Information on Debt Collection activities
CRIBIS S.r.l., with registered office at Via dei Valtorta 48, 20127 Milan, provides this notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), also in compliance with the Order of the Italian Data Protection Authority concerning debt collection dated 30 November 2005.
Controller contact details
- Postal address: CRIBIS S.r.l., Via dei Valtorta 48, 20127 Milan
- E-mail: dirprivacy@cribis.com
- Certified e-mail (PEC): cribis@pec.crif.com
Sources of personal data
CRIBIS S.r.l. carries out debt management and collection activities on behalf of third parties under a licence issued pursuant to Article 115 of Royal Decree No. 773 of 18 June 1931, Consolidated Law on Public Security (“TULPS”). In performing debt collection mandates, CRIBIS processes personal data obtained:
- directly from its client companies, which are generally the holders of the relevant claim entrusted for collection. In relation to those activities, CRIBIS S.r.l. acts as Processor under an appointment pursuant to Article 28 GDPR. The identity of the creditor, as holder of the claim and Controller of the relevant processing, is disclosed by CRIBIS S.r.l. to the Data Subject at the time of the first contact;
- orally and/or directly from the Data Subject during collection activities carried out on behalf of client companies, including through the recording of telephone interactions while the mandate is in force, or through consultation of third-party sources, in full compliance with the principles laid down by the GDPR and the UNIREC Code of Conduct.
Purposes of processing
CRIBIS S.r.l. further informs Data Subjects that activities carried out by telephone in connection with its debt collection services, including inbound and outbound calls (collectively, “Phone Collection”), may be recorded exclusively for the following purposes:
- managing reports, disputes, complaints and/or requests to exercise rights under Articles 15 et seq. GDPR received from the Data Subject in the context of debt collection activities, thereby enabling client companies to manage them as Controllers and holders of the claim being collected;
- managing requests, reports, disputes and/or complaints received from the Data Subject and/or public authorities concerning alleged direct liability of CRIBIS S.r.l. in connection with debt collection activities, for the establishment, exercise or defence of legal claims and/or compliance with legal obligations;
- quality control of CRIBIS S.r.l.’s activities by client companies;
- CRIBIS S.r.l.’s organisational and operational requirements, namely analysing the quality and effectiveness of Phone Collection processes with a view to continuously improving products and services for users, including by identifying and remedying possible training gaps among persons authorised to process personal data.
Legal bases
For purposes 1 and 3 above, the legal basis is determined directly by the client companies acting as Controllers. CRIBIS S.r.l. acts solely as their agent and Processor, complying with its reporting and disclosure obligations under the Article 28 GDPR appointment and the relevant mandate, in full compliance with the GDPR.
For purpose 2, the legal basis is compliance with a legal obligation under Article 6(1)(c) GDPR or CRIBIS S.r.l.’s legitimate interest in managing disputes and establishing, exercising or defending legal claims under Article 6(1)(f) GDPR.
For purpose 4, the legal basis is CRIBIS S.r.l.’s legitimate interest under Article 6(1)(f) GDPR.
No prior consent is required for purposes 2 and 4, which are pursued by CRIBIS S.r.l. in its own capacity. The Data Subject retains the right to object to processing based on legitimate interests and to exercise the rights described below against CRIBIS S.r.l.
Processing methods
Processing is carried out in accordance with the principles of lawfulness, fairness, relevance, transparency and data minimisation, with full protection of the Data Subject’s rights and confidentiality and in line with industry best practices and the UNIREC Code of Conduct for debt management and protection processes.
Only personal data necessary to perform the out-of-court debt management and collection mandate is processed. Such data falls exclusively within the category of ordinary personal data.
Personal data is processed manually and/or by electronic means following the adoption of appropriate technical and organisational measures pursuant to Article 32 GDPR. No automated decision-making, including profiling within the meaning of Article 22 GDPR, is carried out.
Before a call is recorded, the Data Subject is informed through a dedicated script and advised that the full notice is available on the CRIBIS website.
Personal data recorded during calls will not be disclosed to third parties other than the client company, as holder of the claim and Controller, and will not be disseminated. Within CRIBIS S.r.l., it will be accessible only to specifically authorised personnel and solely for the purposes described above.
Data Subjects’ personal data will not be transferred outside the European Economic Area. Should future technical, organisational or operational requirements make a transfer necessary, CRIBIS S.r.l. will carry it out only where the conditions for lawfulness under Articles 44 to 49 GDPR are met. The Data Subject may request information concerning the transfer, including the location to which the data has been transferred.
Further information, including details of any Processors, may be requested by writing to the Controller using the contact details set out above.
Retention period
For purposes 1 and 3, the retention of personal data and recorded telephone calls, where applicable, is linked to the duration of the mandate received from the client companies and/or the instructions given to CRIBIS S.r.l. under its appointment as Processor pursuant to Article 28 GDPR. Data may be retained for a longer period, limited to the time necessary for dispute management and/or prescribed by law, exclusively for purpose 2. For purpose 4, recordings will be retained for a maximum of 180 days after termination of the relevant mandate received from the client company.
Data Subjects’ rights
The Data Subject may at any time exercise against CRIBIS S.r.l., in relation to purposes 2 and 4, the right to: (i) obtain confirmation as to whether personal data concerning them is being processed and receive the information listed in Article 15 GDPR; (ii) obtain rectification of inaccurate personal data and completion of incomplete personal data; (iii) obtain erasure pursuant to and within the limits of Article 17 GDPR; (iv) obtain restriction of processing in the cases set out in Article 18 GDPR; (v) receive personal data concerning them in a structured, commonly used and machine-readable format in the cases provided for by Article 20 GDPR; (vi) object to processing pursuant to and within the limits of Article 21 GDPR; and (vii) withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Where the Data Subject considers that the processing of their personal data infringes applicable law, they may lodge a complaint with the Italian Data Protection Authority by following the instructions available on its website.
For processing carried out for purposes 1 and 3, the Data Subject may exercise their rights by contacting the relevant CRIBIS S.r.l. client company, whose identity is disclosed at the time of the first contact, as Controller of the processing in question.
Data Protection Officer
For any questions concerning the processing of personal data, the Data Subject may contact CRIBIS S.r.l. using the contact details above and may contact the Data Protection Officer at: e-mail dirprivacy@cribis.com; certified e-mail (PEC) cribis@pec.crif.com.
Do you have any questions or want to receive a quotation?
Ask for information immediately