Data subject rights and how to exercise them
Articles 7, 12-22 and 77-79 of Regulation (EU) 2016/679
Version of
Translation provided for convenience only: in case of discrepancy, the Italian text prevails.
1. Introduction
As a data subject you have the right to know how your data are used and to act on them. This page lists the rights the GDPR grants you towards CIAS Elettronica S.r.l., the data controller, and explains how to exercise them simply and free of charge.
2. Your rights
- Access (Article 15) — obtain confirmation that your data are being processed and receive a copy, together with information on purposes, categories, recipients, retention period and source.
- Rectification (Article 16) — have inaccurate data corrected or incomplete data completed. Many account data can be updated directly from your profile in the Portal.
- Erasure (Article 17) — obtain the deletion of your data when they are no longer necessary, when you withdraw consent, when you object to the processing or when the processing is unlawful, unless retention is required by a legal obligation or to defend a right.
- Restriction (Article 18) — have your data merely stored, and not otherwise processed, while the accuracy or the lawfulness of the processing is verified.
- Portability (Article 20) — receive in a structured, commonly used and machine-readable format the data you provided that are processed on the basis of a contract or consent, and transmit them to another controller.
- Objection (Article 21) — object, on grounds relating to your particular situation, to processing based on legitimate interest (for instance security logs); the Controller may continue only by demonstrating compelling legitimate grounds that override your interests.
- Automated decisions (Article 22) — not be subject to decisions based solely on automated processing that produce legal effects. The Portal takes no such decisions.
- Withdrawal of consent (Article 7(3)) — withdraw at any time the consent given, as easily as it was given, without affecting the lawfulness of previous processing.
- Information on recipients (Article 19) — know to which recipients rectifications, erasures or restrictions have been communicated.
3. How to exercise your rights
You may send your request, without any particular formality, to one of the following contact points of the Controller:
- e-mail: info@cias.it
- post: CIAS Elettronica S.r.l., Via Durando 38, 20158 Milan (Italy)
The Controller has not appointed a data protection officer (DPO): please address your requests to the contact points of the Controller listed above.
To let us reply, please state: the right you wish to exercise, the data or processing concerned, the e-mail address linked to your account and a contact for the reply. If the request comes from an address other than the account one, or in case of reasonable doubt about your identity, we may ask for further information to identify you (Article 12(6)).
- Timing: we reply within one month of receiving the request; the period may be extended by two further months in complex cases or when many requests are received, in which case you will be informed with the reasons.
- Costs: exercising your rights is free of charge. Only for manifestly unfounded or excessive requests, in particular because of their repetitive character, may the Controller charge a reasonable fee or refuse to act, giving reasons.
- If we cannot act: we will inform you of the reasons and of the possibility of lodging a complaint with the supervisory authority or seeking a judicial remedy.
4. What you can do directly from the Portal
- Update your account data (name, company, e-mail, telephone, language) from your profile, if your authorisation level allows it.
- Change your password, reset multi-factor authentication and revoke trusted devices.
- Ask for the deactivation of your account from the member of the chain who created it or from CIAS.
5. Complaint to the supervisory authority and judicial remedy
If you believe that the processing of your data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority of the Member State where you reside, work or where the alleged infringement occurred (Article 77). In Italy the authority is the Garante per la protezione dei dati personali — Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it — PEC protocollo@pec.gpdp.it. The procedure is described on the Garante website.
Your right to an effective judicial remedy against the controller or the processor (Article 79), before the courts of the Member State where they have an establishment or where you reside, remains unaffected.