-
-
HYY’s data protection statement
The personal data processed by the Student Union of the University of Helsinki (HYY) are classified into the following groups:
- Students’ data from the student register
- Data collected in connection with organising the Student Union’s administration: the Representative Council, other positions of trust, student representatives in administration, personnel, child care service Little HYY and access control
- The Student Union’s other activities and services
-
-
-
Students’ data from the student register
The Student Union of the University of Helsinki is a public corporation governed by the Universities Act. All students completing a basic degree at the University of Helsinki are members of the Student Union, which may also accept other students at the University as its members. The University maintains a student register, which also functions as the Student Union’s member register according to the aforementioned principles. In accordance with a separate agreement made with the University, the Student Union uses its member register, which is in connection to the student register, in its operations. The data are processed in matters related to membership in the Student Union for communication, verifying membership and maintaining contacts. The aim is to fulfil the Student Union’s statutory obligations and to offer services.
-
-
-
Basis for processing the data
The processing of the data is based on the EU’s General Data Protection Regulation (2016/679) or on national legislation applied to the matter in question as well as the agreement between the Student Union and the University of Helsinki on the disclosure and use of data.
- Payment of the membership fee: Universities Act (558/2009), Section 46
- Checking eligibility in the Representative Council elections and, for those elected to the Representative Council, during the Representative Council’s term
- EU’s regulation 2016/679, Article 6, paragraph 1, point (c): processing is necessary for compliance with a legal obligation to which the controller is subject
- Universities Act (558/2009), Section 46, subsection 6
- Government Decree on Universities (770/2009), Section 4
- Entering members into the electoral roll for Representative Council elections (right to vote):
- EU’s regulation 2016/679, Article 6, paragraph 1, point (c): processing is necessary for compliance with a legal obligation to which the controller is subject
- Universities Act (558/2009), Section 46, subsection 6
- Government Decree on Universities (770/2009), Section 4
- EU’s regulation 2016/679, Article 6, paragraph 1, point (b): processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract
- Checking eligibility to represent students in the University’s administrative bodies both at the time of selection and during the term:
- EU’s regulation 2016/679, Article 6, paragraph 1, point (e): processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller
- EU’s regulation 2016/679, Article 6, paragraph 1, point (c): processing is necessary for compliance with a legal obligation to which the controller is subject
- Universities Act (558/2009), Section 46, subsection 2
- Handling other statutory duties and duties set by the Student Union’s own Constitution, administration of memberships and ensuring the efficiency of services when student cards, the Ylioppilaslehti and Studentbladet magazines, invitations, newsletters and certificates of employment or position of trust are sent to members, if needed:
- EU’s regulation 2016/679, Article 6, paragraph 1, point (a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes (Ylioppilaslehti/Studentbladet magazines, invitations, newsletters)
- EU’s regulation 2016/679, Article 6, paragraph 1, point (b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (certificates of position of trust, sending student cards)
- EU’s regulation 2016/679, Article 6, paragraph 1, point (c) processing is necessary for compliance with a legal obligation to which the controller is subject (administration of memberships)
- Employment Contracts Act (55/2001), Chapter 6, Section 7 (certificates of employment)
Members can manage the consent they have given on the disclosure of data related to the delivery of Ylioppilaslehti in the Sisu service of the University of Helsinki.
-
-
-
Contact person
Person in charge: Secretary General of the Student Union of the University of Helsinki (paasihteeri@hyy.fi).
Contact person: Chief Financial Officer of the Student Union of the University of Helsinki (hallinto@hyy.fi).
-
-
-
Categories of personal data
The Student Union processes the following data through the student register:
- Basic details of members (including student number, personal ID, name and contact details)
- Members’ study rights
- Members’ registrations for academic terms
- Members’ membership fee payments
- Recortds of year tags received
- Membership in student nations
Data source: Members disclose the data on themselves. The University of Helsinki discloses the data on study rights.
Storage period: The Student Union does not save the data; it only processes them.
The data are processed by the officials of the Student Union within the framework of their job descriptions and authorities.
-
-
-
Right to access, right to rectification, right to erasure, right to restriction, right to object
All demands related to the rectification or erasure of data must be addressed to the University of Helsinki. Members of the Student Union of the University of Helsinki do not have the right to demand restrictions on the disclosure of their membership information to the Student Union of the University of Helsinki.
-
-
-
Right to lodge a complaint to the supervising authority
Data protection ombudsman: tietosuoja@om.fi.
-
-
-
Principles of the protection of personal data
The Student Union generally does not store the data, it only processes them. The processing takes place using an encrypted connection to the student register of the University of Helsinki. If needed, the data may be saved in order to fulfil statutory obligations.
