web
You’re offline. This is a read only version of the page.
close

1. General

At the heart of its mission, all the partnerships and actions it carries out as an aeronautical school, ENAC is committed to respect for the protection of privacy and transparency with regard to the collection and processing of data. This policy governing the protection of personal data applies to any external stakeholder in direct or indirect contact with the establishment. The term external speaker refers to any individual who is not an ENAC agent, a candidate for an entrance exam at ENAC, a student in initial training or a trainee in continuing education. The term external speaker thus includes, without being exhaustive, concepts such as individual contractor, self-employed entrepreneur, service provider within a company holding a public contract from ENAC, examiner of the DGAC, member of the jury, speaker, guest, supervisor or head of a competition center, individual who needs a badge to access the campus of the institution . To ensure the proper application of the legislation in force (Law No. 78-17 of 6 January 1978 on data processing, files and freedoms, European regulation on data protection, Regulation EU/2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data) and respect for all Enac has appointed a data protection officer (DPO) who will be the specialized interlocutor in the matter both within the institution and in its relations with the supervisory authority, the Commission Nationale de l'Informatique et des Libertés (CNIL).


2. Data collected by ENAC

In accordance with the legislation in force, ENAC undertakes to carry out lawful, fair and transparent processing. For this, the data are collected within the framework of determined, explicit and legitimate purposes with regard to the activities of the establishment. Nevertheless, ENAC reserves the right to carry out data processing not provided for in this document. However, the unplanned processing is carried out taking into account the analogue nature of it in relation to the purposes initially intended, the nature of the data processed in order to exclude all so-called sensitive data and any possible consequences for the rights and freedoms of individuals. ENAC only processes and collects personal data concerning natural persons, for whom there are legal bases. These include their consent and possibly a contract where the processing of the data is necessary for the performance of a contract with such persons. When the processing of data is subject to their consent, they have the right not to consent, to withdraw their consent at any time and to oppose it.

ENAC ensures that the collection of data is limited to the data necessary for the proper functioning of the establishment and all its services. No data that is not adequate or irrelevant to the needs and operation of the institution will be collected unnecessarily. ENAC refrains from collecting personal data without informing the persons concerned.

2.1 Data transmitted to ENAC

Depending on the services provided and their status, people are required to transmit several pieces of information, sometimes essential because they are likely to identify them. This information and its purpose are (list that may evolve):
•    Civil status, identity, identification data, photographs
       - Name of use, surname of birth, first name(s), date of birth, e-mail address, telephone number for identification
       - Place of birth and nationality for travel and payment of vacations
       - Identity document, Social Security number and proof of affiliation to Social Security, personal postal address for payment of vacations
       - Identity photography for granting of a name badge
•    Personal life
       - Marital status (married, single,...) for payment of vacations
       - Personal vehicle information for reimbursementof travel expenses and granting of a campus access sticker
       - Travel-related loyalty and subscription cards, emergency contacts, travel or accommodation preferences for travel
•    Professional life
       - Administrative situation (employee, manager, retiree ...) for payment of vacations
       - Ministry/corps/grade/number for civil servants for payment of vacations
       - Certificate of being without an employer for payment of vacations
       - Employer's company name and SIRET for payment of vacations
       - Business postal address for identification
       - Position held, professional skills, CV for professional qualification (information required as part of the ISO 9001 certification of ENAC's teaching delivery process, collected solely for ENAC's quality needs, and therefore not distributed to a third party or used for commercial purposes).
•    Economic and financial information
       - Bank Identity Statement (RIB) for payment of vacations and reimbursement of travel expenses
       - Salary slip, certificate of the social security contribution ceiling, pension statement (or equivalent certificate), authorization of cumulation of activity, certificate of tax address (if foreign), K-Bis extract, URSSAF contribution call, notice of economic and territorial contribution for payment of vacations

2.2 Data retention period

Personal data is used in the context of the various services, actions, partnerships and collaborations for the duration of the objective pursued. Once the period corresponding to each need has been exceeded, the data of the persons are erased or anonymized in order to no longer allow the identification of the persons concerned. However, exceptions to this rule are data archived for specific purposes.


