{"id":13171,"date":"2019-11-21T09:15:55","date_gmt":"2019-11-21T08:15:55","guid":{"rendered":"https:\/\/www.viafirma.com\/blog-xnoccio\/?p=13171"},"modified":"2025-11-17T08:47:49","modified_gmt":"2025-11-17T07:47:49","slug":"personal-data-rights-obligations","status":"publish","type":"post","link":"https:\/\/www.viafirma.com\/en\/personal-data-rights-obligations\/","title":{"rendered":"Personal data: what are your rights and obligations?"},"content":{"rendered":"\r\n<p class=\"has-text-align-center\">More than ever we are aware of the value of our personal information, but do we know what obligations and rights we have over our data? In this article we analyze the main aspects of current legislation.<\/p>\r\n\r\n\r\n\r\n<p><!--more--><\/p>\r\n\r\n\r\n\r\n<p>Everything related to <a href=\"https:\/\/www.viafirma.com\/en\/personal-data-rights-obligations\/\">personal data and its protection<\/a> is a trend in an increasingly connected society, in which this information is constantly flowing thanks, in large part, to new technologies.<\/p>\r\n\r\n\r\n\r\n<p>That is why citizens must be more aware than ever of the rights and obligations concerning personal information. The <a href=\"https:\/\/www.aepd.es\/es\" target=\"_blank\" rel=\"noopener\">Spanish Data Protection Agency (AEPD)<\/a> is working hard to raise awareness of this issue, a task that is worth highlighting.<\/p>\r\n\r\n\r\n\r\n\r\n\r\n<p>In this article we will discuss the rights and obligations that affect us in this matter and that are included in the current legislation.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">The GDPR and your personal data rights<\/h2>\r\n\r\n\r\n\r\n<p>At the European Union level, the regulation on personal data is a matter of the <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">General Data Protection Regulation (GDPR)<\/a>. Adopted in 2016 and mandatory since 2018, this regulation is made to homogenize the regulations of the different member countries in terms of data protection.<\/p>\r\n\r\n\r\n\r\n<p>It sets out the rights and obligations that we will discuss below, and one of its main objectives is to streamline the process by eliminating the associated bureaucratic barriers.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">Rights<\/h2>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Transparency: your right to information<\/h3>\r\n\r\n\r\n\r\n<p>When some of the personal data is collected through different ways, such as web forms, on paper, by telephone or through an application, the person who owns such data must be duly informed of this fact.<\/p>\r\n\r\n\r\n\r\n<p>In the event that the delivery of data is done directly, the notification will be prior to shipment, while if it is done through third parties through a legal transfer, there will be a set deadline. Such notification may be made by ordinary mail, electronic means or notifications within an app.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Of access<\/h3>\r\n\r\n\r\n\r\n<p>This includes the right to communicate with whoever is processing your data. Thanks to it you can demand to know what is being done with them and for what purpose, to whom they have been sent, until when they can have them, request changes or deletions, make a claim or know where they have been obtained in the case of a transfer by a third party.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">To rectification<\/h3>\r\n\r\n\r\n\r\n<p>It may happen that the personal information we provide contains errors or is incomplete. For this reason, we may at any time ask you to modify it in order to correct such errors or to complete the information that requires it.<\/p>\r\n\r\n\r\n\r\n<p>It may be necessary to attach documentation verifying the plausibility of such changes.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Of opposition<\/h3>\r\n\r\n\r\n\r\n<p>It is possible to refuse data processing, whether it is carried out for public interest purposes, subject to exceptions that must be duly justified by the data controller, or for marketing purposes.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">To oblivion<\/h3>\r\n\r\n\r\n\r\n<p>It may be one of the best known by the vast majority of the population. It deals with the deletion of personal data. In order for it to materialize, some requirements must be met.<\/p>\r\n\r\n\r\n\r\n<p>Among these premises, we can highlight that this information is being used illegitimately, for a purpose that does not coincide with the original one, if it is required by any legal provision or if the aforementioned right of opposition has been exercised.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">To the limitation of the processing of your data<\/h3>\r\n\r\n\r\n\r\n<p>With it, the use of the personal data provided can be restricted to a certain extent. There are two possible options, to request the suspension of the data or to request its conservation.