Processing of Personal Data for registration and participation in SELAE games

General information The  fulfilment of the object of this contract entails the  processing by SELAE of personal data (“Personal Data”) of the user. SELAE declares to scrupulously respect the  user’s fundamental  rights regarding the processing of their personal data, and strict compliance with current regulations.

The following are identified for the purpose of regulation and compliance in matters of protection of Personal Data:

• Regulation (EU) 2016/679 of the European Parliament and of the Council, concerning the protection of natural persons with regard to the processing of Personal Data and the free circulation of these data (“GDPR”).
• Organic Law 15/1999, of 13 December, on the Protection of Personal Data (“LOPD”), and Royal Decree 1720/2007, of 21 December, which approves the  LOPD’s Development Regulation (“RLOPD”), as long as they are not repealed,  in those terms which do not contradict the  GDPR. Note that the procedure in the Congress of the project of new  Organic Law on the Protection of Personal Data is  underway, which will foreseeably repeal and replace the current LOPD.


The purpose of the  processing is the  proper operational, commercial and legal management of the participation  by the user in the SELAE  lotteries when said participation is identified, and therefore, the use of the Platform.

It is reported that there are two different steps in the registry  processing. The first is related to the verification of registration data and the possibility of registering, in automated consultation with the General Directorate for the Regulation of Gambling (“DGOJ”);. For this purpose, only the strictly necessary data is collected. In the positive case, the second step occurs, which entails the collection of additional data, although strictly necessary, and the signing of the  gaming contract.

In case of rejection in the first step, the  data subject may request the support of the SELAE team, and in any case may exercise  their right to request that the decision not be made automatically.

The user can rectify and update various forms of Personal Data through the Platform, under a self-service system. They may also request changes through the Customer Service Department - note that these requests are processed as service requests and not as exercises of data protection rights.

The following information is provided regarding the processing of Personal Data, using the layer technique.

Layer I information

BASIC DATA PROTECTION INFORMATION

Reference

information

Data Controller

SOCIEDAD ESTATAL LOTERÍAS Y APUESTAS DEL ESTADO, S.M.E., LTD. (SELAE) – A86171964

Purposes

Management of participation in SELAE  lotteries when participation is identified through the Platform, which includes the aspects associated with the use of the Platform, including  for explanatory purposes:

  • Registration, modifications and terminations in the relationship and therefore in the Platform.
  • Purchase, payment and sharing of products and collection of prizes, within all  gaming modes.
  • Assistance and relationship, including assistance, information, complaints, suggestions, congratulations and claims.
  • Activities associated with the quality and safety of the Platform, including surveys regarding the service.
  • Activities related to legal compliance, including aspects of the  Gaming Act, Prevention of Money Laundering, Fraud Prevention and  as many regulatory aspects  as may be applicable, including the management of Personal Data rights.
  • Activities associated with the improvement and evolution of games, including data dissociation activities, statistical studies and  analytics/big data.
  • Activities associated with responsible game management and support for  responsible gaming by the user.
  • Provision of additional services, some of which include informative and commercial communications, always at the request of the  data subject.

Legitimation.

Legal basis

The  legitimating grounds for the  processing are:

-  Execution of a contract.

-  Compliance with a legal obligation (communications).

-  Consent of the interested party in the case that  processing is required.

Recipients

Economic communications to financial entities (banks and collection / payment instrument managers) used by the participant and by SELAE for product collections and payment of prizes.

No other communication  shall be made to other entities, except for those communications that occur due to obligation or legal necessity to entities that include, among others:

  • The Directorate General for the Regulation of  Gaming (“DGOJ”).
  • Tax authorities.
  • Others, such as SEPBLAC, the State  Law Enforcement Forces and Bodies, Judges, Public Prosecutor's Office, Courts and other Public Administrations or Authorities that may require it in the exercise of their powers.
  • Others, such as notaries, solicitors, solicitors and lawyers.

There are no transfers to third countries or international  organisations that do not offer  sufficient guarantees.

 

Rights

To access, rectify and delete data as well as other rights, as explained in the additional information.

Source of the Data

-  The  data subject.

-  The DGOJ in terms of viability of participant registration and  capacity for gaming.

-  Banking Entities of the  data subject.

 

Additional information

You can consult the additional and detailed information on Data Protection in the Information of Layer II (Information Note RGPD-Layer II, text below).

