Skip to content

Personal Data Protection

11minút, 0sekúnd

PERSONAL DATA PROTECTION

Pavol Jozef Šafárik University in Košice (hereinafter referred to as “UPJŠ”) is a controller that processes personal data.

IDENTIFICATION DATA OF THE CONTROLLER

Univerzita Pavla Jozefa Šafárika v Košiciach
Šrobárova 2
041 80 Košice
ID No.: 00397768

Since 25 May 2018, Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), known as GDPR, has been in effect.

DATA PROTECTION OFFICER

Mgr. Gabriela Ciberejová
Univerzita Pavla Jozefa Šafárika v Košiciach
Šrobárova 2
041 80 Košice

Telephone: 055/234 1586
e-mail: zodpovedna-osoba@upjs.sk

PERSONAL DATA PROTECTION SINCE MAY 2018

If any entity processes personal data concerning you (collects, stores, publishes, or otherwise handles your data), you are considered a data subject.
Your rights regarding the processing of personal data are regulated by in Act No. 18/2018 Coll. on Personal Data Protection and on amendments to certain acts (Act No. 18/2018 Coll.) and Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR).

DATA PROTECTION OFFICER

The above rights (except for the right to file a motion to initiate proceedings on personal data protection under the authority of the Office for Personal Data Protection of the Slovak Republic) may be exercised by email or in writing by post to the Data Protection Officer who supervises the processing of personal data at UPJŠ. In order for a request to exercise rights to be accepted, it is necessary to sufficiently identify the person submitting the request, clearly specify the subject of the request, and sign the request. The controller may request additional information necessary to confirm the identity of the data subject if it has reasonable doubts about the identity of the natural person submitting the request.
Data Subject´s Request to Exercise Rights
The Data Protection Officer may also be notified of a personal data breach or any other significant facts relating to the processing of personal data by Pavol Jozef Šafárik University in Košice.

UPJŠ is considered the controller also in cases where your personal data are processed by UPJŠ faculties and/or independently managed organisational units of UPJŠ (e.g. student dormitories, libraries, specialised facilities, etc.). The controller has the status of a public higher education institution pursuant to Act No. 131/2002 Coll. on Higher Education Institutions and on amendments to certain acts, as amended.

UPJŠ processes your personal data in order to fulfil the obligations and tasks arising for it as a public higher education institution from:
• generally binding legal regulations;
• the legitimate or public interests pursued by us;
• contractual relationships.

On what legal basis is your personal data processed?

If the legal basis for the processing of personal data is consent, the data subject may withdraw their consent at any time without affecting the lawfulness of the processing based on consent given before its withdrawal. The provision of personal data is voluntary, and failure to provide personal data has no negative consequences for the rights of the data subject or the services provided by the controller.

If the legal basis for the processing of the data subject’s personal data is the conclusion or performance of a contractual relationship, the provision of personal data is a requirement necessary for the conclusion of the contract. Failure to provide personal data may result in the non-conclusion of a contractual relationship between the data subject and the controller.

If the legal basis for the processing of the data subject’s personal data is compliance with the controller’s legal obligation, the provision of the such personal data is a legal requirement. Failure to provide the data subject’s personal data may result in non-compliance with the legal requirements arising from specific regulations.

If the legal basis for the processing of personal data is the legitimate interest of the controller, the data subject is obliged to tolerate such processing, except where the interests or fundamental rights and freedoms of the data subject override such interests. The data subject has the right to object to the processing of personal data at any time.

Who do we provide your personal data to?

The recipients of the personal data of data subjects are various groups of entities to whom we provide your personal data, most often in the course of fulfilling our legal obligations, and/or UPJŠ employees with whom you come into contact as data subjects.

External recipients of personal data include:

  • Road transport operators, public transport operators, rail transport operators
  • Foreign higher education institutions providing mobility programmes for UPJŠ students
  • European Union institutions
  • Organisations financing certain student mobility programmes
  • International organisations and international networks of cooperating universities of which UPJŠ is a member
  • State authorities exercising powers in the field of education
  • Scientific institutions
  • Civic associations
  • Companies providing technical support for information systems that do not perform processing operations on personal data, but may have access to the content of the data
  • Companies participating in scientific and research projects in incubators or science parks
  • Companies participating in scientific and research activities
  • Postal delivery services and postal companies
  • Lawyers
  • Notaries
  • Bailiffs
  • Auditors

Where we use a processor for the processing of personal data, we always verify in advance whether the processor meets the organisational and technical requirements necessary to ensure the security of the processing of your personal data. Where we use our own recipients (UPJŠ employees) to process personal data, your personal data are always processed on the basis of authorisations and instructions through which we inform our recipients not only about the internal rules for personal data protection, but also about their legal liability for any breaches of these rules. If we are requested by a public authority to disclose your personal data, we assess whether the legally established conditions for such disclosure are met. We do not provide your personal data without first verifying that the relevant conditions have been fulfilled.

How long do we store your personal data?

