Personal Data Protection Policy - Statement of Intent
Fast S.p.A. considers the protection of personal data to be a fundamental value that inspires its daily activities; it safeguards and promotes the protection of personal data and the rights of the data subjects through data protection policies and information and awareness campaigns.
Fast S.p.A. adopts all appropriate measures to ensure a high level of protection of the personal data of those concerned, such as customers, employees and suppliers, fostering the development of a culture of confidentiality.
The development and implementation of actions aimed at protecting personal data are based on the following guiding principles:
- lawfulness, fairness and transparency of processing;
- 'data minimisation', ensuring that processing is limited to what is necessary in relation to the purposes to be pursued;
- storage of personal data for a period not exceeding the pursuit of the aforementioned purposes;
- implementation of appropriate technical and organisational measures to ensure the security of personal data.
The appropriate data protection strategy is pursued through the implementation, proper implementation and maintenance of a privacy management system that complies with the requirements of Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR).
The main actions through which the data protection policy is implemented are:
- timely adaptation to all regulatory changes and updates;
- ensuring that innovations and transformations in service delivery processes are always accompanied by data protection objectives;
- effective and transparent information to ensure that data subjects are provided with all relevant information, including instructions and cooperation measures of the companies responsible for processing;
- the identification of roles and responsibilities within the organisation and the planning and implementation of programmes aimed at achieving continuous improvement objectives. This, with particular attention to safeguarding the rights of those concerned;
- carrying out a data protection impact assessment when a processing operation presents a high risk for the rights and freedoms of individuals;
- the prohibition of the transfer of personal data to countries established outside the territory of the EU, in the absence of adequate safeguards;
- training and information to its staff, fostering the development of a sense of responsibility and awareness of the entire organisation towards the protection of the confidentiality of the personal data of the individuals concerned.