 

Layer II information

Applicable  regime in the Protection of Personal Data and Identity of the  Data Controller

The  fulfilment of the  purpose of this contract involves the processing of personal data, identifying, for purposes of regulation and compliance with the protection of personal data (“Personal Data”):

• Regulation (EU) 2016/679 of the European Parliament and of the Council, concerning the protection of natural persons with regard to the processing of Personal Data and the free circulation of these data (“GDPR”).
• Organic Law 15/1999, of 13 December, on the Protection of Personal Data (“LOPD”), and Royal Decree 1720/2007, of 21 December, which approves the  LOPD’s Development Regulation (“RLOPD”), as long as they are not repealed,  in those terms which do not contradict the  GDPR. Note that the procedure in the Congress of the project of new  Organic Law on the Protection of Personal Data is  underway, which will foreseeably repeal and replace the current LOPD.

In accordance with the applicable regulations,  SOCIEDAD ESTATAL  LOTERÍAS Y APUESTAS DEL ESTADO,  S.M.E.,  S.A. (hereinafter,  “SELAE”) declares to respect the requirements of the current regulations on the protection of Personal Data, and specifically in relation to the protection and the  fulfilment of the duty of secrecy of the Personal Data, and declares to apply, at least, the technical and  organisational measures that the legislation imposes.

And in particular, with regard to the collection and processing of Personal Data for the purposes associated with this contract, as follows:

Management of participation in SELAE  lotteries when participation is identified through the Platform, which includes the aspects associated with the use of the Platform, including  for explanatory purposes:

• Registration, modifications and terminations in the relationship and therefore  on the Platform.
• Purchase, payment and sharing of products and collection of prizes, within all  gaming modes.
• Assistance and relationship, including assistance, information, complaints, suggestions, congratulations and claims.
• Activities associated with the quality and safety of the Platform, including surveys regarding the service.
• Activities  related to legal compliance, including aspects of the  Gaming Act, Prevention of Money Laundering, Fraud Prevention and  as many regulatory aspects  as may be applicable, including the management of Personal Data rights. In the case of the Prevention of Money Laundering, the processing occurs in relation to the purchase of the product and/or collection of the prizes stipulated therein..
• Activities associated with the improvement and evolution of games, including data dissociation activities, statistical studies and analytics / big data.
• Activities associated with responsible game management and support for  responsible gaming by the user.
• Provision of additional services, some of which include informative and commercial communications, always at the request of the interested party.


Data Controller

SOCIEDAD ESTATAL LOTERÍAS Y APUESTAS DEL ESTADO, S.M.E.,  S.A. (SELAE)

• Tax ID No.: A-86171964
• Address: c / Poeta Joan Maragall, 53, 28020 Madrid.
• Phone: 900 11 23 13 / 91 596 23 00  (Customer Service)
• Contact with the Data Protection Officer:
• Postal: SELAE, Registry, attention  “Data Protection”,  C/Poeta Joan Maragall 53, 28020 Madrid
• Electronic: communication form at www.loteriasyapuestas.es


Personal Data, purposes and term during which the data is conserved 

In compliance with the principle of limitation of purpose, SELAE  shall only request and process  Personal Data that are appropriate, relevant and limited  in relation to the purposes for which they are  processed, being specific, explicit and legitimate purposes. The data collected and  their specific purpose, together with the conservation period and the consequence of not providing them, are:

Personal Data collected, obtained by means of disclosures and generated

Collected in the check with DGOJ verification of identity and possibility to participate (they will not be preserved if the registration is not completed):

• Given name, first and second surname (second surname, optional).
• Date of birth: day, month, year.
• NIE or NIF
• Processing

Obtained to complete the registration:

• E-mail
• Password
• Security question
• Secret response
• Country of residence
• Postal address including postal code
• Fiscal region
• Nationality
• Telephone number (optional)
• IBAN for deposit of prizes (optional)

Data received by means of disclosures:

• Gambling permit (DGOJ)
• Transfers from financial entities

Data generated as a consequence of the use of the Platform by the user:

• Stakes made
• Prizes received
• Income and payments
• Shared stakes
• Participatory groups
• Records of the SAC
• Exercise of rights

All the foregoing

For commercial purposes:

• Given name (does not include Surnames)
• Email (if the channel is activated)
• Telephone number (if the channel is activated)
• Date of birth (surveys)
• Processing

Purposes

All those indicated, except the ones related to crime prevention or commercial information.

Term of retention

6 years following the termination of the contract and effective removal from the Platform.

Consequence if the data are NOT provided

You may not register if you do not provide all the data to be collected, except those indicated as optional.


Legal basis of the processing 

The various components of the processing carry various legitimating grounds. They are:

• Execution of the Gaming Contract (present contract).
• Compliance with legal obligations and needs:

• Law 13/2011, of 27 May, regulating gaming
• Law 10/2010, of 28 April, on the prevention of money laundering and the financing of terrorism
• Law 58/2003, of 17 December, General Taxation Law
• Other rules applicable to the Data Subject.


