At Endesa we are committed to ensuring that our customers' personal data will be used transparently and securely, so we want you to know that you have control over your data at all times. As an Endesa customer, provided that the current regulations allow it, you can decide who receives your personal data, under what conditions and for what purpose.
To make this possible, we have updated our Data Protection Policy as part of our review and continuing improvement process and in accordance with the best practices in Corporate Governance and Compliance. This new Data Protection Policy replaces the one that previously regulated the processing of your data as an Endesa customer, and we hope to renew your trust in us by informing you how we collect, process and protect your personal data.
2. Who can process your data?
3. What personal data do we process?
4. Why do we process the data?
5. Why are we entitled to process your personal data?
6. How long will we keep your data?
7. Do we process the data of minors?
8. What security measures apply?
9. What information do we share with third parties?
10. What rights do I have with regard to the processing of my personal data?
11. How can I contact the Endesa Data Protection Officer?
12. Changes to the Data Protection Policy
To help you better understand our Data Protection Policy, we will start by defining below some of the concepts included in it:
- Customer: a natural person who maintains a contractual relationship with Endesa.
- Contract: an agreement that regulates the terms and conditions applicable when contracting any Endesa product or service.
- Joint controllers: two or more data controllers who jointly determine the objectives and/or methods of data processing. In this sense, Endesa Energía and Endesa X will be joint controllers for the processing of certain data.
- Distribution company: the company responsible for distributing energy to your home. In the Spanish electricity market, citizens cannot choose their distribution company; it is determined by the area you live in.
- Data processor: natural or legal person who processes personal data on behalf of the data controller.
- Endesa: Endesa Energía, S.A.U. and Endesa X Servicios S.L.
- Endesa Energía: Endesa Energía S.A.U.
- Endesa X: Endesa X Servicios S.L.
- Endesa Group: The Endesa group is made up of the parent company, Endesa S.A., and all its subsidiaries. You can see the complete list of companies in the Endesa Group here: https://www.endesa.com/en/about-endesa/who-we-are/subsidiaries.
- LOPDGDD: Organic Law 3/2018, of 5 December, on Protecting Personal Data and Guaranteeing Digital Rights.
- Packaged Energy Offer: set of products or services, directly related to the field of energy, that are jointly marketed by Endesa Energía and Endesa X under the Endesa brand, with more advantageous conditions or at a better price than if purchased separately.
- Data controller: natural or legal person who, alone or together with others, determines the purposes and methods of data processing.
- GDPR: European Parliament and European Council Regulation (EU) 2016/679, of 27 April 2016, on the protection of natural persons with regard to personal data processing and the free movement of these data, which repeals Directive 95/46/EC.
- Web user: holder of a contract with Endesa Energía or with Endesa X who is registered with either the Endesa Energía or Endesa X website.
2) Who can process your data?
The following companies in the Endesa Group will process your personal data as "Joint Controllers," except for any processing that must be carried out to comply with the particular conditions or services for a specific product or service contracted with one of them, in which case they will be considered separate "Data controllers":
- Endesa Energía, S.A.U. with Tax ID No. A81948077 and its registered office at: Calle Ribera del Loira, 60, 28042, Madrid - Spain.
- Endesa X Servicios S.L. in the formation stage.
In this sense, Endesa Energía and Endesa X have reached a joint controller agreement that duly reflects their respective functions and relationships as joint controllers for the stakeholders. The essential aspects of this agreement are at your disposal, if requested.
3) What personal data do we process?
Personal data are any information that directly identifies you or allows you to be identified, including, for example, your first and last name, e-mail address, Universal Supply Point Unification Code (CUPS), etc. You may have provided some of this data directly when you signed your contract with us but other data may have been inferred from our relationship with you, such as the electricity or gas consumption corresponding to the supply point of which you are the effective user.
The data that may be processed are grouped into the following categories:
- Data included in the contract or subsequently provided during the contractual relationship: first name, last name, ID No., supply point (CUPS), telephone no., e-mail address, contracted rate and data entered in energy advice tools.
- Data derived from the provision of services during the contractual relationship: number of contacts made and the incidents resolved or ongoing, contract requests made, results of satisfaction surveys, commercial communications made, historical consumption at the supply point of which you are the effective user, billing history and any data that may be collected from your visits to our websites through the use of “cookies”.
