Privacy notice for Uniarts Helsinki’s electronic communication, IT and support services

Articles 13 and 14 of the EU General Data Protection Regulation. Information for data subjects. Drawn up on 16 May 2018; updated on 15 July 2025.

1. Controller

University of the Arts Helsinki (Uniarts Helsinki)
Postal address: P.O. Box 1, 00097 Uniarts
Phone number: +358 294 47 2000 (switchboard)

2. Unit and person in charge of processing personal data

Digital Services, CDO & CIO Mari Nyrhinen, firstname.lastname@uniarts.fi, +358 294 47 2000 (switchboard)

3. Contact person for the processing of personal data

IT Support Services, Manager Juha Rosvall, firstname.lastname@uniarts.fi , +358 294 47 2000 (switchboard)

4. Data protection officer

Find contact details for Uniarts Helsinki’s data protection officer on the data protection homepage.

5. Name of the register

Uniarts Helsinki’s electronic communication, IT and support services

On the basis of the Universities Act, the mission of Uniarts Helsinki is comprised of teaching, research and artistic activities. Universities are autonomous, which ensures the freedom of science, art and highest education. Their autonomy also entails the right to make decisions on matters related to their internal administration. The Universities Act also states that the university community comprises teaching and research staff, other staff and students. Visiting researchers, emeritus professors and similar persons with whom the university has concluded an agreement to this effect may also be part of the university community.

The purpose of processing personal data in Uniarts Helsinki’s electronic communication and support services, in accordance with this privacy notice, is to enable the use of electronic services by the aforementioned users of the university as well as possible subcontractors and assignees and to resolve problem situations.

In this context, electronic communication, IT and support services refer to programmes and software platforms that enable communication, collaboration and other activities between two or more parties over an internet connection. These include, for example, email software and servers, various instant messaging tools and internet calls, electronic collaboration and teamwork tools, online learning platforms, facility booking services and various service support systems such as ticketing systems, equipment management and leasing systems, distribution solutions (e.g. loan devices, AV equipment), printing services, remote management and monitoring systems for devices, process modelling tools, access control, etc.

Uniarts Helsinki’s right to process personal data is based on:

  • An agreement.
  • The data controller’s legitimate interest.

The processing of personal data is necessary for the implementation of an agreement (employment contract, right to study or other agreement) between the university and the data subject.

The primary basis for the personal data processing described above is the legitimate interest of Uniarts Helsinki as the data controller, which allows for the processing of data required for the operation of electronic services for the purposes described above. Legitimate interest in this context refers to Uniarts Helsinki’s right to use essential tools and electronic services necessary for organising its operations and for enabling study, research and work for students, employees and others working on its behalf. In addition, our university’s legitimate interest means the right to document the use of electronic services in order to analyse operations, ensure business continuity and fulfil various statutory or contractual reporting and demonstration obligations.

In many processes, the submission of personal data is a necessary prerequisite for handling the matter.

We do not use automated decision-making or profiling as referred to in the GDPR in our services.

7. What data do we process?

When delivering electronic communication services, Uniarts Helsinki processes the personal data of two or more parties involved in the communication, i.e. the senders and recipients. These parties may include the university’s own users, subcontractors or assignees, current or potential customers and partners.

In connection with electronic communication, IT and support services, Uniarts Helsinki processes the following basic personal data of data subjects:

  • Name or alias.
  • Contact information (email address, phone number and site of work).
  • Role or position within the organisation.
  • Username and access rights.
  • Additionally, users may voluntarily provide information to the service (e.g. a photograph).

In addition to basic data, Uniarts Helsinki processes the following information:

  • Communication-related data, such as sender and recipient details.
  • Technical service implementation data, such as IP address, device serial numbers and identifiers.
  • Service request data, such as the request ID.
  • Switchboard service data, such as a brief job description, substitute and supervisor.
  • Device register data, such as the user’s workstation location or device installation location and details related to the device and its location.
  • Printing ID.
  • Facility booking system data, such as reservation details.
  • Access control system data, such as granted access rights and their duration.

8. Where do we get data?

Uniarts Helsinki gathers data from the following sources:

  • User data is automatically received from Uniarts Helsinki’s user and access authorisation management. Personal data is regularly obtained from the electronic messaging services themselves by automatically monitoring the communication of data subjects, as well as directly from the data subjects during registration and use of the services. User data for user management comes from the HR system Mepco and the study management system Peppi.
  • In service requests, the user enters a description of the service need or the problem to be solved.
  • The telephone directory used by the switchboard service is compiled from the university’s subscription data provided by the telephone operator and the user and access authorisation management register and enriched with job information in cooperation with HR, communications team and supervisors.
  • Basic information about devices in the device register is entered by the IT administration when the user receives the device for use.
  • Data collected through remote management and monitoring of workstations and phones is enriched with information from the device register.
  • Basic personal data for access control systems is obtained from user management, and if necessary, the user is created manually by Facilities Services when the person comes on site to collect an access tag or key.
  • When printing, the user activates their printing ID at a multifunction device and provides their username and password.