-
-
-
Data collected in connection with organising the administration of the Student Union of the University of Helsinki
Data collected in connection with organising the Student Union’s administration: the Representative Council, other positions of trust, student representatives in administration, personnel, child care service Little HYY and access control
-
-
-
Representative Council
-
-
-
Purpose of processing the data
The Representative Council uses the highest decision-making power in the Student Union of the University of Helsinki. The data of members of the Student Union of the University of Helsinki who are running as candidates for the Representative Council are used for organising elections that are open to all members of the Student Union of the University of Helsinki. The Representative Council, including vice members, is formed based on the election result. The data of the elected Representative Council are used to organise the operation of the Representative Council and its Representative Council groups.
-
-
-
Basis of processing the data
Data Protection Regulation, Article 6, paragraph 1, point (e). Data Protection Act, Section 4.1, paragraph 1. Universities Act, Section 46.6, and Government Decree on Universities, Section 4. In the case of the potential political opinion of a candidate or member of the Representative Council, Data Protection Regulation, Article 9, paragraph 2, point (e).
-
-
-
Contact person
Secretary general of the Student Union of the University of Helsinki (paasihteeri@hyy.fi)
-
-
-
Description of the categories of data subjects and categories of personal data
Name, personal ID, faculty, address, phone number, email address, name of electoral coalition, names of the representative and vice representatives of the electoral coalition. Names categorised by electoral coalition in the list of candidates. The list of members of the Representative Council includes information about the election result for each candidate and electoral coalition.
-
-
-
Categories of recipients of the personal data
The names and electoral coalitions of those running in the Representative Council elections are published at hyy.fi. Their contact details can be accessed by those taking part in organising the elections as well as employees who oversee the Representative Council’s operation. The list of members of the Representative Council is published at hyy.fi and meetings of the Representative Council are publicly livestreamed online.
-
-
-
Transfer of data to third countries
A system or cloud service that stores the data outside the EU may be used for processing the data. If any data are transferred outside the European Union or the European Economic Area, the transfer requires the country in question to guarantee a sufficient level of data protection or the data controller to provide sufficient guarantees on the protection of the data subjects’ privacy and rights through contractual clauses or other means or the data subject to have unambiguously consented to the transfer.
-
-
-
Planned time limits for the erasure of data
Candidate declaration forms, combined lists of candidates and documents from the meetings of the Central Election Committee and the Representative Council are permanently archived. Recordings of the Representative Council’s meetings are stored online until further notice to ensure the transparency of decision-making processes.
-
-
-
Other persons in positions of trust
-
-
-
Purpose of processing the data
The Student Union’s self-governance includes the right to decide on how to best organise its internal administration. When deciding on the compositions of administrative bodies, personal data are collected for the organisation of administration.
-
-
-
Basis of processing the data
Data Protection Regulation, Article 6, paragraph 1, point (e). Data Protection Act, Section 4.1, paragraph 1. Universities Act, Section 46.6. In the case of the potential political opinion of a candidate of member of the Representative Council, Data Protection Regulation, Article 9, paragraph 2, point (e).
-
-
-
Contact person
Secretary general of the Student Union of the University of Helsinki (paasihteeri@hyy.fi)
-
-
-
Description of the categories of data subjects and categories of personal data
Name, Representative Council group, student number, faculty, address, phone number, email address, position in the administrative body, title, special diets. Remuneration is paid for some of the positions of trust. In these cases, personal data that is required for paying the remuneration is collected: bank details, personal ID, tax card.
-
-
-
Categories of recipients of the personal data
The names and email addresses of those serving in positions of trust are displayed at hyy.fi. Other data are available to the people involved in the Student Union’s administration.
-
-
-
Transfer of data to third countries
A system or cloud service that stores the data outside the EU may be used for processing the data. If any data are transferred outside the European Union or the European Economic Area, the transfer requires the country in question to guarantee a sufficient level of data protection or the data controller to provide sufficient guarantees on the protection of the data subjects’ privacy and rights through contractual clauses or other means or the data subject to have unambiguously consented to the transfer.
-
-
-
Planned time limits for the erasure of data
In each case, the data are stored for the duration of the term of the administrative body in question. After this, all data that is not included in the material to be archived are destroyed. Documentation created in the Student Union’s administration, including data on the people who participate in the administration, is permanently archived.
-
-
-
Student representatives in administration
-
-
-
Purpose of processing the data
The Student Union’s statutory duties include appointing student representatives to the administrative bodies of the University of Helsinki referred to in the Universities Act, Chapter 3. When making decisions on these student representatives, personal data are collected in order to appoint these individuals and arrange communication with them.
-
-
-
Basis of processing the data
Data Protection Regulation, Article 6, paragraph 1, point (e). Data Protection Act, Section 4.1. Universities Act, Section 46.2.
-
-
-
Contact person
Secretary general of the Student Union of the University of Helsinki (paasihteeri@hyy.fi)
-
-
-
Description of the categories of data subjects and categories of personal data
Name, email address. Personal ID or student number in cases where the person’s eligibility needs to be verified.
