CHANGES IN THE PROCESSING OF YOUR PERSONAL DATA REQUIRED BY ROYAL DECREE 958/2020

Detection of Possible Risk Behaviours and Actions Deriving From Them

It involves behavioural profiling, automated decision making, and the need to accept/consent

Version 20201223A-P

Alert

Relevant information on changes due to regulatory obligation to the processing of your personal data, which entails profiling of your behaviour, automated decision making, the need to accept/consent in order to detect risk behaviours and take action in such case.

From this moment you can only make gaming purchases or make deposits to Lotobolsa by accepting/consenting to the new aspects of the processing of your personal data. Only the data of purchases/deposits made since 15 January will be processed, not the ones made before then. The subscriptions that you may have will be disabled on 15 January unless you accept/consent to the new aspects first, which requires making at least one bet or making one deposit before that date as a way to show your acceptance/consent.

The rest of this page presents general information and Layer I information regarding the new aspects of the processing. When making a gaming purchase or deposit to your lotobolsa we will remind you of this information. This information, as well as more extensive information (Layer II) can be viewed and downloaded in PDF format from  https://www.loteriasyapuestas.es/f/loterias/web_corporativa/DatosPersonales/ClientesyUsuarios/Inscritos/vigente/EstipulacionesDatosPersonales-JuegoResponsable.html

The general terms and conditions for the processing of personal data are contained in the gaming contract that you can consult at https://juegos.loteriasyapuestas.es/jugar/cas/configuracion/datos-cuenta/politicas.

 

General information on the new aspects of the processing of your personal data by SELAE for the purposes of Royal Decree 958/2020

The recently approved Royal Decree 958/2020, of 3 November, on commercial communications regarding gambling activities (available in the BOE, at www.boe.es/eli/es/rd/2020/11/03/958/con obliges the entire sector and therefore also SELAE to modify some aspects of its operations, among them, to analyse the purchases of each registered user in order to detect possible risk behaviours and, in the case of detected cases, to take the appropriate action.

This entails new aspects in the processing of your personal data (due to legal obligation), which requires that previously

-   you are duly informed: on this page, which is presented (once) to all users after logging in, we inform you extensively, as well as we remind you at the time of each gaming purchase and each lotobolsa deposit, and that

-   you accept/consent to the new aspects of the processing that we will carry out from 15 January: proceeding to complete the gaming purchases or lotobolsa deposits, as indicated in said pages, entails declaring that you understand and agree to have been informed and that continuing with the purchase/deposit, you declare that you accept/consent to the processing by SELAE of your personal data for the detection of risk behaviours as required by Royal Decree 958/2020, in a free, specific, informed and unequivocal manner.

If at any time you do not accept/consent to the processing, it is sufficient that you avoid making any deposits or gaming purchases. Since the processing is a legal requirement, it is not possible to refuse your consent and make a deposit to lotobolsa or participate in any games.

These terms and conditions complement what is indicated in the gaming contract.

The information on your gaming purchases and lotobolsa deposits must be processed to comply with the established regulations, for the following purposes:

-   Detection of possible risk behaviours

-   The execution, in case of detection, of the legally required measures:

o   sending an email (or equivalent means) informing you that it has been detected that you may have developed a risk behaviour;

o   restriction of issuance of commercial communications;

o   other possible measures adopted within SELAE’s Responsible Gaming framework contemplated in its action protocol. You can obtain information on other possible measures adopted within SELAE’s Responsible Gaming framework here: https://www.selae.es/es/web-corporativa/responsabilidad-social/gestion-responsable-del-juego/juego-responsable

-   The execution, in the case of self-prohibition and self-exclusion, of the legally required measures: the suspension of the gaming account and communication of the consequences associated with said suspension

The new aspects of the processing entail profiling your behaviour, generating data that may eventually be considered of special characteristics, and automated decision making.

The detection of possible risk behaviours will come into effect on 15 January, processing for this purpose all gaming purchases or lotobolsa deposits that occur after that date, but none of the ones prior to that date. If your wish is that your data is not processed for the purpose of determining possible risk behaviours, you should not make any purchase or deposit after 14 January.

The rest of this page presents Layer I of information regarding the new aspects of the processing. At the time of making a gaming purchase or a deposit to lotobolsa we will remind you that you are going to accept/consent to the new aspects of personal data processing and that when purchasing or making a deposit to lotobolsa you declare to be informed and accept/consent to the new aspects of the processing.

