Data protection policy

IDENTIFICATION OF THE DATA CONTROLLER

a)Name and contact details of the data controller:

  • Company name / Name and surname: CLINICA DE LA MEMORIA, SL
    – CIF/NIF:
    – Activity: Memory clinic
    – Contact telephone number:
    – Contact email address: info@clinicadelamemoria.es
    – Website (URL): www.clinicadelamemoria.es
  • b)Name and contact details of the joint data controller:
  • There is no joint data controller
    c)Name and contact details of the controller's representative:
  • The controller's representative is established within the territory of the European Union

d)Name and contact details of the data protection officer:

– The entity responsible for the data processing has not appointed a data protection officer

I. PURPOSE OF THE DOCUMENT.
In its 2015-2019 Strategic Plan, the Spanish Data Protection Agency expressed its desire for data controllers to achieve a high level of compliance with the obligations imposed by data protection regulations, promoting a data protection culture that brings about a clear improvement in competitiveness, compatible with economic development.

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016) (hereinafter, GDPR), provides a modernized and accountability-based framework for data protection in Europe.

In this sense, Article 5, paragraph 2, of Regulation (EU) 2016/679 explicitly establishes the principle of "proactive responsibility" (accountability), according to which the data controller shall be responsible for, and be able to demonstrate compliance with, the following principles relating to processing:

  • Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject ('lawfulness, fairness and transparency');
  • Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes ('purpose limitation');
  • Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ('data minimisation');
  • Personal data shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay ('accuracy');
  • Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject ('storage limitation');
  • Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures ('integrity and confidentiality').

In short, the principle of "proactive responsibility" (accountability) requires a conscious, diligent, and proactive attitude on the part of organizations regarding all personal data processing activities they carry out.

In this sense, the Management / Governing Body of CLINICA DE LA MEMORIA, SL advocates for a proactive compliance policy, aiming to ensure that the fundamental right to data protection is actively respected in the pursuit of its purposes.

Consequently, this document is drawn up with the purpose of establishing the Policy of CLINICA DE LA MEMORIA, SL in relation to compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016), as well as with Spanish personal data protection regulations (Organic Law, its implementing regulations, and specific sectorial legislation).

II. COMMITMENT OF THE MANAGEMENT / GOVERNING BODY TO DATA PROTECTION.
The Management / Governing Body of CLINICA DE LA MEMORIA, SL (hereinafter, the data controller), assumes maximum responsibility and commitment to the establishment, implementation, and maintenance of this Data Protection Policy, guaranteeing the continuous improvement of the data controller with the objective of achieving excellence in relation to compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016), and with Spanish personal data protection regulations (Organic Law, specific sectorial legislation, and its implementing regulations).

The Data Protection Policy of CLINICA DE LA MEMORIA, SL is based on the principle of proactive responsibility (accountability), according to which the data controller is responsible for compliance with the regulatory and jurisprudential framework governing said Policy, and is capable of demonstrating it before the competent supervisory authorities.

In this sense, the data controller shall be governed by the following principles, which must serve all its personnel as a guide and framework of reference in the processing of personal data:

1.Data protection by design: the data controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing.

2.Data protection by default: the data controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed.

3.Data protection in the information life cycle: the measures guaranteeing the protection of personal data shall be applicable throughout the complete life cycle of the information.

4.Lawfulness, fairness and transparency: personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject.

5.Purpose limitation: personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.

6.Data minimisation: personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.

7.Accuracy: personal data shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.

8.Storage limitation: personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.

9.Integrity and confidentiality: personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

10.Information and training: one of the key elements to guarantee the protection of personal data is the training and information provided to the personnel involved in its processing. Throughout the information life cycle, all personnel with access to data shall be properly trained and informed about their obligations regarding compliance with data protection regulations.

The Data Protection Policy of CLINICA DE LA MEMORIA, SL is communicated to all personnel of the data controller and made available to all interested parties.

