On this page you will find information on how Åbo Akademi University, as a public authority, processes personal data. The university complies with the General Data Protection Regulation (GDPR).
Åbo Akademi University is responsible for all processing of personal data within its operations. This document describes how your personal data is processed at Åbo Akademi University.
Åbo Akademi University processes personal data in accordance with regulation (EU) 2016/679 of the European Parliament and of the Council, see link below. These provisions are often referred to as the General Data Protection Regulation (GDPR).
How do we use your personal data?
Åbo Akademi University processes personal data in order to fulfill our assignment as a public authority (university), i.e. to provide first-class research and education and collaborate with society. We also do it to review and develop our operations, and to comply with the law.
All processing of personal data at Åbo Akademi University occurs in order to promote these purposes. Processing must also have a legal basis. Only the personal data needed for a particular purpose is processed.
Your contact, course coordinator, supervisor or head of research at Åbo Akademi University can provide you with more information on how your personal data as an employee, student or outside party is processed. If you have not received any information, you can contact the Data Protection Function at Åbo Akademi University. Contact information can be found at the bottom of this page.
What personal data do we collect?
At Åbo Akademi University, there are various reasons for collecting personal data. The most common reasons are that you are a student, researcher, study participant, employee, participant in a conference or other event, job applicant, apply to become a student, or that you have contacted or collaborated with the university for some other reason.
Most of this information will be collected directly from you. In certain cases, we also collect data from other sources such as from other public authorities.
What personal data we process depends on the information we need. The following information is often necessary:
- Contact information such as your name, address, phone number and email address.
- Personal identity numbers are processed when we need to ensure your identity or to coordinate your information between systems to ensure uniform information.
- Bank or other financial information in order to disburse a payment or send an invoice.
- Personal data that has been collected within the framework of participation in a research study.
- Study results or other information regarding your studies at Åbo Akademi University.
- Information on how you use our websites, for example cookies, which are used to improve user-friendliness.
- Information regarding conference or course participation.
- Personal data which is necessary for an employment or if you have applied for a job or applied to become a student.
How is your personal data protected?
Åbo Akademi University must ensure that all processing of personal data is protected through appropriate technological and organisational measures. The measures must ensure a security level appropriate to the risk. The security aspects must include confidentiality, integrity and availability as well as adequate technological protection. This may involve only giving those authorised access to the information, encrypting the information, storing it in specially protected locations and making a processing copy.
Who can access your personal data?
A lot of information at Åbo Akademi University constitutes official documents. If your personal data can be found in an official document, anyone who requests access to this document can view your personal data, unless the Act on the Openness of Government Activities (621/1999) prevents it.
In addition to this, your personal data may be disclosed to Åbo Akademi University’s partners in research projects, to suppliers or other parties that need access to it due to an agreement between Åbo Akademi University and you. Data may also be disclosed to outside parties if it is needed for a public interest task, as part of the exercise of official authority or because of a legal obligation that Åbo Akademi University has.
A public interest task is a task Åbo Akademi University must fulfill according to law, or according to decisions based on laws, but which is not directly part of Åbo Akademi University’s assignment as a public authority.
When transferring personal data to another party, Åbo Akademi University takes all legal, organisational and technological precautions necessary in order to protect your data. You will be informed if we plan to disclose information about you to other organisations.
Åbo Akademi University will only transfer personal data to other parties if there is a legal basis for this.
For how long do we store your personal data?
We only store your personal data for as long as is necessary for the purpose of the processing, or as long as is required by law.
- If, for example, you are an employee, we process your personal data for as long as we need to manage your employment conditions.
- If you are a student, we process your personal data as long as it is needed to administrate you as a student at Åbo Akademi University.
- If you are a participant in a study, we process your personal data for as long as is necessary to ensure the quality of the research.
In regard to official documents, personal data is managed in accordance with the Act on the Exercise of Freedom of Expression in Mass Media (460/2003) and acts regarding archiving (Lag om yttrandefrihet i masskommunikation (460/2003), Arkivlag (831/1994) and Lag om Riksarkivet (1145/2016)). In many cases, this means that your personal data may be stored in Åbo Akademi University’s central archive in perpetuity.
