General Information on Data Protection
PKF Attest is a multidisciplinary firm that provides professional services in different areas of the market through different companies. Notwithstanding the existence of these, it acts in the business environment as a single organization in the provision of its services, therefore, the data protection regulations are fully applicable to its activity. Specifically, it processes data for the following purposes:
PKF Attest, for the proper provision of its services, accesses and processes information under the instructions of its customers, acting as data controller or data processor, as appropriate:
- Legal and tax services: legal and tax advice, official bookkeeping, payroll, accounting and other administrative services.
- Financial services: economic and financial advice and consultancy, account auditing, education and training, bankruptcy administration, advice on company acquisitions and corporate restructuring and reorganization processes, in the field of capital markets and in the planning of programs and calls for financial and tax aid for R&D&I.
- Consulting services: design, development, commercialization, implementation, maintenance, advice and consulting of all types of IT Solutions, Strategic, Organizational, Commercial, Management Systems, Processes and Improvement, People Development and Management, Quality, Environment and Energy, Corporate Social Responsibility, Occupational Health and Safety, Education and Training, Regulation and Public Policies and Data Analytics.
PKF Attest processes information about its employees and collaborators for the proper administration of the group; to manage the employment relationship, to evaluate their professional performance; and to comply with legal obligations arising from the employment relationship, the prevention of money laundering and the protection of personal data.
PKF Attest processes data of its candidates in order to manage the various selection processes for the recruitment of people.
PKF Attest also processes personal data for the management of sending corporate information, sending information about events and / or activities organized or of which it is part.
In any case, the personal information provided will be processed in a lawful, fair and transparent manner in relation to the persons concerned. Such processing shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
The legitimacy for the processing of personal data varies according to the purposes described above and groups of persons concerned, and unequivocal consent is obtained when necessary in accordance with the provisions of current legislation on data protection.
When the legitimation is not consent, the data will be processed in compliance with a contract or pre-contract to which the data subject is a party, or on the basis of the legitimate interest of the data controller.
When data are collected in web forms, the fields marked with an asterisk are mandatory and if they are not provided, the service in question cannot be managed.
To this end, PKF Attest, as part of its commitment to the security and confidentiality of information that may be stored or processed and that contains personal data of the client (even temporarily), has adopted the necessary measures to prevent the alteration, loss, unauthorized access or processing of such data:
- Confidentiality: through adequate controls and administration of users with access to the systems. All PKF Attest personnel have signed an annex to their employment contract that includes confidentiality and the duty of secrecy regarding access to information and personal data that they may have in the performance of their work.
In addition, the application of encryption technologies has been implemented, both in information storage and transmission. Use of confidentiality preservation technologies, applying access control or identity management solutions, among others.
- Integrity: The information systems have security policies and password policies that limit and protect the information available by assigning access profiles both on local servers and in the Microsoft cloud used in the organization.
- Availability: through resource allocation policies and backup policies covering all systems, including projects and services provided to customers. Systematic data recovery tests are carried out in the event of serious incidents that could limit data availability.
- Implementation of resilience mechanisms that allow for the monitoring and rapid detection of incidents and guarantee the articulation of the foreseen recovery mechanisms.
- Implementation of incident response protocols, both physical and logical, to ensure rapid and effective resolution of incidents.
- Implementation of auditing practices to periodically verify the implementation of the different security measures and their effectiveness.
Likewise, PKF Attest has obtained the status of Microsoft Gold Partner, which necessarily implies passing the audits that Microsoft establishes in relation to software licenses and their use.
With regard to the business area of the Group's Securities Agency, PKF Attest Capital Markets AV, S.A., it is expressly stated that all calls made to and received from the distribution department of said business area will be recorded, in order to comply with the provisions of the regulations applicable to investment services entities, complying in all cases with the provisions of this policy.
PKF Attest has defined the actions to be followed for its suitability as a consulting services provider, which include:
- Risk analysis differentiated by treatment instead of the current security system for the information systems as a whole.
- Organizational measures to adapt the annex to the personnel employment contract to the requirements of the GDPR regarding the obligations of personnel with access to customer data.
- Reinforcement of the current incident management process to include the prevention of security breaches and their due notification to the Control Authority and/or the Data Controller, as appropriate.
Periodic internal communications addressed to personnel on the data protection and security policies applied in the entity, the purpose of which is to raise awareness of the importance of complying with and adapting to these policies, regardless of the type of work.
Regarding the destination of the data: these will only be transferred under the conditions under which it has been informed in each case, and in compliance with legal provisions.
In relation to the time of conservation of the data, these will be treated in which they are collected and until the end of the purpose for which they were collected or at the time when the consent given is revoked.
The persons concerned are informed of the possibility of exercising their rights of:
- Access to your personal data, as well as request the rectification of inaccurate data or, where appropriate, request its deletion when, among other reasons, the data is no longer necessary for the purposes for which it was collected.
- The data subject has the right to exercise the right to be forgotten and the right to data portability whenever technically feasible.
- In certain circumstances, the persons concerned may request the limitation of the processing of their data, in which case they will only be kept for the exercise of the right to defend possible claims.
- In certain circumstances and for reasons related to their particular situation, the persons concerned may object to the processing of their data. PKF Attest will stop processing the data, except for compelling legitimate reasons, or the exercise of the right to defend possible claims.
The interested party is informed of the possibility of exercising the aforementioned rights through the e-mail address privacidad@pkf-attest.es.
You have the right to file a complaint with the Spanish Data Protection Agency www.aepd.es if you do not agree with the attention you have received regarding your rights .

