Security Measures for the Processing of Personal Data through the Website
Cookies Policy
- Cookies are files that are installed on the user's browser to track their browsing history. They are commonly used in marketing to offer content, products, or services related to the user's interests.
- In order to place a cookie on the user's browser, explicit consent must be obtained. This means that tacit or implied consent is no longer sufficient; it must be effective, voluntary, and unequivocal. For example, by checking an acceptance box.
- "On the other hand, the intention to use the user's cookies must be presented through a two-layer information approach. The first layer simply indicates that the website uses third-party cookies, with a link to the second layer, which provides more detailed information about the purpose, whether the data will be shared with third parties, and the duration of retention in the database.
- As a general rule, explicit consent from the user is required to place any cookie, but this is not always the case. For example, it is not necessary for cookies related to user input, security, multimedia playback, or authentication.
Legal Notice
The legal notice is a text that must be included on the website whenever it involves:
- Corporate websites
- Websites or blogs with advertising
- Online stores
- Portals offering the provision of some type of service
The legal notice must include the following information:
- Company/user name and contact details
- Company/user name and contact details
- Company registration number, if registered as a business entity
- Information about mandatory administrative authorizations obtained
- In the case of practicing a regulated profession, the details of the Professional Association, academic title, or ethical standards related to the practice of the profession must be provided.
COOKIES INFORMATION
The second paragraph of Article 22 of Law 34/2002, of July 11, on Information Society Services and Electronic Commerce establishes:
- “Service providers may use data storage and retrieval devices on recipients’ terminal equipment, provided that the recipients have given their consent after being provided with clear and comprehensive information regarding their use, in particular regarding the purposes of data processing, in accordance with the provisions of Organic Law 15/1999 of December 13 on the Protection of Personal Data.
- Where technically feasible and effective, the recipient’s consent to the processing of data may be provided through the use of appropriate browser settings or other applications. The foregoing shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network or, to the extent strictly necessary, for the provision of an information society service expressly requested by the recipient.
- In particular, it should be noted that, in accordance with the provision cited above, it applies to any “data storage and retrieval devices” on any “recipients’ terminal equipment,” and that the annex to the aforementioned LSSI defines a “service recipient or recipient” as the “natural or legal person who uses, whether or not for professional reasons, an information society service.”
- Thus, Article 22 of the LSSI and this guide refer to the use of cookies and similar technologies (such as local shared objects or flash cookies, web beacons or bugs, etc.) to store and retrieve data from a terminal device (e.g., a computer, a mobile phone, or a tablet) belonging to a natural or legal person who uses, whether for professional or non-professional purposes, an information society service.
- There are two legal obligations imposed by the regulations, namely: the obligation of transparency and the obligation to obtain consent.
- Article 22 of the LSSI also provides that, where technically possible and effective, the recipient’s consent to the processing of data through cookies and similar technologies may be provided through the use of appropriate browser settings or other applications. However, this possibility does not preclude the storage or technical access necessary solely for the purpose of transmitting a communication over an electronic communications network or, to the extent strictly necessary, for the provision of an information society service expressly requested by the recipient.
- Consequently, the information about cookies provided when consent is sought must be sufficiently comprehensive to enable users to understand their purposes and how they will be used.
- Definition and general purpose of cookies.
- Information about the types of cookies used and their purpose.
- Identification of who uses the cookies, that is, whether the information obtained through cookies is processed solely by the publisher and/or also by third parties with whom the publisher has contracted to provide a service that requires the use of cookies, including the identification of such third parties.
- Information on how to accept, refuse, or revoke consent for the use of cookies, as provided through the features made available by the publisher (the cookie management or configuration system that has been enabled) or through any standard platforms that may exist for this purpose.
- Where applicable, information regarding data transfers to third countries carried out by the publisher.
- When profiling involves automated decision-making that produces legal effects concerning the user or similarly significantly affects the user, information must be provided regarding the logic used, as well as the significance and the anticipated consequences of such processing for the user, in accordance with Article 13(2)(f) of the GDPR.
- Data retention periods for various purposes, as set forth in Article 13.2(a) of the GDPR.
- With regard to the other information required under Article 13 of the GDPR that does not specifically refer to cookies (for example, the rights of data subjects), the publisher may refer to the privacy policy.
The cookie policy must include the following information:
For the use of non-exempt cookies, it will always be necessary to obtain the user’s consent. This consent may be obtained through explicit means, such as clicking on a button that says “I consent,” “I accept,” or similar terms. It may also be inferred from an unambiguous action taken by the user, in a context where the user has been provided with clear and accessible information about the purposes of the cookies and whether they will be used by the publisher itself and/or by third parties, such that it can be understood that the user accepts the installation of cookies. Under no circumstances does the user’s mere inactivity imply the granting of consent in and of itself.
In accordance with Article 22(2) of the LSSI, consent must be given by the “recipients” of information society services.
According to section (d) of the Annex to the LSSI, the term “recipient of the service or recipient” refers to “the natural or legal person who uses an information society service, whether or not for professional purposes.” And in accordance with the definitions provided in the relevant section, the term “recipient” is synonymous with “user,” which is the term used in this guide.
Therefore, the information must be provided directly to the user so that they can give or withhold their consent.