Security Certificate
CERTIFICATE OF SECURITY LEVEL QUALIFICATION WITH RESPECT TO THE ENS
JOSÉ MIGUEL APARICIO SERRANO, with ID number 22693106H, representing IDEAS NORMATIVAS, S. L., with tax ID B98832330 and registered office at DR. VICENTE ZARAGOZÁ, 1 . 2 . 5 46020 VALENCIA (Valencia), acting as the privacy consulting firm for TOBEIT, S. L., with tax ID B66311341 and registered office at Mallorca 272, 5th 6th, 08037 Barcelona, under a valid contract for consulting, adaptation, maintenance, and updates to applicable privacy regulations.
CERTIFIES
1. GDPR – LOPDGDD Regulatory Compliance
In accordance with Regulation (EU) 2016/679 of April 27 (GDPR), and Organic Law 3/2018 of December 5 (LOPDGDD), IDEAS NORMATIVAS, S. L. complies with all provisions of the GDPR regarding the processing of personal data under its responsibility and does so explicitly in accordance with the principles set out in Article 5 of the GDPR. These principles state that data must be processed lawfully, fairly, and transparently in relation to the data subject, and must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
IDEAS NORMATIVAS, S. L. guarantees that it has implemented appropriate technical and organizational policies to apply the security measures established in Article 32 of the GDPR in order to protect the rights and freedoms of data subjects, and has provided the appropriate information for them to exercise those rights.
2. Security Level Qualification in Accordance with the ENS
In accordance with Article 1.2 of Royal Decree 3/2010, of January 8, which regulates the National Security Framework (ENS) in the field of Electronic Administration, IDEAS NORMATIVAS, S. L. ensures access, integrity, availability, authenticity, confidentiality, traceability, and preservation of data, information, and services used through electronic means made available to TOBEIT, S. L. for document management related to compliance with privacy regulations.
IDEAS NORMATIVAS, S. L. has assessed the impact that an incident affecting information or systems security would have on the organization, based on criteria analyzed for the processing of personal data in electronic environments, and has determined that the affected security level corresponds to the LOW level.
VALENCIA, 11/10/2022
JOSÉ MIGUEL APARICIO SERRANO | B66311341
