GENERAL PRIVACY INFORMATION
Dear Sir/Madam, We wish to inform you that Cagliari Cruise Port S.r.l. is the Data Controller responsible for processing your personal data. Its registered office is located at Molo Rinascita Porto Cagliari snc – 09123 Cruise Terminal – Cagliari (CA), and its certified email address (PEC) is cagliaricruiseport@legalmail.it. The Data Protection Officer (DPO) is Mr Rocco Sgrò, Solicitor (roccosgro@pec.it).
We also inform you that, in accordance with data protection legislation, in your capacity as the ‘Data Subject’ and in our capacity as the ‘Data Controller’, the personal data provided will be processed for the purposes set out below, in accordance with current legislation and, in any event, in full compliance with the principles of fairness, lawfulness and transparency, in order to protect your privacy and your rights.
The processing of personal data is carried out with due regard for fundamental rights and freedoms, as well as the dignity of the Data Subject, with particular reference to privacy, personal identity and the right to the protection of personal data.
The company wishes to inform you that it has installed a video surveillance system to ensure greater security for people and property. Indeed, in accordance with the principle of transparency, the company has placed a series of signs along the perimeter of the ferry terminal indicating the use of CCTV cameras.
The video surveillance and recording system consists of a total of 11 cameras, of which 6 are fixed external cameras and 5 are fixed internal cameras; a monitor for live images and a recording unit are located in a secure and protected area.
The images captured by the Data Controller are processed using electronic means and in compliance with personal data protection legislation, the EDPB Guidelines 3/2019 on processing personal data through video devices and the guidance and FAQs on video surveillance issued by the Italian Data Protection Authority (Garante per la protezione dei dati personali). The legal basis for the lawfulness of the video surveillance is the Data Controller’s legitimate interest in ensuring the security of persons and property (Article 6(1)(f) GDPR), together with compliance with legal obligations relating to the implementation of security checks required by EU, national and local legislation on port security and port facilities and access to designated areas (Article 6(1)(c) and (e) GDPR; e.g. EC Regulation No 725/2004, EU Directive No 65/2005, Legislative Decree No 203/2007, Port Authority Orders, Harbour Master’s Office Orders).
Furthermore, we wish to inform you that the CCTV system has been authorised by the Labour Inspectorate following an agreement with the trade union organisation.
- Data transfers to foreign countries or international organisations:
The company may need to transfer your personal data to countries outside the European Union/European Economic Area (EEA), to so-called ‘third countries’. Such transfers to third countries may include all the processing activities mentioned above and will take place only in full compliance with the safeguards provided for in Articles 44 et seq. of the GDPR. Where the European Commission has not adopted an adequacy decision in respect of the destination country, the transfer will be carried out on the basis of appropriate safeguards, such as the standard contractual clauses adopted by the European Commission, a copy of which may be obtained by contacting the Data Controller or the DPO at the contact details set out above. As the processing described in this notice is based on legal obligation, public interest and legitimate interest rather than on consent, any such transfer is not conditional upon your consent.
- Methods of Processing and Data Protection:
Processing is carried out for operations performed with or without the aid of automated processes, such as collection, recording, organisation, storage and all other activities provided for in Article 4(2) of the GDPR 2016/679.
Therefore, the data collected will be processed using electronic or otherwise automated, IT and telecommunications tools, or by manual processing using methods strictly related to the purposes for which the personal data were collected and, in any event, in such a way as to ensure their security at all times.
In this regard, the company has implemented technical and organisational measures designed to provide an adequate level of security and confidentiality for personal data. These measures take into account the state of the art in technology, the costs of implementation, the nature of the data and the risks associated with the processing. The aim is to protect the data from accidental or unlawful destruction or alteration, accidental loss, unauthorised disclosure or access, and other forms of unlawful processing.
Furthermore, when the company processes personal data, it collects and processes personal data that is adequate, relevant and not excessive, as required to fulfil the purposes set out above, and further ensures that such personal data remains up to date and accurate.
The Data Controller does not carry out any wholly automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
- Rights of the Data Subject:
The Data Subject may, at any time, exercise their rights by submitting requests to the Data Controller and/or the DPO at the contact details provided below, in accordance with Article 15 of the EU General Data Protection Regulation (GDPR) 679/2016. You may exercise the following rights:
Right to rectification: You may obtain the rectification of personal data concerning you or provided by you. The organisation makes reasonable efforts to ensure that the personal data in its possession is accurate, complete, up to date and relevant, based on the most recent information available.
Right to restriction of processing: You may obtain a restriction on the processing of your personal data where:
- You contest the accuracy of the personal data whilst the organisation verifies its accuracy;
- The processing is unlawful and you request a restriction on the processing or the erasure of your personal data;
- The organisation no longer needs to retain the personal data, but you still need it to establish, exercise or defend your legal claims; or
You exercise your right to object to the processing whilst the organisation verifies whether your legitimate grounds override those of the organisation.
