Not-primary information about data processing concerning students
This document is provided pursuant to Article 13 ofEU Regulation 2016/679 of 27 April 2016 on protection of natural persons with regard to personal data processing and in compliance with the legislation on personal data processing.
This information is addressed to all those who can be identified as students of Politecnico di Milano and to the services dedicated to them.
Data Processing Controller
The Data controller of Politecnico di Milano is the General Manager upon authorization of the pro-tempore Rector – contact: dirgen(at)polimi.it .
Internal Data Processor
Dr. Assunta Marrese, the Undergraduate and Graduate Students Service Manager, e-mail assunta.marrese(at)polimi.it.
Data will be processed by other authorized parties and, for this purpose, in compliance with current legislation.
Responsible for Data Protection and Contact Points
Dr. Vincenzo Del Core, e-mail: privacy(at)polimi.it , phone: +39 0223999378
Legal basis and purpose of the treatment
The data processing takes place exclusively for the institutional purposes of public interest provided by the laws containing provisions about education, in compliance with the principles of legality, correctness, transparency, relevance, adequacy and needs pursuant to Article 5 of EU Regulation n. 679/2016.
Then, the data will be processed in order to be able to manage the admission application to the study programmes of Politecnico di Milano and prepare what is necessary to allow, always for institutional purposes and specific security needs, the use of technological tools for access purposes containing personal information, available through specific recognition devices.
Subsequently, if the admission request is successful, the data will also be processed to manage the whole university career until the status remains as student, as identified by the Student Career Regulations of Politecnico di Milano, available in the "University Regulations" section of the University Web site (http://www.normativa.polimi.it/).
Finally, the same data, at the end of the student status, will be processed to manage the certifications provided.
The processing of so-called "details" is carried out exclusively for institutional purposes provided by the current law, for what concerns the admission request and the educational career.
In detail, the data collected will be processed for carrying out the following activities:
- enrolment and attendance of lectures of university courses and through e-learning;
- university career management;
- management of curricular and extracurricular internships;
- calculation of the amounts of tuition fees to be paid;
- use of telematic and e-mail services;
- use of library services;
- access to laboratories and other protected facilities;
- sending and communication related to your university career;
- application of safety measures in the workplace according to the provisions of Legislative Decree n. 81/2008;
- disciplinary procedures for students;
- surveys for evaluation of education and customer satisfaction;
- archiving and storage of data concerning the university career (educational career carried out, positions, qualifications obtained);
- elections of student representative and for possible fulfilment of duties related to the position held by the interested party in the University bodies;
- outgoing guidance and job placement activities;
- use of contributions, financial aid and services related to the right to university study;
- statistics and historical and scientific research surveys;
- processes related to the preparation of the final works for different study programmes;
- services provided to support users with disabilities and specific learning disorders (DSA - disturbi specifici di apprendimento);
- services related to the field of counselling and psychological support (POLIPSI);
- incoming and outgoing student mobility;
- registration and certification issuance for participation in events and training courses and Summer School;
- accreditation procedures for study programmes;
- placement test/check of initial knowledge;
- State examination;
- career management for students in gender transition;
- provision of services for students that are detainees or in a state of restriction of their personal freedom.
Nature of data
The transmission of personal data must be considered as mandatory.
The failure to communicate data makes it impossible to carry out the operations necessary to finalize the relation between student and University, as well as purposes and correct administrative and educational management of the student career, necessary to fulfil the obligations provided by the law.
The processing of any aggregate or anonymous data does not imply the application of EU Regulation n. 679/2016.
Data Categories for calculation of the Amounts of Tuition Fees to be paid
In accordance with Article 14 of EU Regulation n. 679/2016, the calculation of university tuition fees requires that Politecnico di Milano asks you for information on the ISEE and Equivalent ISEE value, the members of your family, as well as all the information related to DSU, directly from the INPS database, in application of the D.P.C.M. of 5 December 2013, n. 159, provided that they are not more of what required and related to this purpose, in order to apply possible financial aid.
Special categories of data
For the purposes of data processing mentioned above, in specific situations, particular data categories may be collected and processed upon request of the interested party, such as:
- racial and ethnic origin (for non-EU citizens, and for refugee status);
- state of health (in case of pregnancy or for students with disabilities);
- judicial data (for users and students that were detainees);
- sex life (for any sex assignment rectification).