3. Use of the data collected

ENAC uses the data collected to:
•    to perform the contracts concluded between the data subject and the institution, 
•    to inform the data subject of any changes to the contractual relationship between him and the establishment,
•    to prepare the intervention of the person concerned on the pedagogical and logistical aspects, in particular by offering personalized reception conditions,
•    to provide the data subject with the services, products or information requested,
•    to certify the reality of the intervention of the person concerned, 
•    to pay the person concerned remuneration in the form of vacations or reimbursements of travel expenses,
•    improve the experience of the person concerned with the establishment,
•    to respond to any request from a natural person,
•    to ensure compliance with the applicable legislation, the internal regulations and the privacy policy of the establishment
•    to carry out statistics and analyses,
•    to carry out technical operations on the tools made available to the person concerned and the institution,
•    to detect any fraudulent, abusive or illegal activity and to protect the data subject from this.


4. Data sharing and transfer

4.1 Data sharing and its recipients

It is possible that ENAC is obliged to share/disclose information about the person concerned in several cases:
•    Where the establishment is required to do so by law,
•    In the case of an injunction or any other judicial measure,
•    Where the institution believes in good faith that such sharing/disclosure is reasonably necessary for the performance/performance of certain contracts, to investigate, prevent or take action against actual or suspected illegal activities, investigate complaints from third parties, assist judicial institutions, ensure the security and integrity of its systems,  exercise and protect the rights of the institution.

Certain third parties, whether authorised national authorities, partners/collaborators or having any other capacity, may have access to information relating to the data subject to the extent necessary to carry out certain tasks or obligations arising from contracts concluded with ENAC. However, they are obliged not to disclose them or to use them for purposes other than those provided for in the said contracts. In the event of non-compliance with the rules on the protection of personal data and/or violation of its rights, ENAC will take the necessary measures for the cessation of the unlawful act and for the compensation of the damage where it exists. The data subject may also bring a legal action against these third parties in their capacity as subcontractors.

4.2 Data transfer

ENAC processes the data collected and has the computer activity of this application hosted on the Microsoft Azure cloud, located on the national territory. The servers on which the information is stored may nevertheless be located in other territories of the Member States of the European Union or outside the European Union, in accordance with Microsoft's data protection policy.

The data necessary for each processing purpose are then stored and processed on the servers of :

  • ENAC (Toulouse) for needs related to schooling, planning of interventions, reimbursement of expenses
  • the DGAC and the DGFIP (France) for the needs related to the payment of vacations
  • the University of Toulouse (France) for needs related to the creation and updating of rights on the personal badge
  • private companies such as E-Dialog or Visiativ Managed Services (France) for needs related to meal subsidies and business travel, knowing that these are then communicated to ENAC's travel provider, road, rail, air or sea carriers, as well as to accommodation companies according to the services engaged by ENAC.



5. The rights of the data subject

Any person concerned by the collection and processing of his or her personal data by the institution has several rights.

The right of access - Article 15 GDPR

The data subject has the right to obtain confirmation from ENAC whether or not personal data concerning him or her are being processed. Where this is the case, it may obtain access to such data and to the following information:
•    The purposes of the processing
•    The data retention period envisaged where possible or the criteria for determining this period when it cannot be given
•    The recipient(s) to whom the data have been or will be communicated and in particular recipients established in third countries or international organisations
•    The source of the personal data where they have not been collected directly from the data subject
•    The existence of the rights of rectification and/or erasure of data of individuals and the right to object to processing
•    The right to lodge a complaint with a supervisory authority
•    The existence of automated decision-making (including profiling) and in a proven case, at least fill in useful information about the logic attached to automated decision-making, the importance and consequences of the processing.

The right to object – Article 21 GDPR

The data subject shall have the right to object at any time and on grounds relating to his or her personal situation, to the processing of personal data necessary for the performance of a task carried out in the public interest by the public authority or to processing necessary for the purposes of legitimate interests pursued by ENAC or by a third party. In terms of prospecting, in particular commercial prospecting, the data subject may exercise this right without having to justify a legitimate reason.
The right to object is exercised:
•    Either at the time of collection of the information,
•    Or later, by contacting the ENAC employee, responsible for the processing in question.

