ÅBO AKADEMI UNIVERSITY
PRIVACY NOTICE
According to the EU General Data Protection Regulation GDPR (EU 679/2016), Art. 13-14
The notice concerns a long-term register, system, or tool:
Purchase suggestions to the Library
__________________________________________________________________________
Data controller
Åbo Akademi University
Tuomiokirkontori 3
20500 Turku
Finland
Åbo Akademi University is controller for the personal data collected and processed in the university’s activities – in teaching, guidance, research, administration, and cooperation, internally and externally.
Responsible unit for the processing that is described in this document:
ÅAU Library
Contact person: Yrsa Neuman, yrsa.neuman@abo.fi, +358 2 2154193
Data Protection Officer at Åbo Akademi University: dataskydd@abo.fi, +358 2 215 31 (switchboard)
__________________________________________________________________________
Why do we treat your personal data?
The purpose is to let students and staff at Åbo Akademi University and Novia (Turku) make purchase suggestions or place book orders using own funds. A suggestion or request is made using a form in E-lomake. The data is stored in E-lomake and sent to two library email accounts. The data is used for evaluation of the suggestion, carrying out purchases and to be able to reach the person who made a suggestion or request.
According to GDPR there must always be a legal basis for processing personal data. The legal basis for processing your personal data is:
Consent: Consent means that you are consulted and answer yes (by written or oral statement) to that your personal data is processed for a specific purpose. You give your consent completely voluntary after that you have been informed about how your personal data is processed (i.e. collected, stored, shared, archived, etc.). When consent is the only legal basis for processing your personal data, you have the right to withdraw your consent at any time. You can notify that you have regretted your consent by sending an e-mail to registrator@abo.fi. The processing completed before you withdrew consent is not affected.
The purpose of processing personal data is to be able to make a hold on the suggested book for the requestor, or to notify the requestor when a suggested e-book has been made available, or to be able to contact the requestor to enquire more information about their suggestion.
Which personal data is processed and by whom?
Name
E-mail address
Campus address
Data is processed by staff at Åbo Akademi University Library.
From where do we collect your personal data and how is the data processed?
The data is collected using a form in E-lomake. The data is provided by the person themselves.
Data is stored in E-lomake and two library e-mail accounts.
Over one year old data is deleted once a year in June.
Is your personal data transferred to a third party (outside Åbo Akademi University) for processing?
No, personal data will not be transferred for processing outside Åbo Akademi University.
Is your personal data transferred to a third party (outside Åbo Akademi University) for the needs of the third party?
No, personal data will not be transferred outside Åbo Akademi University.
Is your personal data transferred outside EU/EEA?
No, personal data is not transferred outside EU/EEA.
__________________________________________________________________________
Additional information about how the register, system, or tool is handled at Åbo Akademi University
Principles for how the data is protected:
The data is processed only by staff within Åbo Akademi University Library.
List of regular data sources:
No data is collected from other sources.
Principles and regulations for storage and storage time:
Over one year old data is deleted once a year in June.
Information on automated decision-making (when applicable):
Not applicable.
__________________________________________________________________________
What rights do you have when Åbo Akademi University processes your personal data?
Åbo Akademi University is responsible for taking appropriate technical and organisational measures to protect personal data against unauthorized or illegal processing and against damage to or loss of personal data. Personal data must always be processed in a fair and transparent manner in accordance with applicable data protection regulations
According to the EU General Data Protection Regulation GDPR, you have the right to
– get transparent information on how your personal data is processed and how you can exercise your rights (Art. 12)
– get access to your personal data at Åbo Akademi University and information on the processing of data (Art. 15)
– have your personal data corrected (Art. 16). Note that employees and students at Åbo Akademi University can in most cases correct their own data according to the instructions on the intranet.
– have your data erased (“the right to be forgotten”) in certain situations (Art. 17)
– restrict the processing of your personal data in certain situations (Art. 18)
– have your personal data transferred between systems in certain situations (Art. 20)
– object to the processing of your personal data in certain situations (Art. 21)
– not be subject to automated decision-making, with certain exceptions (Art. 22)
You have also the right to be informed of a personal data breach involving a high risk for your personal data (Art. 34).
When the purpose of the processing is scientific research, statistics or archival purposes, the rights may be restricted by the Data Protection Act (1050/2018). Restrictions on rights always require special protective measures.
If you have questions about your rights, you can contact the responsible contact person (see above) or the ÅAU Data Protection Officer (dataskydd@abo.fi). See also the overall information on the processing of personal data on the ÅAU website (www.abo.fi/en/processing-of-personal-data-at-abo-akademi-university).
You have the right to lodge a complaint with the data protection authority if you believe that the processing of your personal data is an infringement of the General Data Protection Regulation (GDPR).
Contact information to the data protection authority
Office of the Data Protection Ombudsman
PL 800
00531 Helsinki
+358 29 566 6700 (switchboard)
tietosuoja@om.fi
tietosuoja.fi