Municipality of ........................
Information on the processing of personal data pursuant to Article 13 of Regulation (EU) 2016/679 (G.D.P.R.)
The name of the local authority, as the controller of personal data, considers privacy and the protection of personal data to be the main objective of its activity. We therefore invite you, before transmitting any personal data to the Data Controller, to read this Information carefully: it contains important information on the processing of the personal data of the data subject. ‘Personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
This information notice:
– for the website https://www.comune......................prov.it (hereinafter: “Site”) and is not extendable to websites that may be consulted by the user through links within the Site;
– is an integral part of the Site and of the services offered by the Authority;
– is made pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter: “Regulation”), to those who interact with the web services of the Website and the Data Controller, either through simple consultation or through the use of specific services made available through the Website.
According to the rules of the Regulation, the processing carried out by the Data Controller will be based on the principles of lawfulness, correctness, transparency, purpose limitation and storage, data minimization, accuracy, integrity and confidentiality.
The following information is therefore provided:
Data Controller
MUNICIPALITY OF .....................
(the contact details of the body are indicated in extended form at the bottom of the Institutional Website)
Data Protection Officer (DPO)
The DPO can be contacted at the addresses indicated at the bottom of the Institutional Site
1. TYPE OF PERSONAL DATA PROCESSED
As a result of browsing the Site, we inform you that the Data Controller will process your personal data which may consist of an identifier such as a name, an identification number, an online identifier or one or more elements characteristic of your physical, economic, cultural or social identity suitable for making the data subject identified or identifiable.
Other personal data freely provided by the user in the information request forms could be processed (for example to obtain information on courses or for requests to enrol in training courses). Any ‘special categories of personal data’ referred to in Article 9(1) of the Regulation should be processed only with the explicit consent of the user.
Navigation data
The computer systems and software procedures used to operate the Website acquire, during their normal operation, certain personal data the transmission of which is implicit in the use of internet communication protocols. This information is not collected to be associated with identified data subjects, but by their very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of the computers used by users connecting to the Site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the user’s IT environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the Site and to check its correct functioning, to identify anomalies and/or abuses, and are deleted immediately after processing. The data could be used to ascertain responsibility in the event of hypothetical computer crimes against the site or third parties: without prejudice to this possibility, at present the data on web contacts do not persist for more than fourteen days.
1.1 Data provided voluntarily by the user
The optional, explicit and voluntary sending of e-mails to the addresses indicated on this site or the use of restricted areas and the completion of web forms entails the subsequent acquisition and processing of the data necessary to offer the requested service and/or respond to requests, as well as any other personal data entered. Specific information may be reported or displayed on the pages of the site prepared for particular services on request. Where access to particular services is subject to prior registration of personal data, the following general provisions shall apply:
• personal data, collected and stored in databases, will be processed by employees appointed by the data controller, and will not be disseminated or communicated to third parties, except in the cases provided for by law and in the manner permitted by it;
• the interested party has the right to exercise the rights provided for in this statement.
1.2 Cookies
In order to facilitate users’ browsing experience, the Website uses cookies.
Cookies are small text strings that the websites visited by the user send to the computer and to any device used to access the internet (such as smartphones and tablets), where they are stored and then re-transmitted to the same sites on the next visit by the same user.
Cookies can be stored permanently and have a variable duration (so-called persistent cookies), but they can also disappear when the browser is closed or have a limited duration (so-called session cookies). Similarly, cookies can be installed by the site you are visiting (so-called first-party cookies), but also by other websites (so-called third-party cookies) and can be used for different purposes, such as performing computer authentication, monitoring sessions and storing information regarding the activities of users accessing a particular site.
Depending on the purpose of use, it is possible to distinguish the cookies installed on the Site in the following categories: technical, functional and analytical cookies.
This Site uses technical cookies, which are necessary for the proper functioning of the Site and to offer the user a smooth and slow navigation (e.g. to allow access to restricted areas to be maintained for as long as the user remains on the Site), as well as to correctly provide the services that the user requests during his navigation. These are therefore tools used by the Data Controller to ensure, for example, efficient navigation, session stability, log-in permanence and preselection of the selected navigation country. They are also necessary to remember the choices made by the user with regard to the display of certain elements of the page, such as information and communication banners.