This information, as well as more extensive information (Layer II) can be viewed and downloaded in PDF format from  https://www.loteriasyapuestas.es/f/loterias/web_corporativa/DatosPersonales/ClientesyUsuarios/Inscritos/vigente/EstipulacionesDatosPersonales-JuegoResponsable.html

The general terms and conditions for the processing of personal data are contained in the gaming contract that you can consult at https://juegos.loteriasyapuestas.es/jugar/cas/configuracion/datos-cuenta/politicas.

 

 

Tratamento de datos persoais. Información básica (capa I)

Processing of personal data - Basic information (layer I)

We inform you of how SELAE processes and protects your data to detect possible risk behaviours and the actions that arise in such case.

 

Data Controller

SOCIEDAD ESTATAL LOTERÍAS Y APUESTAS DEL ESTADO, S.M.E., S.A. (SELAE) – A86171964

Purposes

Comply with the regulations established for Responsible Gaming: for the detection of risk behaviours; for the execution, in case of detection, of the legally required measures: sending an email (or equivalent means) informing you that it would have been detected that you could have developed risk behaviours, restriction of the issuance of commercial communications, and other possible measures adopted in the Responsible Gaming framework of SELAE contemplated in its action protocol; and the execution, in case of self-prohibition and selfexclusion, of the legally required measures: the suspension of the gaming account and communication of the consequences associated with said suspension.

You can obtain information on other possible measures adopted within SELAE’s Responsible Gaming framework here:
https://www.selae.es/es/web-corporativa/responsabilidad-social/gestion-responsable-del-juego/juego-responsable

The foregoing must be understood with the implications that it entails: as in any processing, the data must be processed to satisfy business obligations within the legal framework and management needs - such as the corresponding economic-financial control of transactions and audits as detailed in Layer II - while always respecting due confidentiality and privacy and the principles of data minimisation and being pseudonymised or anonymised when feasible.

Legitimation

The legitimising basis of the processing is the legal obligation, within the development of a contractual relationship.

Recipients

SELAE does not carry out any systematic communication to other entities.

One-off communications may be produced for reasons of protection of SELAE’s interests and legal needs that could arise for the administrative and legal defence of SELAE’s interests.

The regulations do not consider communications that are made at the request of Authorities within the legal framework, which, if applicable, are mandatory.

SELAE does not transfer these data to third countries or international organisations that do not offer sufficient guarantees.

Profiling with data result of special characteristics and automated decision making

A profile is drawn up since the data is processed to detect eventual risk behaviours (behaviour evaluation), the result of the profile being a piece of data that may have special characteristics.

For the detection of possible risk behaviours, the existence of activity patterns based on the volume, frequency and variability of product purchases and deposits to the lotobolsa will be evaluated objectively and automatically, without prejudice to other quantitative or qualitative elements that may also be relevant according to the mechanics of the different games or the experience of SELAE.

The evaluation will be carried out in an automated manner. In case of detection, the data subject will be informed. You have the right to obtain human intervention from SELAE to express your point of view and challenge the decision.

Consent

Based on the plausible generation of personal data as a result of the profiling based on precaution, consent to the processing will be obtained.

Rights

To access, rectify and delete data as well as other rights, as explained in the Layer II information.

Source of the data

The data originates from the actions of the data subject, but they are derived, not collected from the data subject.

Period of retention

This data is processed for the purposes of compliance with gambling regulations, which require that the data be retained for six years following the termination of the gaming contract.

Additional information

You can consult additional and detailed information on Layer II Data Protection below.

 

 

Processing of personal data - Detailed information (Layer II)

SELAE offers digital access to its gaming products through its Digital Game Marketing Platform (which includes the loteriasyapuestas.es website and SELAE's official apps). The platform allows, among other functionalities fully described in the gaming contract, the purchase of SELAE games, the subscriptions and collection of the corresponding prizes that are paired with the corresponding collection and payment mechanisms respectively. Likewise, these services entail the submission of information identified as essential for the development of the relationship. In addition, you can select to receive additional services among which there are various information services regarding the games and commercial activities of SELAE.

All these operations entail the processing of various personal data of those who voluntarily register on the platform and sign the gaming contract, where the processing are described in detail. The sole purpose of data processing is to provide the indicated services, which entails processing the data to satisfy business obligations within the legal framework and management needs of SELAE as detailed below, as well as meeting the justified requirements of the authorities with powers in the corresponding matters.