-
-
-
Categories of recipients of the personal data
The names and email addresses of those serving in positions of trust are displayed at halloped.fi. Other data are available to the people involved in the Student Union’s administration. The personal ID / student number is deleted after the verification process.
-
-
-
Transfer of data to third countries
A system or cloud service that stores the data outside the EU may be used for processing the data. If any data are transferred outside the European Union or the European Economic Area, the transfer requires the country in question to guarantee a sufficient level of data protection or the data controller to provide sufficient guarantees on the protection of the data subjects’ privacy and rights through contractual clauses or other means or the data subject to have unambiguously consented to the transfer.
-
-
-
Planned time limits for the erasure of data
In each case, the data are stored for the duration of the term of the administrative body in question. After this, all data that is not included in the material to be archived are destroyed. Documentation created in the administration of the Student Union of the University of Helsinki, including data on people who have served as student representatives in administration, is permanently archived.
-
-
-
Personnel
-
-
-
Purpose of processing the data
Employees’ personal data are collected and stored to fulfil obligations related to employment contracts.
-
-
-
Basis of processing the data
Statutory obligations related to employment contracts. Data Protection Regulation, Article 6, paragraph 1, points (b) and (c). In the case of special categories of personal data, Article 9, paragraph 2, point (b).
-
-
-
Contact person
Secretary general of the Student Union of the University of Helsinki (paasihteeri@hyy.fi)
-
-
-
Description of the categories of data subjects and categories of personal data
Name, personal ID, address, email address, phone number, membership in a trade union (if the membership fee is paid in connection with the payment of salary), special diets, records of working hours, bank details, tax card.
-
-
-
Categories of recipients of the personal data
The names and photos of employees (photo with the employee’s consent) are displayed at hyy.fi to help employees attend to their duties and to facilitate contacts. Other data are available to the employer’s representatives. The Student Union has outsourced the calculation of salaries and a part of its statutory obligations related to personnel to Ylva, the company owned by the Student Union.
-
-
-
Transfer of data to third countries
A system or cloud service that stores the data outside the EU may be used for processing the data. If any data are transferred outside the European Union or the European Economic Area, the transfer requires the country in question to guarantee a sufficient level of data protection or the data controller to provide sufficient guarantees on the protection of the data subjects’ privacy and rights through contractual clauses or other means or the data subject to have unambiguously consented to the transfer.
-
-
-
Planned time limits for the erasure of data
The data are stored for the duration prescribed in legislation. After this, data that is not included in the material to be archived are destroyed. A record of individuals who have served as employees of the Student Union of the University of Helsinki will be included in the Student Union’s archived material.
-
-
-
Child care service Little HYY
-
-
-
Purpose of processing the data
Organising the operation of the child care service maintained by the Student Union in a safe and responsible fashion.
-
-
-
Basis of processing the data
Consent of the data subject’s guardian.
-
-
-
Contact person
Chief financial officer of the Student Union of the University of Helsinki (hallinto@hyy.fi)
-
-
-
Description of the categories of data subjects and categories of personal data
Data: child’s name, date of birth and allergies, guardian’s name, phone number, email address and home municipality. In addition to this, the guardian may voluntarily declare any other information that affects the child’s care. The data are stored manually on customer information forms.
-
-
-
Transfer of data to third countries
The data are not disclosed to external parties.
-
-
-
Planned time limits for the erasure of data
The data are destroyed two years after the child care relationship has ended at the latest.
-
-
-
Access control in properties
-
-
-
Purpose of processing the data
The use and monitoring of premises under the Student Union’s control in order to better oversee the maintenance and safety of the properties and prevent any potential misuse and crime. The electronic access control system is used to ensure the maintenance of order and can be used to help make people answer for any damages they have caused.
-
-
-
Basis of processing the data
EU’s Data Protection Regulation 2016/679, Article 6, paragraph 1, point (b).
-
-
-
Contact person
Chief financial officer of the Student Union of the University of Helsinki (hallinto@hyy.fi)
-
-
-
Description of the categories of data subjects and categories of personal data
Name, basis of the access right (such as employment contract, position of trust or contract for organisational premises), premises for which the access right has been granted and the access right’s period of validity.
-
-
-
Categories of recipients of the personal data
The Student Union’s employees within the limits of their job descriptions. The authorities, such as the police, if needed.
-
-
-
Transfer of data to third countries
A system or cloud service that stores the data outside the EU may be used for processing the data. If any data are transferred outside the European Union or the European Economic Area, the transfer requires the country in question to guarantee a sufficient level of data protection or the data controller to provide sufficient guarantees on the protection of the data subjects’ privacy and rights through contractual clauses or other means or the data subject to have unambiguously consented to the transfer.
