Privacy notice for Uniarts Helsinki’s user management, access management and log management

Articles 13 and 14 of the EU General Data Protection Regulation. Information for data subjects. Drawn up on 17 May 2018; updated on 14 July 2025.

1. Controller

University of the Arts Helsinki (Uniarts Helsinki)
Postal address: P.O. Box 1, 00097 Uniarts
Phone number: +358 294 47 2000 (switchboard)

2. Unit and person in charge of processing personal data

Digital Services, CDO and CIO Mari Nyrhinen, firstname.lastname@uniarts.fi, +358 40 704 4296

3. Contact person for the processing of personal data

IT Support Services, Manager Juha Rosvall, firstname.lastname@uniarts.fi, +358 50 59 11 453

4. Data protection officer

Find contact details for Uniarts Helsinki’s data protection officer on the data protection homepage.

5. Name of the register

Uniarts Helsinki’s system for user management, access authorisation management and log management

On the basis of the Universities Act, the mission of Uniarts Helsinki is comprised of teaching, research and artistic activities. Universities are autonomous, which ensures the freedom of science, art and highest education. Their autonomy also entails the right to make decisions on matters related to their internal administration. The Universities Act also states that the university community comprises teaching and research staff, other staff and students.

In order to be able to organise its teaching, research and artistic activities in practice and to arrange its internal administration, the university needs to process information on individuals who are part of the university community and to maintain up-to-date information on these persons who are authorised to use the various services of the university. The user and access authorisation management system of the university processes data on the teaching and research staff, other staff, students and persons who have some other kind of contractual relationships with the university, for the aforementioned purposes.

In practice, the user and access authorisation management system is used for performing, for example, the following measures:

  • Creating the university usernames and email addresses at the start of a contractual relationship or when a student’s right to study becomes valid.
  • Assigning users a pre-determined user group on the basis of their personal responsibility area or right to study, which will allow them to access the storage resources or email lists as required by their duties.
  • Digital Services assign system administrators based on requests to maintain user group information.
  • Managing the lifecycle of user access rights so that the username is deactivated when the contractual relationship or right to study expires or during the investigation of suspected misuse related to university rules or information security.
  • Forwarding of data on active users to the login services used by the university in such a manner that students, staff members and other users of the university’s services have access to the electronic tools intended for them and that their right to use these tools expires when their username is deactivated.
  • In Digital Services, users’ personal data is checked, for example, when it is necessary to determine the person’s relationship with the university and when the user has not been able to change their password or activate their username in the suomi.fi service.
  • The administrators of user groups can see the members of the groups they maintain and are able to delete and add users in/from their group (they can see the user’s name).

The purpose of the processing of personal data in user management and log data systems in accordance with this privacy notice is to enable the processing of personal and other data situated in the other data systems of Uniarts Helsinki, to supervise and monitor data security, to investigate system incidents and failures, to prevent and look into data breaches and to make usage analyses. The information contained in user management and log data systems is separated from the data of other information systems either logically or physically, meaning it is stored in completely separate systems and on separate servers, and it is not used for any purposes other than the above-mentioned system monitoring and investigation activities.

Uniarts Helsinki’s right to process personal data is based on:

  • The university’s public interest.
  • An agreement.
  • As regards certain support functions, the processing of data required for the operation of the user management and log data system is based on the legitimate interest of both the university acting as the data controller and the data subjects themselves, for the purposes described above.

The legitimate interest in this context refers to the university’s right to detect, prevent and investigate errors and both accidental and intentional data protection breaches in its information systems, in order to ensure the continuity of university operations and to prevent and minimise damage.

The processing of personal data is necessary for the implementation of an agreement (employment contract, right to study or other agreement) between the university and the data subject.

In addition, the university’s legitimate interest includes the right to monitor the use of information systems containing personal data and other confidential information, including access to data and the addition, modification and deletion of data. Such monitoring and access control measures are also essential to ensure the rights and legal protection of data subjects and compliance with good data processing practices.

The use of log data is governed by the university’s system administration rules, log rules and applicable legislation.

In many processes, the submission of personal data is a necessary prerequisite for handling the matter.

We do not use automated decision-making or profiling as referred to in the GDPR in user management, access authorisation management and log management.

7. What data do we process?

Uniarts Helsinki processes the following personal data of university users in user management systems:

  • Basic information of the data subject such as name, job title, personal identity code, staff or student number, username, email address(es), study programme code, preferred language of communication, phone number, postal address.
  • Start and expiration date of access rights.
  • The data subject’s role (student / staff) and area of responsibility as well as membership in user groups.
  • Identifiers unique to the data subject in systems connected to user management.
  • A personal identity code is necessary to reliably verify the user’s identity, for example, when handling matters related to the user’s username.

In log systems, Uniarts Helsinki processes not only the personal data of university end users but also the personal data that is subject to logging in the university’s information systems and the logical personal data registers composed of these. The data protection and processing of personal data in these registers are described in the privacy notices related to each register and type of personal data processing, which can be found in the list of notices on Uniarts Helsinki’s website.

In addition, Uniarts Helsinki processes the following personal data of users of the system itself (university staff and students as well as external support persons and administrators) in the user management and log information system:

  • The user’s login and communication details (e.g. username and password, IP address, session ID, routing information).
  • Device information (e.g. MAC address, device ID).
  • Access level to the log system (how the user can view, modify and/or delete logs).
  • Log data viewed, modified and deleted by the user, as well as timestamp and identification information related to these actions.