9. To which parties do we disclose and transfer data and do we transfer data outside the EU or the EEA?

Personal data collected from the operation of electronic communication services will not be disclosed to third parties without the explicit prior consent of the data subjects, except in situations where an authority or other entity has a right, based on national or EU-level law, regulation or other binding provision, to request access to the personal data and related processing information. In such cases, data will only be disclosed to the extent necessary under the relevant provision.

To implement the data processing described in this privacy notice, Uniarts Helsinki uses subcontractors who assist in providing electronic services and in related data processing. Despite any subcontracting chain, Uniarts Helsinki remains the data controller of the personal data described in this notice at all times and is responsible for the actions of its subcontractors as if they were its own.

Through data processing agreements with subcontractors, the university ensures that these parties are committed to protecting the personal data of data subjects as described in this notice.

Personal data related to electronic communication services is processed both within and outside the EU and EEA.

We have ensured the protection of the data subject’s personal data by entering into the necessary processing agreements with our subcontractors.

In cases where we transfer personal data outside the EU/EEA, we have taken appropriate security measures in connection with the transfer. We use the standard contractual clauses adopted by the EU.

10. How do we protect data and for how long do we store it?

A valid username and access rights are required to use the systems.

As the controller, Uniarts Helsinki has taken the necessary technical and organisational measures and also requires the same from the service providers it uses.

Only those employees of Uniarts Helsinki and its service providers who need to process system user data as part of their duties are authorised to perform system maintenance. Each user with admin rights has their own username and password in the system.

The security of services is organised both technically and administratively in accordance with the best practices and policies in the field. The server equipment of the systems is protected both by software and physically with firewalls, security software, hardening, passwords and usage monitoring. The data centres where the servers are physically located are locked and access is controlled.

Personal data under this privacy notice is stored in information systems for as long as the data content is useful for using the service or for monitoring and documenting its use. In practice, data is retained depending on the communication service, in accordance with contracts made with regular subcontractors, taking into account the nature of the communication service. When an employment relationship, a student’s right to study or other contractual relationship with the university ends, the username is deactivated and the user’s data is deleted from the systems after a certain waiting period, which is a maximum of 9 months.

When the use of personal data for the purposes described above is no longer possible due to the expiry of the retention period, the data is deleted from electronic services and their information systems. Some data may be stored in backups of university services, which are regularly destroyed according to the backup schedule.

We take reasonable steps to ensure that the data subject’s personal data being stored in the register is not outdated, erroneous or incompatible with the purpose of processing. We immediately rectify or erase such data.

11. What are your rights as a data subject?

Data subjects have the following rights:

  • Right to have access to their data.
  • Right to receive information on the processing of their personal data.
  • Right to have erroneous or inaccurate personal data rectified.
  • Right to have data erased.
    • Not applicable if the basis for processing is a statutory duty or a duty in the public interest.
  • Right to restrict processing.
  • Right to object processing i.e. to ask that data is not processed.
  • Right to have data transferred from one system to another.
    • Applicable when the processing is based on an agreement or consent.
  • Right to withdraw their consent.
    • Applicable when the processing is based exclusively on consent.
    • The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
  • Right to receive information on a personal data breach that results in a high risk.
  • Right not to be subject to a decision based on automated processing.

Data subjects have the right to lodge a complaint especially to the supervisory authority of their permanent place of residence or work if they find that the processing of personal data violates the EU’s General Data Protection Regulation 2016/679. Data subjects also have the right to employ administrative appeals and other legal remedies.

12. Who can you contact?

If you have any questions or comments about the processing of your personal data as described in this privacy notice, please contact the contact person mentioned in section 3, who will, if necessary, refer the matter to the data protection officer. If you consider that your rights set out in section 11 are not being fulfilled, you may contact the university’s data protection officer mentioned in section 4 directly.

13. Your responsibility

You are responsible for the data that you submit or make available to Uniarts Helsinki. You must make sure that the information is true and accurate and in no way misleading.

14. Amendments to the privacy notice

When this privacy notice is updated, the date of the new version will be edited to the beginning of the notice. If we make changes to the content, we may take appropriate steps to inform you i