The right to rectification – Article 16 GDPR

The data subject has the right to obtain from ENAC the rectification of personal data concerning him or her that are inaccurate as soon as possible. Taking into account the purposes of the processing, it has the right to have incomplete personal data completed, modified, corrected, including by providing a supplementary declaration.

The right to restriction of processing – Article 18 GDPR

The data subject has the right to obtain the restriction of the processing of his or her personal data by ENAC in the following cases:
•    It contests the accuracy of the personal data and in this case the limitation is made for a period allowing ENAC to verify the accuracy of these;
•    The processing is unlawful but it requests its limitation rather than its erasure;
•    When ENAC no longer needs the data for processing but they are still necessary for the establishment, exercise or defense of legal claims;
•    When it has objected to the processing by exercising its right to object, the processing is limited during the verification to know whether the legitimate reasons pursued by ENAC prevail over its own.

The right to erasure (or right to be forgotten) – Article 17 GDPR

The data subject has the right to obtain from ENAC the erasure of personal data concerning him or her as soon as possible. Thus, ENAC has the obligation and undertakes to erase the personal data desired when at least one of the following reasons applies:
•    When the personal data are no longer necessary for the purposes for which they were collected or processed
•    Where the data subject withdraws the consent on which the processing is based and there is no other legal basis for the processing
•    Where the data subject exercises his or her general right to object and there are no overriding legitimate grounds for the processing or where the data subject exercises his or her specific right to object to commercial prospecting and profiling related to such direct marketing.
•    When the personal data have been unlawfully processed
•    When the personal data must be erased to comply with a European or national legal obligation to which the controller is subject.

The right to erasure may not apply in the following cases:
•    Opposition to the right to freedom of expression and information,
•    Compliance with a European or national legal obligation to which ENAC would be subject,
•    Where the treatment is necessary for the purposes of preventive medicine or occupational medicine (public health interest),
•    When the processing is necessary for archiving, scientific, historical or statistical research purposes,
•    When the processing is necessary for the establishment, exercise or defence of legal claims.

The right to data portability – Article 20 GDPR

The data subject has the right to receive the personal data concerning him/her, which he or she has provided to ENAC, in a structured, commonly used and machine-readable format. It also has the right to transmit this data to a controller other than ENAC, without the institution being able to prevent it in the following cases:
•    When the data processing is based on his consent or is necessary for the performance of a contract
•    When the processing is carried out using automated processes.
•    Where the data subject exercises the right to portability, he or she has the right to have the personal data concerning him or her transmitted directly to another controller where technically feasible.


6. The register of processing activities

6.1 The ENAC register as data controller

As data controller, ENAC is obliged to keep a register of the processing activities carried out under its responsibility. That register shall contain all the information required in accordance with Article 30(1) of Regulation EU/2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

6.2 Enac's register as a subcontractor

Each processor and, where applicable, the processor's representative, shall be required to keep a record of all categories of processing activities carried out on behalf of a controller. This register must contain all the information required in accordance with Article 30(2) of the abovementioned European Regulation EU/2016/679.

These registers are intended to be communicated to the supervisory authority (CNIL) at its request in order to ensure the control of compliance with the legislation in force. Under no circumstances shall these registers be intended to be communicated to any person or entity other than the supervisory authority.


7. Data security

Respecting the privacy of the natural persons concerned, their right to the protection and confidentiality of their personal data, is one of ENAC's priorities. To this end, ENAC ensures the security of the data entrusted to it. This security shall be assessed in the light of the state of knowledge, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks of varying probability and severity to the rights and freedoms of individuals. Thus, the institution implements security measures adapted to the degree of sensitivity of each category of personal data to protect them against any malicious intrusion, loss, alteration or disclosure to third parties.

