EBA Regular Use
DATA PROTECTION NOTICE – ATD REQUESTS
Data Protection Notice
Processing of personal data in the context of access to documents
requests
The European Banking Authority (EBA) processes your personal data in the context of access to
documents requests in accordance with
Regulation (EC) No 45/2001. The EBA processes your
personal data based on
Regulation (EU) 2018/1725 (EUDPR).
The following information is provided as established in Articles 15 and 16 of the EUDPR.
Who is the control er?
The EBA is the controller with regard to the data processing activities described in this data
protection notice.
For more information on the EBA, please consult the EBA website https://eba.europa.eu.
What personal data do we process, for what purpose, who can access it and how long
do we keep them?
The EBA processes the name and the contact details of the person requesting the documents and
any other personal data submitted by the applicant in the request. In addition, the EBA processes
any personal data that may appear in the requested documents.
The purpose of the processing is to ensure the appropriate handling of requests for access to
documents in compliance with the principles, conditions and limits defined in Regulation (EC) No
1049/2001. Such requests may be lodged by any citizen of the European Union and any natural or
legal person residing or having its registered office in a Member State. For the purposes of the
Regulation 1049/2001, the EBA wil send acknowledgement of receipts, analyse requests, assess
possible disclosure of documents originating from the EBA or third parties, inform the applicants of
the decision to disclose or to refuse the disclosure of documents or information and handle possible
confirmatory applications.
Your personal data can be accessed by a limited number of staff members, who are involved on a
need-to-know basis when handling your request for access. Technical measures include storing the
files electronically in a restricted area of the Document Management System of the Legal and
Compliance Unit. The staff of the Legal and Compliance Unit dealing with your access to documents
requests applies strict measures to ensure that your personal data is not accessed by anybody else.
This includes the use of locked closets.
1
EBA Regular Use
SPECIFIC PRIVACY NOTICE – ATD REQUESTS
The EBA wil keep the personal data as long as necessary and for a maximum of ten years after the
closure of the case, or as long as the EBA is under a legal obligation to do so.
Why do we process your personal data and under what legal basis?
The processing of your personal data by the EBA is lawful since the right of access to documents is
laid down in Article 15(3) of the Treaty on the Functioning of the European Union, in Article 42 of
the Charter of Fundamental Rights of the European Union and more in detail in Regulation (EC) No
1049/2001. The EBA respects the provisions of Regulation (EC) No 1049/2001 in accordance Article
72 of its funding Regulation and with
the Decision of the Management Board on Access to
Document EBA DC 036 of 27 May 2011.
Wil the processing of your personal data involve any transfer outside of the EU?
Your personal data is processed within the EU/EEA and will not leave that territory.
What are your rights regarding your personal data?
You have the right of access to your personal data and to relevant information concerning how we
use it. You have the right to rectify your personal data. Under certain conditions, you have the right
to ask that we delete your personal data or restrict its use. You have the right to object to our
processing of your personal data, on grounds relating to your particular situation, at any time. We
will consider your request, take a decision and communicate it to you. For more information, please
see Articles 14 to 21, 23 and 24 of the Regulation.
You can send your request by post in a sealed envelope or via email (see section on contact details
below).
You have the right to lodge a complaint
If you have any remarks or complaints regarding the way we process your personal data, we invite
you to contact the Data Protection Officer (DPO) of the EBA (see section on contact details below).
You have, in any case, the right to
lodge a complaint with the European Data Protection Supervisor, our supervisory authority for data protection matters.
Contact details for enquiries regarding your personal data
Should you wish to contact the EBA, we encourage you to send an email to
xxx@xxx.xxxxxx.xx by
stating in the subject “Data Protection Enquiry”.
If you wish to contact the DPO of the EBA personal y, you can send an e-mail t
o xxx@xxx.xxxxxx.xx
or a letter to the postal address of the EBA marked for the attention of the DPO of the EBA.
The postal address of the EBA is DEFENSE 4 – EUROPLAZA, 20 Avenue André Prothin, CS 30154,
92927 Paris La Défense CEDEX, France.
2
EBA Regular Use
SPECIFIC PRIVACY NOTICE – ATD REQUESTS
You can also find contact information on the EBA’s website:
https://eba.europa.eu/contacts
3