Data Privacy Policy

Effective since 24 May 2018, in line with GDPR

General information

The European Public Real Estate Association (EPRA) takes your privacy seriously and manages your data in accordance with the European General Data Protection Regulation (GDPR) and other applicable data protection regulations. This Privacy Policy seeks to inform you, in a transparent manner, about the data we collect, the purpose of collecting it, how long we store it for, the way we use it and the rights you have regarding the processing of such data.

This Privacy Policy explains how we collect, process and use personal data in connection with the operation of our website. Personal data comprises of details about your personal or factual circumstances. We process your personal data that we collect, store and use exclusively within the framework of the applicable legal regulations.

We invite you to read this data privacy policy thoroughly. If you have any other questions, do not hesitate to contact our responsible Data Protection Officer (DFO), at the following e-mail address: barney.coleman@epra.com - Barney Coleman, EPRA Director of Operations.

By visiting our webpage, subscribing to our newsletter or registering to our events, you (hereinafter also referred to as Data Subject) will give your consent for the processing of your personal data in accordance with the following terms and conditions. The processing of personal data is necessary for the purposes referred to in this Data Privacy Policy.

As the data controller, EPRA has implemented numerous technical and organisational measures to ensure the most complete protection of personal data processed through our website. However, Internet-based data transmissions may in principle have security gaps, so absolute protection may not be guaranteed. For this reason, every Data Subject is free to transfer personal data to us via alternative means, e.g. by telephone.

 

Processing of personal data and transfer to third parties

 

The data processor liable for the use of personal data is The European Public Real Estate Association (hereinafter also referred to as Processor or EPRA), address Square de Meeus 23, 1000 Brussels, Belgium, e-mail info@epra.com, not-for-profit association registered in Belgium under number 0811738560 and VAT registration number BE 0811.738.560.

The Processor shall have the right to authorise other persons or institutions (hereinafter also referred to as Authorised Processor) to process the personal data of the Data Subject, provided that the Processor and Authorised Processor have entered into an agreement,pursuant to which the Authorised Processor shall be obligated to keep the data to be processed confidential and ensure the performance of obligations arising from the applicable laws to the Authorised Processor.

The Processor shall make an up-to-date list detailing the names, addresses and other contact information of all of the Authorised Processors available to the Data Subject upon the Data Subject's request.

The Processor currently uses the following third-party services, that have been authorised as processors. The Authorised Processors have confirmed their status as GDPR compliant.

 

      • MailChimp;
      • Wordpress;
      • Flickr;
      • Google Analytics;
      • YouTube/Vimeo videos, Twitter feeds;
      • Typeform;
      • DocuSign;
      • Google Translate;
      • Google Maps;
      • Google Fonts.
    • This personal data is processed on the basis of Article 6(1)(f) GDPR. The protection of our

website and the optimisation of our services constitute a legitimate interest of the European Public Real Estate Association.

    1. We use Google Analytics, which is a web analysis service from Google Inc., that uses text files

which are stored on your device and allow the analysis of your use of the website.

    1. Any information collected by analysing services is anonymous and is carried out within the scope of this privacy policy. It is not possible to establish a connection to a visitor. This is done in particular by anonymising the IP address.
    2. We do use cookies, but mainly to ensure functionality of the website - please read our 1Y.U

cookie policy here and should you need more information, please contact our DPO at barney.coleman@epra.com.

    1. EPRA has no influence on what information will be used with the suppliers and processes and

will not receive any personal information on the service providers. For details, contact the Privacy Policy pages of the Authorised Processors.

  1. Personal data processing
    1. The provision of your personal data is voluntary. You are not legally obliged to make your personal data available to us. If you choose not to make your personal data available to us, this holds no consequences for you, except that you cannot take part in our activities.
    2. Personal data that you make available to us via our website will only be stored until the purpose for which it was processed has been fulfilled or until you tell us to delete your data.