This information responds to the additional processing of personal data that SELAE needs to carry out to comply with the Responsible Gaming regulations established in Royal Decree 958/2020, of 3 November, on commercial communications regarding gambling activities (available in the BOE, at www.boe.es/eli/es/rd/2020/11/03/958/con). The processing will come into effect on 15 January, covering all gaming purchases or lotobolsa deposits that occur after that date, but none of the ones prior to that date. If your desire is for your data not to be processed, you should not make any purchases or deposits after 14 January.

 

Purpose of the additional processing:

The information on your gaming purchases and lotoblosa deposits will be processed in order to comply with the regulations established regarding Responsible Gaming, for the following:

-   Detection of possible risk behaviours

-   The execution, in case of detection, of the legally required measures:

o   sending an email (or equivalent means) informing you that it has been detected that you may have developed risk behaviours;;

o   restriction of issuance of commercial communications;;

o   other possible measures adopted within SELAE’s Responsible Gaming framework contemplated in its action protocol. You can obtain information on other possible measures adopted within SELAE’s Responsible Gaming framework here: https://www.selae.es/es/web-corporativa/responsabilidad-social/gestion-responsable-del-juego/juego-responsable

-   The execution, in the event of self-prohibition and self-exclusion, of the legally required measures: the suspension of the gaming account and communication of the consequences associated with said suspension.

This includes meeting business obligations within the legal framework and management needs of SELAE.

The new aspects of the processing entail the profiling of your behaviour, generating data that may be considered to have special characteristics, and automated decision making.

The regulations that protect your rights to protect personal data always require that you are duly informed, and especially when the processing may be intensive or significant. On the other hand, since it could be considered that some of the data could have sensitive aspects, out of prudence in the protection of your rights, SELAE has considered that it is necessary that in order to deal with you, you accept/consent to said processing. The consequence of not doing so is not being able to purchase gaming products or make deposits to lotobolsa. Since the processing is a legal requirement, it is not possible to refuse consent and simultaneously participate in the games or make deposits to lotobolsa. If at any time you decide to stop accepting/consenting to the processing (which does not have retroactive effects), it is enough that you do not make any deposits or gaming purchases.

The information is presented to all those registered once after accessing (login) the platform, although it is always accessible at the addresses indicated below. It is reiterated and facilitated in a link to the extensive information at the time of each product purchase and deposit to lotobolsa - a purchase and deposit that entails declaring that you understand and accept having been informed and that by continuing with the purchase/deposit you declare that you accept/consent to the processing by SELAE of your personal data for the detection of risk behaviours as required by Royal Decree 958/2020, in a free, specific, informed and unequivocal manner.

The processed data, which are incorporated into a file, are circumscribed in the data on purchases and deposits to lotobolsa.

In any case, SELAE declares that it will scrupulously respect the user’s fundamental rights regarding the processing of their personal data, and in strict compliance with current regulations:

·  Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and the free movement of such data (“GDPR”).

·  Spanish Organic Law 3/2018, of 5 December, on Personal Data and Digital Rights Protection (“LOPDP”).

These terms and conditions on processing and protection of personal data complement what is indicated in the gaming contract, with regard to the new features introduced by Responsible Gaming.

Data Controller

SOCIEDAD ESTATAL LOTERÍAS Y APUESTAS DEL ESTADO, S.M.E., S.A. (SELAE)

§  Tax Identity Number: A-86171964

§  Address: c/ Poeta Joan Maragall, 53, 28020 Madrid.

§  Telephone No.: 900 11 23 13 / 91 596 23 00 (Servicio de Atención al Cliente)

§  Contact the Data Protection Officer (DPO)

§  By post: SELAE, Registry, attention “Data Protection”, C/Poeta Joan Maragall 53, 28020 Madrid

§  Electronic: communication form athttps://www.loteriasyapuestas.es/es/contacto-proteccion-datos

 

Personal Data, purposes and term during which the data is conserved

In compliance with the principle of limitation of purpose, SELAE shall only request and process Personal Data that are appropriate, relevant and limited in relation to the purposes for which they are processed, being specific, explicit and legitimate purposes. The data collected and their specific purpose, together with the conservation period and the consequence of not providing them, are:

Personal Data collected, obtained by means of disclosures and generated

Purposes

Term of Retentionn

If the data is NOT provided

Collected:

Those already collected in terms of participation in the games and deposits to lotobolsa: all purchase data (game, day, quantity, combinations, purchase date and time) and lotobolsa deposits (addition method, quantity, date and time).

Generated: profiling produced, existence or absence of possible risk behaviour, communications about the eventual situation.

Compliance with gambling regulations.

The detection of possible risk behaviours.

