world. Unions: Union membership and/or membership of works council or trade groupings. Economic-financial and insurance: Bank, current account, income, rent, credit, loans, guarantees, pension and/or retirement plan, assets, economic salary data, tax/tax benefits, compensation, indemnity, insurance, mortgages, seizures, debts. Medical or health: occupational accidents, degree of disability or incapacity and/or degree of occupational disability and other health-related data. Administrative: administrative procedures, arbitration, claims, appeals, penalties. Judicial: judicial procedures, suits, penalties. Social: aid, subsidies, social welfare benefits, employment benefits and pensions. Infrastructure: video-surveillance images. 

8 - Processing system Mixed (IT systems and hardcopy documents).
9- Data transfers

Organizations or individuals directly related to the data controller. Client companies at whose facilities outsourced workers provide services, for the purposes of personnel identification, access control, and compliance with business activity coordination obligations (provision of fitness certificates, occupational risk prevention training certificates, and required employment documentation). General Treasury of Social Security, the Public Employment Service (SEPE), and other public authorities with jurisdiction in the matter. Banking and financial institutions. Tax authorities. Occupational accident insurance providers and occupational risk prevention companies. Training companies or entities and organizations managing training subsidies before the State Foundation for Employment. Insurance companies. Courts and tribunals. Legal representatives (court agents). Notaries. Law enforcement agencies. Works Council and/or employee representatives. Entities, clients, and/or suppliers before whom it is necessary to identify employees or users. Public and private entities for participation in projects, tenders, and grants. Other recipients provided for by law. Parent company and/or other entities belonging to the corporate group for business organization and human resources management purposes. In the case of candidates: to increase employment opportunities.

International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes Corporate Structure / Outsourced Workers / Equivalent Self-Employed Professionals / Internships: The data will be stored during the life of the relationship. Once terminated, the work data will be stored and blocked during the legally required periods to address potential liabilities; except for name and surnames, job positions and dates of hiring and departure which will be stored as a historic log of permanent workers based on the entity’s legitimate interest. Temporary workers: Data will be stored for the duration of the engagement with the temporary employment agency (ETT) and, upon termination, will be stored and blocked for the legally required periods to address potential liabilities or enter into a new contract. The company shall, based on a legitimate interest, store the name and surnames, job position, reason for termination and dates as a historic log of workers for an indefinite period based on the entity’s legitimate interest. External: Data will be stored for the duration of the commercial contract with the entity (employer) and, upon termination, will be stored and blocked for the legally required periods to address potential liabilities. Candidates: Throughout the personnel selection processes and upon termination, for 1 year for future processes. Business information: until unsubscription is requested. Images/voice: while published in the media described and are used for the purpose for which they were obtained, unless your consent is withdrawn.
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.
Field Content
1 - Name of the activity Supplier management
2 - Responsible for the treatment / DPO Col·legi Oficial de Psicologia de Catalunya -COPC- / Lant Advisors SLP
3- Purpose of the processing

Tax, accounting and administrative management of suppliers 

4- Legal grounds for the processing Provision of the service: GDP 6.1. b) execution of contract
5- Categories of data subjects Suppliers, contact persons and/or legal representatives.
6- Origin of the data The data subjects themselves or their legal representative.
Categories of personal data

Identification and contact data; economic-financial and insurance.

7 - Identification data

Identification and contact details: Name, surnames, identification documents (DNI, NIE or passport), address, telephone no., email. Name, surnames, telephone no. of contact persons. Name, surnames and signature of legal representatives

Economic-financial and insurance: Bank data.

8 - Processing system Mixed (IT systems and hardcopy documents).
9- Data transfers

Organisations or persons directly related to the controller. Competente Public Administrations.. Tax administration. Banking entities. Such cases as legally provided.

International Transfers
10- Country
11 – Category of recipients
12- Company
13- Legal grounds
14- Data erasure timeframes Data will be stored for the duration of the relation and, upon termination, will be stored for the legally required periods to address potential liabilities.
15- General description of the technical and organizational security measures
FUNCTIONS AND OBLIGATIONS Deliver to all users in accordance with their user profiles, their functions and obligations relating to the security measures to be complied with and the consequences of any breach.
IDENTIFICATION AND AUTHENTICATION Individual identification and authentication Procedure for assigning and distributing passwords Password complexity and changes.
ACCESS CONTROL Updated list of authorised users and access. Access control allowed in keeping with the functions assigned and systems to prevent non-authorised access. Granting of access permits only for authorised personnel. Physical access control to the premises where the information systems are located.
BACKUP COPIES Frequency of backups Procedures for generating backup copies and data recovery. Remote backup copies systems.
MEDIA MANAGEMENT Inventory management and identification of media. Media stored under lock and key Log of incoming and outgoing media. Media destruction measures.
INCIDENT LOG Log containing the type, time detected, person reporting, effects and corrective measures of the incident. Notification procedure and incident management Data recovery procedures
OTHER TECHNICAL MEASURES Use of antivirus and firewalls.
Screen savers.
Remote access control
Standards of use of email and the internet.
Use of peripherals (printers, photocopiers and multi-function devices).
NON-AUTOMATED PROCESSING Application of document filing criteria to facilitate consulting, locating and handling of Rights. Use of storage devices with locking systems (key, codes...). Custody of active documents to prevent non-authorised access.
DATA PROCESSORS List of data processors. Description of services rendered. Adoption of warranties by processors.