At Endesa, we only process the data that are strictly necessary for the specific purposes set out in this Data Protection Policy and only for the time required to do so, as stated in Section 6 and always respecting all the principles and obligations contained in both the GDPR and the LOPDGDD.
The questions listed below explain in detail why and how we process your data.
4) Why do we process the data?
At Endesa we process your personal data in order to manage the provision of products and services that you have contracted with us, to comply with the legal obligations imposed, for example, on energy or consumption, to send out commercial communications about products and services that may be of interest to you, or to gather information about how you browse our websites through the use of “cookies”. The specific purposes for which we use your data are detailed below:
a) To manage any products and services contracted with Endesa
Your data will be processed in order to manage the product or service that you contract.
You should also know that if you request a product or service that can entail deferred payment or the provision of a periodic billing service, prior to entering into any contract, we may consult credit records and registers as we deem appropriate to determine your credit standing, always in strict compliance with the applicable regulations. The result of any such consultation may, where appropriate, condition the entry into force of the contract. In addition, in the event of default, Endesa may communicate your data to these records, always complying with the guarantees granted by the legislation in force in these cases.
If you started the contracting process on one of our websites and input your personal data but were unable to complete the process, do not worry; we will send up to a maximum of two reminders to your e-mail address with support or help so that you can successfully complete the contracting process that you had started.
Once you become our customer, in order to provide you with the best possible service, your data may be used to deal with your queries and requests on all our service channels (including by telephone, face-to-face and on our websites), send you informative communications and conduct service quality and customer service satisfaction surveys, identify you in the contracting processes that you initiate with us, bill you for the energy supplied or provide you with energy advisory services.
In addition, if you are registered with the website, your personal data may be processed in order to manage the services available to you as a user of this website, for example, the “electronic billing service”, for which we need to use your e-mail address to send you your bills. On this issue, you should be aware that, if you provide us with your e-mail address, it will be treated as the preferred means for sending any type of communication relating to our contractual relationship.
b) To comply with the established legal obligations
Your data may also be processed to comply with any type of legal obligation, such as contracting access to the networks with the “Distribution Company”, taking the steps required to ensure that the supply is provided successfully, exchanging information with the Distribution Company in order to bill your energy consumption, and meeting the requirements of the National Markets and Competition Commission and the Spanish Data Protection Agency, among other legal obligations.
c) To send out commercial communications on products and services in the interests of the customer
Other processing of your personal data may also be carried out based on Endesa's legitimate interests. You can object to these as indicated in section 10.
We will perform this processing in order to send you information on Packaged Energy Offers that are related with your contracted service and best fit your energy consumption needs, and, where appropriate, allow you to obtain improvements on your bill (or even benefits for the service already contracted) as a result of contracting the supply of electricity or gas and a value-added service together.
To do this, your personal data may be analysed beforehand in order to draw up a basic profile from which we can find out whether the commercial campaign being carried out fits your needs and preferences in terms of energy consumption. This analysis may take into account the data included in the previous section (demographic data, contracted rate, historical consumption, products and services contracted with Endesa, etc.), so it may be necessary for Endesa Energía and Endesa X occasionally to exchange specific parts of your data in order to ensure that the campaigns and Packaged Energy Offers that we send to you are not repetitive, unnecessary or annoying. In any case, the full communication of your data will only take place if you have given us your consent.
Anyway, we remind you that at any time you can object to both the receipt of commercial communications and the communication of any of your data between Endesa Energía and Endesa X, although in this case you will not be able to take advantage of the Packaged Energy Offers, by exercising your right of objection on the channels indicated in section 10.
Bear in mind that you can only receive commercial communications of this type while you are still an Endesa customer, unless you subsequently authorise us in this respect.
In addition, as explained in section 5, any complex profiling, including the assumptions provided for in article 22 of the GDPR, will be subject to our having previously obtained explicit, informed, free and unequivocal consent from the affected party.
