Participants in events / training / webinars
GWW Grynhoff and Partners Radcowie Prawni i Doradcy Podatkowi spółka partnerska (‘GWW Legal’) and GWW Ladziński, Cmoch i Wspólnicy spółka komandytowa (‘GWWTax’) as Joint Administrators (controllers who jointly determine the purposes and means of data processing), in connection with organised or co-organised trainings, conferences, webinars or other similar events, process the personal data of persons interested/participating in these trainings, conferences, webinars or other similar events (‘Participants’).
In fulfilment of the obligations imposed by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016. on the protection of natural persons in relation to the processing of personal data and on the free movement of such data and the repeal of Directive 95/46/EC (‘RODO’), in relation to the processing of Participants’ personal data by the Joint Administrators, the Joint Administrators provide the following information on the principles of processing of their personal data by the Joint Administrators, including the purposes of the processing, the legal basis for the processing, the storage period, the recipients of the personal data, as well as the rights of persons whose personal data is processed by the Joint Administrators.
1. JOINT CONTROLLERS
The Joint Controllers of the Participants’ personal data are the companies:
- GWW Grynhoff i Partnerzy Radcowie Prawni i Doradcy Podatkowi sp. p. with its registered office in Warsaw at 4 Książęca Street (00-498 Warsaw), entered in the Register of Entrepreneurs of the National Court Register conducted by the District Court for the City of Warsaw in Warsaw, XII Economic Division of the National Court Register, under the KRS number 0000541501, NIP 7792022623, REGON 631226810, and
- GWW Ladziński, Cmoch i Wspólnicy sp. k. with registered office in Warsaw, 4 Książęca Street (00-498 Warsaw), entered into the register of entrepreneurs of the National Court Register kept by the District Court for the Capital City of Warsaw in Warsaw, XII Economic Division of the National Court Register, under KRS number 0000956566, NIP 7010313649, REGON 145496595.
2. CO-ADMINISTRATORS’ RESPONSIBILITIES
As part of the Co-Administration Agreement concluded between the Joint Administrators, the Joint Administrators have agreed on the scopes of their responsibility regarding the fulfilment of their obligations under the RODO, including in particular that:
- with regard to the fulfilment of the obligation to provide information to personal data subjects, in accordance with the provisions of Articles 12 to 14 of the RODO, the Joint Controller who collects personal data or initiates the collection of personal data is responsible;
- with regard to the exercise of the rights of the personal data subjects as set out in Articles 7(3) and 15-22 RODO, i.e. withdrawal of consent, exercise of the right of access to personal data, rectification, erasure, restriction of processing, portability of personal data, objection to the processing of personal data, the Joint Controller who received the request is responsible;
- with regard to the fulfilment by the Joint Controllers of their obligations concerning the management of personal data breaches, their notification to the supervisory authority (Art. 33 RODO) and to the personal data subject (Art. 34 RODO), the Joint Controller who first became aware of the breach shall be competent; in the event of simultaneous information about the breach, the Joint Controller on whose side the breach occurred shall be competent;
- if, on the basis of the above rules, it cannot be determined which Co-Administrator is responsible for fulfilling the obligations set out in these paragraphs, GWW Legal is responsible.
Notwithstanding the above arrangements, the data subject may exercise his or her rights under the RODO against any of the Joint Controllers.
3. CONTACT DETAILS
The Joint Controllers have designated a single point of contact for all requests and enquiries concerning the personal data they process:
- when contacted by post, by sending a letter to: Personal Data Coordinator: 4 Książęca Street,00-498, Warsaw, marked ‘Personal Data’,
- in the case of contact by e-mail, by sending an e-mail to: odo@gww.pl.
4. WHAT PERSONAL DATA ARE PROCESSED BY THE JOINT CONTROLLERS AND WHAT IS THE SOURCE OF THIS DATA
The Joint Administrators process Participants’ personal data that has been provided to them directly by the Participants or by the organisation employing or delegating the Participant – in particular the Participant’s name, position, specialisation, contact details, information about the organisation employing or delegating the Participant, other data necessary due to the purpose or nature of the training, conference, webinar or other similar event.
The provision of personal data is voluntary, however it is necessary in order to participate in a training course, conference, webinar or other similar event organised/co-organised by the Joint Administrators.