-
-
-
Planned time limits for the erasure of data
The data are stored for a maximum of six (6) months after the access right has expired. The lists of users submitted by organisations operating under HYY that are referred to in the contract for organisational premises are stored for two (2) weeks after the access rights have expired.
-
-
-
The Student Union’s other activities and services
-
-
-
Purpose of processing the data
The Student Union of the University of Helsinki organises events and other informal activities, allocates premises, rents out items, provides guidance, maintains contacts with student associations and other interest groups, concludes agreements, creates surveys, maintains email lists and rewards distinguished individuals such as members, people active in organisations, teaching personnel and alumni. Data collected while performing these functions are used to conduct practical arrangements as expediently as possible and to provide services.
-
-
-
General bases of processing the data
EU’s Data Protection Regulation 2016/679, Article 6, paragraph 1, point (b).
-
-
-
Categories of personal data
Data are collected in the Student Union’s informal activities on a case-to-case basis as needed for the activities in question.
- Data source: the person themselves
- Storage period: Documentation created in the Student Union’s administration is permanently archived.
- Possible recipients of data: People organising the events and activities in question, necessary administrative personnel
- Possible transfer of data to third countries: The data may be stored and transferred to third countries using technical devices if this serves some purpose.
-
-
-
Bases of processing the data and categories of personal data
-
-
-
Organisational data: data on the people in charge of organisations
Basis: EU’s Data Protection Regulation 2016/679, Article 6, paragraph 1, point (b).
Data: Name, email address and phone number of the chair of the organisation’s board or another person in charge of communication. The organisation’s email address and street/postal address are also collected, and these may be the same as the address of the chair or another member of the board. In addition to this, the names and email addresses of vice chairs, members of the board, treasurers and other people involved in the organisation are collected based on voluntary declarations.
-
-
-
Event data: invitation and participant data (for training and other events)
Basis: EU’s Data Protection Regulation 2016/679, Article 6, paragraph 1, point (b); in the case of allergy information, EU’s Data Protection Regulation 2016/679, Article 9, paragraph 2, point (a).
Data: Name, phone number, email address, possible organisation the person is representing, title, position in the association, special diets, allergies, name of companion and, if needed, payment details.
-
-
-
Data on cooperation partners / contract partners
Basis: EU’s Data Protection Regulation 2016/679, Article 6, paragraph 1, point (b); in the case of allergy information, EU’s Data Protection Regulation 2016/679, Article 9, paragraph 2, point (a).
Data: contact person’s name, email address and phone number. For events, also special diets, organisation or company, position in the organisation or company, allergies, name of companion and, if needed, payment details.
-
-
-
Rewarding: Honours awarded by the Student Union
Basis: EU’s Data Protection Regulation 2016/679, Article 6, paragraph 1, point (f): processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Data: data on the person being nominated and the persons nominating them to facilitate contacts with them. Name, email address, phone number, title, field of study and possible support organisation of the person nominated for honours as well as the justifications for the nomination given by the party making the proposal and their contact details. People who have received honours in previous years are recorded in a shared file, which means that the database grows every year.
-
-
-
Email lists
Basis: EU’s Data Protection Regulation 2016/679, Article 6, paragraph 1, point (a): the data subject has given consent to the processing of his or her personal data for one or more specific purposes.
Data: email address and name.
-
-
-
Data submitted through surveys
Basis: EU’s Data Protection Regulation 2016/679, Article 6, paragraph 1, point (a)
Data: name (on a voluntary basis), phone number and email address.
-
-
-
Right to access, right to rectification, right to erasure, right to restriction, right to object
People participating in the Student Union’s other activities have the right to access the data collected on them and to get any possible mistakes rectified. The erasure of the data and the restriction of the processing of the data cannot be requested while the activity in question is still ongoing without also waiving the right to receive the service, product or right in question. In this case, too, all commitments concerning the person in question that have been created up to that time will remain in place.
-
-
-
Transfer of data to third countries
A system or cloud service that stores the data outside the EU may be used for processing the data. If any data are transferred outside the European Union or the European Economic Area, the transfer requires the country in question to guarantee a sufficient level of data protection or the data controller to provide sufficient guarantees on the protection of the data subjects’ privacy and rights through contractual clauses or other means or the data subject to have unambiguously consented to the transfer.
-
-
-
Planned time limits planned for the erasure of data
In each case, the data are stored for the duration that is necessary to provide the service or activity in question. After this, all data that is not included in the material to be archived are destroyed. Documentation created in the Student Union’s administration is permanently archived.
-
-
-
Contact person
Secretary general of the Student Union of the University of Helsinki (paasihteeri@hyy.fi)
-
-
-
Principles of the protection of personal data
With the consent of the data subject, personal data may be collected using any kinds of means. However, any collected data are only processed, transferred and stored using means that are equivalent to the original collection method or more secure than it.
-