En su consecuencia, la presente Política de Protección de Datos involucra a todo el personal del responsable del tratamiento, que debe conocerla y asumirla, considerándola como propia, siendo cada miembro responsable de aplicarla y de verificar las normas de protección de datos aplicables a su actividad, así como identificar y aportar las oportunidades de mejora que considere oportunas con el objetivo de alcanzar la excelencia en relación con su cumplimiento.

This Policy shall be reviewed by the Management / Governing Body of CLINICA DE LA MEMORIA, SL (corrected from CLINICA DE LA MEMPOERIA, SL) as many times as deemed necessary, in order to adapt, at all times, to the current provisions regarding personal data protection.

In …………………………………………, on the …… day of......

Signed: Mr./Ms. .....................................
Management / Governing Body of CLINICA DE LA MEMORIA

III. NEED TO APPOINT A DATA PROTECTION OFFICER.
The need to appoint a Data Protection Officer has NOT been identified.
This is due to the fact that none of the following conditions are met:
The processing is carried out by a public authority or body.

  • The core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale.
  • The core activities of the controller or the processor consist of processing on a large scale of special categories of personal data:
    o Personal data revealing racial or ethnic origin.
    o Personal data revealing political opinions.
    o Personal data revealing religious or philosophical beliefs.
    o Personal data revealing trade union membership.
    o Genetic data.
    o Biometric data for the purpose of uniquely identifying a natural person.
    o Data concerning health (physical or mental).
    o Data concerning a natural person's sex life or sexual orientation.
  • The core activities of the controller or the processor consist of processing on a large scale of data relating to criminal convictions and offenses, as well as to related procedures, precautionary measures, and security measures.
  • The controller is a professional association (Colegio profesional) or a General Council (Consejo General), regulated by Law 2/1974 of February 13 on professional associations.
  • The controller is an educational institution providing education regulated by Organic Law 2/2006 of May 3 on Education, or a public or private University.
  • The controller is an entity that operates networks or provides electronic communications services in accordance with the provisions of General Telecommunications Law 9/2014 of May 9, and regularly and systematically processes personal data on a large scale.
  • The controller is an information society service provider that carries out large-scale profiling of the users of the service.
  • The controller is an entity included in Article 1 of Law 10/2014 of June 26 on the organization, supervision, and solvency of credit institutions.
  • The controller is a financial credit institution regulated by Title II of Law 5/2015 of April 27 on the promotion of business financing.
  • The controller is an insurance or reinsurance undertaking subject to Law 20/2015 of July 14 on the organization, supervision, and solvency of insurance and reinsurance undertakings.
  • The controller is an investment services firm regulated by Title V of the recast text of the Securities Market Law, approved by Royal Legislative Decree 4/2015 of October 23.
  • The controller is an electricity distributor or supplier, in accordance with the provisions of Law 24/2013 of December 26 on the Electricity Sector.
  • The controller is a natural gas distributor or supplier, in accordance with Law 34/1998 of October 7 on the Hydrocarbons Sector.
  • The controller is an entity responsible for a common file used for the assessment of financial solvency and creditworthiness.
  • The controller is an entity responsible for a common file used for fraud management and prevention.
  • The controller is an entity that carries out advertising and commercial prospecting activities, and performs processing based on the preferences of the data subjects or conducts activities that involve their profiling.
  • The controller is a healthcare center legally required to maintain patients' medical records in accordance with the provisions of Law 41/2002 of November 14, which regulates patient autonomy and rights and obligations regarding clinical information and documentation.
  • The controller is an entity that has as one of its objectives the issuance of commercial reports that may refer to natural persons.
  • The controller is an operator that carries out gambling activities through electronic, computer, telematic, and interactive channels, in accordance with the provisions of Law 13/2011 of May 27 on Gambling Regulation.
  • The controller carries out any of the activities regulated by Title II of Law 5/2014 of April 4 on Private Security.

