Personal Data Protection Policy
1. Who is the data controller and who is the data protection officer?
The n² Notary Office processes personal data in the course of its business activities.
n² Notaries, located at 1490 Court-Saint-Etienne, Boucle Joseph Dewez 1, with company number BE1008.595.904 RPM Walloon Brabant, acts as the data controller for the processing of personal data carried out within the firm (hereinafter “the firm”). The data controller is the natural or legal person who determines the purposes and means of processing personal data.
The firm is committed to protecting privacy. The firm is committed to protecting and processing your personal data with particular care and in a fully transparent manner, in strict compliance with privacy protection laws, including the General Data Protection Regulation (EU) 2016/679 (hereinafter “GDPR”).
In accordance with the GDPR and the Code of Conduct, the firm has appointed a Data Protection Officer, namely Privanot ASBL. The Data Protection Officer can be contacted at the following email address: info@privanot.be, or by mail at the following address: Privanot asbl, Rue de la Montagne 30, 1000 Brussels.
Through this personal data protection policy, we aim to provide you with further details on how we process the personal data we hold. In this policy, you will find answers to the following questions:
- Who is the data controller and who is the data protection officer?
- Why is your personal data processed?
- What is the legal basis for processing your personal data?
- What personal data does the firm process?
- What are the sources of information?
- To whom may your personal data be disclosed?
- Who are our data processors?
- Will your personal data be transferred outside the European Economic Area (EEA)?
- How long will your personal data be retained?
- How are the security and confidentiality of your personal data ensured?
- Can conversations with the notary’s office be recorded?
- What are your rights?
Please note that information regarding the processing of personal data of internal employees for human resources purposes is set forth in the firm’s employment regulations. Information regarding the processing of personal data of external employees for human resources purposes is set forth in the firm’s service agreements or general policy documents.
2. Why is your personal data processed?
Purposes —The firm collects and processes personal data primarily to ensure the legal validity of transactions for which the notary certifies authenticity, as well as to manage the cases entrusted to the notary.
- In addition, processing operations are necessary to carry out other important tasks and objectives, namely the management of the firm’s files, including processing carried out before and after the execution of an authentic instrument, such as necessary research and verifications, as well as any other processing required to fulfill the notary’s duties as a public official and the tasks entrusted to them by citizens;
- administrative management and tracking of citizens’ files, including billing and accounting;
- Conducting the necessary verifications and controls in accordance with anti-money laundering legislation;
- ensuring the security of buildings, property, staff, and visitors through video surveillance;
- Optimizing website navigation through the use of cookies;
- improving user-friendliness and services by utilizing citizen feedback and statistical analysis of the firm’s operations and services using software;
- improve the quality of the notary office’s operations in the preparation of deeds and documents necessary for notaries to perform their duties as public officials through the use of low-risk artificial intelligence systems.
3. What is the legal basis for the processing of your personal data?
Lawfulness —The processing of personal data by the notary is considered lawful provided that, in most cases, it is necessary to comply with a legal obligation to which the notary is subject or necessary for the performance of a task in the public interest entrusted to the notary handling the case within the firm.
The processing of personal data is carried out by the firm based on, among other things, but not limited to, the following laws:
- Law of 25 Ventôse, Year XI, on the organization of the notarial profession;
- The Law of September 18, 2017, on the prevention of money laundering and terrorist financing and on restrictions on the use of cash.
In addition, the lawfulness of the processing may also be based on the legitimate interests of the data controller, such as improving client satisfaction or securing the firm’s premises through the use of surveillance cameras.
Finally, the lawfulness of processing may be based on the data subject’s consent, for example when non-functional cookies are used on the firm’s website.
4. What personal data does the firm process?
Depending on the services you use, the firm may process the following personal data:
- identification data (last name, first name, marital status, national ID number, place and date of birth, etc.);
- contact information (mailing address, email address, phone number, etc.);
- economic and financial data (bank account number, etc.);
- data relating to legal capacity;
- data regarding professional activity;
- data regarding transactions conducted within the firm;
- data resulting from AML due diligence obligations, such as national and international financial sanctions lists, PEP status, and adverse information from public sources regarding predicate offenses to money laundering, countries posing a high AML risk or considered tax havens, and judicial data);
- data regarding family, social, tax, or other circumstances that the notary is required to collect from official sources and government agencies concerning you;
- CCTV footage;
- data regarding the quality and satisfaction with the services provided.
