Statement

 

1. Introduction

Iberia Finance (“we,” “us,” “our,” or “the Company”) is fully committed to complying with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), including its amendments and interpretations applicable through 2026, as well as all related EU data protection legislation.

This GDPR Compliance Statement explains how Iberia Finance fulfills its obligations as a Data Controller and/or Data Processor under the GDPR. It outlines our commitment to protecting the rights and freedoms of data subjects within the European Union and European Economic Area (EU/EEA).

This statement should be read together with our Privacy Policy, Terms and Conditions, and Cookie Policy.

—

2. Scope of Application

2.1 Territorial Scope

This GDPR Compliance Statement applies to the processing of personal data where:

– We process personal data of data subjects located in the EU/EEA, regardless of whether processing occurs within the EU
– We offer goods or services to data subjects in the EU/EEA
– We monitor the behavior of data subjects within the EU/EEA
– We process personal data as a controller or processor established in the EU
– Member State law applies by virtue of public international law

2.2 Material Scope

This statement covers all personal data processing activities conducted by Iberia Finance, including:

– Collection, storage, and use of personal data
– Processing related to account management and financial services
– Identity verification and regulatory compliance
– Marketing and communications
– Analytics and service improvement
– Data sharing with third parties

2.3 Exclusions

This statement does not apply to:

– Processing by natural persons for purely personal or household activities
– Processing by competent authorities for law enforcement purposes (covered by the Law Enforcement Directive)
– Anonymous data that cannot be linked to an identifiable person

—

3. Data Controller and Processor Roles

3.1 Data Controller

Iberia Finance acts as a Data Controller when:

– Determining the purposes and means of processing personal data
– Processing personal data of our customers and website visitors
– Making decisions about how personal data is used
– Establishing relationships with data subjects

3.2 Data Processor

Iberia Finance acts as a Data Processor when:

– Processing personal data on behalf of business clients
– Providing services under instructions from another controller
– Handling data where the client determines purposes and means

3.3 Joint Controllers

Where Iberia Finance and another entity jointly determine purposes and means of processing, we enter into joint controller arrangements that:

– Define respective responsibilities
– Establish a point of contact for data subjects
– Allocate compliance obligations
– Ensure transparency for data subjects

3.4 Data Protection Contact

For all data protection matters:

Email: [email protected]
Subject Line: “GDPR Compliance Inquiry”

—

4. Lawful Basis for Processing

4.1 Article 6 Lawful Bases

We process personal data only when we have a valid legal basis under Article 6 of the GDPR:

a) Consent (Article 6(1)(a))

We rely on consent for:
– Marketing communications
– Non-essential cookies
– Optional data collection
– Certain profiling activities

Requirements for valid consent:
– Freely given without coercion
– Specific to particular purposes
– Informed with clear information
– Unambiguous through affirmative action
– Withdrawable at any time
– Documented for accountability

b) Contract Performance (Article 6(1)(b))

We rely on contract performance for:
– Account creation and management
– Transaction processing
– Service delivery
– Customer support
– Billing and payments

c) Legal Obligation (Article 6(1)(c))

We rely on legal obligation for:
– Identity verification (KYC)
– Anti-money laundering (AML) compliance
– Counter-terrorist financing (CTF)
– Tax reporting (FATCA/CRS)
– Regulatory reporting
– Record retention

d) Vital Interests (Article 6(1)(d))

We may rely on vital interests for:
– Life-threatening emergencies
– Protecting physical safety
– Urgent medical situations

e) Public Interest (Article 6(1)(e))

We may rely on public interest for:
– Fraud prevention
– Security purposes
– Regulatory cooperation

f) Legitimate Interests (Article 6(1)(f))

We rely on legitimate interests for:
– Fraud prevention and detection
– Network and information security
– Service improvement
– Business analytics
– Direct marketing to existing customers
– Legal claims defense

Legitimate Interest Assessments (LIAs) are conducted and documented for all processing based on this basis.