The execution, in case of detection, of the legally required measures:

-          sending an email (or equivalent means) informing you that it has been detected that you may have developed a risk behaviour;

-          restriction of issuance of commercial communications;

-          Other possible measures adopted within SELAE’s Responsible Gaming framework contemplated in its action protocol. You can obtain information on other possible measures adopted within SELAE’s Responsible Gaming framework here: https://www.selae.es/es/web-corporativa/responsabilidad-social/gestion-responsable-del-juego/juego-responsable

The execution, in the event of self-prohibition and selfexclusion, of the legally required measures: the suspension of the gaming account and communication of the consequences associated with said suspension.

This includes satisfying corporate compliance obligations within the legal framework and the management business activities of SELAE necessary for the correct provision of the service and its improvement, and the defence of SELAE’s interests. This includes the governance, direction, management, monitoring, supervision and auditing of the service, which entail aggregated statistical analysis, process improvement, information protection and compliance with regulations, including the protection of personal data; all within the scope of compliance with Royal Decree 958/2020 - always respecting due confidentiality and privacy and the principles of data minimisation and being pseudonymised or anonymised when feasible, as soon as it is feasible.

For 6 years after the date of the transaction, although it can be interrupted in the event of legal actions.

Corresponds due to legal obligation, for the purposes of compliance with the Gambling Regulation law.

You will not be able to buy SELAE gaming products or make a depositto lotobolsa.

 

Legal basis of the processing

The various components of the processing carry various legitimate bases. They are:

The legitimising basis of the processing is Royal Decree 958/2020, of 3 November, on commercial communications regarding gambling activities, as well as contractual (Gaming Contract).

 

Recipients of Personal Data

The following disclosures of Personal Data are foreseen:

No systematic communication of the data generated as a result of the processing is contemplated.

One-off communications may be produced to satisfy the protection of SELAE’s interests and legal needs that may arise for the administrative and legal defence of SELAE’s interests, such as in administrative actions and litigation, which, among others, include communications to notaries public, solicitors and lawyers. The data communicated, except legal obligation or procedural need, will be previously dissociated.

The regulations do not consider communications to the transfer of data that may occur under the request of the State Security Forces and Bodies, Judges, Public Prosecutor’s Office, Courts and Tribunals and other Public Administrations or Authorities that require it in the exercise of their powers within the legal framework, which, if applicable, are mandatory. In order to carry out the communication, any pertinent documentation must be required. In principle, the General Directorate for the Regulation of Gambling is the competent authority in this matter, and it must have a relevant cause to access the data such as in an inspection procedure. The regulations do not contemplate a systematic and periodic transfer of these data.

 

Transfers:

SELAE does not effect transfers of these data to third countries or international organisations that do not offer sufficient guarantees. Cross-border transfers to countries that offer adequate guarantees are also not contemplated, but SELAE reserves the right granted by the personal data protection regulations to do so, in terms of processing orders carried out on behalf of SELAE in countries that offer sufficient guarantees.

 

Profiling, Special Data and Automated Decision Making:

A profile is drawn up since the data is processed to detect eventual risk behaviours (behaviour evaluation), the result of the profile being a piece of data that may have special characteristics.

For the detection of possible risk behaviours, the existence of activity patterns based on the volume, frequency and variability of product purchases and deposits to the lotobolsa will be evaluated objectively and automatically, without prejudice to other quantitative or qualitative elements that may also be relevant according to the mechanics of the different games or the experience of SELAE. The evaluation will be carried out in an automated manner. In case of detection,

the data subject will be informed. You have the right to obtain human intervention from SELAE to express your point of view and challenge the decision.

 

Consent

Based on the plausible generation of personal data as a result of the profiling based on precaution, consent to the processing will be obtained.

 

Exercise of rights and contact details of the Data Protection Officer

 

The user has the right to require that SELAE allows them to exercise their rights regarding personal data.

SELAE, as the Data Controller/Data Processor, guarantees the data subjects the exercise of the legally established data protection rights, including those including the request for the right to:

·  Access their personal data

·  Rectification or deletion of their personal data

·  Limit their processing

·  Object to their processing

·  The portability of the data

·  Exclusion from automatic decisions

·  Any other rights included in current regulations

§  Withdrawal of acceptance/consent to the processing of data for purposes of compliance with Royal Decree 958/2020 (Responsible Gaming) with the associated consequences.

