PRIVACY NOTICE AND CONSENT FORM FOR:
The Open Space Innovation Platform (OSIP)
[For Internal Reference - DPNR Reference Number 1572]
Kindly provide this “DPNR Reference Number” in any communication with the ESA Data Protection Officer (DPO@esa.int) for quick reference of the Processing in question.
This Privacy Notice was last updated in 2023
-----------------------------------------------------------------------------------------------------------------------
Introduction
The European Space Agency (herein the “Agency” or “ESA”) is an intergovernmental organisation established by its Convention opened for signature in Paris on 30 May 1975. The Protection of Personal Data is of great importance for ESA, which strives to ensure a high level of protection as required by the ESA Framework on Personal Data Protection (herein the “ESA PDP Framework”) which applies for processing of Personal Data at ESA, available at:
http://www.esa.int/About_Us/Law_at_ESA/Highlights_of_ESA_rules_and_regulations
The ESA PDP Framework applicable for the processing of Personal Data within ESA is composed of the following elements:
- the Principles of Personal Data Protection, as adopted by ESA Council Resolution (ESA/C/CCLXVIII/Res.2 (Final)) adopted on 13 June 2017;
- the Rules of Procedure for the Data Protection Supervisory Authority, as adopted by ESA Council Resolution (ESA/C/CCLXVIII/Res.2 (Final)) adopted on 13 June 2017; and
- the Policy on Personal Data Protection adopted by Director General of ESA on 5 February 2018 and effective on 1 March 2022
Scope of this Privacy Statement
This notice is intended to inform you about the processing of your personal data in ESA’s Open Space Innovation Platform (OSIP) and more specifically about:
- the identity of the Data Controller and contact details of the ESA Data Protection Officer (“DPO”);
- the type of personal data collected and processed;
- the modalities of collection of personal data;
- the purpose and legal basis of the collection and processing;
- the recipients to whom the personal data of the Data Subject is disclosed;
- the time-limits for storing the personal data;
- your rights and the modalities by which you can exercise them and the practical modalities of exercising your rights and those rights of other persons, when processed in this Processing Activity under the ESA PDP Framework.
Please be aware that all references to “Data” in this document if not otherwise stated relate to data by which an individual could be identified/ having an identifying character, broadly defined as Personal Data.
This notice furthermore enables ESA to obtain your consent relating to the collection and further processing of your personal data, under the ESA PDP Framework where relevant.
Description and the Purpose for this Processing of your Personal Data: What is this processing about?
ESA Processes Your Personal Data in order to:
- Provide you with access to and to enable the use of ESA’s Open Space Innovation Platform (OSIP) (https://ideas.esa.int);
- Manage your relationship with the Agency as well as your requests and applications in relation to OSIP;
- Enable your participation to the OSIP activities;;
- Send you notifications in connection with idea submissions;
- Evaluate submissions and eventually assess the suitability of your technical background or other personal data related assessments;
- Other purposes that will be disclosed to you when such information is requested;
- The information is used for authentication on the OSIP website, to enable interaction on the website with other users and ESA and to allow the management of Channels and Campaigns management.
Legal Basis: What is the legal basis for processing the personal data?
- 5.2.1 i. (a) PDP; The performance of an activity carried out by the Agency within its purpose and in the framework of, and in conformity with, the ESA Convention, the “Agreement between the States Parties to the Convention for the establishment of a European Space Agency and the European Space Agency for the protection and the exchange of classified information” done in Paris on 19 August 2002, and the applicable rules and procedures, including ESA Security Regulations and Directives; this includes Processing necessary for the Agency’s management and functioning, Dispute Resolution Procedure, and or Investigation Procedures;.
- 5.2.1 i. (d) PDP; Security
- 5.2.1 i. (g) PDP; A purpose covered by the Consent of the Data Subject.
Consent is collected via a dedicated form that requires acceptance before being able to access OSIP. In case of a change to this privacy notice, a renewed consent acceptance will be requested.
Data Controllers, Data Processors, other Recipients of Personal Data and their Contact Details: Who Processes what data in which capacity?
The following table lists all the involved companies, agencies or otherwise, where your personal data may be processed and all relevant information concerning their involvement in this activity.
|
Processing Entity and Responsibility
|
Personal Data Categories
|
Type of Personal Data in detail
|
Description of Processing Responsibilities and specific Purpose of the Processing
|
|
European Space Agency (ESA) as
Controller
|
|
Gender
First Name, Last Name
Year of birth
E-mail address
Country of residence
Affiliated Company
Information in connection with your use of the website, such as information in server logs, including information about when you logged in.
IP (internet protocol) address and data about your system activity
Cookies
Other information that you provide, and which may directly or indirectly identify you, such as affiliation, photos, comments and, ideas
Personal information that might be requested in idea forms such as your e-mail address, postal address, ESA Entity Codes, CVs or other related information that is necessary for the purposes defined below.
|
Your personal data are collected and further processed as described in this Privacy Notice upon the decision taken by: ESA based on your consent. You have the right to withdraw your consent in accordance with PDP 5.4.2.
ESA processes your Personal Data through and limited to staff directly involved in supporting OSIP.
