Whistleblowing system – Data protection information for Spain
We take the topic of data protection and confidentiality very seriously and adhere to General Data Protection Regulation of the EU (GDPR) and the applicable national data protection laws. Please read this data protection information carefully before sharing any information.
Party responsible for the data processing:
The party responsible for the data processing is:
Aldi Supermercados, S.L
Alemanya, 5
08783 Masquefa (España)
However, if the report is directed to ALDI Central de Compras, S.L.U., ALDI Dos Hermanas Supermercados, S.L., ALDI Masquefa Supermercados, S.L., ALDI Pinto Supermercados, S.L. or ALDI San Isidro Supermercados, S.L., the company responsible for the processing would be the corresponding company in each case.
You can reach the data protection responsible by email at protecciondatos@aldi.es or by writing to the above address.
Purpose of the whistleblowing system, legal foundation and provider
The whistleblowing system (BKMS® System) serves for secure and confidential receiving, processing and managing of reports concerning violations of the compliance rules. The processing of personal data within the framework of the BKMS® System is based on the legitimate interest of our company in discovering and preventing abuses and thereby protects the company, its employees and customers from possible damages.
The whistleblowing system is operated by a specialised company, EQS Group GmbH, Bayreuther Str. 35, 10789 Berlin in Germany, on behalf of ALDI Supermercados, S.L.
The legal foundation for this processing of personal data is Article 6 paragraph 1 point f GDPR.
Processing of personal data
Personal data and information entered into the whistleblowing system are stored in a database of a high security data centre managed by EQS Group GmbH. Only authorised personnel of ALDI Supermercados, S.L. have access to these data. EQS Group GmbH and other third parties do not have access to the data. This is ensured in the certified procedure through extensive technical and organisational measures.
All data are stored in encrypted form and protected by passwords at various levels so that access is limited to a very restricted group of recipients comprising employees of ALDI Supermercados, S.L. who are expressly authorised and competent.
Type of collected personal data
The use of the system to submit reports concerning irregularities is voluntary. If you share information via the communication system, we collect the following data and information of a personal nature insofar as you make this available to us:
- your name
- your workplace (if you are an employee of the company) and
- the names and other personal data of persons whom you list in your report, if applicable.
Confidential handling of information
Incoming reports are received by a small selection of expressly competent and authorized specially trained compliance employees of ALDI Supermercados, S.L. and are always handled confidentially. The compliance employees of ALDI Supermercados, S.L. will evaluate the matter and perform any further investigation required by the specific case.
During the processing of a report or the conducting of a special investigation, it may become necessary to forward reports to other parties. We will always ensure that the applicable data protection regulations are complied with when sharing reports.
Everyone who has access to the data is obligated to maintain confidentiality.
Information about the accused
In certain cases, we are legally obligated to inform accused parties of any reports received against them as soon as the disclosure of this information no longer jeopardises the investigation. Your identity as a whistleblower, if you even reveal it, will not be disclosed.
Your rights
Pursuant to European data protection legislation, you and the persons named in the report have a right of access, rectification, erasure, restriction of processing and right to object to the processing of your personal data. If the right to object to the processing of the personal data is invoked, the necessity of the stored data for the examination of a report will be evaluated immediately. Data that are no longer needed will be deleted at once. You also have the right to appeal with the supervisory authority.
Retention period of personal data
Personal data are saved as long as necessary for the investigation and conclusive evaluation of the complaint or for as long as a legitimate interest exists on the part of the company or as long as required by law.
The retention period for data in the complaint system applies only for the period that is required to decide whether or not an investigation of the reported circumstances should be initiated. Three months after entry of the data, they are removed from the complaint system as required by law, except in the cases provided for by law.
If retention of the data is required for the further investigation and evaluation of the circumstances, they can be further processed in the system if the access is restricted to the listed personnel or, if this is not possible, within another environment by the body of the party that is responsible for this purpose.
Use of the whistleblowing portal
Communication between your computer and the whistleblowing system takes place over an encrypted connection (SSL). The IP address of your computer will not be stored during your use of the whistleblowing system. To maintain the connection between your computer and the BKMS® system, a cookie is saved on your computer that consists only of the session ID (null cookie). The cookie remains valid only until the end of the session and is deleted when you close your browser.
It is possible to set up a postbox within the whistleblowing system that is secured with an individually chosen pseudonym/user name and password. This allows you to send reports either by name or in an anonymous, safe way. This system only stores data inside the whistleblowing system, which makes it particularly secure. It is not a form of regular e-mail communication.
Note on sending attachments
When submitting a report or an addition, you can simultaneously send attachments. If you wish to submit an anonymous report, please take note of the following security advice: files can contain hidden personal data that could endanger your anonymity. Remove this data before sending. If you are unable to remove this data or are uncertain about how to do so, copy the text of your attachment into your report text or send the printed document anonymously to the address listed in the footer, citing the reference number received at the end of the reporting process.
Information on data protection for the website
Please also note the data protection information on our website:
https://www.aldi.es/politica-de-privacidad-y-proteccion-de-datos/