Transfer of data to a non-EU/EEA country
Åbo Akademi University may transfer personal data to a third country outside the EU/EEA, primarily as part of international research projects. Åbo Akademi University will then take all reasonable legal, organisational and technological precautions necessary to achieve an adequate security level for your personal data. You will also be informed if this should occur.
Rights under the General Data Protection Regulation
The GDPR gives you the following individual rights at Åbo Akademi University:
Right of access
You have the right to be informed if Åbo Akademi University is processing your personal data. You also have the right to a free copy of the personal data that is being processed. If you request such personal data excerpts several times, Åbo Akademi University will charge a fee to cover the administrative costs. In connection with such a request, Åbo Akademi University also provides further information on the processing, its purpose, categories of processed personal data, expected storage time, etc.
Right to rectification
You have the right to request that your personal data be rectified if it is incorrect. You can do this by, for example, providing your contact, course coordinator, supervisor or head of research at Åbo Akademi University with a supplementary statement. Åbo Akademi University is obligated to correct your personal data without undue delay. Åbo Akademi University is not obligated to correct your data if it is not longer managed actively.
Right to erasure (‘right to be forgotten’)
You have the right to request that your personal data be erased from Åbo Akademi University’s systems if the personal data is no longer needed to meet the purpose for which it was collected.
There may be provisions that state that Åbo Akademi University cannot not delete your data, for example the provisions on official documents, research and study documentation. If your personal data has been transferred to other parties, Åbo Akademi University will take all reasonable measures to inform these parties about your request.
If Åbo Akademi University cannot delete your data for legal reasons, we will limit the processing of your data to only include what is necessary to fulfill our obligations.
Right to restrict processing
You have the right to request that the processing of your personal data be restricted – this means that we will only process your personal data for certain specific purposes. Åbo Akademi University can restrict processing in the following cases:
- You claim that your personal data is incorrect and Åbo Akademi University requires time to verify the accuracy of the data.
- Åbo Akademi University no longer requires the data, but you have requested that we continue to store it because you require it to exercise a legal claim.
- You object to processing carried out by Åbo Akademi University. In that case, processing is limited until it has been established whether your reasons for objecting override Åbo Akademi University’s legitimate reasons for processing the data.
- You want us to erase your personal data, but we cannot comply for some reason.
Right to data portability
In certain cases, you have the right to receive your personal data or to have your personal data transmitted to another controller than Åbo Akademi University. This applies when your personal data concerns you and was supplied by you, the data is processed on the basis of consent or a contract, the processing is carried out by automated means, the transfer is technically feasible, and, the rights and freedoms of others are not adversely affected by the transfer.
Right to object to processing
In certain cases, you have the right to object to Åbo Akademi University’s processing of your personal data, for example in regard to research or teaching. Åbo Akademi University will then cease processing unless we have imperative grounds to continue with it, or if processing is necessary to exercise a legal claim.
Right to not be subject to automated decision-making
In certain cases, you have the right not to be subject to a decision based solely on automated processing (also applies to profiling). This applies to fully automated decision-making that produces legal effects on you, except when the decision is necessary for a contract between you and the Åbo Akademi University, or, authorised by a law, or, based on your explicit consent.
Right to whitdraw consent
When the only basis for the processing of your personal data is consent, you have the right to whitdraw your consent at any time. Withdrawal of consent does not affect processing performed before the withdrawal.
Right to lodge a complaint with the Data Protection Authority
You have the right to lodge a complaint wit the Data Protection Ombudsman if you consider that the processing of your personal data violates the EU General Data Protection Regulation (EU) 2016/679.
If you have any questions on data protection, please get in touch with the person responsible for the register, the person responsible for a project or course or the Data Protection Function (contact details below).
Data Protection Function, Förvaltningsämbetet, Åbo Akademi University
firstname.lastname@example.org, phone: +358 2 21531 (switchboard)
Postal address: Dataskydd vid Åbo Akademi, Domkyrkotorget 3. 20500 Åbo
Anna-Maria Nordman, Data Protection Offier