7.1 Security of processing

ENAC and its possible subcontractors shall implement the appropriate technical and organisational measures in order to guarantee a level of security adapted to the risks, including, inter alia, as required:
•    Means to ensure the confidentiality, integrity, availability and ongoing resilience of processing systems and services,
•    Means to restore the availability of and access to personal data within the appropriate time limits in the event of a physical or technical incident,
•    Limited and secure access to personal data,
•    Pseudonymisation and encryption of personal data as soon as possible or necessary,
•    A procedure to regularly test, analyse and evaluate the effectiveness of technical and organisational measures to ensure the security of processing.

When assessing the appropriate level of security, particular account shall be taken of the risks posed by the processing, resulting in particular from the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, transmitted, stored or otherwise processed personal data.
ENAC and its possible subcontractors (partners, collaborators, etc.) undertake to take all necessary measures to ensure that any natural person acting under their authority and having access to personal data, does not process them, except on their instructions, unless obliged to do so by national or European Union law. In addition, all persons having access to the data of the data subject are bound by a duty of confidentiality and are subject to disciplinary measures and/or sanctions if they do not comply with the obligations imposed.

7.2 Data protection: Privacy by design / Privacy by default

From the elaboration, design, selection and use of a product, software, service, etc. that may be based on one or more processing of personal data, ENAC takes into account the law for the protection of this data. Thus, for example, all software designed in-house and involving the processing of personal data is designed taking into account the state of knowledge and the nature, scope, context and purposes of the processing operation(s) as well as the risks, the degree of probability and severity of which varies,  that the processing presents for the rights and freedoms of individuals. Indeed, by adopting a meticulous internal organization and security processes on several levels, ENAC wishes to secure all products, software, services or other devices from their launch and at each stage of their use.
By default, only the personal data necessary for each specific purpose of the processing are/will be processed. This applies to the amount of personal data collected, the extent of their processing, their duration of conversation and their communication to third parties. These measures ensure that, by default, personal data are not made accessible to an indeterminate number of natural persons.

7.3 Notification of a personal data breach

ENAC regularly monitors systems for vulnerabilities, attacks or other security breaches in an attempt to prevent and/or address them as soon as possible. Nevertheless, despite all the efforts of the establishment and all the precautionary, technical and organizational measures put in place to guarantee the security of personal data, this does not allow it to guarantee you absolute security of the information entrusted to it. ENAC, as a public entity, has no guarantee that the data will not be accessible, disclosed, modified or destroyed by a violation of its technical or physical protections.
Notwithstanding, any personal data breach (external intrusion, voluntary/involuntary disclosure, unauthorized access, destruction, etc.) must be notified to the CNIL unless the violation is not likely to create a risk to the rights and freedoms of individuals. The CNIL will study the risk of this violation and, in the event that it proves to pose a risk to the rights and freedoms of individuals, may require ENAC to notify the violation to the persons concerned.


8. Remedies and liability

Natural persons concerned by the collection and processing of their personal data by ENAC have the right to lodge a complaint with a supervisory authority, in particular in the Member State in which their habitual residence, place of work or place where the personal data breach is alleged to have occurred.
The natural persons concerned also have the right to a judicial remedy against a decision issued by a supervisory authority pursuant to Article 78 of the abovementioned European Regulation EU/2016/679.


9. Modification of the policy governing the processing and collection of personal data

Due to legislative developments, ENAC may occasionally modify this policy governing the processing and collection of personal data. Where necessary, ENAC will inform the persons concerned. In order to be aware of any changes or updates made to this governance policy, ENAC advises the persons concerned to regularly consult this charter.


10. Contacts

If you have any questions about this personal data protection policy, the person concerned may contact ENAC by contacting :
•    data controller: 
       Director General of the National School of Civil Aviation
       7 avenue Edouard Belin – BP 54005 – 31055 Toulouse Cedex 4
•    to the department concerned by the collection and processing of their personal data, whose contact details are mentioned in the "Contact Us" section.
•    to the Data Protection Officer: dpo@enac.fr

In case of refusal to accept the present conditions, the interventions of the person concerned cannot be processed in the ENAC information system.
The person is then invited to inform the ENAC manager who sent him the link with the invitation code to the ENIX application.


11. Applicable Version

In the event of any contradiction between the French version of this policy and the English language version, the French version of this policy shall prevail in interpretation.