8. Where do we get data?

Uniarts Helsinki gathers data from the following sources:

  • We receive user data for user management automatically from the employment contract information stored in the HR system (Mepco) for staff and from the student information system (Peppi) for students.
  • User group information is updated partly automatically and partly manually based on change requests received from the university’s system administrators or other authorised persons.
  • Changes to users’ basic information are made in the HR or student administration system and then manually by the IT team in the user and access management system (e.g. name or email address change due to a name change).
  • Log system personal data is regularly obtained from other university information systems, which in turn store information from the regular sources mentioned in the university’s privacy notices. In addition, information about users of the user management and log information system is obtained from data collected and entered into the system during the creation of access rights, as well as from data collected about users and their devices during use.

9. To which parties do we disclose and transfer data and do we transfer data outside the EU or the EEA?

Access to the university’s user and access authorisation management register is granted to IT administration staff who, when necessary, perform maintenance tasks in the register, for example based on requests from system administrators.

Information on active users is regularly transferred from the user register to certain university systems, some of which are managed by external service providers. Data protection is ensured through data processing agreements with these providers. Personal data is not transferred outside the EU or the EEA, unless it is necessary for ensuring the technical implementation.

In cases where we transfer personal data outside the EU/EEA, we have taken appropriate security measures in connection with the transfer. We use the standard contractual clauses adopted by the EU.
Uniarts Helsinki is part of the HAKA and eduGAIN federations, like other Finnish higher education institutions. In these federated services, the user approves the data to be released to the service during login and can choose whether to approve the data each time or only when the data content changes. The user can also withdraw their consent at any time.

We do not disclose data from the user and access authorisation register to any parties other than partners with contractual relationships with the university for user authentication purposes, for official data collection, or to institutions committed to the GÉANT Code of Conduct.

10. How do we protect data and for how long do we store it?

Personal data processed under this privacy notice is stored in user management and log systems for as long as the content of the data or other information linked to it in the log system is useful for the relevant purpose. In practice, data may be needed, for example, to investigate data protection breaches or data leaks, which is why the data is retained for at least the time required to investigate such cases and for the period necessary to safeguard the university’s legitimate interests, determined by the statute of limitations for such actions. The limitation and prosecution periods for data protection offences and related compensation claims vary between two and five years.

For the purposes of incident investigation and usage analysis, the necessary personal data is retained in user management systems for a few months after the expiration of access rights, and in the log system typically for 2–3 months from the time the data is logged.
When it is no longer possible to use personal data for the purposes described above after the retention period has expired, the data is automatically deleted from the user management and log systems. Some data may be stored in backups made from the user management and log systems, but these are regularly destroyed according to the backup schedule.

We take reasonable steps to ensure that the data subject’s personal data being stored in the register is not outdated, erroneous or incompatible with the purpose of processing. We immediately rectify or erase such data.

The security of user management and log systems is organised both technically and administratively in accordance with the best practices and policies in the field. Data stored in the user management and log system is kept in a logically separate entity from other information systems and on physically separate servers and network drives, so it is not possible to access, modify or delete data in the user management and log system with the same user IDs and access rights as in the actual information systems. The server equipment of the user management and log system is protected both by software and physically with firewalls, security software, hardening, passwords and usage monitoring. The data centres where the servers are physically located are locked and access is controlled. Access to user management and log systems is restricted so that access rights are granted only to individuals who absolutely need access to user management and log data as part of their work.

11 What are your rights as a data subject?

Data subjects have the following rights:

  • Right to have access to their data.
  • Right to receive information on the processing of their personal data.
  • Right to have erroneous or inaccurate personal data rectified.
  • Right to have data erased.
    • Not applicable if the basis for processing is a statutory duty or a duty in the public interest.
  • Right to restrict processing.
  • Right to object processing i.e. to ask that data is not processed.
  • Right to have data transferred from one system to another.
    • Applicable when the processing is based on an agreement or consent.
    • The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
  • Right to withdraw their consent.
    • Applicable when the processing is based exclusively on consent.
  • Right to receive information on a personal data breach that results in a high risk.
  • Right not to be subject to a decision based on automated processing

Data subjects have the right to lodge a complaint especially to the supervisory authority of their permanent place of residence or work if they find that the processing of personal data violates the EU’s General Data Protection Regulation 2016/679. Data subjects also have the right to employ administrative appeals and other legal remedies (https://tietosuoja.fi/en/notification-to-the-data-protection-ombudsman).

12. Who can you contact?

If you have any questions or comments about the processing of your personal data as described in this privacy notice, please contact the contact person mentioned in section 3, who will, if necessary, refer the matter to the data protection officer. If you consider that your rights set out in section 11 are not being fulfilled, you may contact the university’s data protection officer mentioned in section 4 directly.

13. Your responsibility

You are responsible for the data that you submit or make available to Uniarts Helsinki. You must make sure that the information is true and accurate and in no way misleading.

14. Amendments to the privacy notice

When this privacy notice is updated, the date of the new version will be edited to the beginning of the notice. If we make changes to the content, we may take appropriate steps to inform you in a manner consistent with the significance of the changes.