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">To the portability of your data<\/h3>\r\n\r\n\r\n\r\n<p>This right facilitates the transfer of data between data controllers. This ensures that they are interoperable, reusable and machine-readable because they are in a properly structured format.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Not to be subject to individualized decisions<\/h3>\r\n\r\n\r\n\r\n<p>In other words, as a general rule, no decision that legally or negatively affects the person who owns the personal data may be taken solely on the basis of the study of this information.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-12976\" src=\"https:\/\/www.viafirma.com\/wp-content\/uploads\/2019\/11\/RGPD-y-datos-personales-1-1024x678.jpg\" alt=\"RGPD and personal data\" width=\"768\" height=\"509\" \/><\/figure>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">Obliations<\/h2>\r\n\r\n\r\n\r\n<p>Once we know our rights, we must also know the obligations that data controllers must comply with. These obligations are based on a series of relative principles that we will describe next to these obligations.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Relative principles<\/h3>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\">Fairness, loyalty and transparency<\/h4>\r\n\r\n\r\n\r\n<p>It protects data from unlawful processing or processing for malicious purposes. This ensures that personal data falls under the protective umbrella of the GDPR.<\/p>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\">Purpose limitation<\/h4>\r\n\r\n\r\n\r\n<p>The data must be collected and processed on the basis of a specific purpose, without forgetting, of course, that this purpose must be covered by the law in force.<\/p>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\">Data minimization<\/h4>\r\n\r\n\r\n\r\n<p>We will only work with the information that is strictly necessary to achieve the objectives set, so no additional data will be made available without justification.<\/p>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\">Accuracy<\/h4>\r\n\r\n\r\n\r\n<p>The data must be accurate and up to date. Appropriate steps must be taken to correct errors or update the data.<\/p>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\">Conservation period<\/h4>\r\n\r\n\r\n\r\n<p>Personal data must be kept as long as they can be useful for the fulfillment of the purpose for which they were collected. Once this time has elapsed, they should be deleted or action should be taken to ensure that the owners cannot be identified through them.<\/p>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\">Integrity and security<\/h4>\r\n\r\n\r\n\r\n<p>Appropriate technical and other measures shall be implemented to prevent unlawful processing, damage, loss or destruction of personal data.<\/p>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\">Proactive responsibility<\/h4>\r\n\r\n\r\n\r\n<p>According to it, data controllers must take measures such as risk analysis, communication of security breaches or a register with all the processing received by these data.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Security<\/h3>\r\n\r\n\r\n\r\n<p>Appropriate technical and organizational measures must be taken to ensure that the data is adequately protected against theft, loss or alteration of any kind.<\/p>\r\n\r\n\r\n\r\n<p>As we can deduce, these measures are closely linked to many of the relative principles just described.<\/p>\r\n\r\n\r\n\r\n<p>Some of the most common and undisputed security measures are:<\/p>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li>Preliminary risk and impact assessment.<\/li>\r\n<li>Report any security breaches that are detected.<\/li>\r\n<li>Do not allow access to users who are not authorized to do so.<\/li>\r\n<li>Make backup copies of personal data.<\/li>\r\n<li>Encrypt and encrypt information, essential when working with personal and sensitive data.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Special categories of data<\/h3>\r\n\r\n\r\n\r\n<p>It is important to highlight that there are some types of personal data that require special mention, and that the <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">GDPR<\/a> expressly prohibits, with some exceptions, their processing. These special data are classified as:<\/p>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li>Ethnic or racial.<\/li>\r\n<li>Biometric data.<\/li>\r\n<li>Health data.<\/li>\r\n<li>Data of a sexual nature.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p>The RGPD has meant a great advance in terms of personal data rights and obligations. From Viafirma we have a high level of commitment with this regulation, having it constantly present in the development of our solutions, as it is the case of <a href=\"https:\/\/www.viafirma.com\/en\/documents\/\">Viafirma Documents.