5. What are the sources of information?
As a public official, the notary is required to collect and use personal data about you in the course of performing their duties.
Personal data about you comes from:
- from you or your legal representative;
- from authentic data sources strictly regulated by specific legislation, such as the National Registry, the Social Security Cross-Reference Database, the Central Inheritance Registry, the Central Registry of Cohabitation and Marriage Contracts, etc.;
- official bodies authorized to provide data to notaries in the course of their public duties;
- the AML screening tool of the National Chamber of Notaries;
- footage recorded by one or more video surveillance cameras.
6. To whom may your personal data be disclosed?
The personal data processed by the firm may be disclosed to third parties (“recipients”), depending on the context of the processing, and specifically:
- to legally authorized partners, such as public services and notarial institutions, for the storage of deed transcriptions and their metadata as part of electronic registration and for the entry of your data into the central registries of the notarial profession (e.g., the Central Register of Marriage Contracts, the Central Register of Power-of-Attorney Agreements, the Central Register of Declarations Regarding the Appointment of an Administrator or a Trusted Person, etc.);
- to the Royal Federation of Belgian Notaries (asbl), regarding data pertaining to real estate, for entry into a notarial database intended to generate statistics and enable notaries to estimate the value of real estate in the course of their duties;
- to the Provincial Chamber of Notaries responsible for your case and/or the National Chamber of Notaries (for example, in connection with their accounting oversight functions or in the context of preventing and combating money laundering);
- to the Financial Information Processing Unit (CTIF), for example, in connection with the prevention and combating of money laundering;
- to judicial authorities, for example in connection with the prevention and combating of money laundering;
- to authorities involved in national and international cooperation in the context of preventing and combating money laundering;
- to other notaries involved in your case (for example, in connection with a real estate sale);
- to the State Archives for the preservation of files, notarial records, and wills;
- to banks involved in your case;
- tothe certified public accountant/tax specialist who manages the office’s accounting;
- to subcontractors responsible for the firm’s management and continuity, such as software providers for the preparation of deeds.
7. Who are our subcontractors?
A subcontractor is a natural or legal person, a public authority, an agency, or another entity that processes personal data on behalf of the firm.
The firm uses the following categories of subcontractors, among others:
- hardware providers;
- software providers, for example for file management and accounting;
- server/backup providers;
- paper document destruction service providers;
- video surveillance camera providers;
- consultants or external contractors;
- etc.
8. Will your personal data be transferred outside the European Economic Area (EEA)?
In principle, your personal data will not be transferred outside the European Economic Area (hereinafter “EEA”).
However, in the event that your personal data is nevertheless transferred to countries outside the EEA and the European Commission has determined that the country to which the data is transferred does not provide an adequate level of protection, the firm will strive to protect your personal data by providing additional safeguards (for example, by entering into standard contractual clauses approved by the European Commission, by adopting binding corporate rules, etc.).
9. How long will your personal data be retained?
Pursuant to the principle of data minimization, the aforementioned data may only be retained for as long as necessary to fulfill the intended purpose, in accordance with the specifically applicable laws and the statutes of limitations for commercial and personal claims. The retention periods listed below correspond to those specified in the firm’s record of processing activities.