Right of access: You may ask the organisation for information about the personal data it holds concerning you, including details of the categories of personal data and special categories of personal data the organisation holds or controls, the purposes for which they are used, where they were collected (if not directly from you) and to whom they may have been disclosed.
Right to data portability: Upon your request, the organisation will transfer your personal data to another Data Controller, where technically feasible, provided that the processing is based on your consent or is necessary for the performance of a contract.
Right to erasure: You may request that the organisation erase your personal data where:
- The personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- You have the right to object to further processing of your personal data, and you exercise this right to object;
- The personal data has been processed unlawfully.
Right to object: You may object at any time to the processing of your personal data, provided that the processing is not based on your consent but on the legitimate interests of the organisation or a third party. In such cases, the organisation will no longer process your personal data unless it can demonstrate compelling and legitimate grounds, an overriding interest in the processing or the establishment of facts, or the exercise or defence of a legal claim. Should you object to the processing, please specify whether you wish to have your personal data erased or the processing restricted.
Right to lodge a complaint: In the event of an alleged breach of applicable data protection legislation, you may lodge a complaint with the competent authorities in your country or in the place where the alleged breach is said to have occurred.
- Changes to this privacy policy:
Any future changes or additions to the processing of personal data, as described in this Privacy Policy, will be notified via the usual communication channels used by the company (for example, by email or on the website).
A. PASSENGER INFORMATION
-
- Categories of data processed:
We would like to inform you that, in accordance with current data protection legislation, ‘personal data’ generally refers to any information relating to an identified or identifiable natural person, directly and/or indirectly, by reference to a name, an identification number, location data, an online identifier or one or more factors specific to their physical, physiological, genetic, psychological, economic, cultural or social characteristics.
In your capacity as a passenger transiting through the port area under the jurisdiction of Cagliari Cruise Port S.r.l., the personal data processed will consist of your personal details (first name, surname, nationality, identity document and tax code details, date of birth, place of residence) as shown on your identity document.
The Data Controller does not intentionally collect special categories of personal data. Where the Data Subject is a minor, their personal data is processed solely for port security purposes and under the responsibility of the accompanying adult.
Furthermore, for the management of embarkation and disembarkation procedures, the Data Controller will process your personal data contained in a list provided by the shipping agent in order to comply with the requirements of current legislation issued by the National Maritime Security Programme and the various sector-specific circulars issued.
Part of the personal data processed for the management of embarkation and disembarkation is not collected directly from you but is obtained from the passenger lists provided by the cruise lines, ferry companies or such other applicable operational passenger transporting company. Such data does not originate from publicly accessible sources.
- Legal basis for processing, the nature of data provision and the purposes of processing:
This privacy notice provides information on how the company collects and processes users’ personal data during their interactions with Cagliari Cruise Port S.r.l., including data that users may provide to the Cagliari cruise port.
The personal data collected is necessary for the fulfilment of the legal obligations relating to monitoring and the public interest to which the Data Controller is subject, which may include, by way of example and without limitation, responding to any requests for information from the relevant authorities, such as the Harbour Master’s Office or law enforcement agencies, for security reasons and, more generally, to comply with the obligations laid down by EU legislation, laws and acts having the force of law, as well as by orders and directives from Law Enforcement and/or Judicial Authorities.
This processing is based on Article 6(1)(c) (compliance with a legal obligation) and Article 6(1)(e) (performance of a task carried out in the public interest) of the GDPR.
Consequently, the processing of personal data relates exclusively to port access, security, logistics and regulatory compliance in the context of our terminal’s operations.
The provision of your personal data for the purposes set out above is mandatory, as it is required in order to comply with applicable port security legislation and to permit access to and transit through the port area. Should you decline to provide such data, the Data Controller will be unable to grant you access to the terminal and the port area or to complete embarkation and disembarkation procedures.
The processing of the data referred to in the previous paragraph is carried out for the following purposes:
- To maintain port security and prevent unlawful acts;
- To monitor incoming and outgoing traffic;
- To comply with security regulations – maritime and customs authorities;
- To comply with requests for investigations or to provide evidence in support of any formal inquiries into port incidents;
- To respond to any requests for access from the Data Subject;
- Emergency management.
-
- Sharing of personal data:
Your data is processed using IT and/or telecommunications tools, in accordance with organisational procedures and logic strictly related to the purposes set out above. In all cases, specific security measures are observed to prevent data loss, unlawful or improper use, and unauthorised access.
The data collected by the Data Controller will be shared solely for the purposes set out above and, therefore, will not be shared and/or transferred to third parties other than those indicated in this privacy notice.
Personal data may be accessed by employees of Cagliari Cruise Port S.r.l., who are authorised to process such data, have been specifically trained for this purpose, and will do so solely for the purposes set out above.
Furthermore, personal data may be transferred, where required, to entities belonging to:
- Public entities for the purposes of any checks;
- Relevant authorities (Maritime Authority – Law Enforcement Agencies – Judicial Authorities);
- Appointed security companies;
- IT service providers appointed as Data Processors.
