Data protection policy
Create a page with access from the footer of the website, called “Data Protection Policy” so that with a single click it displays the following text:
Corporate data protection policy
Purpose and Scope of application
The Col·legi Oficial de Biòlegs de la Comunitat Valenciana (hereinafter, COBCV), expresses its commitment to compliance with Regulation (EU) 2016/679 General Data Protection (RGPD), Organic Law 3/2018 on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), and other applicable regulations.
This policy is applicable to governing bodies, workers and collaborators of COBCV, as well as to suppliers and third parties who process personal data on behalf of or under the authority of the College.
Principles governing the processing of personal data
COBCV will process personal data in accordance with the principles of legality, loyalty, transparency, limitation of purpose, minimization, accuracy, limitation of retention period, integrity, confidentiality and proactive responsibility.
Personal data of special categories will only be processed when it is necessary, one of the circumstances provided for in article 9 of the RGPD exists and the appropriate guarantees apply.
Registration and Inventory of treatment activities
The COBCV will keep its Register of Processing Activities updated, in accordance with article 30 of the RGPD, identifying the purposes, categories of interested persons and data, recipients, international transfers, conservation periods and general security measures corresponding to each activity.
Likewise, the COBCV will publish its Inventory of processing activities by electronic means, in accordance with articles 31.2 and 77.1.g of the LOPDGDD.
The Public Inventory of Processing Activities can be consulted here: https://cobcv.com/legal/rat/
The Public Inventory will not include internal assessments of risks, vulnerabilities, configurations, or detailed information on security measures.
Risk management and impact assessments
The COBCV will analyze the risks that personal data processing may represent for people's rights and freedoms.
When a treatment may entail a high risk, especially due to its nature, scope, context or purposes, the COBCV will previously carry out an Impact Assessment related to Data Protection, in accordance with article 35 of the RGPD.
Where necessary, additional measures will be taken to reduce the identified risks. If a high risk persists that cannot be reasonably mitigated, prior consultation will be carried out with the supervisory authority provided for in article 36 of RGPD.
Security and management of personal data breaches
The COBCV will apply appropriate technical and organizational measures to guarantee a level of security appropriate to the risk, taking into account the state of the art, the costs of application, the nature, scope, context and purposes of the processing.
The COBCV will have procedures to detect, analyze, document and manage personal data breaches. When legally required, breaches will be notified to the supervisory authority and communicated to the affected persons, in accordance with articles 33 and 34 of RGPD.
People's rights
The COBCV will facilitate the exercise of the rights of access, rectification, deletion, opposition, limitation, portability and not to be subject to decisions based solely on automated treatments, when applicable.
Requests will be attended to within the deadlines and in accordance with the conditions established in the RGPD and the LOPDGDD.
Interested parties can consult how to exercise their rights in the COBCV Privacy Policy.
Digital rights in the workplace
The COBCV will guarantee the digital rights of workers in accordance with the LOPDGDD and, in particular, those related to the use of digital devices, digital disconnection, the use of video surveillance systems, sound recording and geolocation systems, when such means are used.
The COBCV will inform workers in advance about the criteria for using these means and will approve the internal policies that are necessary.
Training and confidentiality
People who, due to their functions, have access to personal data will receive training and instructions appropriate to their responsibilities.
These people will be subject to the duty of confidentiality and must comply with the policies, procedures and security measures approved by COBCV. The training will be reviewed and updated periodically.
Providers and processors
Before contracting services that involve access to personal data, COBCV will evaluate whether the provider offers sufficient guarantees to apply appropriate technical and organizational measures.
The relationship with those in charge of processing will be regulated by the corresponding contract or legal act, in accordance with article 28 of RGPD.
Supervision and continuous improvement
The COBCV will apply review and control procedures to verify the effectiveness of the measures implemented, detect possible deficiencies and adopt the necessary corrective actions.
This policy will be reviewed periodically and whenever relevant regulatory, organizational or technological changes occur.
Data Protection Officer
The COBCV has appointed a data protection officer, in accordance with articles 37 to 39 of the RGPD and article 34.1.l of the LOPDGDD. His designation has been communicated to the Spanish Data Protection Agency.
The data protection officer shall exercise his or her duties independently, participate appropriately and in a timely manner in matters related to data protection, and act as a point of contact for interested persons and the supervisory authority.
You can contact the data protection officer at:
BUSINESS ADAPTER, S.L.Email: fmoya@businessadapter.es (reference: COBCV).
Approval and validity
This policy has been approved by the COBCV Governing Board and will remain in effect until replaced or modified.
Approval date: July 31, 2025. Version: 01.
The COBCV Governing Board
This corporate policy expresses the general principles of action of COBCV and does not replace the detailed information contained in its Privacy Policy.