1. CONTROLLER DETAILS
MIA’s Data Protection Officer is Maria Mifsud Farrugia who may be contacted by email at firstname.lastname@example.org and by telephone at 22581900.
2. PERSONAL DATA
The term “personal data” refers to all personally identifiable information about the participant which includes all the information provided to us in the Continuing Professional Education (CPE) registration form and all information which may arise that can be identified with an individual personally, including information of third party’s provided to us by a company or other corporate entity registering on behalf of a participant(s).
The personal data that the MIA collects about the participant are the data voluntarily provided to us for CPE registration purposes.
The MIA collects personal information to fulfil its role as a professional representative body. As we perform various different functions and activities to service the needs of its members, registered students and other non-member users, the personal information requested and collected will vary depending on your group.
We typically collect the following categories of data:
(a) Identification Data and other Contact Data: such as name(s), surname(s), identity card number, date and place of birth, nationality, residential address, and e-mail address, telephone numbers or any similar contact information available;
(b) Student/Professional/Other User Data: such as student or employment details, educational qualifications, work history, current employment and position;
(c) Registration Data on courses and other events: such as information connected to training, CPE records, attendance records for CPE courses and events and subscription information with respect to journals, reports and newsletters issued by the MIA;
(d) Regulatory Data: such as certificates, or information requests received from legal bodies, such as the Accountancy Board, government authorities or regulators; or
(e) Transaction Data and Transaction Information: bank account and credit card details or details of payments, statements, incoming and outgoing payments.
We only collect information, including personal data that we believe to be relevant and required for the MIA to carry out its functions and activities and to conduct its business as required by law and regulatory obligations.
3. THIRD PARTY DATA
Where you provide us with personally identifiable information relating to other people, such as your directors, officers, employees, advisors or other related persons, you shall be solely responsible for making sure that the provision of such data by you to the MIA fully complies with applicable data protection law and the relevant person in regard to whom the data relates has been provided with the necessary information at law regarding the MIA’s processing of his personal data and where necessary you will obtain their consent to our use of their information.
Any information notices, consents or other applicable requirements that may be required to be fulfilled for the provision of third party data to us shall be borne solely by you and you hereby fully indemnify the MIA and shall render the MIA completely harmless against all costs, damages or liability of whatsoever nature resulting from any claims or litigation (instituted or threatened) by any third party against the MIA as a result of the provision of any third party personal data by you to the MIA.
4. PURPOSES OF PROCESSING
Typically, the MIA will process your personal data for the following purposes:
(a) Enrolling you as a member of the MIA;
(b) Registering you as a student member of the MIA;
(c) Registering you as a user of the Institute’s services;
(d) Creating and providing access to an online account via our website;
(e) Registering you to attend a CPE training course or other event organised by us and maintaining records of CPE declarations;
(f) Registering you as a speaker;
(g) Communicating with you about your MIA account, including process payments, membership dues, or registration fees;
(h) Providing you with, products, services, or information you have requested from us or which are offered by MIA and/or its business partners;
(i) Keeping you updated and providing notices or advertisements, circulars, agendas that are consistent with MIA’s organisational purpose;
(j) To request your participation in MIA or third-party surveys or other initiatives;
(k) Monitoring your performance on CPE courses and assist you in the tracking of your progress; or
(l) Providing marketing information about the MIA’s services as well as news, events, and other information connected thereto.
5. HOW DO WE COLLECT YOUR PERSONAL DATA
The use for which your personal information is requested and collected will vary depending on your group. Typically the MIA will collect personal data in the manners outlined below:
(a) By email, by written correspondence, on hard copy forms (such as event registration forms, sponsorship or membership acceptance forms employed by the MIA);
(b) When you post a query, submission, complaint, request subscription or registration, effect a payment transaction or otherwise make contact with us through our website;
(c) When you contact us voluntarily in other circumstances such as when seeking to attend an MIA organised or sponsored event or function; or
(d) Electronic systems such as online registration forms.
Generally, you would have provided your personal data to the MIA directly. However, in some instances, we may collect personal data about you from third-party sources, such as educational providers, the Accountancy Board, online searches or from public registers including professional associations. Third parties such as regulators or service providers of the MIA may also have provided your personal data to us.
From time to time MIA would also like to contact non-member users about its products and services, promotional offers, marketing as well as information in relation to the products and services provided by third parties (“Marketing”).
Marketing will be carried out primarily through the circulation of e-mails or by phone. Other means of communication may also be used, however, the MIA shall always seek your prior consent.
You may withdraw consent to the processing of personal data for Marketing purposes at any time by sending us an e-mail email@example.com. Alternatively, you may unsubscribe to such communications by clicking the “Unsubscribe” link contained in the footer of any Marketing email you will receive from us.
However, please note withdrawal of consent for Marketing communication does not affect the lawfulness of the processing of personal data based on such consent prior to its withdrawal.
7. LEGAL BASIS
The COMPANY’s legal basis for processing personal data provided will vary from activity to activity. In some instances, processing may have more than one lawful basis. The following information below summarises the basis on which we process personal information.
(a) For the purpose of effecting the registration form concluded with the MIA (including the taking of the steps necessary to complete the registration form or any amendments) with regard to the processing for the purposes of participating in a CPE course or event;
(b) For the purposes of performing our contract with you, such as our sponsorship or joint collaboration agreements, or in anticipation of you becoming a member, student or general user of the Institute;
(c) Where we have a legitimate interest in using it, such as day to day operational and business purposes, including, maintaining our membership database or for the purposes of managing our contracts and relationships with our members, students, non-member users, suppliers, or service providers;
(d) For compliance with our legal or regulatory obligations, including, enabling members to attain their CPE requirements to maintain their professional competence by providing information about courses and events, ongoing monitoring and certification or regulatory reporting obligations; and
(e) If we need and you have given your consent to use of your personal data for a particular purpose, including Marketing consent.
The recipients of the personal data are:
(a) Selected individuals within the Institute;
(b) MIA’s affiliates; and
(c) Third parties to whom disclosure may be required as a result of legal obligations imposed on the MIA.
The MIA’s recipients of personal data are located within the EU.
9. PROCESSING REQUIREMENT
The processing of personal data is not a statutory requirement: it is a requirement in order to complete the registration form. Failure to provide personal data impedes us from being in a position to conclude registration for the participant.
10. AUTOMATED DECISION-MAKING AND PROFILING
Your personal data will not be used for any automated decision-making or profiling.
11. DATA RETENTION
Information will be retained for no longer than is necessary for the purpose for which it was obtained by us, or as required or permitted for legal and regulatory purposes, and for legitimate business purposes. In certain circumstances, where required by law or applicable regulations or where the Institute deems it necessary for our legitimate business, regulatory and/or legal purposes, we may hold the data for a longer or shorter period.
For as long as we hold personal data about an individual, that individual may (where applicable):
(a) Request access to and rectification of personal data where incomplete or inaccurate;
(b) Request erasure of his personal data;
(c) Object to the processing of his personal data;
(d) Request provision of his personal data in a structured, commonly used and machine-readable format; and
(e) Request transmission to himself or another controller indicated by the individual.
Please note that your rights are not absolute.
MIA and its Data Protection Officer may be contacted on complaints regarding the processing of personal data at the details indicated above. A right to lodge a complaint with the Office of the Information and Data Protection Commissioner in Malta (www.idpc.gov.mt) is also in place.
Date last updated: 9 August 2018