We store personal data for as long as it is necessary for the purposes for which it is processed. In general, the retention period is based on legal regulations. If not specified by law, we always determine the retention period for your personal data based on specific purposes through our internal regulations and/or our UPJŠ Records Retention Rules and Records Retention Plan in accordance with Act No. 395/2002 Coll. on Archives and Registries and on amendments to certain acts, as amended.

We process students’ personal data during their studies at UPJŠ and subsequently for 50 years after the end of their studies within the student register (Section 73(9) of the HEI Act).

In the case of employees, we process personal data during the contractual relationship and subsequently until the expiry of the statutory periods for the retention of documents, usually 5 to 10 years, in some cases up to 70 years from the date of birth of the employee.

In the case of business partners, we process personal during the contractual relationship and subsequently for the period required by specific legal regulations (e.g. 10 years for accounting purposes, 10 years for tax purposes). Unless specific legal regulations stipulate a longer retention period, we usually retain your personal data for five years after the end of the contractual relationship.

We store camera recordings for 7 days.

Further information on the periods for which we retain personal data can be found in our Records Retention Plan, (Amendment No. 2).

If we process your personal data on the basis of consent, we are obliged to stop processing your personal data for that purpose once the consent is withdrawn. However, this does not preclude us from continuing to process your personal data on another legal basis, in particular to comply with legal obligations.

Is your personal data subject to cross-border transfers?

We generally restrict any cross-border transfers of personal data to third countries outside the European Economic Area (i.e. outside the EU Member States, Iceland, Norway and Liechtenstein), unless such transfers are necessary. This is because these third countries may not, according to the decisions of the European Commission, ensure an adequate level of personal data protection. However, in certain cases such transfers do occur. Your personal data may be transferred to a third country, in particular, where you apply to UPJŠ for cross-border mobility under available student or staff mobility programmes that enable study and/or work stays at foreign universities. Without restrictions, personal data may be transferred within the European Economic Area and to the following countries that currently provide an adequate level of personal data protection according to the decisions of the European Commission: the Principality of Andorra, Argentina, the Faroe Islands, Guernsey, Israel, Jersey, New Zealand, Canada (commercial organisations), the Isle of Man, Switzerland, the Oriental Republic of Uruguay, and the United States of America (companies certified under the Privacy Shield framework).
Transfers to any other third countries (or to companies that do not meet the specific sectoral requirements in the case of Canada and the United States of America) constitute cross-border transfers of personal data to a third country that does not ensure an adequate level of protection. If such a transfer is necessary, we seek to implement appropriate safeguards pursuant to Article 46 of GDPR, ensuring that the recipient of personal data in the third country is subject to an equivalent personal data protection regime as applies in the EU. Most commonly, this involves entering into so-called Standard Contractual Clauses approved by the European Commission, where objectively possible. If this is not possible, we must proceed in accordance with the derogations for specific situations under Article 49 of GDPR. The most common cases involve your consent to the transfer or the performance of a contractual relationship.
UPJŠ also uses secure cloud services provided by a verified provider with servers located within the EU jurisdiction. However, cross-border transfers of data to the United States may also occur on the side of the cloud service provider, which acts as our processor. This processor is Microsoft Inc., which is certified under the legal safeguards known as the Privacy Shield framework. More information about the specific legal safeguards applicable to these cross-border transfers of data containing your personal data can also be found in Microsoft’s Privacy Statement.

Is there automated processing of personal data with legal effect and/or other significant impact on you?

Automated individual decision-making pursuant to Article 22 of GDPR may occur in the following cases:

CHECKING THE ORIGINALITY OF THE FINAL THESIS

Procedure usedAnti-plagiarism software that scans publicly available sources and thus obtains a huge amount of data from other theses and professional publications from abroad, and evaluates the degree of similarity between the thesis and other theses in the register.
PurposeCorrect determination of the percentage of match between the assessed final thesis and other final and academic theses in fulfilment of the legal obligations of a public university.
Expected consequencesDecision based on percentage match (positive/negative). Negative: rejection of theses showing signs of plagiarism for defence.

 

Cookies

Cookies are small text files that improve the use of the website, e.g. by recognising previous visitors when logging into the user environment, remembering the visitor’s choice when opening a new window, measuring website traffic, or assessing how the website is used to improve user experience. Our website uses cookies primarily to ensure proper functioning of the website and to measure its traffic. You can prevent these files from being stored on your device at any time by adjusting your web browser settings. Your browser settings are considered as your consent to the use of cookies on our website under Section 55(5) of teh Electronic Communication Act. However, by blocking cookies you may limit the functionality of some websites (especially if you need to log in).

Social media

We recommend that you familiarise yourself with the privacy policies of the social media platform providers through which we communicate. Our privacy policy only explains the basic issues related to the management of our profiles. We only have typical administrative rights when processing your personal data through our profiles. We assume that by using social media, you understand that your personal data is primarily processed by social media platform providers and that we have no control over this processing, further provision of your personal data to third parties, and cross-border transfers to third countries carried out by the social media platform providers, and we are not responsible for it.


Study at UPJŠ