Our policy

The Directorate and Governing Body of Morna Valley School SL — the data controller — assume maximum responsibility for the establishment, implementation and ongoing improvement of this Data Protection Policy. We aim for excellence in compliance with Regulation (EU) 2016/679 (the GDPR) and Spanish data protection legislation.

The policy rests on the principle of proactive responsibility: the controller is responsible for compliance with the regulatory and case-law framework, and able to demonstrate it to the competent supervisory authorities.

The principles that guide us.

Every member of staff is governed by these principles when processing personal data — they serve as both a guide and the framework we hold ourselves to.

  1. 01.

    Data protection from design

    We apply appropriate technical and organisational measures (such as pseudonymisation) both when determining the means of processing and at the time of the processing itself, integrating the necessary guarantees from the outset.

  2. 02.

    Data protection by default

    By default, only personal data that is necessary for each specific purpose of processing is processed.

  3. 03.

    Protection across the information lifecycle

    Measures to ensure the protection of personal data are applied throughout the entire information lifecycle, not just at collection.

  4. 04.

    Lawfulness, loyalty and transparency

    Personal data is treated in a lawful, fair and transparent manner in relation to the data subject.

  5. 05.

    Limitation of the purpose

    Personal data is collected for specific, explicit and legitimate purposes, and never processed in a manner incompatible with those purposes.

  6. 06.

    Data minimisation

    Personal data is adequate, relevant and limited to what is necessary for the purposes for which it is processed.

  7. 07.

    Accuracy

    Personal data is accurate and kept up to date; reasonable steps are taken to ensure that inaccurate data is deleted or rectified.

  8. 08.

    Limitation of the retention period

    Personal data is kept in a form that allows identification of the data subject only for as long as necessary for the purposes of the processing.

  9. 09.

    Integrity and confidentiality

    Personal data is treated in a way that ensures adequate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.

  10. 10.

    Information and training

    All staff with access to personal data is trained and informed about their obligations under data protection regulations, throughout the information lifecycle.

Commitment in practice.

This policy is communicated to all personnel responsible for processing and made available to all interested parties. Every member of staff is responsible for implementing it, verifying the data protection rules applicable to their activity, and identifying opportunities for improvement. The policy is reviewed by the Directorate as often as needed to adapt to current data protection provisions.