Concept of "regular and systematic monitoring"
The notion of regular and systematic monitoring of data subjects is not defined in the GDPR, but the concept of "monitoring of the behavior of data subjects" is mentioned in Recital 24 and clearly includes all forms of tracking and profiling on the internet, including for behavioral advertising purposes:

To determine whether a processing activity can be considered to monitor the behavior of data subjects, it should be established whether natural persons are tracked on the internet, including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning her or him or for analyzing or predicting her or his personal preferences, behaviors, and attitudes.

However, the concept of monitoring is not confined to the online environment and online tracking should only be considered as an example of monitoring the behavior of data subjects.

The Article 29 Working Party interprets "regular" as having one or more of the following meanings:
– Ongoing or occurring at particular intervals for a particular period;
– Recurring or repeated at fixed times;
– Constantly or periodically taking place.

The Working Party interprets "systematic" as having one or more of the following meanings:
– Occurring according to a system;
– Pre-arranged, organized or methodical;
– Taking place as part of a general plan for data collection;
– Carried out as part of a strategy.

Examples of activities that may constitute regular and systematic monitoring of data subjects include:
– Operating a telecommunications network;
– Providing telecommunications services;
– Email retargeting;
– Data-driven marketing activities;
– Profiling and scoring for purposes of risk assessment (e.g. for purposes of credit scoring, establishment of insurance premiums, fraud prevention, detection of money laundering);
– Location tracking, for example, by mobile apps;
– Loyalty programs;
– Behavioral advertising;
– Monitoring of wellness, fitness and health data via wearable devices;
– Closed-circuit television;
– Connected devices, such as smart meters, smart cars, home automation, etc.

Concept of “large scale”
The Article 29 Working Party recommends that the following factors be considered when determining whether processing is carried out on a large scale:
– The number of interested parties affected, either as a specific figure or as a proportion of the corresponding population;
– The volume of data or the variety of data elements that are being processed;
– The duration, or permanence, of the data processing activity;
– The geographical scope of the treatment activity.

Examples of large-scale treatment include:
– The processing of patient data in the normal course of a hospital's activity;
– The processing of movement data of people using a city's public transport system (e.g. tracking via transport cards);
– The processing of real-time geolocation data of customers of an international fast food chain for statistical purposes by a data controller specializing in the provision of these services;
– The processing of customer data in the normal course of business of an insurance company or a bank;
– The processing of personal data for behavioral advertising by a search engine;
– The processing of data (content, traffic, location) by telephone or internet service providers.

Examples of cases that do not constitute large-scale treatment include:
-The processing of patient data by a single doctor;
– The processing of personal data relating to criminal convictions and offences by a lawyer.

IV. NEED TO CONDUCT AN IMPACT ASSESSMENT.

There is NO detected need to conduct an impact assessment.

This is due to the fact that none of the following conditions are met:
The controller carries out a systematic and comprehensive evaluation of personal aspects of natural persons based on automated processing, such as profiling, and on the basis of which decisions are made that produce legal effects for natural persons or similarly significantly affect them.

  • The data controller carries out large-scale processing of special categories of personal data:
    Personal data that reveals ethnic or racial origin.
    Personal data revealing political opinions.
    o Personal data that reveals religious or philosophical beliefs.
    o Personal data that reveals union affiliation.
    o Genetic data.
    o Biometric data intended to uniquely identify natural persons.
    o Data relating to health (physical or mental).
    o Data relating to the sex life or sexual orientation of natural persons.
    o Data relating to criminal convictions and offenses, as well as related precautionary and security proceedings and measures.

The person in charge carries out a large-scale systematic observation of a publicly accessible area.

Concept of “systematic”
The Working Party interprets "systematic" as having one or more of the following meanings:
– Occurring according to a system;
– Pre-arranged, organized or methodical;
– Taking place as part of a general plan for data collection;
– Carried out as part of a strategy.

V. RISK ASSESSMENT.
Risk determination

The main novelty introduced by Regulation (EU) 2016/679 is the evolution from a model based fundamentally on compliance control to another resting on the principle of accountability (active responsibility). This requires a prior risk assessment by the data controller regarding the risks that the processing of personal data could generate, in order to adopt the appropriate measures based on that assessment.