ESA IT systems are used. Personal Data are processed in the EU/EEA. ESA Processors are subject to appropriate technical and organisational measures for the protection of personal data and may include PDP 5.2.1 i. (e) performance of a contract concluded by the ESA within its purpose. System logs are processed for security purposes (PDP 5.2.1.i. d).
|
|
ESA DPO
|
All Personal Information required to accomplish the DPO’s duties as defined in the ESA PDP
|
All Personal Information required to accomplish the DPO’s duties as defined in the ESA PDP
|
According to ESA PDP Framework, your first and unique point of contact concerning personal data matters is the ESA Data Protection Officer (“DPO”). In this regard your personal information may be processed by ESA’s DPO to reply to your requests and to exercise your rights under the ESA PDP. Processing relies on the legal basis: PDP 5.2.1.i.(b) compliance with a legal obligation to which the Agency is subject;
|
|
Processor: Hype Innovation
|
Personal data involved in the setup and maintenance of the website
|
Security and website maintenance.
|
Hype Innovation: Management of the system is done by ESA.
ESA Processors are subject to appropriate technical and organisational measures for the protection of personal data and may include PDP 5.2.1 i. (e) performance of a contract concluded by the ESA within its purpose. System logs are processed for security purposes (PDP 5.2.1.i. d).
|
|
Processors: Campaign/ Channel managers and evaluators
|
Idea submissions, comments
|
Personal data provided within idea submissions or comments
|
Approved Campaign/Channel managers and evaluators evaluate your ideas you have submitted for selection.
|
Contact Details per involved entity:
|
Entity
|
Contact Details
|
|
European Space Agency (ESA)
|
Headquarters: 8-10 RUE MARIO NIKIS, CS 45741, 75738 PARIS CEDEX 15, France.
Your first point of contact is ESA’s DPO at DPO@esa.int at all times.
You may also contact Leopold Summerer in charge for this Activity directly by Leopold.Summerer@esa.int
|
|
ESA DPO
|
Data Protection Officer: DPO@esa.int
|
|
Hype Innovation, ESA Processor
|
Please contact ESA as Controller
|
Personal Data Retention and Deletion: How long are your personal data retained by ESA?
Your Personal Data is stored and processed based on the following timeframes:
|
Personal Data Categories and Place of Processing
|
Retention
|
|
ESA retains Personal Data for the time period necessary to fulfil the legitimate purpose of the processing, thereafter it is deleted. Please refer to the specific retention periods defined for the activity in which you participate.
|
Personal data is deleted when it is no longer necessary or after your account in OSIP is inactive for two years. Content inserted (ideas, comments) may be anonymised and may remain on the platform.
|
Your rights (Data Subject Rights) How can you access, erase, rectify, complete or amend your personal data?
You have the right to be informed in a transparent manner about: the processing of your personal data (the Controller, purpose, recipients, etc.); your rights and the modalities of exercising these, (e.g. erasure, rectification, completion, or amendment as per the conditions under PDP 5.1. i.; right for every interested Data Subject to lodge a complaint before the Supervisory Authority in case the former demonstrates or has serious reasons to believe that a Data Protection Incident occurred in relation with his/her Personal Data, following a decision of the Agency (e.g. Data Protection Officer). The right of information under PDP 5.4.1 i. and the right of access under Section 5.4.1 ii. shall not apply: (a) where and insofar as the Data Subject is already in possession of the information; (b) for the right of information, when processing of Personal Data is necessary for any Investigation or Dispute Resolution Procedure; (c) for the right of access, where and insofar such access would conflict with an Investigation Procedure concerning the Data Subject.
If you would like to exercise any of those rights, please send a request explicitly specifying your query to the ESA DPO via e-mail at dpo@esa.int or addressed to the:
ESA Headquarters
Data Protection Officer
8-10 RUE MARIO NIKIS
CS 45741
75738 PARIS CEDEX 15
FRANCE
via postal service.
Please keep in mind that the more specific information you can provide to us about the Activities, Events, Systems, ESA Departments and/or Processes where your personal data is to your knowledge stored, the sooner we can respond to your enquiry, request or complaint.
If you wish to submit a complaint to the ESA Data Protection Supervisory Authority, you are required to comply with the Rules of Procedure of the Supervisory Authority set forth in the ESA PDP Framework:
(https://www.esa.int/About_Us/Law_at_ESA/Highlights_of_ESA_rules_and_regulations).
You will be required to demonstrate that a Data Protection Incident occurred in relation to your personal data, following a decision of the Agency or at least be able to provide serious reasons and indicators to establish that such an incident occurred.
You are at any point able to request anonymisation via the user profile settings on OSIP. Please note, that content like ideas, comments, etc. added by you might remain anonymized on the platform without a possibility to recover the connection at a later stage or by a new registration.
PERSONAL DATA BREACH: What should you do in case of a data protection incident?
If you have any concerns about your personal data or became the victim of a data breach of ESA processed personal data, you should contact ESA’s DPO, as first point of contact, by sending an email to: dpo@esa.int and provide all information available to you regarding the potential breach.
CONSENT for OSIP
The processing of your personal data described in this privacy notice is based on consent, to be indicated by either ticking the consent box in this form or sending ESA the signed form by email.
If your consent was not already obtained by ESA (including by other modalities) and is required under the ESA Framework on Personal Data Protection, you agree with the collection and further processing of your personal data. You will be able to withdraw your consent depending on the modality used to collect your personal data, in particular:
- By deleting your account (please note, that content like ideas, comments, etc. added by you might remain on the platform without a possibility to recover the connection to your account at a later stage or by your new registration).
- I have read and understood all the information provided to me with regard to the processing of my personal data for OSIP and I hereby explicitly consent to the use of my personal data for the purpose of accessing the Open Space Innovation Platform and using its provided functionalities
- I am aware of my right to revoke my consent at any time by deleting my account/ user profile on OSIP or by contacting the ESA DPO directly under DPO@esa.int, copy OSIP team (ideas@esa.int or Leopold.Summerer@esa.int) and of my other rights as stated in the Privacy Notice provided to me in connection with this Consent Declaration.