5. PURPOSE OF PERSONAL DATA PROCESSING AND LEGAL BASIS
The Joint Administrators process Participants’ personal data:
- in order to conclude and perform the contract between the Participant and the Co-Administrators concerning the participation in a training course, conference, webinar or other similar event organised/co-organised by the Co-Administrators (legal basis under Article 6(1)(b) of the RODO);
- for the purpose of sending an invitation to a training course, conference, webinar or other similar event organised/co-organised by the Joint Administrators (legal basis under Article 6(1)(f) RODO) in relation to an expressed interest in receiving information about training courses, conferences, webinars or other similar events;
- for purposes arising from the legitimate interests pursued by the Joint Administrators or third parties (legal basis of Art. 6(1)(f) RODO), which are: enrolling the Participant for the training, conference, webinar or other similar event and organising and conducting the training, conference, webinar or other similar event, the execution and settlement of agreements entered into by the Joint Administrators with organisations employing or delegating Participants for the training, conference, webinar or other similar event and entities cooperating with the Joint Administrators in connection with the organisation and conduct of the training, conference, webinar or other similar event, including suppliers of goods and services to the Joint Administrators (e.g. platforms and applications used to conduct the training/conference/webinar); establishing, investigating or defending against claims relating to the training, conference, webinar or other similar event; demonstrating the fulfilment of the Joint Administrators’ legal obligations; implementing internal procedures, including anti-fraud;
- for other purposes, on the basis of the consent separately granted by the Participants (legal basis under Article 6(1)(a) of the DPA).
6. RECIPIENTS OF PERSONAL DATA
The Joint Administrators will only share personal data with other entities (recipients of personal data) if they have a legal basis to do so. If the Joint Controllers transfer personal data to recipients located outside the European Union or the European Economic Area (EEA), this is only done if an adequate level of data protection has been confirmed for that third country by the European Commission or an adequate level of data protection has been agreed with the recipient (e.g. using so-called standard contractual clauses).
Personal data may be made available to public authorities or other entities entitled to such access by law.
Depending on the purpose for which the Joint Controllers process Participants’ personal data, recipients of their personal data may also be: entities providing ICT services to the Co-Administrators, entities providing IT/technical/service support services, suppliers of software used by the Co-Administrators (including platforms/applications used to conduct the training/conference/webinar), entities providing courier or postal services, entities providing consulting or marketing services, other entities cooperating with the Co-Administrators in connection with the organisation and conduct of the training, conference, webinar or other similar event.
The processing of personal data in ICT systems, may result in the transfer of such data to the servers of IT software and service providers, in connection with the Co-Administrators’ use of the services/software that the aforementioned providers provide. Some of these servers are located in the USA. Data transfer to the USA only takes place if the data recipient has joined the EU-US Data Protection Framework (i.e. the European Commission has confirmed an adequate level of data protection) or an adequate level of data protection has been agreed with the data recipient using so-called standard contractual clauses. A copy of the applicable safeguards including standard contractual clauses can be obtained from the Joint Controllers.
7. RETENTION PERIOD OF PERSONAL DATA
Participants’ personal data shall be processed until the purpose of the processing ceases to exist or the data subject raises an effective objection (whichever comes first).
Personal data processed on the basis of the Participant’s consent will be processed until the purpose of the processing ceases or the consent is withdrawn (whichever is earlier).
8. INFORMATION ON AUTOMATED DECISION-MAKING, INCLUDING PROFILING
Personal data will not be processed in a purely automated manner (including profiling), which may produce legal consequences for the data subjects or in a similar manner significantly affect their situation.
9. RIGHTS OF PERSONAL DATA SUBJECTS
To the extent and in the cases prescribed by law, in particular the RODO, data subjects (data subjects), including Participants, have the following rights:
- The right to withdraw consent (Article 7 of the RODO) – if the processing of personal data is carried out on the basis of consent, this consent may be withdrawn by the data subject at any time (however, this does not affect the lawfulness of the processing carried out before the withdrawal of consent). Consent is entirely voluntary.