 

    1. Personal data comprises any information which allows us to identify you. We may collect the following personal or other data from you, depending of the nature of the event or project:

 

      • First name;
      • Last name;
      • E-mail;
      • Organisation;
      • Position.
    • We might ask for the following additional information, due to accreditation requirements or in the case of a specific age-restricted activity:
      • Date of birth/age;
      • Passport or ID number and expiry date;
      • Place of birth;
      • Residence (full home address).
    • We may collect other information that may be relevant to the project or event. In those cases we will ask for specific consent from the Data Subject.
    • Please note that photographs may be taken at our events. For networking purposes, we may share the participant list with the attendees and the partner organisations. By registering to

our events, you give consent that your photo may be taken and published and your full name, organisation and position may be shared.

    1. Throughout the process of becoming a member of EPRA, we need to collect the following information:
      • Name of the organisation;
      • Address;
      • Legal form of the organisation;
      • Contact details of the legal representatives and certain employees (full name, title, e­ mail address, telephone number) as provided at the moment of the conclusion of the EPRA membership agreement.
  1. Purposes for processing the personal data

 

    1. We use the personal information provided only to ensure the selected application or performance.
    2. In the organisation of events, we will use the provided data for identification purposes and for the registration processes and also for providing you with any further, additional information concerning the event. We may use your full name, organisation and position also to create

participants lists, which are intended to share with other participants for networking purposes.

    1. By subscribing to our newsletter, we will use the given data to provide you with our updates, newsletters and policy positions, which are sent to inform you about EPRA's views and proposals about an array of issues. Also, we intend to inform you about the upcoming events

and to share any other relevant information that is in your best interest.

    1. When registering to our events, participants are given the choice to opt in or out of our contact database, and/or sign up for future email communications.
    2. Your data will not be shared with any other party, except with the Authorised Processors or

 

if said otherwise. In case of an event your first name, last name, organisation and position might be shared with other participants for networking purposes.

 

Social media

 

Our website contains simple links to the following social media networks:

 

    1. Twitter;
    2. Linkedln;
    3. YouTube.

Transfer of data to the social media operators mentioned takes place only if the corresponding icon is clicked. If you click on one of these icons, a page of the corresponding social media operator opens in a popup window. There, you can publish information according to the regulations of the social media operator.

We do not transmit personal information to these third parties to display the content. They have their own cookie and privacy policies which we do not control. Please informyourself about the data collected by third-party providers from the respective provider.

 

Rights of the Data Subject

 

If a Data Subject wishes to avail of this right of confirmation, he or she may, at any time, contact us by e-mail barney.coleman@epra.com.

Right of confirmation: Each Data Subject shall have the right granted by the European legislator to obtain from the controller the confirmation as to whether and which personal data concerning him or her are being processed.

Right of access: Data Subject has the right to obtain free information about his or her personal data stored at any time and to obtain a copy of this information. Furthermore, the European directives and regulations grant the Data Subject access to the following information:

 

  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  • the existence of the right to request from the controller rectification or erasure of personal data, or restriction of processing of personal data concerning the Data Subject, or to object to such processing;
  • the existence of the right to lodge a complaint with a supervisory authority.
    1. Right to rectification: the Data Subject has the right without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the

processing, the Data Subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

    1. Right to erasure (Right to be forgotten): Data Subject has the right for the erasure of

personal data concerning him or her without undue delay, and Processor shall fulfil the obligation to erase personal data without undue delay where one of the following grounds applies, as long as the processing is not necessary:

      • the personal data is no longer necessary in relation to the purposes for which they were

 

collected or otherwise processed;

      • the Data Subject withdraws consent to which the processing is based according to point

(a) of Article 6(1) of the GDPR, or point (a) of Article 9(2) of the GDPR, and where there is no other legal ground for the processing;

      • the Data Subject objects to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or the Data Subject objects to the processing pursuant to Article 21(2) of the GDPR;
      • the personal data have been unlawfully processed;
      • the personal data must be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
      • the personal data have been collected in relation to the offer of information society services referred to in Article 8(1) of the GDPR.
      • If a Data Subject wishes to avail of this right of confirmation, he or she may, at any time, contact us by e-mail barney.coleman@epra.com.

 

To further inform yourself on your rights as a Data Subject, under the relevant EU Law effective as of 24 May 2018, please consult the full law text here.