4.2 Article 9 Special Categories

Where we process special category data (e.g., biometric data for identity verification), we rely on:

– Explicit consent (Article 9(2)(a))
– Substantial public interest (Article 9(2)(g))
– Legal claims (Article 9(2)(f))

4.3 Legal Basis Documentation

We maintain records of:
– Legal basis for each processing activity
– Balancing tests for legitimate interests
– Consent records
– Legal obligation references

—

5. GDPR Principles Compliance

5.1 Lawfulness, Fairness, and Transparency (Article 5(1)(a))

Lawfulness:
– All processing has a valid legal basis
– We comply with all applicable laws
– Processing is authorized and documented

Fairness:
– We process data in ways data subjects would reasonably expect
– We do not use data in ways that cause unjustified harm
– We consider data subject rights and interests

Transparency:
– Clear privacy notices provided
– Information provided at collection
– Easy-to-understand language used
– Contact information readily available

5.2 Purpose Limitation (Article 5(1)(b))

– Data collected for specified, explicit, legitimate purposes
– No incompatible further processing
– New purposes assessed for compatibility
– Compatible purposes documented

5.3 Data Minimization (Article 5(1)(c))

– Only adequate data collected
– Only relevant data collected
– Only necessary data collected
– Regular reviews of data collection

5.4 Accuracy (Article 5(1)(d))

– Data kept accurate and up to date
– Inaccurate data erased or rectified
– Regular accuracy checks
– User ability to update information

5.5 Storage Limitation (Article 5(1)(e))

– Data retained only as long as necessary
– Retention periods defined and documented
– Secure deletion after retention
– Anonymization where appropriate

5.6 Integrity and Confidentiality (Article 5(1)(f))

– Appropriate security measures implemented
– Protection against unauthorized processing
– Protection against accidental loss
– Protection against destruction or damage

5.7 Accountability (Article 5(2))

– Compliance demonstrated and documented
– Records of processing maintained
– DPIAs conducted where required
– Training provided to staff
– Regular compliance reviews

—

6. Data Subject Rights

6.1 Overview of Rights

We facilitate the exercise of all GDPR data subject rights:

| Right | Article | Response Time |
|——-|———|—————|
| Right to be Informed | 13-14 | At collection |
| Right of Access | 15 | 30 days |
| Right to Rectification | 16 | 30 days |
| Right to Erasure | 17 | 30 days |
| Right to Restrict Processing | 18 | 30 days |
| Right to Data Portability | 20 | 30 days |
| Right to Object | 21 | 30 days |
| Rights re: Automated Decisions | 22 | 30 days |

6.2 Right to be Informed (Articles 13-14)

We provide clear information about:
– Identity and contact details of controller
– Purposes and legal bases for processing
– Recipients of personal data
– International transfer details
– Retention periods
– Data subject rights
– Right to withdraw consent
– Right to lodge complaints
– Whether provision is statutory/contractual
– Existence of automated decision-making

6.3 Right of Access (Article 15)

What You Receive:
– Confirmation of processing
– Copy of personal data
– Processing purposes
– Data categories
– Recipients
– Retention period
– Data source
– Automated decision information

How to Request:
Email: [email protected]
Subject: “GDPR Access Request”

Response: Within 30 days (extendable by 60 days for complex requests)

6.4 Right to Rectification (Article 16)

What We Do:
– Correct inaccurate data
– Complete incomplete data
– Notify recipients of changes

How to Request:
Update in account settings or email: [email protected]

6.5 Right to Erasure (Article 17)

Grounds for Erasure:
– Data no longer necessary
– Consent withdrawn
– Processing unlawful
– Legal obligation
– Objection to processing

Exceptions:
– Legal compliance obligations
– Legal claims
– Public interest
– Archiving purposes

How to Request:
Email: [email protected]
Subject: “GDPR Erasure Request”

6.6 Right to Restrict Processing (Article 18)

Grounds for Restriction:
– Accuracy contested
– Processing unlawful
– Controller no longer needs data
– Objection pending verification

How to Request:
Email: [email protected]
Subject: “GDPR Restriction Request”

