Address: PL 52 (Ketunpolku 1), Kajaani

Similar documents
Art. I Right to Access to Personal Data

PROCEDURE RIGHTS OF THE DATA SUBJECT PURSUANT TO THE ARTICLES 15 TO 23 OF THE REGULATION 679/2016

Privacy policy. 1.1 We are committed to safeguarding the privacy of our website visitors.

Aalto Summer continuing education

(1) General information

closer look at Rights & remedies

Information leaflet about processing of personal data for Newsletter Recipients (hereinafter Data Subject)

***I DRAFT REPORT. EN United in diversity EN 2012/0010(COD)

Information about the Processing of Personal Data (Article 13, 14 GDPR)

DIRECTIVE 95/46/EC OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL. of 24 October 1995

Charter on personal data

PRIVACY POLICY STATEMENT ON THE PROCESSING OF PERSONAL AND SENSITIVE DATA OF THE CUSTOMERS WITHIN THE MEANING OF ARTICLE 13 AND FF. OF REGULATION (EU)

5418/16 AV/NT/vm DGD 2

SUBSIDIARY LEGISLATION DATA PROTECTION (PROCESSING OF PERSONAL DATA IN THE POLICE SECTOR) REGULATIONS

Brussels, 29 November 2007 (Case ) 1. Procedure

COMP Article 1. Article 1 Subject matter and objectives

National Police Board INSTRUCTION 1 (10)

Act CXII of on the Right of Informational Self-Determination and on Freedom of Information 1 CHAPTER I GENERAL PROVISIONS. 1.

A combined file and information system description and information document regarding the Data System for Administrative Matters

16 March Purpose & Introduction

The Act on Processing of Personal Data

Data Protection Policy. Malta Gaming Authority

Declaration on the protection of personal data in the company TAJMAC ZPS, a.s.

Factsheet on the Right to be

European Data Protection Supervisor Your personal information and the EU administration: What are your rights?

EUROPEAN PARLIAMENT COMMITTEE ON CIVIL LIBERTIES, JUSTICE AND HOME AFFAIRS

AmCham EU Proposed Amendments on the General Data Protection Regulation

Charities & Not-for-Profits Overview of Data Protection Law

THE DATA PROTECTION BILL (No. XIX of 2017) Explanatory Memorandum

Opinion on a notification for Prior Checking received from the Data Protection Officer of the European Ombudsman on verification of telephone bills

General Data Protection Regulation

Brussels, 3 May 2006 (Case ) 1. Procedure

Privacy International's comments on the Brazil draft law on processing of personal data to protect the personality and dignity of natural persons

9091/17 VH/np 1 DGD 2C

PROJET DE LOI ENTITLED. The Data Protection (Bailiwick of Guernsey) Law, 2017 ARRANGEMENT OF SECTIONS PART I PRELIMINARY

SKILLSTAR 2018 NONPROFIT KFT. DATA PROTECTION POLICY

REGULATION (EU) 2016/679 General Data Protection Regulation

EUROPEAN PARLIAMENT Committee on the Internal Market and Consumer Protection

RESTREINT UE/EU RESTRICTED

Free and Fair elections GUIDANCE DOCUMENT. Commission guidance on the application of Union data protection law in the electoral context

Data Protection Bill [HL]

SCHEDULE 1 DATA TRANSFER AGREEMENT (Data Controller to Data Controller transfers)... 16

Brussels, 16 May 2006 (Case ) 1. Procedure

BINDING CORPORATE RULES PRIVACY policy. Telekom Albania. Çaste që na lidhin.

Introduction. The highly anticipated text of the Irish Data Protection Bill 2018 has been published.

PROTECTION OF PERSONAL INFORMATION ACT NO. 4 OF 2013

The Ministry of Technology, Communication and Innovation and The Data Protection Office. Workshop On DATA PROTECTION ACT 2017

DATA PROTECTION (JERSEY) LAW 2018

8557/16 SHO/ra 1 DGD 2

General Rules on the Processing of Personal Data SCHEDULE 1 DATA TRANSFER AGREEMENT (Data Controller to Data Controller transfers)...