This site is part of the AGID project for website statistics of the PA – Web Analytics Italia, for which information on the processing of personal data please refer to https://webanalytics.italia.it/privacy
2. PURPOSE OF THE TREATMENT
The processing of data will be carried out for the following purposes:
inclusion of the user’s personal data in the Entity’s personal data and computer databases;
a) subscription to the newsletter, if this service is active;
(b) fulfillment of specific user requests;
c) fulfillment of any legal, accounting and tax obligations;
d) accessibility of the Site and monitoring of its correct functioning;
e) tracking access to the body’s IT network in connection with any defensive or functional checks required by the judicial authorities.
3. LEGAL BASIS
The aforementioned processing purposes are based on lawfulness in the following legal bases:
– in relation to the purposes referred to in points (a) to (d), the processing is necessary to comply with a legal obligation to which the data controller is subject – pursuant to Articles 6(1)(c) and 6(3)(b) of the G.D.P.R. and Article 2-ter of Legislative Decree No 196/2003;
– in relation to the purposes referred to in points e)-f) the processing is necessary for the pursuit of the legitimate interest of the data controller or third parties – pursuant to Article 6(1)(f) G.D.P.R.
4. CATEGORIES OF DATA RECIPIENTS
The Authority may communicate the personal data provided, in order to comply with obligations imposed on it by laws, regulations or EU legislation, to the following categories of parties:
a) subjects who typically act as data processors pursuant to art. 28 of the Regulation, such as: i) persons, companies or professional firms that provide assistance and advice to the Data Controller in accounting, administrative, legal, tax and financial matters relating to the provision of services provided by the Authority; ii) subjects with whom it is necessary to interact for the provision of services (for example hosting providers); subjects delegated to carry out technical maintenance activities (including the maintenance of network equipment and electronic communications networks); (all: “Recipients”); the list of data processors processing data may be requested from the Data Controller;
b) subjects, bodies or authorities, autonomous data controllers, to whom the communication of the personal data of the interested party is mandatory by virtue of legal provisions or orders of the authorities;
c) persons authorised by the Data Controller to process personal data pursuant to Article 29 of the Regulation in order to carry out activities strictly related to the provision of the Services provided by the Authority (e.g. employees of the Data Controller).
More information on this can be found at the body.
5. METHODS OF TREATMENT
All personal data are processed mainly through electronic tools and methods; however, paper processing is not excluded a priori.
6. PERIOD OF STORAGE OF PERSONAL DATA
The personal data processed for the purposes indicated above will be kept for the time strictly necessary to achieve those same purposes in compliance with the principles of minimization and limitation of storage pursuant to art. 5.1.e) of the Regulation. In any case, the Data Controller will process personal data in compliance with current legislation on the conservation of administrative documentation and, in particular, with the Retention and Discard Maximum adopted by the Authority, as well as with the Technical Rules on the digital preservation of acts defined by AGID. Once the indicated terms have elapsed, personal data will be deleted or made anonymous, except in cases where storage is necessary for a period subsequent to that indicated, in the event of any disputes, requests from the competent authorities or pursuant to applicable legislation.
More information on this can be found at the body.
7. SECURITY MEASURES
The Data Controller undertakes to take all necessary security measures in order to minimize the risks of destruction or loss, even accidental, of the data, unauthorized access or processing not allowed or not in accordance with the purposes indicated in this document.
8. USER RIGHTS
Pursuant to Article 15 et seq. of the Regulation, users have the right to request, at any time, access to, rectification or erasure of their personal data, restriction of processing in the cases provided for in Article 18 of the Regulation, and to obtain the data concerning them in a structured, commonly used and machine-readable format, in the cases provided for in Article 20 of the Regulation. At any time, the user may revoke any consent given pursuant to Article 7 of the Regulation (where required as a condition for the lawfulness of the processing); lodge a complaint with the competent Supervisory Authority (Guarantor for the Protection of Personal Data) pursuant to Article 77 of the Regulation, if it considers that the processing of its personal data is contrary to the legislation in force.
You can make a request to object to the processing of your personal data pursuant to Article 21 of the Regulation, in which you must provide evidence of the reasons justifying the opposition: the Data Controller reserves the right to assess the request, which will not be accepted in the event of the existence of compelling legitimate reasons to proceed with the processing that prevail over the interests of the data subject, rights and freedoms.
Applications relating to the exercise of the aforementioned rights may be submitted either to the undersigned Data Controller or to the designated Data Protection Officer, at the addresses indicated above.
9. PROVISION OF PERSONAL DATA
Please note that the communication of personal data as listed above is an obligation according to the conditions specifically identified by law, and their provision is also mandatory. Failure to provide such data could make it impossible to obtain the requested service.
Page updated on 12/05/2025