Therefore, the data controller is obliged to implement timely and effective measures and must be able to demonstrate the compliance of the processing activities with the aforementioned Regulation, the Organic Law, its implementing regulations, and specific sectoral legislation, including the effectiveness of those measures. These measures must take into account the nature, scope, context, and purposes of the processing, as well as the risk to the rights and freedoms of natural persons.

Accordingly, the data controller shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. When assessing the adequacy of the level of security, particular consideration shall be given to the risks presented by the processing of data, in particular as a result of the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

In this regard, the risks to the rights and freedoms of natural persons, of varying likelihood and severity, may result from data processing which could lead to physical, material or non-material damage, in particular in the following cases:

-In cases where the treatment may give rise to problems of discrimination, identity theft or fraud, financial losses, damage to reputation, loss of confidentiality of data subject to professional secrecy, unauthorized reversal of pseudonymization or any other significant economic or social harm;

-In cases where data subjects are deprived of their rights and freedoms or prevented from exercising control over their personal data;

-In cases where the personal data processed reveals ethnic or racial origin, political opinions, religion or philosophical beliefs, trade union membership and the processing of genetic data, data relating to health or data concerning sex life, or criminal convictions and offenses or related security measures;

-In cases where personal aspects are evaluated, in particular the analysis or prediction of aspects related to work performance, economic situation, health, personal preferences or interests, reliability or behavior, situation or movements, in order to create or use personal profiles;

– Where personal data of vulnerable natural persons, in particular children, are processed;

-In cases where the processing involves a large amount of personal data and affects a large number of interested parties.

Determining the risk of treatment operations

The likelihood and severity of the risk to the rights and freedoms of the data subject should be determined by reference to the nature, scope, context and purposes of the data processing. Thus, the risk should be weighed on the basis of an objective assessment through which it is determined whether the data processing operations pose a low risk, risk (standard risk) or a high risk.

For the purposes of this data protection policy, processing operations shall be considered to pose a high risk to the rights and freedoms of natural persons in the following cases:

1. Where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic, moral or social disadvantage for the affected individuals.

2. Where the processing may deprive the affected individuals of their rights and freedoms or may prevent them from exercising control over their personal data.

3. Where the processing of the following categories of data is not merely incidental or ancillary:

-Personal data that reveals ethnic or racial origin.
-Personal data that reveals political opinions.
-Personal data that reveals religious or philosophical convictions.
-Personal data that reveals union affiliation.
-Genetic data.
– Biometric data for the purpose of uniquely identifying a natural person.
-Data relating to health.
-Data relating to the sexual life or sexual orientation of a natural person.
-Personal data relating to criminal convictions and offenses, as well as related precautionary and security proceedings and measures.

4. Where the processing would involve an evaluation of personal aspects of the affected individuals in order to create or use personal profiles of them, in particular by analysing or predicting aspects concerning their performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, financial solvency, location or movements.

5. When processing data of groups of affected persons in situations of special vulnerability and, in particular, minors and persons with disabilities.

6. When there is a mass processing that affects a large number of affected people or involves the collection of a large amount of personal data.

7.Cuando los datos de carácter personal fuesen a ser objeto de transferencia, con carácter habitual, a terceros Estados u organizaciones internacionales respecto de los que no se hubiese declarado un nivel adecuado de protección. En tal sentido, se considera que tienen un nivel adecuado de protección los siguientes Estados:

The States of the European Economic Area (EEA):

-States of the European Union.
-Iceland.
-Liechtenstein.
-Norway.