Finally, for the cases in which you have given us your consent, we can also help you, on any communication channel (including, among others, e-mail, text messages and phone calls), to stay informed about products and services offered by other companies with which we collaborate that may be of interest to you, related to the energy, home, insurance, motoring, financial services and leisure sectors. Your data will only be transferred to other companies in the Endesa Group or to third parties related to these sectors if you have given us your express consent.
We would also remind you that you can withdraw your consent at any time using the channels indicated in Section 10 of this Data Protection Policy.
d) To manage the web services
If you have registered with the Private Customer Area on the Endesa website, your personal data may be processed in order to manage the website's services.
e) To gather information when you browse our websites
Endesa's web pages, like many other internet portals, use a technology known as "cookies" to collect information on your interactions with their web pages, provided that you have authorised their use.
If you would like more details about how this technology works, you can consult the section "Cookies at Endesa".
5) Why are we entitled to process your personal data?
Depending on the specific purpose for which we need to process your data (for example, to properly manage the contractual relationship we have with you, to comply with applicable legal obligations, to send out commercial communications or to collect information when you browse our websites), we will have the applicable legal bases of legitimacy.
We therefore inform you below of the bases of legitimacy that will allow us to carry out the different types of processing:
a) Performance of the contract
The legal basis for us to be able to manage the products and services that you have contracted with us is “performance of the contract”, which legitimises us to carry out the necessary personal data processing (including processing your e-mail address) to deal with your queries and requests on all our service channels (including by telephone, face-to-face and our websites), send you informative communications and conduct service quality and customer service satisfaction surveys, identify you in the contracting processes that you initiate with us, bill you for the energy supplied or provide you with energy advisory services.
Therefore, refusing to provide the personal data requested or giving us inaccurate or incomplete data may result in our being unable to properly provide the services that you contracted. Therefore, we would like to remind you that you are responsible for providing truthful data, as well as for notifying Endesa of any future changes to those data.
b) Compliance with legal obligations.
As previously stated, sometimes we need to use your personal data to comply with some kind of legal obligation; therefore, the legal basis that legitimises us to perform this processing consists, specifically, of fulfilling these legal obligations.
Consent constitutes a legitimate basis for Endesa to process personal data, after obtaining the express, free, unequivocal and informed consent of the interested party.
Therefore, any processing that is carried out with the purpose of sending you commercial communications about other products or services offered by third-party companies relating to energy, home, insurance, motoring, financial and leisure services, as well as the transfer of your data to these companies, is legally based on the "consent" that you may have given. Similarly, any commercial communication addressed to consumers who are not Endesa customers is subject to obtaining their express prior consent.
Any complex profiling, including the assumptions provided in article 22 of the GDPR, will be subject to having previously obtained explicit consent from the affected party. Therefore, as long as you do not withdraw your consent, you may continue to receive communications of this type, or your data may remain under the control of the companies with which we collaborate.
Any "consent" that you have given in each case will be the legal basis for the processing of personal data associated with managing your web user account on the website, as well as, where appropriate, the processing of your e-mail for sending out e-bills.
Furthermore, we would like to remind you that if you have given your consent for any of the purposes described above, you have the right to withdraw it at any time without this having any consequences on the services or products that you have contracted. You will find the information that you need to exercise your right to withdraw your consent in section 10 of this Data Protection Policy.
d) Legitimate interest
Legitimate interest constitutes a legitimate basis as long as Endesa's interest in processing a customer's data falls within the customer's reasonable expectations, taking into account their relationship with Endesa. Any interested party always has the possibility of exercising the right to object, as specified in section 10.
To this end, the processing carried out in order to send you information on Packaged Energy Offers that are related with your contracted service and best fit your energy consumption needs and, where appropriate, allow you to obtain improvements on your bill (or even benefits for the service already contracted) as a result of contracting the supply of electricity or gas and a value-added service together (including the occasional exchange of data that may be carried out, solely and exclusively, between Endesa Energía y Endesa X to ensure the effectiveness of said campaigns), are carried out based on Endesa's “legitimate interest”.
We therefore inform you that the regulations in force allow us to use legitimate interest as a basis for legitimisation that entitles us to perform the above processing based on the expectations that you may have as our customer. For this reason, we remind you that you can object at any time to the processing identified in the previous section, by exercising your right to object through the channels indicated in section 10.