- Right of access and right to obtain a copy of the data (Article 15 RODO) – the data subject is entitled to obtain from the Joint Controllers information about the processing of his/her personal data – including the source of the personal data, the purposes of the processing, the categories of personal data processed, the intended duration of the processing and the recipients to whom the data are disclosed – and to obtain a copy of his/her personal data that are processed by the Joint Controllers. The right to obtain a copy must not adversely affect the rights and freedoms of others (including those arising from copyright or trade secrets).
- Right to rectification (amendment) of personal data (Article 16 RODO) – the data subject has the right to request the Joint Controllers to rectify inaccurate or complete incomplete personal data concerning the data subject.
- Right to erasure of personal data (‘right to be forgotten’ of Art. 17 RODO) – the data subject has the right to request from the Joint Controllers the immediate erasure of his/her personal data where (i) the personal data are no longer necessary for the purposes for which they were collected or otherwise processed, (ii) he/she has withdrawn the consent on the basis of which the processing took place, and there will be no other legal basis for the Joint Administrators to process his/her personal data, (iii) he/she has objected under Art. 21 (1) RODO to the processing and there will be no overriding legitimate grounds for the processing of his/her personal data or has objected under Art. 21(2) RODO against the processing of his or her personal data, (iv) his or her personal data has been unlawfully processed, (v) the erasure of his or her personal data is required in order to comply with a legal obligation to which the Joint Controller is subject, (vi) his or her personal data has been collected in connection with the offering of information society services as referred to in Article 8(1) RODO. The right to erasure is not an absolute right. This right does not apply to the extent that the processing is necessary, inter alia, to comply with a legal obligation requiring processing under the law to which the Joint Controller is subject or to establish, assert or defend claims.
- The right to restrict the processing of personal data (Art. 18 RODO) – the data subject has the right to request the Joint Controllers to restrict the processing of his/her personal data where (i) he/she disputes the correctness of his/her personal data – for a period allowing the Joint Controllers to verify the correctness of the data; (ii) the processing is unlawful and the data subject objects to the erasure of the personal data, requesting instead the restriction of the use of the personal data, (iii) the Joint Controller no longer needs the personal data for the purposes of the processing, but they are needed by the data subject to establish, assert or defend a claim; (iv) the data subject has objected under Art. 21(1) against the processing – until it is determined whether the Joint Controllers’ legitimate grounds override the data subject’s grounds for objection. The exercise of this right means that the Joint Controllers may only process the requested personal data, with the exception of storage, with the data subject’s consent, or for the establishment, exercise or defence of claims, or for the protection of the rights of another natural or legal person, or for important grounds of public interest of the Union or of a Member State.
- Right to data portability (Article 20 RODO) – The data subject has the right to receive, in a structured, commonly used, machine-readable format, personal data concerning him or her which he or she has provided to the Joint Controllers, and has the right to send that personal data to another controller without hindrance from the Joint Controllers to whom the personal data has been provided, where (i) the processing is based on consent or on the basis of a contract; and (ii) the processing is carried out by automated means. In doing so, the Data Subject has the right to request that his or her personal data be sent by the Joint Controllers directly to another controller, insofar as this is technically possible. The exercise of the right to data portability, shall not adversely affect the rights and freedoms of others.
- Right to object(Article 21 RODO) – the data subject has the right to object at any time – on grounds relating to his/her particular situation – to the processing of personal data concerning him/her based, inter alia, on the legitimate interests of the Joint Controllers, including profiling. The exercise of this right means that the Joint Controllers are no longer allowed to process this personal data unless they demonstrate the existence of valid legitimate grounds for the processing, overriding the interests, rights and freedoms of the data subject or grounds for establishing, asserting or defending claims. If the Joint Controllers process personal data for the purposes of direct marketing, the data subject has the right to object at any time to the processing of personal data concerning them for such marketing, including profiling, to the extent that the processing is related to such direct marketing. The exercise of this right means that the Joint Controllers will not process personal data for such purposes.
The Joint Controllers will exercise the above rights in accordance with the provisions of the RODO and other relevant legislation. In order to exercise the data subjects’ rights or to obtain further information on their rights, please contact the Joint Controllers (contact details are indicated in section 3).
10. RIGHT TO COMPLAIN
If the Participant considers that the processing of his/her personal data by the Joint Controllers violates the provisions of the RODO or other generally applicable data protection legislation, he/she may lodge a complaint with the President of the Data Protection Authority.