Retention periods vary depending on the nature of the documents, namely:
- client files for citizens will be retained as long as the citizen has not chosen to change notaries, and will be retained for a maximum of the citizen’s lifetime to enable the provision of advisory services (in accordance with Article 9 of the Law of Ventôse, Year XI, governing the organization of the notarial profession);
- files are retained for 30 years after their closure for evidentiary purposes (in accordance with Article 3.27 of the New Civil Code);
- Minutes are retained for 50 or 75 years after the signing of the deed and are then transferred to the National Archives (in accordance with Article 62 of the Law of Ventôse, Year XI, on the Organization of the Notarial Profession);
- the books (accounts) are retained for 10 years after the close of the fiscal year (in accordance with Article 33 of the Law of Ventôse, Year XI, concerning the organization of the notarial profession);
- account statements are retained for 10 years after the close of the fiscal year (in accordance with Article 33 of the Law of Ventôse, Year XI, on the Organization of the Notarial Profession);
- Personal data subject to the Anti-Money Laundering Act is deleted at the end of a 10-year retention period (in accordance with Articles 60 and 62(1) of the Law of September 18, 2017, on the Prevention of Money Laundering and Terrorist Financing and on Restrictions on the Use of Cash);
- camera footage will be retained for a maximum of one month (in accordance with Article 6 of the amended Act of March 21, 2007, on the Installation and Use of Surveillance Cameras);
- Personal data processed for the management of the website is retained for as long as necessary to achieve the purposes for which it was collected;
- Personal data processed using artificial intelligence software will no longer be processed by these technologies once your case has been closed by the firm.
10. How are the security and confidentiality of your personal data ensured?
The firm takes appropriate technical and organizational measures to ensure a level of security commensurate with the risk. In addition, the firm ensures that it adopts the security measures for the processing of personal data set forth in the Code of Conduct of the National Chamber of Notaries dated January 28, 2021.
Security measures are taken to prevent the loss, destruction, alteration, or unauthorized disclosure of personal data that is transmitted, stored, or otherwise processed, or unauthorized access to such data;
In particular, the notary’s office ensures that:
- access to the premises containing data storage media is restricted to authorized persons;
- the server environment is properly secured;
- personal data is stored and destroyed securely;
- secure access to the data necessary to achieve the intended purpose is provided to employees and subcontractors;
- a procedure for reporting any personal data breaches, applicable to all members of the firm, is established;
- a procedure for managing the rights of data subjects, applicable to all members of the firm, is established;
- an information security policy accessible to all members of the firm is implemented;
- a GDPR awareness policy for firm members is in place;
- technical security measures, such as firewalls, antivirus software, and regular security updates, are implemented.
These measures are regularly monitored and reviewed by the aforementioned DPO following an audit.
In accordance with Article 28 of the GDPR and Article 2 of the Code of Ethics of the National Chamber of Notaries dated January 28, 2021, the notary office has signed a data processing agreement with the various processors it engages.
11. Can conversations with the notary’s office be recorded?
The relationship of trust between the notary and the citizen requires that meetings with the notary’s office not be recorded in any form, whether audio or video. This stems in particular from the professional secrecy, duty of discretion, and confidentiality to which the notary is bound, as well as from the GDPR, which also applies to recordings made by the citizen themselves. The rights and freedoms of third parties are also thereby safeguarded.
This prohibition does not apply to recordings necessary for the processing of the case itself, about which all parties concerned are informed in advance and in a transparent manner.
12. What are your rights?
Under the Data Protection Act, as a data subject whose personal data is processed by the law firm, you have several rights.
Thus, depending on the circumstances and subject to compliance with its legal obligations and the fulfillment of its public interest missions by the data controller, you have the following rights:
- Right to Information : You have the right to know, among other things, what personal data the firm processes about you, the purposes of such processing, how long this data will be retained, etc.;
- Right of Access : You have the right to view and obtain a copy of the personal data concerning you that is held and processed by the firm;
- Right to Rectification : You have the right to have any inaccurate or incomplete personal data concerning you corrected;
- Right to erasure : You have the right to request the deletion of your personal data processed by the firm;
- Right to restriction of processing : You have the right to restrict the processing of your personal data, for example, if you contest the accuracy of the data;
- Right to data portability : You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to a third party;
- Right to object : You have the right to object to the processing of your personal data by the notary’s office.
You may exercise your rights directly with the notary’s office by email (info@n2notaires.be) or by mail (at 1490 Court-Saint-Etienne, Boucle Joseph Dewez 1) or with the Data Protection Officer by email info@privanot.be.
Finally, if you believe that your rights are not being respected in accordance with the GDPR, you are entitled to file a complaint with the Data Protection Authority (rue de la Presse 35, 1000 Brussels, or via their website https://www.autoriteprotectiondonnees.be/).
Cookies