Privacy Notice

Coursera

INFORMATION NOTICE ON THE JOINT CONTROLLERSHIP BETWEEN LEONARDO AND COURSERA FOR THE PROCESSING OF YOUR PERSONAL DATA

Pursuant to and for the purposes of Regulation (EU) 2016/679 (“GDPR”) and any national and European legislation applicable from time to time on the processing of personal data (jointly, the “Privacy Law”) we inform you on the following points:

1. As part of the project aimed at developing your professional skills and competences (the “Project”), the company of the Leonardo Group joining the Project (hereinafter referred to as “LDO”) makes available to you some online courses provided by Coursera Inc. (“Coursera”);

2. the personal data processed as part of the Project are common personal data such as name and surname, email address, information related to the business role, as well as data relating to the choice of courses and browsing experience on the Coursera site, and data contained in the evaluation forms where provided for the verification of learning and self-assessment of specific courses (the “Personal Data”), relating to employees who will use the online courses offered by the Project (the “Data Subjects”);

3. the GDPR provides for the protection and processing of personal data in the light of the principles of lawfulness, transparency, protection of confidentiality and the rights of the data subjects with regard to their personal data;

4. LDO and Coursera act as joint controllers of the processing (the “Joint Controllers”) of the above mentioned Data Subjects’ Personal Data for the performance of the activities related to the Project.

5. In order to access the Coursera’s services on the Coursera’s platform, the Personal Data are processed on the basis of the explicit and informed consent of the Data Subjects.

6. Personal data will be processed in both paper and electronic and/or automated form, i.e. both manually and electronically. In any case, all appropriate procedures will be adopted to protect their confidentiality, in compliance with current regulations and professional secrecy.

7. Appropriate security measures will be used to ensure the protection, security, integrity and accessibility of personal data, in accordance with the provisions of Article 32 of the GDPR.

8. Personal data will be transferred outside the territory of the European Union, but only on the basis of the appropriate guarantees provided by the Privacy Law.

9. Personal data will be kept only for the time strictly necessary to achieve the purposes of the Project, unless provisions of law and/or regulation and/or by other authorities legitimated by law do not require longer retention periods. Personal data for which there is no longer a legal basis for their storage, will be irreversibly anonymized or destroyed in a secure manner.

10. Any list of data processors and other subjects to whom the data are communicated may be viewed at the request of the Data Subjects.

11. Data Subjects may exercise their rights under Articles 15 to 22 of the GDPR (e.g. access to personal data as well as their rectification, erasure, restriction of processing, copying of personal data in a commonly used and readable structured format by automatic means and transmission of such data to another data controller), including the right to withdraw their consent to the processing of their personal data, without prejudice to the lawfulness of processing prior to such withdrawal. It will be the responsibility of the Joint Controllers to verify the legitimacy of the Data Subjects’ requests by providing feedback, as a rule, within 30 days.

12. To exercise the rights referred to in the previous point, as well as in case of any complaints or reports on how to process data, the Data Subjects may send an email to the company’s Data Protection Officer or to the Group Data Protection Officer at DPO.leonardo@leonardocompany.com or DPO.leonardo@pec.leonardocompany.com, who will address the Data Subject’s request to the competent company’s Data Protection Officer or competent data controller. They may also submit their complaints or reports to the Data Protection Authority of their country or to the Italian data protection authority (www.garanteprivacy.it).

Having understood all of the above, and having received specific information on the processing of my personal data pursuant to Article 13 of the GDPR, by clicking on the button “Agree” below I give my consent to the processing of my personal data for the purposes of carrying out the Project.