  • Switzerland. Commission Decision 2000/518/EC of 26 July 2000.
  • Canada. Commission Decision 2002/2/EC of 20 December 2001 concerning entities subject to the scope of the Canadian data protection law.
  • Argentina. Commission Decision 2003/490/EC of 30 June 2003.
  • Guernsey. Commission Decision 2003/821/EC of 21 November 2003.
  • Isle of Man. Commission Decision 2004/411/EC of 28 April 2004.
  • Jersey. Decisión 2008/393/CE de la Comisión, de 8 de mayo 2008.
  • Faroe Islands. Commission Decision 2010/146/EU of 5 March 2010.
  • Andorra. Decisión 2010/625/UE de la Comisión, de 19 de octubre de 2010.
  • Israel. Commission Decision 2011/61/EU of 31 January 2011.
  • Uruguay. Commission Decision 2012/484/EU of 21 August 2012.
  • New Zealand. Commission Decision 2013/65/EU of 19 December 2012.

Estados Unidos. Aplicable a las entidades certificadas en el marco del Escudo de Privacidad UE-EE.UU. Decisión (UE) 2016/1250 de la Comisión, de 12 de julio de 2016. En la página web del Escudo de privacidad se accede a la relación de las entidades certificadas: https://www.privacyshield.gov/list.

8. Other risk assumptions based on the activity of the data controller.

VI. REGISTRO DE ACCIONES INFORMATIVAS Y FORMATIVAS.
The Data Protection Policy of CLINICA DE LA MEMORIA, SL is based on the principle of proactive responsibility (accountability), according to which the data controller is responsible for compliance with the regulatory and jurisprudential framework governing said Policy, and is capable of demonstrating it before the competent supervisory authorities.

In this regard, the data controller is governed, among others, by the principle of information and training, according to which one of the keys to guaranteeing the protection of personal data is the training and information provided to the staff involved in the processing of the same, educating employees in the so-called culture of data protection.

En su consecuencia, todo el personal de la entidad con acceso a los datos será convenientemente formado e informado acerca de sus obligaciones en relación con el cumplimiento de la normativa de protección de datos, recibiendo el apropiado conocimiento, capacitación y actualizaciones regulares de la Política de Protección de Datos de CLINICA DE LA MEMORIA SL.

Regarding the methodology of the information and training activities, it is recommended to combine different methodologies for better knowledge assimilation by the participants, citing the following as examples:

  • Content presentation or lecture: The teacher explains the content theoretically with the help of resources such as PowerPoint presentations.
  • Simulations or case studies: The teacher proposes situations for the participants to solve, which allow them to better assimilate the knowledge acquired.
  • Group dynamics: In order to activate interaction between the participants and the teacher.

Regarding teaching staff, it is recommended to use data protection and privacy professionals with prior teaching experience. This role may fall to the data protection officer of the entity responsible for processing, if one has been appointed. Furthermore, at the end of the training, it is advisable to administer knowledge assessment tests to the participants.

For the purpose of internal control management of compliance with the principle of information and training within the entity, a "Record of training and information actions" has been prepared for staff on data protection matters.

RECORD OF INFORMATION AND TRAINING ACTIVITIES
REF. INFORMATIVE AND/OR TRAINING ACTION No. 1
Identification of the information and/or training action
Name of the action  
Name of the teaching entity  
Contact details of the training provider   
Characterization of the informative and/or training action
Training modality In-person training
 E-learning / Distance training
Objectives of the training action / Training objectives   
Profile of the participants   
Duration of the training activity  
Brief description of the program and contents of the training activity       
Methodology of the training action   
Teaching staff / Teaching personnel   
Teaching resources used in training    
Training evaluation   
RECORD OF INFORMATION AND TRAINING ACTIVITIES
REF. INFORMATION AND/OR TRAINING ACTION No. 2
Identification of the information and/or training action
Name of the action  
Name of the teaching entity  
Contact details of the training provider   
Characterization of the informative and/or training action
Training modality In-person training
 E-learning / Distance training
Objectives of the training action / Training objectives   
Profile of the participants   
Duration of the training activity  
Brief description of the program and contents of the training activity       
Methodology of the training action   
Teaching staff / Teaching personnel   
Teaching resources used in training    
Training evaluation