Categories of data recipients and possible data transfer
The data processed for the aforementioned purposes will be communicated or, in any case, will be accessible to the professors of the study programme you have chosen and to the employees and collaborators of the offices of Politecnico di Milano that, as authorized persons for data processing, will be properly trained by the data controller.
The University can forward your personal data, of which it is the data controller, also to other public administrations or foreign bodies (e.g.: embassies) if these institutions must process them for procedures related to their institutional work, as well as to all those public entities to whom, with the same prerequisites, the communication is compulsorily provided in accordance to EU provisions, laws or regulations, as well as insurance companies for possible accident insurances.
In particular, the personal data processed will be forwarded to the following third parties:
- MIUR research institutions;
- Conference of Italian University Chancellors (CRUI – Conferenza Rettori Università Italiane);
- Ministry of Health;
- Ministry of Home Affairs;
- Ministry of Foreign Affairs;
- Internal Revenue Office;
- European Community;
- Police Headquarters, Prefecture, Public Prosecutor's Office, Embassies, Legal Council of State;
- Judicial authority;
- Insurance institutions and INAIL;
- Foreign universities and academic and research institutions;
- Professional and Trade Associations;
- CNUDD - National University Conference of Delegates for Disability;
- CALD - Coordination of Lombardy universities for disabilities and specific learning disorders (DSA);
- INDIRE, National Agency;
- National Register of Students, as required by law 170 of 11 July 2003;
- Public and private bodies requesting confirmations to self-certifications received, in accordance with the "Consolidated Act regarding the legal and regulatory dispositions on administrative documentation" - Presidential Decree of 28 December 2000, n. 445, modified by article 15 of the law n.183 of 2011;
- Bank Treasurer of Politecnico, for services related to economic transactions;
- Sostanza Srl, a company that provides information exchange tools between students and University staff (LiveHelp chat system);
- Other companies providing "Software as a service" (SaaS) used by the University;
- Companies used for registration of personal details in use for carrying out Ministerial tests;
- Individuals or legal entities that provide consulting services or work with Politecnico to provide financial aid for education.
Transfer to extra-EU Country
Personal data may be transferred abroad, in accordance with the provisions of the Regulations, even in countries outside the European Union when this is necessary for one of the purposes indicated in this information document.
The transfer to non-EU countries, in addition to cases where this is guaranteed by the adequacy decisions of the European Commission, is carried out in a way to provide the appropriate guarantees required by the articles 46 or 47 or 49 of the Regulations.
The data processing(s) carried out for the above mentioned purposes can be performed both through paper and digital means, manually and/or with electronic tools or, in any case, through automated tools, including in-house databases: and / or external database of companies and consortia: CINECA, CISIA, Sostanza Srl, other companies providing "Software as a service" (SaaS) used by the University. They are also stored in digital format and paper archives for an indefinite period of time due to the transparency and good operation of the public administration.
The data collected will be stored through proper security measures to allow access to duly authorized staff and guarantee the confidentiality and data integrity.
The storage period will be defined according to the principle of necessity of processing. Therefore, for what concerns storage times, data and documents that contain them will be kept for the period necessary to fulfil the legal obligations and the managerial, administrative and educational needs. In particular:
- the data concerning the university career will be kept indefinitely, taking into account the storage obligations provided by current legislation.
- data related to the use of computer systems (e.g.: time and duration of connection) or use of e-mail will be processed by automated tools and stored only for the time strictly necessary to achieve the purposes for which they were collected, except different legal provisions (maximum 12 months);
- the data related to any disciplinary proceedings that may incur will be kept for an indefinite period of time, except in those cases where the final provision will be cancelled by a final judgement or withdrawn by the administration.
Right of the interested party
At any time, the interested party can exercise the rights provided by the EU Regulation n. 679/2016 and in particular:
- Right of access to personal data and all information pursuant to Article 15 of the Regulations;
- Right related to correction and anonymised change of data processed;
- Right to cancel (right to be forgotten) your data, except for those already included in documents that must be kept by Politecnico di Milano and unless there is a legitimate reason in order to proceed with data processing;
- Right to limitation of data processing, pursuant to Article 18 of the Regulations;
- Right to object to personal data processing, without prejudice to what is required in relation to the need for mandatory data processing in order to take advantage of the services offered;
- Right to withdraw the consent given for non-compulsory data processing, without prejudice about legality of treatment, based on the consent given before the withdrawal.
Methods of exercise of the rights and complaint
Last update: August 2, 2019