You are on page 1of 5

1

Aalto University 13 May 2019

Privacy notice
The Open University registration service (AIMO)

General Data Protection Regulation (EU) (2016/679), Articles 13 and 14

This notice applies to students and other data subjects whose personal data are processed in the personal data
file mentioned in the title.
See the privacy notice for students at into.aalto.fi for more information on the protection of students’ personal
data at Aalto University. https://into.aalto.fi/display/contact/Privacy+notice

Name: The Aalto University Open University customer register and course registra-
tion system (AIMO)

Date: 13 May 2019

Controller, unit in charge: Aalto University


Aalto University Foundation
Postal address: P.O. Box 11000, FI-00076 AALTO
Street address: Otakaari 24, 02150 Espoo
Tel. (exchange): 09 47 001

Eija Zitting, Head of Learning Services

Person in charge of the Person in charge:


data file and Learning Services, Manager Milla Vaisto-Oinonen
contact person
Contact person:
Learning Services, system administrator Matti Ojala
A: Personal data collected
directly from the data sub- Yes
ject The following information is saved in the register:
- Username
- Personal identification number (or date of birth if suomi.fi identifi-
cation cannot be used)
- Individual’s full name
- Former names, if any
- Email address
- Complete postal address
- Country of residence
- Telephone number
- Gender
- Preferred language
- Nationality
- Name of payer
- Address of payer
2

B: Personal data collected


elsewhere than from the Yes
user The following information is saved in the register:
- Personal identification number either from the Suomi.fi identifica-
tion service or the user ID register of the Aalto University IT Ser-
vices
- Person’s full name either from the Suomi.fi identification service or
the user ID register of the Aalto University IT Services
- Email address from the user ID register of the Aalto University IT
Services
- Country of residence from the student information system (Oodi)
- Telephone number from the student information system (Oodi)
- Preferred language from the student information system (Oodi)
- Nationality from the student information system (Oodi)
- Aalto University student number from the student information sys-
tem (Oodi)
- User ID (username@aalto.fi) from the user ID register of the Aalto
University IT Services

1. Contact details of unit in charge

Learning Services, avoin@aalto.fi

2. Data protection officer and contact details

Jari Söderström, Senior Legal Counsel, Aalto University


Postal address: P.O. Box 11000, FI-00076 AALTO
Street address: Otakaari 24, FI-02150 Espoo
Tel. (exchange): 09 47 001
dpo@aalto.fi

You may contact the Aalto University data protection officer if you have questions about the university’s
data protection policies, this privacy notice or other matters concerning the processing of personal data at
Aalto University.

3. Purpose and legal grounds for the processing of personal data

The AIMO service is a tool for registering for Open University courses, and the registration data serves as a
basis for creating rights to study for the registrants. A right to study cannot be created in the system with-
out sufficiently detailed personal data. The AIMO system collects the registration data, personal and ad-
dress data of those registered for Open University courses to the extent necessary for customer manage-
ment in the system, while also containing data on the students’ course fee payments. The students’ basic
information and the details of their right to study are transferred to the Oodi student information system.

The university’s right to process personal data as a controller is based


· on the necessity to perform a task carried out in the public interest or in the exercise of official
authority (Article 6(1) point e)
· on the necessity to comply with a legal obligation (General Data Protection Regulation, Article
6(1) point c)
· on the consent given by the data subject and, in certain cases, when necessary for the perfor-
mance of a contract (Article 6(1) points a and b).
The university has a right as controller to process special categories of personal data when
3

· the processing is necessary for reasons of substantial public interest (Article 9(2), point g).
Main statutes
· Universities Act (558/2009) and the decrees given under it
· the Government Decree on University Degrees (794/2004) as amended and any prior decrees
concerning degrees in science and technology, business, and art and design
· the act on national study and degree registers (laki valtakunnallisista opinto- ja tutkin-
torekistereistä, 884/2017, chapter 5)
· the General Data Protection Regulation (EU) 2016/679 and its complementary national statutes
· the Act on the Openness of Government Activities (621/1999)