• Consent of the user.

The following are applicable:

• Both contractual and compliance obligations and legal requirements for participation (use of the Platform).
• Those of consent to those additional services specified in the contract or offered by the Platform that may require consent, and that the user can manage through the corresponding selection panel of the user area.



Recipients of Personal Data


The following disclosures of Personal Data are foreseen:

Economic communications to financial entities (banks and collection/payment instrument managers) used by the participant and by SELAE for product collections and payment of prizes.

No other communication shall be made to other entities, except for those communications that occur due to obligation or legal necessity to entities that include, among others:

• The Directorate General for the Regulation of Gambling (“DGOJ”), the authorising body and supervisor of the gaming sector. Communications for the exercise of its functions and the fulfilment of SELAE, which include the verification of identity and subjective prohibitions, the control of gaming, and when applicable to meet other legal obligations or requirements.
• Tax Authorities, including the State Agency of Tax Administration and the corresponding Autonomous Region Agencies. Communications for the entry of the withholdings made in the larger prizes and the satisfaction of whichever fiscal obligations are normatively established.
• Others, such as SEPBLAC, the State Law Enforcement Forces and Bodies, Judges, Public Prosecutor's Office, Courts and other Public Administrations or Authorities that may require it in the exercise of their powers. In order to carry out the communication, any pertinent documentation must be required.
• Others, such as notaries, attorneys, attorneys and lawyers, to satisfy any legal needs that may arise for the legal defence of SELAE’s interests.

 

The following Transfers are planned:

There are no transfers to third countries or international organisations that do not offer adequate guarantees, except in the event that the user provides a contact email address whose service provider may be involved in such situation.

Note that the service provider processes personal data on behalf of the data subject and not of SELAE, therefore, this aspect is the responsibility of the user.

 

Exercise of rights and Contact Data of the Data Protection Officer

The user has the right to ask SELAE to exercise their rights in relation to their Personal Data.

SELAE, as the Data Controller/Data Processor, guarantees the data subjects the exercise of the legally established data protection rights, including those including the request for the right to:

• Access to their personal data
• Rectification or deletion of their personal data
• Limiting of their processing
• Opposition to their processing
• The portability of the data
• Exclusion of automatic decisions
• Any other rights included in current regulations

You can exercise your rights:

a) Either by means of a written request duly signed and sent by postal mail to: SELAE, Register, Att: “Data Protection” service, C/Poeta Joan Maragall 53, 28020 Madrid (or whichever channel may complement or replace it, and, as long as the requirement is maintained, the general register of the Spanish Data Protection Agency is notified), with the reference “Exercise of Rights”, clearly and expressly indicating the processing referred to in the exercise of the right, the petition or right being exercised as well as the given name, surname(s) and postal address for the response, and attaching a copy of both sides of a reliable identification document (DNI, NIE, Passport or Driver’s Licence) on, in order to identify you unequivocally. SELAE will process said personal data on the legitimating grounds of legal compliance, with the sole purpose of responding to your exercise of your rights.

b) Or by means of a request sent through the communication form with the Data Protection Officer on www.loteriasyapuestas.es. You must provide a contact email address of a stable mailbox where you can receive communications and, to complete the request, the user must send an email to the address indicated, an email that must be issued with an advanced signature using a recognised electronic certificate among those accepted by the Public Administrations.

You also have the right to contact the Data Protection Officer of SELAE and this contact can be made using the mechanisms described above.

The user may withdraw any consent that has been given without affecting the legality of the processing based on the consent prior to its withdrawal. You may, in addition to the modification in the Platform through self-service through the corresponding selection panel, and the Customer Service Department, contact the Data Protection Officer.

Claim made to a Supervisory Authority

Participants have the right to seek the protection of the Spanish Data Protection Agency, an independent authority for monitoring compliance with data protection regulations.

Existence of Automated Decisions (including profiling)

The users are not profiled. There is only one automated decision, corresponding to the user registration, and as required by the Gaming Act. It consists of comparing the data provided by the user with that of the DGOJ, and, following the indications of their systems, to reject or admit the registration of the user, based on the verification of said data and its entry or otherwise into subjective prohibitions. The user can contact the Customer Service Department.

Source of Personal Data

All data is collected from the data subject, except for:

• Feasibility of registration of the participant and the situation regarding capacity for gambling (no gambling ban), information provided by the Directorate General for the Regulation of Gambling.
• Banking Entities of the data subject.