– are collected for the exercise of the functions of PA within the scope of their
responsibilities;
– refer to the parties to a contract or preliminary contract for a business,
employment or administrative relationship, and are necessary for its maintenance or fulfilment;
– are contained in sources accessible to the public and their processing is
necessary to satisfy the legitimate interest pursued by the controller or the
third party to whom the data are communicated, unless the fundamental
rights and freedoms of the data subject are jeopardised;
c) the purpose of processing the data is to protect a vital interest of the data subject.
This aspect is mentioned in Art. 22 of the Law 34/2002 with regard to the use by
service providers of devices to store and retrieve data in terminal equipment owned
by the users. In its ninth additional provision, Law 34/2002 establishes that service
providers in the Society of Information, domain name registries and registry agents
operating in Spain must cooperate with the competent CERT to solve any cyber
security incidents that may affect the internet, and they must follow the security
guidelines established in the codes of conduct that derive from this law. This
cooperation includes submitting all the technical evidence necessary to prosecute
crimes derived from said cyber security incidents: maintaining the secrecy of
communications, they will supply all necessary information, including IP addresses
that may be compromised by or involved in the crimes.
Furthermore, we must take into account that personal data may only be collected
for the specified, explicit and legitimate purposes of the data controller. Data
controllers must previously inform data holders about the purposes of collecting
the data requested. The processing has to be restricted to personal data which are
adequate, relevant and not excessive in relation to the purposes for which they were
obtained (Art. 5 and 6 OLPPD, 8 ROLPPD).
2.1.3 Protection of Minors’ Personal Data Processed by Electronic
Means
According to Art. 13 of the ROLPPD, “Data pertaining to data subjects over fourteen
years of age may be processed with their consent, except in those cases where the
law requires the assistance of parents or guardians in the provision of such data.” The
consent of parents or guardians shall be required for children under 14 years old. The
precept adds that data regarding information about any other member of the minor’s
family unit, or about their characteristics, cannot be collected from the minor (e.g.
data relating to the professional activity of the parents, financial information, sociological data or any other kind), without the consent of the persons to whom such data
refer. Nevertheless, data regarding the identity and address of the father, mother or
guardian may be collected for the sole purpose of obtaining the authorisation set out
above. The law underlines the idea that information regarding data processing aimed
at minors shall be expressed in easily understandable language, with express
376
F. M. Corvo López
responsibilities;
– refer to the parties to a contract or preliminary contract for a business,
employment or administrative relationship, and are necessary for its maintenance or fulfilment;
– are contained in sources accessible to the public and their processing is
necessary to satisfy the legitimate interest pursued by the controller or the
third party to whom the data are communicated, unless the fundamental
rights and freedoms of the data subject are jeopardised;
c) the purpose of processing the data is to protect a vital interest of the data subject.
This aspect is mentioned in Art. 22 of the Law 34/2002 with regard to the use by
service providers of devices to store and retrieve data in terminal equipment owned
by the users. In its ninth additional provision, Law 34/2002 establishes that service
providers in the Society of Information, domain name registries and registry agents
operating in Spain must cooperate with the competent CERT to solve any cyber
security incidents that may affect the internet, and they must follow the security
guidelines established in the codes of conduct that derive from this law. This
cooperation includes submitting all the technical evidence necessary to prosecute
crimes derived from said cyber security incidents: maintaining the secrecy of
communications, they will supply all necessary information, including IP addresses
that may be compromised by or involved in the crimes.
Furthermore, we must take into account that personal data may only be collected
for the specified, explicit and legitimate purposes of the data controller. Data
controllers must previously inform data holders about the purposes of collecting
the data requested. The processing has to be restricted to personal data which are
adequate, relevant and not excessive in relation to the purposes for which they were
obtained (Art. 5 and 6 OLPPD, 8 ROLPPD).
2.1.3 Protection of Minors’ Personal Data Processed by Electronic
Means
According to Art. 13 of the ROLPPD, “Data pertaining to data subjects over fourteen
years of age may be processed with their consent, except in those cases where the
law requires the assistance of parents or guardians in the provision of such data.” The
consent of parents or guardians shall be required for children under 14 years old. The
precept adds that data regarding information about any other member of the minor’s
family unit, or about their characteristics, cannot be collected from the minor (e.g.
data relating to the professional activity of the parents, financial information, sociological data or any other kind), without the consent of the persons to whom such data
refer. Nevertheless, data regarding the identity and address of the father, mother or
guardian may be collected for the sole purpose of obtaining the authorisation set out
above. The law underlines the idea that information regarding data processing aimed
at minors shall be expressed in easily understandable language, with express
376
F. M. Corvo López
