No items found.

Tax Affairs Department

Purpose

Tax management, preparation, submission, and custody of the declarations legally required by the Spanish Tax Administration Agency (AEAT).


Entity in charge


The legal bases for processing are:

  • Article 6(1)(c) of GDPR: Processing is necessary for compliance with a legal obligation to which the controller is subject:
    • Law 58/2003, of December 17, General Tax Law.
    • Law 9/2017, of November 8, on Public Sector Contracts.
    • Royal Legislative Decree 2/2015, of October 23, approving the revised text of the Workers’ Statute Law.
    • Royal Legislative Decree 5/2015, of October 30, approving the Basic Statute of Public Employees Law.
    • Law 38/2003, of November 17, General Subsidies Law.

Data retention periods

Data will be stored for the time necessary to fulfill the purpose for which they were collected and to determine any potential liabilities that may arise from that purpose and the processing of the data. The provisions of the applicable archives and documentation regulations for Navantia will apply.

The economic data of this processing activity will be retained under the provisions of Law 58/2003, of December 17, General Tax Law.


Affected groups

Personnel and/or legal representatives of the entity, employees of the entity and/or legal representatives of the legal entities that maintain economic relations with the entity.


Data type - Infringement

Not processed.

Data types - Special categories

Not processed.

Data type - Identification data

  • Name and surname
  • NIF (NIE, Passport, or Residence Card Number)
  • Postal address
  • Image
  • Telephone
  • Email
  • Signature (handwritten or electronic)

Data type - Other

  • Employment details
  • Economic, financial, and insurance information
  • Information necessary for the budgetary and economic management of Navantia

Security measures

The security measures applied correspond to those provided in Annex II (Security Measures) of Royal Decree 311/2022, of May 3, which regulates the National Security Scheme in the field of Electronic Administration and are described in the documents forming part of Navantia’s Data Protection and Information Security Policy. Security measures corresponding to Annex A of UNE-EN/IEC 27001 - Information Security Management Systems.

Additionally, security measures are adopted for paper-based documentation according to the risks to which they are exposed, in order to ensure the confidentiality of the processed data.


Communication

Communications are foreseen when data can be communicated in accordance with Article 6 of GDPR, in relation to authorised processing of:

  • Spanish state-owned industrial holding company (SEPI)
  • Courts of Justice
  • Tax Authority
  • Social Security General Treasury
  • General intervention of the National Government
  • Spanish Court of Audit
  • Financial institutions
  • National Social Security Institute and mutual funds
  • Ministry of Finance

International transfers

Data transfers to third countries are planned, mainly to Navantia locations dependent on the International Business Directorate in Australia, Saudi Arabia and United Kingdom.