ASSEMBLEIA DA REPÚBLICA [PORTUGUESE PARLIAMENT]

REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April on the protection of natural persons

Privacy Notice 1. CONTROLLER S NAME AND DATA

Case C-553/07. College van burgemeester en wethouders van Rotterdam. M.E.E. Rijkeboer. (Reference for a preliminary ruling from the Raad van State)

Reports of Cases. JUDGMENT OF THE COURT (Second Chamber) 20 December 2017 *

An Bille um Chosaint Sonraí, 2018 Data Protection Bill 2018

PRIVACY POLICY. 1. OVERVIEW MEGT is committed to protecting privacy and will manage personal information in an open and transparent way.

Port Glasgow St Andrew s Data Protection Policy

Adequacy Referential (updated)

Mannofield Parish Church. Registered Scottish Charity No: SC (the Congregation ) Data Protection Policy

OTrack Data Processing Terms

1. Processing of personal data legal basis, purpose and scope Legal basis fulfillment of statutory legal requirements

Data Protection Policy

DATA PROCESSING AGREEMENT. between [Customer] (the "Controller") and LINK Mobility (the "Processor")

Selection procedure at the European Ombudsman's Secretariat

PRIVACY STATEMENT (Everest Notariaat N.V.)

How to read the analysis?

ARTICLE 29 Data Protection Working Party

PERSONAL DATA PROCESSING AGREEMENT

2.3 a definition of the GWR Record Title you will attempt to break and related guidelines which you will need to comply with ( Guidelines ).

Personal Data Protection Act

A Legal Overview of the Data Protection Act By: Mrs D. Madhub Data Protection Commissioner

Application for a visa for a long stay in Belgium This application form is free

6153/1/18 REV 1 VH/np 1 DGD2

Is information about legal entities personal data? No. The DPA only applies to information about individuals as opposed to legal entities.

EVIDENCE ON THE DATA PROTECTION BILL. For the House of Commons Public Bill Committee by Open Rights Group and Chris Pounder

Official Gazette No. 55 issued on 8 May Data Protection Act. of 14 March 2002

O R D E R OF THE MINISTER OF THE INTERIOR OF THE REPUBLIC OF LITHUANIA

EDPS - European Data Protection Supervisor CEPD - Contrôleur européen de la protection des données

CHAPTER [INSERT] DATA PROTECTION BILL Acts [insert] ARRANGEMENT OF SECTIONS PART I PART II

(1) This Act lays down provisions on the competence of an asbestos worker and licences for asbestos removal work and any related registers.

PE-CONS 71/1/15 REV 1 EN

Data Protection Declaration in accordance with the DSGVO

Data Protection Bill [HL]

Policies and Procedures

This unofficial translation is provided for information purposes only and has no legal force. Data Protection Act.

Privacy notice regarding the processing of personal data under the General Data Protection Regulation

REMOTE ACCOUNT TRANSFER SERVICE AGREEMENT

STATOIL BINDING CORPORATE RULES - PUBLIC DOCUMENT

DATA PROTECTION POLICY STATUTORY

The legal framework and guidance on data protection under the. Cross-border ehealth Information Services (CBeHIS) T6.2 JAseHN draft v.2 (20.10.