<\/a><\/p>\r\n\r\n\r\n\r\n<p>For example, one of the most interesting aspects of Viafirma Documents in terms of personal data is the creation of mandatory reading clauses for all types of documents, providing legal certainty and peace of mind to all parties involved. Another application we can mention is the document management of the <a href=\"https:\/\/www.viafirma.com\/en\/ehealth-informed-consent\/\">informed consent<\/a> for health treatments or research in <a href=\"https:\/\/www.viafirma.com\/en\/signature-for-laboratories\/\">laboratories<\/a>.<\/p>\r\n\r\n\r\n\r\n<p>As we have seen, the protection of something as sensitive as personal data is of great concern to the authorities and, consequently, to companies and institutions. This is why we will remain up to date on a subject on which we all need to be fully informed.<\/p>\r\n<p><span style=\"font-weight: 400;\"><div class=\"vf_related_posts_wrapper\"><h2 class=\"vf_related_posts_title\">Related information<\/h2><div class=\"vf_related_posts\"><article class=\"vc_gitem-post-data-source-post\"><a href=\"https:\/\/www.viafirma.com\/en\/incorporate-appropriate-informed-consent-gdpr-php\/\" class=\"vc_gitem-post-link\"><div class=\"vc_gitem-post-image\"><img loading=\"lazy\" decoding=\"async\" width=\"768\" height=\"512\" src=\"https:\/\/www.viafirma.com\/wp-content\/uploads\/2019\/09\/firma-digital-2-1024x682.jpg-768x512.webp\" class=\" wp-post-image\" alt=\"work table with laptop\" srcset=\"https:\/\/www.viafirma.com\/wp-content\/uploads\/2019\/09\/firma-digital-2-1024x682.jpg-768x512.webp 768w, https:\/\/www.viafirma.com\/wp-content\/uploads\/2019\/09\/firma-digital-2-1024x682.jpg-300x200.webp 300w, https:\/\/www.viafirma.com\/wp-content\/uploads\/2019\/09\/firma-digital-2-1024x682.jpg.webp 1024w\" sizes=\"auto, (max-width: 768px) 100vw, 768px\" \/><\/div><\/a><div class=\"vc_gitem-post-data\"><h3 class=\"vc_gitem-post-data-source-post_title\"><a href=\"https:\/\/www.viafirma.com\/en\/incorporate-appropriate-informed-consent-gdpr-php\/\">How to incorporate appropriate informed consent to the GDPR in a PHP portal<\/a><\/h3><p class=\"vc_gitem-post-data-source-post_excerpt\">We explain how to incorporate a GDPR-compliant informed consent in a PHP portal<\/p><\/div><\/article><article class=\"vc_gitem-post-data-source-post\"><a href=\"https:\/\/www.viafirma.com\/en\/5-aspects-gdpr-health-sector-laboratories\/\" class=\"vc_gitem-post-link\"><div class=\"vc_gitem-post-image\"><img loading=\"lazy\" decoding=\"async\" width=\"768\" height=\"475\" src=\"https:\/\/www.viafirma.com\/wp-content\/uploads\/2018\/04\/blog_contrado_sanidad-768x475.webp\" class=\" wp-post-image\" alt=\"Contrato m\u00e9dico\" srcset=\"https:\/\/www.viafirma.com\/wp-content\/uploads\/2018\/04\/blog_contrado_sanidad-768x475.webp 768w, https:\/\/www.viafirma.com\/wp-content\/uploads\/2018\/04\/blog_contrado_sanidad-300x186.webp 300w, https:\/\/www.viafirma.com\/wp-content\/uploads\/2018\/04\/blog_contrado_sanidad-1024x634.webp 1024w, https:\/\/www.viafirma.com\/wp-content\/uploads\/2018\/04\/blog_contrado_sanidad.webp 1228w\" sizes=\"auto, (max-width: 768px) 100vw, 768px\" \/><\/div><\/a><div class=\"vc_gitem-post-data\"><h3 class=\"vc_gitem-post-data-source-post_title\"><a href=\"https:\/\/www.viafirma.com\/en\/5-aspects-gdpr-health-sector-laboratories\/\">5 aspects on the GDPR application in the health sector and the laboratories that you should consider.<\/a><\/h3><p class=\"vc_gitem-post-data-source-post_excerpt\">The approval of the new European Data Protection Regulation, which<\/p><\/div><\/article><\/div><\/div><\/span><\/p>\r\n","protected":false},"excerpt":{"rendered":"Do we know what obligations and rights we have regarding our personal data? We analyze in this article its main aspects...","protected":false},"author":1,"featured_media":31973,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[156],"class_list":["post-13171","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-regulations"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.viafirma.com\/en\/wp-json\/wp\/v2\/posts\/13171","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.viafirma.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.viafirma.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.viafirma.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.viafirma.com\/en\/wp-json\/wp\/v2\/comments?post=13171"}],"version-history":[{"count":2,"href":"https:\/\/www.viafirma.com\/en\/wp-json\/wp\/v2\/posts\/13171\/revisions"}],"predecessor-version":[{"id":95550,"href":"https:\/\/www.viafirma.com\/en\/wp-json\/wp\/v2\/posts\/13171\/revisions\/95550"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.viafirma.com\/en\/wp-json\/wp\/v2\/media\/31973"}],"wp:attachment":[{"href":"https:\/\/www.viafirma.com\/en\/wp-json\/wp\/v2\/media?parent=13171"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.viafirma.com\/en\/wp-json\/wp\/v2\/categories?post=13171"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}