Privacy Notice on the Processing of Personal Data – STADIO MARADONA ATTENDEES
(pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”))
S.S.C. NAPOLI S.p.A. pays the utmost attention to the protection of the personal data of data subjects and therefore guarantees their protection against any event that may put them at risk of breach, as provided for by EU Regulation No. 679/2016 (“GDPR”), as well as by Legislative Decree 196/2003 and subsequent amendments.
The data subject, to whom this privacy notice is provided pursuant to and for the purposes of Article 13 of the GDPR, is invited to read carefully the methods of processing of personal data as described below.
- DATA CONTROLLER
The Data Controller is S.S.C. NAPOLI S.p.A., with registered office at Via del Maio di Porto, 9 – 80133 Naples, Italy, whom you may contact at any time to exercise your rights as indicated below.
- CATEGORIES OF DATA PROCESSED
SSCN, in its capacity as Data Controller, will process data belonging to the following categories:
personal identification data such as first name, last name, gender, date of birth;
contact details: e-mail address, residence address details (country, city, province and postal code);
data relating to your image.
3. PURPOSES OF PROCESSING AND LEGAL BASIS
Your personal data will be processed exclusively for the following purposes, in compliance with the principles of lawfulness, fairness and transparency, and in particular:
the data referred to in point 2.a will be used to allow the Data Controller to issue the access ticket in your name. Consequently, the legal basis for this processing is the performance of a contract to which the data subject is a party, pursuant to Article 6(1)(b) of the GDPR;
the data referred to in point 2.a will be processed by the Data Controller to carry out checks aimed at verifying that you do not fall into any of the following categories: (i) persons subject to measures pursuant to Article 6 of Law 401 of 13/12/1989 (ban from access to places where sporting events are held – DASPO); (ii) persons subject to preventive measures pursuant to Law 1423 of 27/12/1956 (preventive measures against persons deemed dangerous to public safety); (iii) persons with convictions, including non-final judgments, for offences committed in connection with and/or on the occasion of sporting events; (iv) persons subject to administrative or judicial measures providing for a ban on access to stadiums, prohibition and/or removal from stadiums, as well as any other restrictive measure issued by any Authority that, in any way, entails a ban on participation in public gatherings. The legal basis for such processing is therefore identified in the legitimate interest of the Data Controller in ensuring security, pursuant to Article 6(1)(f) of the GDPR, as well as in compliance with a legal obligation to which the Data Controller is subject pursuant to Article 6(1)(c) of the GDPR;
pursuant to Article 130, paragraph 4, of Legislative Decree 196/2003, the data referred to in point 2.b may be used to send e-mail communications regarding services or products similar to those already purchased by the data subject. At the time of data collection and on the occasion of each communication sent for such purposes, you will be informed of the possibility to object to the processing, easily and free of charge, through the procedures indicated in the communications received. The legal basis for this processing is the legitimate interest pursuant to Article 6(1)(f) of the GDPR;
subject to your explicit consent, the data referred to in point 2.b (and in particular your e-mail address) will be used for the purpose of sending promotional and advertising material. Consequently, the legal basis for this processing is the consent of the data subject, pursuant to Article 6(1)(a) of the GDPR, without prejudice to the fact that such consent may be withdrawn at any time;
subject to your express consent, the data referred to in points 2.a and 2.b may also be processed by SSCN in order to analyse your purchasing preferences and consumption habits, so as to offer you personalized content or promotions, thereby expanding your commercial choices. The legal basis for this processing is the express consent of the data subject pursuant to Article 6(1)(a) of the GDPR, which may be withdrawn at any time;
the data referred to in point 2.c may be processed during the sporting event in order to promote the event through the distribution channels planned for the current sports season. The legal basis for this processing is the legitimate interest of the Data Controller in documenting the sporting event, pursuant to Article 6(1)(f) of the GDPR;
the data referred to in point 2.c may be recorded for archival purposes as part of SSCN’s historical archive. The legal basis for this processing is the legitimate interest of the Data Controller in preserving the historical and sporting heritage of the Company, pursuant to Article 6(1)(f) of the GDPR;
the data referred to in point 2.c may be used, modified, altered, transmitted, published, disseminated and transferred in order to promote SSCN’s image, through any means of communication, including but not limited to all broadcasting systems, collective viewing circuits and social networks. The legal basis for this processing is the legitimate interest of the Data Controller in promoting its image, pursuant to Article 6(1)(f) of the GDPR;
the data referred to in point 2.c may also be processed in connection with the activation of the “fan cam”, to be displayed on the giant screens of the sports facility “Stadio Diego Armando Maradona”. The legal basis for this processing is the legitimate interest of the Data Controller in fan engagement, pursuant to Article 6(1)(f) of the GDPR.