ARTICLE 29 Data Protection Working Party

COUNCIL OF THE EUROPEAN UNION. Brussels, 13 September 2011 (OR. en) 10093/11 Interinstitutional File: 2011/0126 (NLE)

DATA PROTECTION LAWS OF THE WORLD. Ireland

LAW OF THE REPUBLIC OF ARMENIA ON PROTECTION OF PERSONAL DATA CHAPTER 1 GENERAL PROVISIONS

An Bille um Chosaint Sonraí, 2018 Data Protection Bill 2018

Act on Verification and Notification of. Origin of Electricity

Fragomen Privacy Notice

Law Enforcement processing (Part 3 of the DPA 2018)

EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE

Transcription:

PRIVACY STATEMENTSivu 1 / 5 Compiled: 30.5.2018 Reviewed: xx.xx.201x, Name of reviewer Privacy statement EU General Data Protection Regulation 2016/679 1 Controller Name: Kajaanin Ammattikorkeakoulu/University of Applied Sce Oy address: Other contact information (e.g. telephone no. during working hours, email): (08) 618 991 kajaanin.amk@kamk.fi 2 Contact person in matters concerning the file 3 Data protection officer Name: Pasi Puskala Address: Telephone: Email: 044 7101 250 pasi.puskala@kamk.fi Name: Data protection officer, KAMK Oy Address: Telephone: Email: 044 7101 237 tietosuojavastaava@kamk.fi 4 File name Student welfare officer s customer register 5 Purpose of personal processing Purpose of personal processing: To manage student welfare customer relations Legal basis for personal processing: In the legitimate interest of the controller to take care of customer relations Law on which personal processing is based: Personal Data Act (523/1999), Archiving Act (831/1994) 6 Data file content Customer : name, date of birth or personal ID number, degree/qualification and year of starting studies, address, telephone number, language of business if other than Finnish, records and notes of discussions during meetings with customers. 7 Legitimate sources of The file contains personal records form Kajaani University of Applied Sciences student management system (ASIO, later to be the PEPPI system) and this is verified and validated with the customer. In addition, entries in the form of records and notes from discussions during customer appointments are made. 8 Authorized recipients of (recipients of personal ) No regular transfers of to third parties.

PRIVACY STATEMENTSivu 2 / 5 9 Transfers of personal to countries or organizations outside the EU and EEA 10 Principles of personal file protection No transfers of to countries or organizations outside the EU and EEA. Manual : This is only for the use of the student welfare officer. These are stored in the secure office of the student welfare officer and in a locked safe. Computer processed : These are only for the use of the student welfare officer. They is stored in a work station, which is in the sole use of the student welfare officer and secured according to security regulations. The Kamit Data Management Unit is responsible for implementing security regulations. 11 Storage, archiving and erasing of personal 12 Right of subject to access own personal Customer files are stored for the period corresponding to the student s right to study. Archived files are stored according to period set out in the Ministry of Social Affairs and Health s Patient Records Act (298/2009). Computer processed customer are removed from the student welfare officer s work station at the latest by the end of the same calendar year when the customer s right to study at Kajaani University of Applied Sciences comes to an end. Right of subject to access own personal ( right of verification ) Data subjects have the right to receive confirmation from the controller that their personal are being processed or that they are not being processed. If their personal are being processed, subjects are entitled to access this. The controller has the duty to provide a copy of the personal to be processed. A request to access is made either during a personal appointment/visit or in writing (with signature in own handwriting or other reliably validated document). The check request is addressed to the file s contact person (see section Contact person in matters concerning the file), who makes the decision as to whether the request will be implemented or not. The subject will be informed of this decision by the person authorized to decide. The subject s identity will be verified before his or her will be provided. He or she has the right know and view concerning him or herself and is entitled to receive this in writing by request. Implementation of right of verification A request to access is made either during a personal appointment/visit or in writing (with signature in own handwriting or other reliably validated document). The check request is addressed to the file s contact person (see section Contact person in matters concerning the file), who makes the decision as to whether the request will be implemented or not. The subject will be informed of this decision by the person authorized to decide.