6.7 Right to Data Portability (Article 20)

What You Receive:
– Structured, commonly used format
– Machine-readable format (JSON/CSV)
– Data you provided to us
– Based on consent or contract

How to Request:
Email: [email protected]
Subject: “GDPR Portability Request”

6.8 Right to Object (Article 21)

Grounds for Objection:
– Legitimate interest processing
– Direct marketing (absolute right)
– Scientific/historical research

How to Object:
Email: [email protected]
Subject: “GDPR Objection Request”

6.9 Rights Related to Automated Decision-Making (Article 22)

Your Rights:
– Not subject to solely automated decisions
– Human intervention
– Express your point of view
– Contest decisions
– Obtain explanations

How to Request:
Email: [email protected]
Subject: “GDPR Automated Decision Request”

6.10 Exercising Your Rights

Submission Method:
1. Email: [email protected]
2. Include: Full name, account number, specific request
3. Verification: We may request ID verification

Response Timeline:
– Acknowledgment: 5 business days
– Full response: 30 days
– Extension: Up to 90 days total (with notice)

Cost: Free, unless requests are manifestly unfounded or excessive

—

7. Consent Management

7.1 Obtaining Consent

When we rely on consent, we ensure it is:
– Freely given without bundling
– Specific to each purpose
– Informed with clear information
– Unambiguous affirmative action
– Documented with timestamp
– Easily withdrawable

7.2 Recording Consent

We maintain records of:
– Who consented
– When consent was given
– What information was provided
– How consent was obtained
– Any changes to consent

7.3 Withdrawing Consent

Methods:
– Account settings
– Email: [email protected]
– Unsubscribe links
– Contacting support

Effect: Processing stops, but prior processing remains lawful

7.4 Children’s Consent

– Services not intended for under-18s
– Age verification implemented
– Parental consent where applicable

—

8. Data Protection Impact Assessments (DPIA)

8.1 When DPIAs Are Required

We conduct DPIAs for processing that is likely to result in high risk:

– Systematic and extensive profiling
– Large-scale special category data
– Systematic monitoring of public areas
– New technologies
– Data matching or combining
– Vulnerable data subjects
– Innovative uses

8.2 DPIA Process

1. Screening to identify need
2. Description of processing
3. Necessity and proportionality assessment
4. Risk identification
5. Risk mitigation measures
6. Consultation with DPO
7. Consultation with supervisory authority (if required)
8. Documentation and review

8.3 DPIA Outcomes

– Processing approved with measures
– Processing modified to reduce risk
– Processing rejected if risks cannot be mitigated

—

9. Data Protection by Design and Default

9.1 By Design (Article 25(1))

We implement appropriate technical and organizational measures at the design stage:

– Privacy-enhancing technologies
– Data minimization in system design
– Access controls by default
– Encryption implemented from the start
– Pseudonymization where possible

9.2 By Default (Article 25(2))

We ensure default settings protect privacy:

– Only necessary data collected by default
– Limited processing scope by default
– Limited retention by default
– Limited accessibility by default

9.3 Implementation Measures

– Privacy requirements in project planning
– Security reviews for new systems
– Regular privacy assessments
– Staff training on privacy by design
– Documentation of design decisions

—

10. Records of Processing Activities (Article 30)

10.1 Controller Records

We maintain records including:

– Controller name and contact details
– Processing purposes
– Data subject categories
– Personal data categories
– Recipient categories
– International transfers
– Retention periods
– Security measures

10.2 Processor Records

For processing activities where we act as processor:

– Processor name and contact
– Controller name and contact
– Processing categories
– International transfers
– Security measures

10.3 Record Maintenance

– Records kept in writing
– Available to supervisory authority
– Regularly updated
– Maintained per Article 30 requirements

—

11. International Data Transfers

11.1 Transfer Mechanisms

For transfers outside the EU/EEA, we use:

a) Adequacy Decisions
– Transfers to countries deemed adequate by the European Commission
– Current adequacy decisions applied

b) Standard Contractual Clauses (SCCs)
– EU Commission-approved clauses
– 2021 SCCs implemented
– Transfer Impact Assessments conducted

c) Binding Corporate Rules
– For intra-group transfers where applicable
– Approved by competent supervisory authority

d) Derogations (Article 49)
– Explicit consent
– Contract necessity
– Legal claims
– Important public interest