The up-to-date list of data processors is available at the Data Controller’s registered office and will be provided upon written request.
- Data Retention Period:
The data will be retained for the time strictly necessary to carry out the intended operations and for no longer than the periods specified by law and sector-specific regulations in relation to the type of processing carried out.
In particular, the personal data transmitted will be retained for a maximum of 24 hours following departure; the same applies to images captured via the CCTV system, subject to any special requirements for further retention in connection with public holidays or office closures, as well as in the event that a specific request from an investigating authority, the judicial authorities or the judicial police must be complied with. Thereafter, personal data will be removed from the company’s active systems.
In any event, the retention period for personal data shall not exceed 24 hours from the time of your departure. Once this period has expired, personal data will be removed from the company’s active systems.
Personal data will be retained for the time strictly necessary to fulfil the purposes set out in the previous paragraph.
B. VISITOR PRIVACY NOTICE
- Categories of data processed:
We inform you that, in accordance with current legislation on data protection, ‘personal data’ generally refers to any information relating to an identified or identifiable natural person, directly and/or indirectly, by reference to a name, an identification number, location data, an online identifier or one or more factors specific to their physical, physiological, genetic, psychological, economic, cultural or social characteristics.
In your capacity as a visitor to the port area under the jurisdiction of Cagliari Cruise Port S.r.l., the personal data processed will consist of your personal details (first name, surname, nationality, identity document and tax code details, date of birth, place of residence) as shown on your identity document.
The Data Controller does not intentionally collect special categories of personal data. Where the Data Subject is a minor, their personal data is processed solely for port security purposes and under the responsibility of the accompanying adult.
Furthermore, in order to manage your activities, the Data Controller will need to process your personal data by also recording other information such as your date of entry and, where access is required by vehicle, the vehicle in which you are travelling and with which you enter the port area, its registration number, and its make and model. The information collected is intended to comply with the requirements of current legislation issued by the National Maritime Security Programme and the various sector-specific circulars issued.
- Legal basis for processing, the nature of the provision of data and the purposes of processing:
The personal data collected is necessary for the fulfilment of the legal obligations relating to control and public interest to which the Data Controller is subject, which may include, by way of example and without limitation, responding to any requests for information from the relevant authorities, such as the Harbour Master’s Office or law enforcement agencies, for security reasons and, more generally, to fulfil the obligations laid down by EU legislation, laws and acts having the force of law, as well as by orders and directives issued by Law Enforcement and/or Judicial Authorities.
This processing is based on Article 6(1)(c) (compliance with a legal obligation) and Article 6(1)(e) (performance of a task carried out in the public interest) of the GDPR. The provision of your personal data is mandatory, as it is required in order to comply with applicable port security legislation and to permit access to the port area. Should you decline to provide such data, the Data Controller will be unable to grant you access to the port area.
The processing of the data referred to in the previous paragraph is carried out for the following purposes:
- To maintain port security and prevent unlawful acts;
- To monitor incoming and outgoing traffic;
- To comply with security regulations – maritime and customs authorities;
- To comply with requests for investigations or to provide evidence in support of any formal investigations into port incidents;
- To respond to any requests for access from the Data Subject;
- Emergency management.
- Sharing of personal data:
Your data is processed using IT and/or telecommunications tools, in accordance with organisational procedures and logic strictly related to the purposes set out above. In all cases, specific security measures are observed to prevent data loss, unlawful or improper use, and unauthorised access.
The data collected by the Data Controller will be shared solely for the purposes set out above and, therefore, will not be shared and/or transferred to third parties other than those indicated in this privacy notice.
Personal data may be accessed by employees of Cagliari Cruise Port S.r.l., who are authorised to process such data, have been specifically trained for this purpose, and will do so solely for the purposes set out above.
Furthermore, personal data may be transferred, where required, to entities belonging to:
- Public entities for the purposes of any checks;
- Relevant authorities (Maritime Authority – Law Enforcement Agencies – Judicial Authorities);
- Appointed security companies;
- IT service providers appointed as Data Processors.
The up-to-date list of data processors is available at the Data Controller’s registered office and will be provided upon written request.
- Data Retention Period:
The data will be retained for the time strictly necessary to carry out the intended operations and no longer than the time limits specified by law and sector-specific regulations in relation to the type of processing carried out.
In particular, the personal data transmitted will be retained for a maximum of 24 hours following the completion of the operations you have carried out. Once this period has expired, the personal data will be removed from the company’s active systems.
With regard to images captured via the aforementioned video surveillance system, please note that these images will be retained for a period of 24 hours following their capture, subject to any special requirements for further retention in connection with public holidays or office closures, as well as in the event that we are required to comply with a specific investigative request from the judicial authorities or the judicial police. Thereafter, the images will be overwritten by subsequent ones, thereby deleting the previous ones.
Personal Data will be retained for the period strictly necessary to fulfil the purposes set out in the previous paragraph.