PRIVACY STATEMENTSivu 3 / 5 The subject s identity will be verified before his or her will be provided. He or she has the right familiarize him or herself with and view concerning him or herself and is entitled to receive this in writing by request. 13 Data subject s right of access to own and to rectification The right of verification will be implemented without undue delay. The right of verification can only be denied in exceptional circumstances. If the right to verification is denied, the subject will be issued with a written certificate of refusal to disclose. The subject has the right to have the matter resolved by the Office of the Data Protection Ombudsman at the following address, PL 800, 00521 Helsinki, email: tietosuoja(at)om.fi. Data subject s right of access and to demand rectification of personal Data subjects have the right to demand that erroneous, inaccurate or incomplete personal be rectified or supplemented by the controller without undue delay. Taking into account the purposes of processing the, the subject has the right to have incomplete personal supplemented by means of providing additional information. The controller is obliged to rectify, correct, or supplement without undue delay erroneous, inaccurate, incomplete or out of date personal by its own initiative or at the demand of the subject. The person responsible for personal file matters, the system administrator or other person in a position of responsibility must rectify the error as soon as he or she notices it or must inform the person who is in sufficient authority to rectify the error. The subject can notify the personal file s contact person of personal errors that he or she notices (see section Contact person in matters concerning the file) and request that the errors be rectified. A rectification request addressed to the personal file s contact person can also be made in writing. The contact person also makes the decision to rectify the error. The identity of the person making the rectification request will also be checked. 14 Other rights of the subject Data must be rectified without undue delay. If the right to rectification is denied, the subject will be issued with a written certificate of refusal to rectify. The subject has the right to have the matter resolved by the Office of the Data Protection Ombudsman at the following address, PL 800, 00521 Helsinki, email: tietosuoja(at)om.fi. The Data Protection Ombudsman can order the controller to rectify the. Data subject s right to have personal erased The subject shall have the right to obtain from the controller the erasure of personal concerning him or her without undue delay and the controller shall have the obligation to erase personal without undue delay. The right to erase exists if the personal are no longer necessary in relation to the purposes for which they were collected or otherwise processed, or the subject withdraws consent on which the processing is based or there is no other legal basis for such processing.

PRIVACY STATEMENTSivu 4 / 5 This right does not apply to statutory files and registers. It is not possible to erase from these files in relation to processing to perform a statutory task. Right to restrict processing Under certain conditions the subject shall have the right to obtain from the controller restriction of processing. If processing has been restricted, such personal can be stored and processed only with the consent of the subject, or if they are required by the subject for the establishment, exercise or defense of legal claims, or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State. A subject who has obtained restriction of processing shall be informed by the controller before the restriction of processing is lifted. Right to object to processing, automated decision-making and profiling The subject shall have the right to object at any time, on grounds relating to his or her particular situation, to processing of personal concerning him or her which is legitimately based on the general interest, the exercise of public power or legitimate interests. The right to object to the processing of personal does not apply to processing required to comply with statutory duties. The subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. The previous paragraph shall not apply if the decision: is necessary for entering into, or performance of, a contract between the subject and a controller; is authorized by Union or Member State law to which the controller is subject, and which also lays down suitable measures to safeguard the subject's rights and freedoms and legitimate interests is based on the subject's explicit consent. Right to lodge a complaint with the supervisory authority Every subject has the right to lodge a complaint with the supervisory authority if he or she believes the processing of his or her personal infringes the protection regulation. This right does not prejudice other administrative or judicial remedies. (Data Protection Regulation section 77). The subject has the right to have the matter resolved by the Office of the Data Protection Ombudsman at the following address, PL 800, 00521 Helsinki, email: tietosuoja(at)om.fi. Verification of identity The controller has the duty to verify the subject s personal ID when the subject exercises the right to access his or her, the right have his or her personal rectified, erased or transferred from one system to another.

PRIVACY STATEMENTSivu 5 / 5 If the person requesting access to his or her personal is previously unknown, or it is not otherwise possible to verify his or her identity, he or she must provide proof of identity before being provided with. The controller may request the subject to provide further information in order to confirm his or her identity.