Lost Items Privacy Policy
Lost Items
Privacy Policy on Finding Lost Items
In compliance with current privacy regulations (Articles 13 and 14 of European Regulation 2016/679 "GDPR", Legislative Decree no. 196/03 and subsequent modifications and additions), the following policy is provided with regard to the data processed in relation to the service for the management of requests and the return of lost items (hereinafter also referred to as the "Service").
1. DATA CONTROLLER
Aeroporti di Roma S.p.A. (“ADR”) with registered office in via Pier Paolo Racchetti, 1 - 00054 Fiumicino.
2. DATA PROTECTION OFFICER
ADR has appointed a Data Protection Officer. The contact details of the Data Protection Officer can be found at www.adr.it.
3. TYPES OF DATA PROCESSED
The data processed by ADR for the management of the Service consists of personal Data¹ such as personal details (e.g. first name, surname, nationality), details of identity documents, contact details (telephone number, e-mail address) and any other data necessary to follow up the report / request for search of lost property and possible collection by the user.
ADR also reserves the right to obtain any other reasonable information to prove / confirm that the requesting user is the actual owner of the lost item.
4. PURPOSE AND LEGAL BASIS OF PROCESSING
Data will be processed for the management of the Service and for the performance of activities strictly related and instrumental in the management of the same. ADR will process the data in order to comply with the applicable airport security regulations; therefore, the legal basis for the processing for the aforementioned purpose is the legal obligation to which the Data Controller is subject pursuant to Article 6 (1) (c) of the GDPR.
In any case, it is always possible to report lost items via ordinary telephone and e-mail channels.
5. PROCESSING METHODS
Data are processed in compliance with the regulations in force by means of IT, telematic and manual tools, with logic strictly related to the purposes indicated, so as to guarantee the quality, security and confidentiality of the data.
6. DATA RECIPIENTS
The only persons who may have access to the data are those entrusted by the Data Controller with the processing and who are authorised to carry out processing operations relating to the activities described above. Furthermore, your data may be processed by:
• the authorised appointees of the companies ADR uses in the field of security, including ADR Security, which is specifically appointed as a data processor pursuant to Article 28 GDPR, and any external companies ADR uses that act as sub-processors pursuant to Article 28 GDPR;
• by IT service providers acting as data processors within the meaning of Article 28 GDPR.
Data may be disclosed to the competent Public Authorities such as ENAC, Polaria, in fulfilment of legal obligations. In any event, personal data shall not be communicated or disseminated.
7. DATA RETENTION PERIODS
Data are only stored for as long as necessary for the purposes for which they are collected in compliance with the principle of minimisation pursuant to Art. 5 (1) (c) of the GDPR. In particular, Data collected will be kept for the time necessary for the management of the procedure and for the subsequent statutory period.
8. TRANSFER OF DATA OUTSIDE THE EU
Data shall not be disseminated and/or disclosed by ADR to third parties located outside the European Economic Area.
9. RIGHTS OF THE DATA SUBJECT
Finally, we hereby inform that Articles 15-22 GDPR grant data subjects specific rights that can be exercised under certain conditions; data subjects may obtain from the Data Controller: access to their personal data and the rectification, erasure, restriction of processing and portability of data concerning them.
Data subjects also have the right to object to the processing. In the event that the right to object is exercised, the Data Controller reserves the right not to comply with the request, and thus to continue processing, if there are compelling legitimate grounds for processing that override the interests, rights and freedoms of the data subject.
The above rights may be exercised by making an informal request to the company's Data Protection Officer (DPO) at the following address: dpo@adr.it.
This is without prejudice to the data subject's right to lodge a complaint with the Italian Data Protection Authority pursuant to Article 77, GDPR.
10. UPDATES AND AMENDEMENTS
The Data Controller reserves the right to change and update this privacy policy over time.
¹Personal data are understood under the GDPR as: "any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person" (the "Data").
Date of last update: September 2025