CEA DIGITAL LAW

Privacy Policy

INTRODUCTION

Privacy Policy — CEA Digital Law®

Ref: CEA-RGPD-02 · Version 1.0 · Last updated: 1 April 2026 ceadigilaw.org · CTR 698529 (Dublin, Ireland) · dataprotection@ceadigilaw.org

1. Data controller

Entity  Comité Euro Americano de Derecho Digital — CEA Digital Law®
Type  Company Limited by Guarantee (CLG), not-for-profit
CTR  698529 (Companies Registration Office, Ireland)
Registered office  The Gables, Torquay Rd, Foxrock, Dublin 18, Ireland
Privacy  dataprotection@ceadigilaw.org
President  Antonio Tejeda Encinas
CEA Digital Law® is an entity with its own independent legal personality. META Channel Corporation Ltd. is a legally separate entity with its own registration number; it operates independently.

2. Processing principles

We process your data in accordance with the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability (Art. 5 GDPR).

3. Processing operations carried out

3.1 Contact form (/contáctenos/)

Data First name, surname, company/position, email, telephone, country, message
Purpose To respond to enquiries and manage institutional or pre-contractual relations
Legal basis Art. 6.1.b GDPR (pre-contractual measures) / Art. 6.1.f GDPR (legitimate interest in follow-up)
Recipients Authorised staff. Processors: Google Workspace (Gmail), IONOS SE (SMTP), WPMU DEV (hosting)
Transfers Google LLC (USA) — EU-US Data Privacy Framework. IONOS and WPMU DEV: EU
Retention 1 year where no formal relationship arises; duration of the relationship + 5 years if it is formalised

3.2 Collaboration form (/colabore/)

Data First name, surname, email, telephone, city, country
Purpose To assess the profiles of collaborators and authors for CEA Digital Law® content
Legal basis Art. 6.1.b GDPR — pre-contractual measures at the request of the data subject
Recipients Authorised staff. Processors: Google Workspace, IONOS SE, WPMU DEV
Transfers Google LLC (USA) — EU-US Data Privacy Framework
Retention 1 year if it does not proceed; duration of the active collaboration + 3 years if it is formalised

3.3 Publication of the profiles of members and officers

Data Full name, position, organisation, country, professional photograph
Purpose Dissemination of the organisational and representative structure of CEA Digital Law®
Legal basis Art. 6.1.f GDPR — legitimate interest. The persons listed hold representative positions in an organisation in which they participate voluntarily
Recipients General public, through the website
Retention For as long as the association with CEA remains active, or until removal is requested
Special right Immediate removal upon request to dataprotection@ceadigilaw.org

3.4 Photographs of institutional events

Data Photographic images of participants in CEA Digital Law® events
Purpose Documentation and dissemination of institutional activities
Legal basis Art. 6.1.f GDPR — legitimate interest in documenting the activities of a not-for-profit organisation
Recipients General public
Retention For as long as they remain relevant for historical documentation purposes, or until removal
Special right Immediate removal upon request to dataprotection@ceadigilaw.org

3.5 Communications and newsletter (when active)

Data Name and email address
Purpose Sending informative communications about CEA Digital Law® activities and events
Legal basis Art. 6.1.a GDPR — explicit consent by double opt-in
Recipients Authorised staff. Email provider: IONOS SE (EU)
Transfers No transfers outside the EEA
Retention Until consent is withdrawn or the subscription is actively cancelled

3.6 Cookies and web analytics

Data Browsing data, device identifiers, anonymised IP address
Purpose Statistical analysis of site usage; improvement of the user experience
Legal basis Art. 6.1.a GDPR — consent managed by the cookie plugin
Recipients Web analytics provider (Google Analytics 4). See the Cookie Policy
Retention Maximum of 13 months from the date of consent

4. Your rights

Under the GDPR, you have the right to:
  • Access: to know what data of yours we process and how
  • Rectification: to have inaccurate or incomplete data corrected
  • Erasure: to have your data deleted when it is no longer necessary or when you withdraw consent
  • Restriction: to temporarily suspend processing in the cases provided for by law
  • Portability: to receive your data in a structured format where applicable
  • Objection: to object to processing based on legitimate interest
  • Withdrawal of consent: at any time, without retroactive effect
Exercising your rights: Write to dataprotection@ceadigilaw.org stating your name, a copy of an identity document and the specific right concerned. A reply will be given within a maximum period of one month, which may be extended by two months on grounds of complexity.

5. Supervisory authorities

DPC — Ireland (lead authority) Data Protection Commission · dataprotection.ie · info@dataprotection.ie
AEPD — Spain Agencia Española de Protección de Datos · aepd.es

6. Security and minors

CEA Digital Law® has adopted the technical and organisational measures necessary to guarantee the security of personal data (HTTPS/TLS encryption, access control, confidentiality agreements). The services are aimed at professionals and at persons over 16 years of age.

7. Updates

This policy may be updated to reflect changes in practices or in the applicable legislation. The date of the last update appears at the beginning of the document. Substantial changes will be communicated proactively to the data subjects concerned.
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.