Introduction
The European Space Agency (herein the “Agency” or “ESA”) is an intergovernmental organisation established by its Convention opened for signature in Paris on 30 May 1975 having its headquarters located at 24 rue du Général Bertrand, CS 30798, 75345 Paris Cedex 07, France.
Protection of Personal Data is of great importance for ESA, which strives to ensure a high level of protection as required by the ESA Framework on Personal Data Protection (herein the “ESA PDP Framework”) which applies in this field. ESA implements appropriate measures to preserve the rights of data subjects, to ensure the processing of personal data for specified and legitimate purposes, in a not excessive manner, as necessary for the purposes for which the personal data were collected or for which they are further processed, in conditions protecting confidentiality, integrity and safety of personal data and generally to implement the principles set forth in the PDP Framework.
The ESA PDP Framework is available at:
http://www.esa.int/About_Us/Law_at_ESA/Highlights_of_ESA_rules_and_regulations
The ESA PDP Framework is composed of the following elements:
- the Principles of Personal Data Protection, as adopted by ESA Council Resolution (ESA/C/CCLXVIII/Res.2 (Final)) adopted on 13 June 2017;
- the Rules of Procedure for the Data Protection Supervisory Authority, as adopted by ESA Council Resolution (ESA/C/CCLXVIII/Res.2 (Final)) adopted on 13 June 2017; and
- the Policy on Personal Data Protection adopted by Director General of ESA on 5 February 2018 and effective on 1 March 2018.
This form is intended to inform you, as data subject, about:
- the identity of the data controller and contact details of ESA Data Protection Officer (“DPO”);
- the type of personal data which is collected and processed;
- the modalities of collection of personal data;
- the purpose of the collection and processing;
- the recipients (if any) to whom the personal data of the data subject shall be disclosed;
- the time-limits for storing the personal data;
- the practical modalities of exercising the rights of the data subject under the ESA PDP Framework.
This form is also enables ESA to obtain your consent relating to the collection and further processing of your personal data, under ESA PDP Framework.
(1) Who is the Data Controller?
Your personal data are collected and further processed as shown below upon decision taken by ESA.
Thus the Data Controller is ESA.
(2) Contact details of ESA Data Protection Officer?
According to ESA PDP Framework, your first point of contact concerning personal data matters is the ESA Data Protection Officer (“DPO”), who may be contacted at DPO@esa.int
For further information on the situations in which you may contact the ESA DPO, please refer to the questions 8 and 9 below.
(3) What kind of personal data about you are collected and further processed?
The personal data which may be collected and further processed for the purposes mentioned below are in particular:
- Title (e.g. Mr, Mrs)
- Name
- Company name
- Country
- Job title
- Main areas of professional interest
- Information in connection with your use of the ESA websites, such as information in server logs, specifically information on how you used the website including your search queries.
You are required not to send to the Agency any sensitive information (including information that indicate, directly or indirectly, the personnel’s ethnic origin, political opinions, adhesion to unions, parties etc., health situation, sexual orientation).
(4) How are your personal data collected or further processed?
Your personal data may be collected by various means, including via an electronic form on ESA ARTES and Business Applications websites e.g. if you sign up for our newsletter, register to access the website and/or apply to attend an ESA event. Any information you provide us with will be stored in a safe and secure location. Your details are held in a password-protected account for the purpose of sending you occasional emails related to the events or activities in which you have expressed an interest.
(5) Why are your personal data collected and further processed?
Your personal data are collected and further processed:
- to provide you access to, and enable the use of the ESA websites;
- to manage your relationship with the Agency as well as your requests and applications in relation to ESA programmes;
- to enable your participation in ESA events;
- to send you notifications in connection with relevant events organised by ESA including conferences, seminars, webinars and training courses;
- to send you newsletters in relation to the ARTES/Business Applications programmes;
- We use the information in aggregated form to analyse the demographics of our subscribers (e.g. how many we have in each country).
- The data may be used to support us in determining user preferences and usage trends on an aggregated basis (e.g. how long users spend on average on the website or in reading particular articles).
In addition to these purposes, the Agency may use your personal information for any of the purposes mentioned in Article 5 of the ESA Policy on Personal Data Protection available at:
http://www.esa.int/About_Us/Law_at_ESA/Highlights_of_ESA_rules_and_regulations
(6) To whom might we disclose your personal data?
The Agency may disclose your personal data to any of the following third party recipients for the fulfilment of all or part of the purposes of the collection and processing of personal data that are mentioned above:
Recipient acting as…
|
Servers of the recipient are located in:
|
Contractors involved in the operation, maintenance and hosting of the website.
Contractor details:
DOTSOFT SA
Bilbomática
|
The contractors has access to the servers via VPN to the ESA cloud support platform, which is located on ESA premises.
|
The Agency does not consider your personal data as an asset for sale and does not sell your personal data to any third parties.
(7) How long do we retain your personal data for?
The Agency may keep your personal data for as long as necessary for the fulfilment of the above mentioned purposes. Your Personal Data shall be deleted thereafter.
(8) How can you erase, rectify, complete or amend your personal data?
The Agency is keen to collect and process accurate personal data and to keep it to date.
You may request the erasure, rectification, completion or amendment of your personal data if, and to the extent that it is inaccurate or incomplete, having regard to the purposes for which they are collected and processed, or if they are processed in violation with the principles referred in ESA PDP Framework.
If you choose to make a request for the erasure of personal data, you understand and agree that you will not receive newsletter updates, event invitations and notifications.
The above mentioned request should be submitted to the ESA DPO, as first point of contact, by sending an email to: dpo@esa.int. Copy to: artes.gdpr@esa.int
You may also be allowed access to your personal data and have the possibility to erase, rectify, complete or amend it: please email artes.gdpr@esa.int for assistance with any such request.
(9) What could you do in case of a data protection incident?
In case of a data protection incident, you should contact ESA DPO, as first point of contact, by sending an email to: dpo@esa.int
In case you wish to submit a complaint, you are required to comply with the Rules of Procedure of the Supervisory Authority set forth by ESA PDP Framework. You will be required to demonstrate that a data protection incident occurred in relation to your personal data, following a decision of the Agency or at least to justify serious reasons to believe that such incident occurred.
(10) Your consent
For those cases where your consent was not already obtained by ESA (including by other modalities) and is required under the ESA Framework on Personal Data Protection, you agree with the collection and further processing of your personal data by accepting or disagreeing using the digital sign up forms provided on our websites.
You will be able to withdraw your consent depending on the modality used to collect your personal data, in particular by unsubscribing from the mailing list.