You can exercise your rights:

a) By means of a request sent by via the Data Protection Form to the Data Protection Officer on this page: https://www.loteriasyapuestas.es/es/contacto-proteccion-datos

b) By means of a written request duly signed and sent by postal mail to: SELAE, Register, Attn: Data Protection Service, Calle Poeta Joan Maragall 53, 28020 Madrid, Spain (or whichever channel may complement or replace it), with the reference “Exercise of Rights”, clearly and expressly indicating the processing referred to in the exercise of the right, the petition or right being exercised as well as the given name, surname(s), National Identity Document, Foreign Residency Document or Passport number and postal address for the response, and attaching a copy of both sides of a reliable identification document (National Identity Document, Foreign Residency Document, Passport or Driver’s Licence) in order to unambiguously identify you. SELAE will process said personal data on the legitimate basis of legal compliance, with the sole purpose of responding to your exercise of your rights.

c) You can also send it by sending an electronic file, although this requires that the exercise be signed with an advanced electronic signature with a recognised digital certificate.

You can obtain detailed information on the processing of your personal data for the exercise of rights athttps://www.loteriasyapuestas.es/es/contacto-proteccion-datos

You also have the right to contact the SELAE Data Protection Officer. This contact can be made using the mechanisms described above.

 

Claim made to a supervisory authority

Data subjects have the right to seek the protection of the Spanish Data Protection Agency, the independent authority that monitors compliance with data protection regulations.

 

Source of personal data

Product purchase and lotobolsa deposit data are collected from the customer.

The data generated is derived by SELAE from the above.

 

OTHER TERMS AND CONDITIONS

Special Categories of Data

SELAE will not ask the customer for data regarding special categories.

 

Other Services (digital, telephonic and postal)

SELAE attends to the matters of the participants registered in its Digital Gaming Marketing Platform, including those related to these processing aspects, in a channelled way through its Customer Service Centre, with the consequent data protection provisions corresponding to said processing, as described in https://www.loteriasyapuestas.es/es/contacto

 

Anonymisation, aggregation and subsequent uses

The information processed may be anonymised (with or without previous aggregation), after it has been dissociated, for later use by SELAE or by third parties for statistical, historical, analytical or research purposes and for the improvement of its services.

 

Acceptance

In accordance with all of the foregoing, if the data subject does not agree with this additional processing of their personal data by SELAE, they must refrain from buying a gambling product and from making a deposit to their lotobolsa using SELAE’s Digital Gaming Marketing Platform.

 

Liability of SELAE

SELAE hereby informs the user that this entity is only responsible and only guarantees the confidentiality, security and processing of the data in accordance with these terms and conditions with respect to the personal data collected from the user through the Digital Gaming Marketing Platform. Moreover, it accepts no liability for any processing and subsequent uses of personal data that could be carried out by third party service providers from the information society that may access such data to provide their services or pursue their business activities. Third-party providers of information society services shall be understood, albeit not restricted to the same, as those natural or legal persons who provide the following services:

(i) transmission over a communication network of data provided by the recipients of the service;

(ii) access services to said network;


 

Data quality

SELAE hereby informs data subjects that, except for the existence of a legally constituted representation, no person can use the identity of another person and communicate their personal data. Accordingly, data subjects must always remember that, if they communicate personal data through any medium to SELAE, it can only include personal data corresponding to their own identity and that are appropriate, pertinent, current, accurate and genuine.

Accordingly, data subjects will be solely responsible for any damage, direct and/or indirect, caused to third parties or SELAE due to use of personal data of another person, or their own personal data when they are false, erroneous, not current, inadequate or not relevant.

Likewise, data subjects who communicate the personal data of a third party to SELAE must have due authorisation from the third party and will be answerable to SELAE and the third party for this obligation, without SELAE having to carry out any additional action, and relieving SELAE of any liability in this respect.

 

Updating of terms and conditions

The necessity or desirability of updating these terms and conditions may arise. Any modification will be published and warned on SELAE’s Digital Gaming Marketing Platform, and the data subject must take into account that the processing of personal data by SELAE will be governed by current terms and conditions. Changes that entail substantial modifications must be communicated to the data subject, without prejudice to the responsibility of the customer to periodically access the terms and conditions published at all times in order to be aware of the latest version in force. The history and modifications are indicated below:

 

Date

Version

Chanages

23 December 2020

20201223A-P

Initial version in production

 

 

This information can be viewed and downloaded in PDF format from  https://www.loteriasyapuestas.es/f/loterias/web_corporativa/DatosPersonales/ClientesyUsuarios/Inscritos/vigente/EstipulacionesDatosPersonales-JuegoResponsable.html

The general terms and conditions for the processing of personal data are contained in the gaming contract that https://juegos.loteriasyapuestas.es/jugar/cas/configuracion/datos-cuenta/politicas.