4. DATA PROTECTION OFFICER
The Data Protection Officer (DPO) can be contacted at the following e-mail address: [email protected].
- METHODS OF PROCESSING AND DATA RETENTION PERIOD
Your personal data will be processed in compliance with the principles of lawfulness, fairness and transparency, using digital means. Your data will be processed exclusively by authorized internal personnel and, where necessary, by duly appointed external data processors pursuant to Article 28 of the GDPR.
Your data will be retained for the period strictly necessary to achieve the above purposes, and in particular, the data relating to the purposes referred to in:
3.a and 3.b will be retained for a period of one year from the sporting event to which the access ticket refers;
3.c will be retained for a period of 12 months from your last interaction;
3.d will be retained until consent is withdrawn and in any case for a period not exceeding 24 months from your last interaction;
3.e will be retained for a period of 12 months from collection;
3.f, 3.g and 3.h will be retained until the achievement of the purposes indicated therein and in compliance with legal limits;
3.i will be deleted immediately after projection on the giant screen.
6. DATA COMMUNICATION AND DISCLOSURE
The data provided may be communicated to third parties, appointed as data processors pursuant to Article 28 of the GDPR where necessary, or to independent data controllers for the above-mentioned purposes.
- PLACE OF DATA PROCESSING
Data processing related to the services takes place within the territory of the European Union and is carried out exclusively by personnel authorized to process the data or by third parties identified by the Data Controller for the performance of specific activities, duly appointed as Data Processors pursuant to Article 28 of the GDPR.
- YOUR RIGHTS AND HOW TO EXERCISE THEM
In relation to the processing described in this Privacy Notice, as a data subject you may, under the conditions set out in the GDPR, exercise the rights provided for in Articles 15 to 21 of the GDPR and, in particular, the following rights:
right of access – Article 15 GDPR: the right to obtain confirmation as to whether or not personal data concerning you are being processed and, where that is the case, to obtain access to your personal data, including a copy thereof;
right to rectification – Article 16 GDPR: the right to obtain, without undue delay, the rectification of inaccurate personal data concerning you and/or the completion of incomplete personal data;
right to erasure (right to be forgotten) – Article 17 GDPR: the right to obtain, without undue delay, the erasure of personal data concerning you;
right to restriction of processing – Article 18 GDPR: the right to obtain restriction of processing where:
the data subject contests the accuracy of the personal data, for the period necessary for the controller to verify the accuracy of such data;
the processing is unlawful and the data subject opposes the erasure of the personal data and requests instead the restriction of their use;
the personal data are necessary for the data subject for the establishment, exercise or defence of legal claims;
the data subject has objected to processing pursuant to Article 21 GDPR, pending verification of whether the legitimate grounds of the controller override those of the data subject.
right to lodge a complaint – Article 77 GDPR: the data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), Piazza Venezia no. 11, 00187 Rome, e-mail: [email protected].
The above rights may be exercised by contacting the Data Controller at the following e-mail address: [email protected].
The exercise of your rights as a data subject is free of charge pursuant to Article 12 of the GDPR. However, in the event of manifestly unfounded or excessive requests, also due to their repetitive nature, the Data Controller may charge a reasonable fee, in light of the administrative costs incurred in handling your request, or may refuse to act on the request.