On the other hand, the processing needed to judge your financial solvency, your acceptance as a customer or, where appropriate, the communication of your data to credit information systems are also carried out based on legitimate interest. Endesa's interest in carrying out this processing is clear, as long as it is an authorisation granted by Art. 20 of the LOPD-GDD to creditors who provide a periodic billing service, as is our case.
Likewise, the processing carried out to perform factoring operations (partial or total advance of loans assigned to financial entities), so that Endesa can operate an efficient business management model, will be carried out based on the legitimate interest of Endesa in being able to obtain financing to undertake its commercial activities.
Also, data may be exchanged by Endesa Energía and Endesa X for administrative purposes, or to promote the proper management of commercial relationships with customers.
6) How long will we keep your data?
The personal data that you provide as a customer will be kept as long as they are required to provide the services under contract. Once they are no longer needed for this purpose, the data will be blocked for the period during which they may be required to deal with complaints or to defend against administrative or legal actions, as well as for the period of limitation of criminal, civil, commercial and/or administrative responsibilities, and it may only be unblocked and processed again for this reason. After this period, the data will be deleted definitively.
In the cases in which you gave your express consent to receiving personalised offers in the area of energy that may be of interest to you when you were not a customer of Endesa, your data will be kept as long as you do not withdraw the consent provided through the channels indicated in section 10.
If you are a web services user, we will save your personal data while you continue to use these services. However, if we detect that you have not used or interacted with your account or with any of our web services during a period of two (2) years, we will proceed to cancel your account by blocking your data. If, after this period, you wish to use any of the web services again, you will need to register again.
7) Do we process the data of minors?
Endesa ensures the proper use of minors' data, guaranteeing respect for the laws that are applicable to them and the measures that are reasonably appropriate in these cases, and, therefore, we do not collect any personal data relating to minors without the prior consent of their parents, guardians or legal representatives.
8) What security measures apply?
In order to make its Data Protection Policy effective and efficient, Endesa has adopted the necessary technical and organisational security measures to prevent the alteration, loss, misuse, processing or unauthorised access to or theft of data, depending on the state of the technology, for all channels in which personal data can be processed, including, therefore, all websites, telephone support services and face-to-face channels.
In addition, we inform you that your data may be subject to an anonymisation process in which they will be replaced by an irreversible identifier, so that the customer behind the identifier cannot be identified, in order to conduct studies and internal analysis to obtain aggregate results that help us to identify general behaviours and improve the quality of the products and services offered.
9) What information do we share with third parties?
Endesa only exchanges personal data with third parties who will be considered Data Processors - for which we will not need your authorisation - in order to properly manage the contractual relationship, or with other collaborating companies when we have been authorised by your consent.
We will also provide your data to the credit information systems in the cases allowed for under current regulations, as well as to credit entities to perform factoring operations, or to public administrations, authorities and organisations to comply with legal obligations.
Below are the details of this processing, the recipients and the basis for legitimacy:
a) Access by third parties to provide a contracted service
Your personal data may be accessed by the service providers that Endesa contracts or may contract, which have the status of Data Processor (including other companies in the Endesa Group), who will carry out the personal data processing required to provide you with the services contracted, following the instructions that Endesa deems appropriate and guaranteeing, at all times, the confidentiality, security and secrecy of the information to which they have access. These third parties will help us, for example, in providing services related to sales, customer service, debt collection, marketing and advertising and professional services.
We also inform you that it is possible that some of the third parties that act as data processors may be located outside the European Economic Space. In particular, your personal data may be accessed by trustworthy providers located in the following countries: United States, India, Colombia and Peru. In all cases, we have legal authorisation to make these types of transfers, since we are authorised for all of them by the Director of the Spanish Data Protection Agency.
b) Occasional exchange of data by Endesa Energía and Endesa X
The occasional exchange of data between Endesa Energía and Endesa X in order to send you Packaged Energy Offers by non-electronic means, as well as to avoid unnecessary repetition of commercial campaigns, is based, as previously indicated, on Endesa's legitimate interest.