11.2 Transfer Impact Assessments

We conduct TIAs for transfers to third countries:

– Assessment of local laws
– Evaluation of government access
– Identification of supplementary measures
– Documentation of conclusions

11.3 Supplementary Measures

Where required, we implement:
– Strong encryption
– Pseudonymization
– Data minimization
– Contractual protections
– Technical safeguards

—

12. Data Breach Management

12.1 Breach Detection

We maintain:
– Monitoring systems
– Incident reporting channels
– Regular security assessments
– Staff training on recognition

12.2 Breach Response

Immediate Actions:
– Contain the breach
– Assess the scope
– Document findings
– Notify DPO

Assessment:
– Nature of breach
– Data categories affected
– Number of data subjects
– Likely consequences
– Measures taken

12.3 Notification Requirements

To Supervisory Authority (Article 33):
– Within 72 hours of awareness
– Unless unlikely to result in risk
– Include required information
– Document all breaches

To Data Subjects (Article 34):
– Without undue delay
– When high risk to rights
– Clear, plain language
– Describe breach and measures

12.4 Breach Records

We maintain records of:
– All breaches (even if not notified)
– Facts and effects
– Remedial actions
– Notification decisions

—

13. Data Protection Officer

13.1 DPO Appointment

We maintain appropriate data protection oversight and provide a dedicated contact for all data protection matters.

13.2 DPO Contact

Email: [email protected]
Subject Line: “Data Protection Officer”

13.3 DPO Responsibilities

– Monitoring compliance
– Advising on DPIAs
– Training staff
– Cooperating with supervisory authorities
– Acting as contact point

—

14. Third-Party Processors

14.1 Processor Selection

We select processors that:
– Provide sufficient guarantees
– Implement appropriate measures
– Comply with GDPR requirements
– Meet our security standards

14.2 Processor Agreements

All processor agreements include:
– Processing instructions
– Confidentiality obligations
– Security measures
– Sub-processor conditions
– Assistance with data subject rights
– Breach notification
– Deletion/return of data
– Audit rights

14.3 Processor Monitoring

We regularly:
– Review processor compliance
– Conduct audits
– Assess security measures
– Update agreements

14.4 Sub-Processors

– Prior authorization required
– Flow-down obligations
– Notification of changes
– Right to object

—

15. Accountability and Governance

15.1 Management Responsibility

– Senior management commitment
– Data protection in strategy
– Resources allocated
– Regular reporting

15.2 Policies and Procedures

We maintain:
– Privacy Policy
– Data Retention Policy
– Security Policy
– Breach Response Policy
– Consent Management Policy
– Subject Rights Policy
– Processor Management Policy

15.3 Training and Awareness

– Regular staff training
– Role-specific training
– Privacy awareness programs
– Training records maintained

15.4 Audits and Reviews

– Regular compliance audits
– Privacy program reviews
– Policy updates
– Corrective actions

—

16. Cooperation with Supervisory Authorities

16.1 Cooperation Commitment

We cooperate fully with supervisory authorities:
– Responding to inquiries
– Providing requested information
– Facilitating audits
– Implementing recommendations

16.2 Lead Supervisory Authority

For cross-border processing:
– Lead authority determined per Article 56
– Main establishment identified
– Consistent application ensured

16.3 Complaint Handling

– Complaints acknowledged promptly
– Full cooperation with investigations
– Remedial actions implemented
– Data subjects informed of outcomes

—

17. Compliance Monitoring

17.1 Regular Reviews

We conduct:
– Annual privacy program reviews
– Quarterly policy reviews
– Continuous monitoring
– Ad hoc assessments

17.2 Key Performance Indicators

We track:
– Subject request response times
– Breach response times
– Training completion rates
– Audit findings
– Complaint volumes

17.3 Continuous Improvement

– Lessons learned from incidents
– Best practice adoption
– Technology updates
– Regulatory change monitoring

