II. Introduction

The protection of natural persons with regard to the processing of their personal data is a fundamental right enshrined in Article 8(1) of the Charter of Fundamental Rights of the European Union and Article 16(1) of the Treaty on the Functioning of the European Union, as incorporated into Article 18(4) of the Spanish Constitution.

TEAM4 COLLECTION AND CONSULTING, S.L.U. (hereinafter “TEAM4”), as part of its commitment to regulatory compliance, adopts this Data Protection Policy, which sets out the rules and principles of conduct intended to guide TEAM4’s staff in relation to the protection of personal data in accordance with current legislation.

II. Purpose

The purpose of this Policy is to inform TEAM4 staff of the applicable data protection legislation and, in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, the GDPR).

The rules of conduct set out in this Policy shall apply in the context of the work carried out by TEAM4’s employees and professionals, and shall aim to protect the personal data of both TEAM4’s own employees and all third parties (suppliers, customers, professionals, etc.) who have dealings with TEAM4.

The rules set out in this Policy are mandatory guidelines for all TEAM4 employees and professionals, who must also use their best endeavours to ensure that they are complied with, including TEAM4 subcontractors involved in activities that involve the processing of personal data.

III Scope of application

This Policy applies to the fully or partially automated or non-automated processing of personal data in the context of the activities carried out by TEAM4.

Furthermore, this Policy applies to all TEAM4 employees and professionals, regardless of their position within the organisation, their professional qualifications or the nature of their relationship with TEAM4.

IV. Data Protection and Information Security Roles

At TEAM4, the following roles have been appointed in the areas of Data Protection and Information Security:

Data Protection Officer (DPO, LISO)

Contact: dpd@team4collection.com

It is also a means of submitting any requests relating to data protection rights.

Head of IT Security (RSI, LCM)

Contact: ciberseguridad@team4collection.com

It also serves as a means of reporting any security incidents.

VPrinciples

Chapter II of the GDPR sets out the principles governing data protection and which, therefore, form the basis of this Policy:

Legality, integrity and transparency

TEAM4 will process personal data lawfully, fairly and transparently, informing the data subject about the processing of their data and the specific purposes thereof.

Purpose limitation

Personal data processed by TEAM4 will always be collected for specific, explicit and legitimate purposes, and will not be further processed in a manner incompatible with those purposes.

Data minimisation

TEAM4 will process only those personal data that are strictly necessary for the purpose for which they were collected.

Accuracy

TEAM4 will ensure that the personal data it processes is accurate and up to date, taking reasonable steps to ensure that it is erased or rectified where it is inaccurate.

Limitation on the retention period

TEAM4 will not retain the personal data it processes for longer than is necessary for the purposes for which it was collected, unless required to do so by law.

Integrity and confidentiality

TEAM4 will endeavour to ensure the integrity and confidentiality of the personal data processed, by implementing technical and organisational measures to protect it.

VI Proactive responsibility

TEAM4 is committed to complying with the principles listed above by exercising due diligence and must be able to demonstrate such compliance by adopting a ‘proactive approach to responsibility’, which entails:

Risk assessment or analysis

The data controller is obliged to implement appropriate and effective measures and must be able to demonstrate that processing activities comply with the applicable legislation. To this end, TEAM4 will carry out a risk assessment or analysis of the processing operations it undertakes.

Impact assessment

TEAM4 will carry out data protection impact assessments in the cases provided for in the applicable legislation, that is, where there is a likelihood that a particular processing operation will result in a high risk to the rights and freedoms of natural persons.

Record of processing activities

TEAM4 will maintain records of the processing activities for which it is responsible, whether acting as a data controller or as a data processor on behalf of its clients.

Security vulnerabilities

In the event of an incident arising in the processing of personal data for which TEAM4 is responsible, and which may result in physical, material or non-material harm or damage to individuals, the internal guidelines and procedures established by TEAM4 for the management of so-called security breaches will be followed.

Data Protection Officer

TEAM4 has appointed a Data Protection Officer (DPO), who will be responsible for overseeing compliance with and the implementation of the Data Protection Management System and will report to the highest level of management.

Contact: dpd@team4collection.com or by post at C/ Julián Camarillo 6-A, 1st floor, 28037, Madrid.

VII Rights of data subjects

TEAM4 undertakes to assist the data subject in exercising their rights as recognised by the applicable legislation:

  • Right of access.
  • Right to rectification.
  • Right to erasure (right to be forgotten).
  • Right to restriction of processing.
  • Right to data portability.
  • The right to object and the right not to be subject to automated individual decisions.

To this end, the guidelines and rules set out in the internal procedures governing the exercise of data subjects’ rights will be followed.

VIII Data processors

TEAM4 has internal contracting procedures in place which regulate and set out the specific measures to be taken with regard to the procurement of services from suppliers who access data in their capacity as data processors, as well as with regard to those suppliers who, whilst not acting as data processors, may accidentally or incidentally access personal data for which TEAM4 is responsible.

The provision of these services will be governed by the relevant data processing agreements or by including ad hoc clauses in the main service contract.

IX International data transfers

At present, TEAM4 does not carry out any data processing that involves the international transfer of data to third countries which do not offer the same level of security as the Member States of the European Union or those recognised by the Commission as safe havens. Should this occur, TEAM4 will ensure that any processing involving the transfer of data outside the Union or to countries that do not have an adequate level of data protection is carried out in accordance with the requirements set out in the applicable legislation.

XImplementation: the Data Protection Management System

In accordance with the principles and standards set out in this Policy, TEAM4 will draw up the necessary internal procedures, or any other supporting internal documents, to enable compliance with applicable legislation, thereby establishing a Data Protection Management System. These procedures or supporting documents shall be binding on all TEAM4 staff.

The Data Protection Officer shall be responsible for monitoring compliance with and the implementation of the aforementioned Data Protection Management System, liaising at all times with the heads of subsidiaries or branch offices.

XIControl and assessment

The Data Protection Management System must be monitored and assessed on a regular basis. To this end, a regular audit will be carried out, under the direction and supervision of the Data Protection Officer, to assess compliance with the provisions of this Policy and with applicable legislation in general.

Furthermore, with regard to the Internal Audit, as part of its annual plan to review all TEAM4 systems, a specific section on data protection will be included in order to monitor compliance with the applicable regulations.

The results of the various audits and other checks will be reported to TEAM4’s governing body.

XII. Approval and publication of the Policy

This Policy was approved by the Management Committee of TEAM4 Collection and Consulting on 15 April 2018.

The Data Protection Policy will be made available as documented information and will be communicated to all data subjects and TEAM4 staff who are required to comply with and implement it.

·Revision table

Rev. Date Description of the amendment Produced Revised Approved
0114/03/2018Initial documentRegulatory ComplianceRegulatory Compliance—
0215/04/2018Political Approval Management CommitteeRegulatory ComplianceRegulatory ComplianceSteering Committee
0314/05/2019ReviewCNCNXX
0401/06/2020Review, logo, REMINDERCNCNXX
0501/06/2021Review without amendmentsCNCNXX
0607/01/2022DPD email addressCNCNXX
0725/04/2023Inclusion of PD roles and contact detailsCNCNXX
0819/12/2023Change logo to Team4, Document reviewCNCNXX