MCONTEXT: GDPR Data Sharing & Candidate Portal Consent
This document outlines the classification of candidate and tenant data collected by ColivingLiguria, establishing what information can be shared in consortium/partner environments and providing the exact consent wording for candidate forms.
1. Data Classification Matrix
To ensure compliance with GDPR (Regulation EU 2016/679), all data fields are categorized into Whitelisted (public/consortium safe) and Blacklisted (restricted to private legal archive).
A. Whitelisted Data Fields
- Definition: Non-sensitive professional and occupational details. These can be shared in restricted Google Drive folders with consortium partners or displayed anonymously/partially on candidate rosters.
- Whitelisted Fields:
- Candidate Display Name (or randomized ID where anonymity is requested).
- Occupancy Class / Profile Type (e.g. Digital Nomad, Volunteer, Artisan, Student).
- Proposed Project / Business Sector (e.g. Agriculture, Software Development, Eco-Tourism).
- Skills & Languages (e.g. Python, Carpentry, fluent in Italian/English).
- Likelihood / Appreciation Score (internal rating of candidate suitability/interaction).
- Proposed Stay Window (target arrival month/duration).
B. Blacklisted Data Fields
- Definition: Personally Identifiable Information (PII) and sensitive personal data. These must NEVER be uploaded to shared Google Drive folders or exposed to third parties without individual specific contracts. They reside strictly in the encrypted offline database or private notary archive.
- Blacklisted Fields:
- National ID Cards / Passport Scans.
- Tax Codes (Codice Fiscale) and VAT numbers.
- Private Phone Numbers & Personal Email Addresses (use a masked alias or the system inbox for early staging).
- Full Home Addresses.
- Health Records / S1 Health Forms / Medical Declarations.
- Bank Details, IBANs, or financial transactions.
2. Candidate Portal Consent Clause
This text must be added to all digital candidate registration forms and applicant landing pages. It must be presented as a mandatory, un-ticked checkbox.
English Version
[ ] GDPR Consent - Partner Data Sharing
I hereby authorize ColivingLiguria S.r.l. to process my personal data and share my professional profile, skills, proposed project details, and availability window with its consortium partners, local businesses, and municipal bodies involved in the rural regeneration projects. I understand this data sharing is strictly limited to facilitating my placement, volunteer opportunity, or startup incubation, and that my sensitive details (such as ID scans, phone numbers, or private emails) will remain confidential and will not be shared. I can revoke this consent at any time by writing to colivingliguria@pec.it.Italian Version
[ ] Consenso GDPR - Condivisione Dati con i Partner
Autorizzo ColivingLiguria S.r.l. al trattamento dei miei dati personali e alla condivisione del mio profilo professionale, delle mie competenze, dei dettagli del mio progetto proposto e del periodo di disponibilità con i partner del consorzio, le aziende locali e gli enti comunali coinvolti nei progetti di rigenerazione rurale. Sono consapevole che questa condivisione è strettamente limitata ad agevolare il mio inserimento, le opportunità di volontariato o l'incubazione di startup, e che i miei dati sensibili (come copie di documenti, numeri di telefono o e-mail private) rimarranno riservati e non verranno condivisi. Posso revocare questo consenso in qualsiasi momento scrivendo a colivingliguria@pec.it.