These exchanges will be made in specific cases and for the purpose described above, without, under any circumstances, the permanent or complete transfer of your data between these two companies for other purposes. You will only receive commercial communications about Packaged Energy Offers by electronic means from companies in the Endesa group other than the company with which you have a contract when you have given your consent to receiving such communications.
The data may also be communicated between Endesa Energía and Endesa X for administrative purposes or to promote proper commercial customer services.
c) Transfer of data to third parties with whom we collaborate
Under no circumstances will personal data be transferred to third-party companies unless you have previously provided us with your consent.
If you have given your consent, your data may be shared with Endesa Group companies or third companies related to the energy, home, insurance, automotive, financial services and leisure sectors.
d) Communication of information to credit information systems
As stated above, it is possible that, in accordance with current regulations, we may communicate your data to the asset and credit solvency registers that we deem appropriate if you have defaulted on a periodic billing service that you have contracted with us, based on our legitimate interest.
e) Factoring operations
Data may be communicated to credit institutions for the sole purpose of factoring operations, so that Endesa can operate an efficient business management model. This processing will be carried out under the strictest security measures and based on the legitimate interest of Endesa in obtaining financing to undertake its commercial activity.
f) Compliance with a legal obligation
Your personal data may be transferred to government departments, authorities and public bodies, including courts and tribunals, when so required by applicable regulations, for example, to the National Commission for Markets and Competition, the tax authorities, etc.
10) What are your rights regarding the processing of your personal data?
The GDPR and LOPDGDD state the following rights in regard to the processing of your personal data that may be exercised before and against any one of the data controllers.
- Access: allows you to confirm whether we are processing your personal data and, if so, which data.
- Rectification: allows you to help us correct errors and modify data that may be inaccurate or incomplete.
- Deletion: allows you to request the deletion of your data, which will mean that Endesa will cease to process them unless there is a legal obligation for them to be retained, in which case they will be duly blocked, or other legitimate reasons prevail for us to process them.
- Limiting processing: allows for, under the conditions established by law, the processing of your data to be halted; however, the data may be kept properly blocked to handle complaints or defend against administrative or judicial actions.
- Objection: allows you to request that we stop processing your personal data that we believe we have a legitimate interest to process, for example, based on your expectations as a customer, as occurs when sending you offers on products and services.
Endesa will stop processing your data, unless compelling, legitimate reasons apply, or it is necessary to deal with complaints or defend against administrative or judicial actions, in which case they will remain duly blocked.
- Portability: allows you to receive your personal data in a structured, commonly used, mechanically readable format so that you can pass them on to another data controller.
- Withdrawal of consent: allows you to stop your data being processed for a purpose that you had previously authorised, for example, the receipt of commercial communications from third parties with whom we collaborate.
To exercise these rights, Endesa Energía can be contacted on any of the following channels:
- By post, by attaching a photocopy of your National ID card, passport or any other identification document, to a letter stating your request, addressed to PO Box 1128, 41080 - Sevilla, Attn. Endesa Operations and Commercial Services.
- By e-mail to the following address: email@example.com including the following information: first name and last name of the data subject, address for the purposes of notifications, photocopy of their National ID card, passport or any other identification document, and a statement of the request.
In addition, we remind you that the regulations in force allow you to file a complaint with the Spanish Data Protection Agency, the contact details of which are as follows:
Spanish Data Protection Agency
Calle Jorge Juan, 6 - CP: 28001 Madrid.
Telephone: 901 100 099 / 91 266 35 17
11) How can I contact the Endesa Data Protection Officer?
Endesa SA, the parent company of the Endesa Group, of which Endesa Energía and Endesa X are members, has appointed a Data Protection Officer for these companies.
If you have any questions regarding the purpose of the processing of your personal data by Endesa, its legitimacy, or any other matter relating to the protection of personal data, you can contact our Data Protection Officer by post at the following address: C/ Ribera del Loira, 60, 28042, Madrid - Spain, or by sending an e-mail to the following e-mail address: firstname.lastname@example.org.
12) Changes to the Data Protection Policy
Whenever Endesa updates this Data Protection Policy as a result of changes to personal data processing, we will duly inform you of this sufficiently in advance so that you can send us any type of query or, where appropriate, exercise your rights as recognised in the regulations in force at that time.
Thank you for the trust you have placed in Endesa.