—

18. Specific Processing Activities

18.1 Identity Verification (KYC)

Purpose: Regulatory compliance and fraud prevention
Legal Basis: Legal obligation, legitimate interest
Data Categories: ID documents, biometric data, personal details
Retention: 5 years after account closure
Recipients: Verification providers, regulators
Safeguards: Encryption, access controls, minimization

18.2 Transaction Processing

Purpose: Service delivery and regulatory compliance
Legal Basis: Contract, legal obligation
Data Categories: Transaction details, account information
Retention: 5-10 years
Recipients: Payment processors, banks, regulators
Safeguards: Encryption, monitoring, access controls

18.3 Fraud Prevention

Purpose: Protecting users and Company
Legal Basis: Legitimate interest, legal obligation
Data Categories: Transaction data, device data, behavioral data
Retention: 5-7 years
Recipients: Fraud prevention agencies, regulators
Safeguards: Profiling controls, human review

18.4 Marketing

Purpose: Promotional communications
Legal Basis: Consent, legitimate interest
Data Categories: Contact details, preferences, usage data
Retention: Until consent withdrawn
Recipients: Marketing platforms
Safeguards: Consent management, opt-out mechanisms

—

19. Data Subject Communication

19.1 Privacy Notices

We provide:
– Clear, concise information
– Layered notices for accessibility
– Plain language
– Regular updates

19.2 Response Standards

– Prompt acknowledgment
– Clear responses
– Plain language
– Complete information
– Timely delivery

19.3 Accessibility

– Multiple contact channels
– Accessible formats on request
– Language support where feasible

—

20. Contact Information

20.1 Data Protection Inquiries

Email: [email protected]
Subject Line: “GDPR Compliance Inquiry”
Support: Available 24/7

20.2 Exercising Your Rights

Email: [email protected]
Required Information: Full name, account number, specific request

20.3 Complaints

To Iberia Finance:
Email: [email protected]

To Supervisory Authority:
EU/EEA data subjects may lodge complaints with their local supervisory authority.
Find your authority: https://edpb.europa.eu/about-edpb/board/members_en

—

21. Definitions

| Term | Definition |
|——|————|
| Personal Data | Any information relating to an identified or identifiable natural person |
| Data Subject | Individual whose personal data is processed |
| Processing | Any operation performed on personal data |
| Controller | Entity determining purposes and means of processing |
| Processor | Entity processing data on behalf of controller |
| Consent | Freely given, specific, informed, unambiguous agreement |
| Legitimate Interest | Business interest not overriding individual rights |
| Special Category Data | Sensitive data requiring additional protection |
| DPIA | Data Protection Impact Assessment |
| SCC | Standard Contractual Clauses |
| Supervisory Authority | Independent public authority for data protection |
| Lead Supervisory Authority | Primary authority for cross-border processing |
| Automated Decision-Making | Decisions without human involvement |
| Profiling | Automated evaluation of personal aspects |

—

22. Document Control

| Version | Date | Changes | Author |
|———|——|———|——–|
| 1.0 | January 1, 2026 | Initial version | Compliance Team |

Next Review Date: January 1, 2027

—

23. Summary of Commitments

Iberia Finance is committed to:

– Processing personal data lawfully, fairly, and transparently
– Collecting data only for specified, legitimate purposes
– Minimizing data collection to what is necessary
– Keeping data accurate and up to date
– Retaining data only as long as necessary
– Protecting data with appropriate security measures
– Demonstrating accountability for compliance
– Facilitating all data subject rights
– Cooperating with supervisory authorities
– Maintaining appropriate records
– Conducting DPIAs where required
– Implementing privacy by design and default
– Managing data breaches appropriately
– Ensuring lawful international transfers
– Training staff on data protection
– Continuously improving our privacy program

—

For all GDPR-related inquiries, contact:

Email: [email protected]
Subject Line: “GDPR Compliance Inquiry”

—

Document Version: 1.0
Last Reviewed: January 1, 2026
Next Review: January 1, 2027

Iberia Finance
[email protected]
https://iberia-finance.com