Privacy Notice (pursuant to Articles 13 and 14 of the European Regulation No. 679/2016)
Grandi Stazioni Rail S.p.A., in the context of the activities carried out for the management of the Purchasing Portal and contractual procedures, processes the personal data of Economic Operators and Contractors that Grandi Stazioni Rail S.p.A. has become aware of for purposes related to the aforementioned activities, including the management of tender procedures, negotiation, conclusion, and execution of contracts, as well as the management of any additional and modifying acts, resolutions, and transactions, in accordance with the methods detailed below.
In this section, we provide our contact details:
Grandi Stazioni Rail S.p.A., the Data Controller, represented by the current CEO, can be contacted via email at titolaretrattamento@grandistazioni.it, with its registered office at Via Giovanni Giolitti No. 34, 00185 Rome.
The Data Protection Officer (DPO) can be contacted via email at protezionedati@grandistazioni.it.
In this section, we outline the types of data we request from you:
The personal data (of Economic Operators and Contractors represented by natural persons or of natural persons, also included in the declarations made for carrying out preliminary checks belonging to their organizations) subject to processing fall into the following categories:
Common data acquired directly from the Economic Operator and Contractor:
Personal details, tax identification code, identity document identifiers (e.g., driving license/ID/passport number), contact details (PEC, email, phone contacts). Based on the needs related to specific contractual procedures, other data may also be processed, including: bank details, economic/financial data, income data, vehicle license plate, credentials, personal identification code (CID), credit card number, credit card transactions, data in CVs (academic qualifications, membership in professional registers/categories).
Data of the Economic Operator and Contractor acquired from Public Administrations and Judicial Authorities in the context of fulfilling obligations related to the execution of contractual procedures: judicial data for checks on exclusion grounds as provided by applicable public procurement laws (D.Lgs. No. 50/2016 and subsequent amendments, and D.Lgs. No. 36/2023 and subsequent amendments), including anti-mafia checks in compliance with current regulations (D.Lgs. No. 159/2011 and subsequent amendments); data related to compliance with tax and contribution obligations.
The processing of judicial data is carried out exclusively within contractual procedures based on the applicable public procurement laws or in the case of signing legality protocols.
Personal data related to marriage, civil union, or cohabitation (special data pursuant to Article 9 of Regulation (EU) 2016/679):
These may be provided in forms used for carrying out preliminary checks, potentially revealing sexual orientation.
The above data will be processed using both electronic and paper-based systems, ensuring appropriate security measures and confidentiality.
In this section, we explain why we ask for your data:
The data we request you to provide are collected and processed for the management of the Purchasing Portal, for carrying out tender procedures, for negotiation, for the conclusion and execution of Contracts, for the management of any additional and modifying acts, and for contract resolutions, as well as for managing transactions.
The processing of personal data is legitimized by the following legal bases:
The necessity of processing for the stipulation and execution of the contract, even in the pre-contractual phase of registering the Economic Operator/Contractor on the Purchasing Portal and in the pre-contractual phases of tender and negotiation (Article 6(1)(b) of Regulation (EU) 2016/679);
The necessity of processing to comply with legal obligations to which the Data Controller is subject (Article 6(1)(c) of Regulation (EU) 2016/679);
Legitimate interest for verifying the absence of conflicts of interest/correlation/pantouflage.
Judicial data are processed to verify the absence of exclusion grounds based on the current public procurement regulations, as provided by letter i) paragraph 3 of Article 2-octies of Legislative Decree No. 196/03 and subsequent amendments, as well as for purposes related to the signing of legality protocols, as provided by letter h) paragraph 3 of Article 2-octies of Legislative Decree No. 196/03 and subsequent amendments, or to fulfill legal obligations related to communications and anti-mafia information or the prevention of mafia-type criminal activity and other serious forms of social danger.
We guarantee that the data provided through the completion of the forms used for conducting preliminary checks will be processed exclusively for the purposes mentioned above.
The provision of data necessary for pursuing the aforementioned purposes is "mandatory," and any refusal could result in Grandi Stazioni Rail S.p.A. being unable to manage the activities related to the contractual procedures in compliance with the legal requirements
In this section, we explain who will process your data and to whom it will be communicated:
The personal data provided for the pursuit of the above-mentioned purposes will be processed by the following parties:
Scope related to Grandi Stazioni Rail S.p.A.:
Authorized individuals for data processing: Personal data will be accessible only to those within Grandi Stazioni Rail S.p.A. who need it for their duties or hierarchical position. These individuals will be properly trained to prevent data loss, unauthorized access, or unauthorized processing of the data.
FS Italiane Group companies, which may, in turn, share the data or allow access to their employees and potential consultants, as necessary for achieving the purposes outlined in section III.
IT service companies, which are suppliers of Grandi Stazioni Rail S.p.A. These companies act as Data Processors on behalf of Grandi Stazioni Rail S.p.A. and have signed a specific Data Protection Agreement that governs the processing entrusted to them, as well as their obligations and security measures for data protection.
Scope not related to Grandi Stazioni Rail S.p.A.:
Personal data may be transmitted to Public Authorities and Judicial Authorities, based on laws or regulations, who act as Autonomous Data Controllers.
In this section, we assure you that your data will not be disclosed:
Personal data will not be subject to disclosure. Institutional publication applies only to information related to contractual procedures necessary to fulfill legal obligations regarding contract publicity, transparency, and anti-corruption.
In this section, we explain how long we will retain your data:
The personal data provided and collected will be retained:
For purposes under sub 1 and sub 2: The personal data you have provided will be kept for a period not exceeding 10 years from the expiration of the Contract or from the date of award for the additional purposes mentioned above, unless there are other requirements due to requests from the Judicial Authority and/or authorities with equivalent status, or in the event of legal disputes before the competent judicial authorities.
For purpose under sub 3, only for the period necessary to achieve that purpose.
IIn this section, we explain the rights we guarantee you:
The EU Regulation 2016/679 (Articles 15 to 23) grants individuals the exercise of specific rights. In particular, in relation to the processing of personal data, the data subject has the right to request Grandi Stazioni Rail S.p.A.:
Access: You can request confirmation of whether or not a data processing activity concerning you is in place, as well as further clarification about the information provided in this notice.
Rectification: You can request that we correct or complete the data you have provided if it is inaccurate or incomplete.
Erasure: You can request that your data be deleted if it is no longer necessary for our purposes, if you withdraw your consent or oppose processing, if the processing is unlawful, or if there is a legal obligation to erase the data.
Restriction: You can request that your data be processed only for the purposes of retention, excluding other types of processing, for the period necessary to rectify your data, in case of unlawful processing for which you oppose erasure, if you need the data for exercising your rights in judicial proceedings, and finally, in case of opposition to processing while we are assessing whether our legitimate reasons override your interests.
Objection: You can object at any time to the processing of your data, unless there are legitimate reasons for us to process the data that override your rights, such as for the exercise or defense of legal claims.
Portability: You can request to receive your data, or have it transmitted to another data controller you specify, in a structured, commonly used, and machine-readable format.
Additionally, the data subject has the right to lodge a complaint if they believe their rights have been violated with the supervisory authority, which in Italy is the Garante per la Protezione dei Dati Personali.
At any time, the data subject can exercise their rights by contacting Grandi Stazioni Rail S.p.A. at titolaretrattamento@grandistazioni.it or by contacting the Data Protection Officer at protezionedati@grandistazioni.it.