Privacy notice for library customer data

Articles 13 and 14 of the EU General Data Protection Regulation. Information for data subjects. Drawn up on 21 February 2019; updated on 10 April 2024.

1. Controller

University of the Arts Helsinki (Uniarts Helsinki)
Postal address: P.O. Box 1, 00097 Uniarts
Phone number: +358 294 47 2000 (switchboard)

2. Unit and person in charge of processing personal data

Library, Library Director Tommi Harju, firstname.lastname@uniarts.fi, +358 40 710 4243

3. Contact person for processing personal data

Library, Specialist Erkki Huttunen, firstname.lastname@uniarts.fi, +358 50 514 7818

Library, Information Specialist Erkki Nurmi, firstname.lastname@uniarts.fi, +358 40 710 4222

4. Data protection officer

Find contact details for Uniarts Helsinki’s data protection officer on the data protection homepage.

5. Name of the register

Library customer register

The Uniarts Helsinki Library is an essential support service for the teaching, research, and artistic activities of the university. Besides students and staff members, the library also serves customers who are not part of the university community but who can register as library customers.

The library customers can borrow and book resources, for example. The library sends out reminders to customers about returning overdue loans and charges fees for unreturned materials. The library also provides access to electronic resources maintained by external service providers within the scope of licences acquired by the library. Use of electronic resources is possible for everyone within the library premises, and also remotely for university students and staff. Customer data is also used for compiling statistics. The library also offers its customers an AI-based search tool that recommends related articles based on an article or written text. Uniarts Helsinki’s right to process personal data is based on:

  • A contractual relationship with the library customer.
  • The public interest, e.g., as regards compilation of statistics
  • Consent (search tool; the customer provides their data voluntarily or agrees to the transfer from the university’s background systems).

We do not use automated decision-making or profiling as referred to in the GDPR in our processing of personal data.

7. What data do we process?

In connection with the customer register, we process the following personal data of a data subject:

  • Basic information about the data subject: name, personal identity code, customer number and/or any other person-specific ID, password.
  • The data subject’s contact information: email address, phone number and address information. Information about the account and agreement: information about past and current loans, payments, requests, agreements and correspondence. Statistical data: relationship with the university and number of loans and requests.
  • Basic and contact information about a data subject under the age of 15: name*, email address, phone number, and address details
  • Providing the personal data marked with an asterisk is a prerequisite for establishing our contractual relationship and/or customer relationship. Without the personal data needed, we cannot provide the services.

The processing of personal identity codes is based on the need to reliably identify the customer in connection with library loan activities and the recovery of unreturned materials and collection of library fees.

We also process the following personal data of library customers using the search tool:

  • Name.
  • Email address.
  • IP address.
  • Cookies.
  • Customer programme (net, Word, Google Doc).
  • Relationship with the university.
  • Single user library.
  • User activity.
  • Phone number of users acting as administrators.
  • Text included in a document added by the user.

8. Where do we get data?

We primarily obtain information from the data subjects themselves.
In addition, we obtain data from the following sources:

  • As regards Uniarts Helsinki’s students and staff, the university’s user and access management register.
  • If needed, data can also be updated from the Population Information System.

9. To which parties do we disclose and transfer data and do we transfer data outside the EU or the EEA?

For personal data processing, we work with subcontractors. We have outsourced IT administration to third-party service providers administering and protecting the server on which personal data is saved. We have also outsourced financial services and fee collection activities. We have taken care of your data protection with our subcontractors by drafting processing agreements for the processing of personal data.

Data will not be disclosed outside the systems necessary for providing library services.

If a user logs into the Finna search service maintained by the National Library using Haka authentication, the Finna service stores the username, name and email address.

If a user logs into the Finna search service using their Arsca library card credentials or links their Arsca library card to a previously created Finna account, the Finna service stores the library card ID, PIN code, first and last names, email address and home library.

If a customer uses the shared loan service of the National Repository Library via the Arsca database or the Finna search service, their basic and contact information is temporarily copied to the customer register of the National Repository Library. The National Repository Library retains customer data as long as the customer has active loans or requests at the National Repository Library.

We do not transfer personal data outside the EU/EEA.

10. How do we protect data and for how long do we store it?

Your data is processed only by the employees of Uniarts Helsinki or by the persons working under the mandate of and on behalf of Uniarts Helsinki who have the right to process personal data.
As the controller, Uniarts Helsinki has taken the necessary technical and organisational measures and also requires the same from the service providers it uses.

We store data for as long as is necessary for the purpose for which the personal data is used. Customer data is valid for a period of three years at a time, after which the customer must update their data. If the data is not updated, the data will expire, and the use of the service is prohibited. Customers whose customer data has last been updated at least three years ago are deleted from the customer register.

We assess the need for retention of the data on a regular basis, taking into account any applicable legislation. In addition to this, we take reasonable steps to ensure that the data subject’s personal data being retained in the register is not outdated, erroneous or incompatible with the purpose of processing. We immediately rectify or erase such data.

11. What are your rights as a data subject?

Data subjects have the following rights:

  • Right to have access to their data.
  • Right to receive information on the processing of their personal data.
  • Right to have erroneous or inaccurate personal data rectified.
  • Right to have data erased.
    • Not applicable if the basis for processing is a statutory duty or a duty in the public interest.
  • Right to restrict processing.
  • Right to object processing i.e. to ask that data is not processed.
  • Right to have data transferred from one system to another.
    • Applicable when the processing is based on an agreement or consent.
    • The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
  • Right to withdraw their consent.
    • Applicable when the processing is based exclusively on consent.
  • Right to receive information on a personal data breach that results in a high risk.
  • Right not to be subject to a decision based on automated processing.

Data subjects have the right to lodge a complaint especially to the supervisory authority of their permanent place of residence or work if they find that the processing of personal data violates the EU’s General Data Protection Regulation 2016/679. Data subjects also have the right to employ administrative appeals and other legal remedies (https://tietosuoja.fi/en/notification-to-the-data-protection-ombudsman).

12. Who can you contact?

If you have any questions or comments about the processing of your personal data as described in this privacy notice, please contact the contact person mentioned in section 3, who will, if necessary, refer the matter to the data protection officer. If you consider that your rights set out in section 11 are not being fulfilled, you may contact the university’s data protection officer mentioned in section 4 directly.

13. Your responsibility

You are responsible for the data that you deliver or make available to Uniarts Helsinki. You must make sure that the information is true and accurate and in no way misleading.

14. Amendments to the privacy notice

When this privacy notice is updated, the date of the new version will be edited to the beginning of the notice. If we make changes to the content, we may take appropriate steps to inform you in a manner consistent with the significance of the changes.