4. A legitimate interest of the controller or third party (applies only to Case A; processing is based on
point f of Article 6(1))

No

5. Categories of personal data

Aalto University processes the following categories of personal data concerning staff:

staff users:
- name
- user ID (username@aalto.fi) from the user ID register of the Aalto University IT Services

Aalto University processes the following categories of personal data concerning students:

Information regarding the student’s studies:


- Name
- Personal identification number
- Gender
- Contact details
- Country of residence
- Nationality
- Data on registration for exams and courses
- Data on payment of course fees

6. Recipients or categories of recipients of the personal data

At Aalto University, personal data is processed only by Aalto employees or contracted individuals working
on behalf of Aalto who need the data for their work duties. The data is protected against unauthorised
processing. Access rights are in place to restrict unauthorised access to the student information systems.
The personal data is processed mainly by Learning Services staff and teaching staff. In addition, personal
data may be processed by Aalto’s other services, such as campus and security services, Learning Centre
services, IT services, HR services and financial services. The personal data of doctoral students are pro-
cessed by also Research Support Services in their research data management system.
Aalto University may also use outside parties to process personal data, such as system service providers
that process personal data on behalf of Aalto on the basis of a commission contract.
Aalto University discloses personal data to parties outside the university or processes data for purposes
other than the original only in situations where such disclosure or processing is permitted by law.
Aalto University may disclose such personal data on students as is necessary to the following recipients:
4

- Aalto University Student Union (AYY)


- The Finnish Student Health Service (FSHS).
- for the Ministry of Education and Culture’s KOTA database
- to the internationalisation services of the Finnish National Agency for Education
- via a technical connection through the National Data Warehouse for Higher Education for the use
of the student admissions register
- via a technical connection to the Social Insurance Institution of Finland, Kela
- via a technical connection through the National Data Warehouse for Higher Education for the use
of the National Supervisory Authority for Welfare and Health
- as a technical record via the National Data Warehouse for Higher Education to Statistics Finland
- to employment authorities
- to the immigration authorities
- Information on the Finnish Bachelor's Graduate Survey to the Finnish Social Science Data Archive
In addition, Aalto University may disclose personal data on students as follows:
- for scientific research
- to comply with the Act on the Openness of Government Activities (621/1999) or with other legal
obligations
- to other Finnish institutions of higher education in order to process a right to study or to transfer
information on completed studies as a part of cooperation in teaching, for example
- to institutions of higher education abroad for the implementation of double and joint degrees or
other cooperation in education such as for transferring information about completed studies
- with the student’s consent, contact information may be disclosed to parties outside the university
for marketing communications or other special purposes
The main sources of information that may be disclosed include the Oodi student information system and
the MoveOn mobility system. Information to be stored permanently and information on student mobility
periods are transferred to Virta, the National Data Warehouse for Higher Education.

7. Planned transfers of personal data to third countries or international organisations

The data protection policy of the university is to exercise particular care when transferring personal data
outside the EU and European Economic Area (EEA) to countries that do not offer the data protection re-
quired by the European General Data Protection Regulation (GDPR). Transfers of personal data outside the
EU and EEA are done in accordance with the requirements of the GDPR.

Data is not transferred to parties outside the EU or EEA.

8. Period for which personal data are stored / Criteria used to determine the period for which data are
stored

The periods for which personal data saved in systems and manual material are stored are based on the law
and the records management plan of Aalto University.

The retention period for the Open University’s student registration data is 6 years.

Periods for which data are stored may vary in individual cases and they may be revised.

9. The right of data subjects to access their own data, to rectify or erase it, to request restrictions on
its processing, or to transfer it from one system to another

Data relating to Aalto’s user administration and system transactions may be accessed by users through a web-
based interface https://openregistration.aalto.fi Requests to review and rectify other data are addressed to
5

the person in charge of the data file.

Information on students’ rights to their own personal data is available in the privacy notice for students.
https://into.aalto.fi/display/contact/Privacy+notice

Requests concerning permissions may be submitted by data subjects to avoin@aalto.fi.

You might also like