Search the site

Privacy and Personal Data Protection

The University for Foreigners of Perugia recognizes the importance of personal data protection and, as the data controller, is committed to processing such data appropriately and transparently with respect to the data subject, i.e., the person to whom the personal data relates.

Privacy notices are one of the tools used to ensure transparency, as they provide a comprehensive overview of data processing activities, the purposes pursued, and the methods employed. Whenever new services or purposes are introduced, these notices are updated; therefore, we encourage you to read the privacy notices regularly as published in this section.

It is important to note that the University for Foreigners of Perugia, hereinafter referred to as the “University,” established by Royal Decree-Law of 29 October 1925, no. 1965, is a public institution of higher education with a special legal status under Law no. 204 of 17 February 1992. The University promotes and organizes educational and scientific research activities aimed at fostering the knowledge and dissemination of the Italian language, culture, and civilization, intercultural dialogue, communication, and international cooperation, in coordination with local stakeholders, representative institutions, and national and international bodies with similar objectives (Art. 1 of the Statute); in carrying out its functions, it is assimilated to Public Administrations (Art. 1, paragraph 2, Legislative Decree 30 March 2001, no. 165).

For these reasons, the University’s data processing activities may be carried out, pursuant to Article 6, paragraph 1 of the General Data Protection Regulation “Regulation (EU) 679/2016” or GDPR, on the following legal bases:

  • processing necessary for the performance of a contract to which the data subject is a party, or for pre-contractual measures taken at the request of the data subject (letter b)
  • processing necessary for compliance with a legal obligation (letter c)
  • processing necessary for reasons of public interest (letter e)
  • processing based on the legitimate interests of the University, provided these do not override the interests, rights, and fundamental freedoms of the data subject, especially if the data subject is a minor (letter f)

If data processing does not fall under these legal bases, including regulatory or institutional calls or procedures, it may only be carried out with the data subject’s consent (Art. 6, para. 1.a). Exceptionally, in particular emergency situations, the University may process personal data, however acquired, for the protection of the data subject or another individual (Art. 6, para. 1.d).

Use of Artificial Intelligence Systems

As part of certain institutional, administrative, educational, and informational services, the University uses artificial intelligence systems.

The use of these technologies complies with personal data protection regulations and is guided by principles of transparency, security, data minimization, and human oversight.

For information on the main systems used by the University, their purposes, and the measures implemented, visit the section Artificial Intelligence at the University for Foreigners of Perugia.

Main processing activities carried out by the University for Foreigners of Perugia

  • Processing for university orientation purposes (also applicable to minors)
  • Processing for the administration of entrance tests or verification of admission requirements
  • Processing for the delivery of educational programmes and management of student careers (from enrolment to graduation, including teaching delivery, administrative procedures, management of fees and refunds)
  • Processing related to the publication of the final thesis or associated materials
  • Processing for the provision of student welfare services and benefits
  • Processing for curricular and extracurricular internship activities
  • Processing for research activities in which the data subject participates
  • Processing for job placement activities
  • Processing for statistical surveys and teaching evaluation
  • Processing for tutoring services, assistance, and social inclusion
  • Processing for fundraising activities, institutional communication and information, and community development
  • Processing for the management of voting rights for representation in university bodies
  • Processing for safety on university premises and for insurance coverage
  • Cross-functional or related processing activities (listed below)

  • Processing for the purpose of conducting competitive examinations/selections
  • Processing for the management of employment relationships
  • Processing of personal data for training and professional development purposes
  • Processing of personal data for the management of the educational offer and the assignment of duties
  • Processing of personal data necessary for the management of research projects
  • Processing of personal data to ensure research monitoring and evaluation
  • Processing of personal data in the context of technology transfer activities
  • Processing necessary for welfare policies and access to benefits
  • Processing for the health and safety of individuals in the workplace
  • Processing of personal data in the provision of fixed and mobile telephone services
  • Processing of data for personnel evaluation
  • Processing of data concerning disciplinary proceedings
  • Cross-cutting processing or processing related to cross-cutting activities (listed below)

  • Data processing related to space management, including through video surveillance systems
  • Processing of personal data for the management of workstations, access to and use of university services, including online services
  • Processing for the management of institutional bodies and official appointments
  • Processing for accident management
  • Processing for the use of library services
  • Data processing related to protocol services and document preservation
  • Processing for the purchase of goods and services, contract agreements, debt recovery, and management of disputes
  • Data processing within email services and collaboration tools
  • Processing of personal data in the context of federated service provision

Further information

The collected data will be retained for the period necessary to achieve the purposes for which they were collected and as established by current legislation or University regulations.

In particular, please note that personal data related to academic records will be retained indefinitely, in compliance with the storage and record-keeping obligations imposed by applicable law.

The regulation grants several rights to the data subject:

  • right of access to personal data
  • right to rectification
  • in cases provided for by law and in the absence of overriding legitimate interests of the University, the right to erasure of data (so-called right to be forgotten)
  • in cases provided for by law, the right to restriction of processing
  • in cases provided for by law and if processing is based on consent, the right to data portability
  • in cases provided for by law and if processing is based on consent, the right to object to processing activities
  • where processing is based on consent, the possibility to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal

To exercise these rights, you may submit a request to the Data Controller at rettore@unistrapg.it or, via PEC, protocollo@pec.unistrapg.it, and to the Data Protection Officer at rpd@unistrapg.it, or alternatively to protocollo@pec.unistrapg.it using the dedicated form.

If you believe that any processing is not compliant with applicable regulations, you can contact the Data Protection Officer at rpd@unistrapg.it and/or file a complaint with the competent supervisory authority, which for Italy is the Garante per la protezione dei dati personali. Alternatively, you may file a complaint with the Data Protection Authority of the EU Member State where you reside or normally work, or where the alleged violation has occurred.

In the case of minors, before submitting data to the University, it is necessary that the privacy notices are read carefully together with parents or legal guardians. The parents or legal representatives of minor users may exercise rights as indicated in the previous section.

The privacy notice, drawn up in accordance with Article 13 of EU Regulation 679/2016, contains a substantial amount of information, summarized as follows:

  1. The details and contact information of the Data Controller and the Data Protection Officer, which for the University for Foreigners of Perugia are as follows:
    1. the Data Controller is the University for Foreigners of Perugia, represented by the Rector as legal representative
    2. the Controller's contact: rettore@unistrapg.it or, via PEC, protocollo@pec.unistrapg.it
    3. the Data Protection Officer's contact: rpd@unistrapg.it, tel. 075 57 46 1
  2. the purposes and legal grounds for the processing of personal data and whether there is a legitimate interest on the part of the Controller
  3. the nature (personal/special category) and types of data processed (identification, contact, etc.)
  4. whether the provision of data is mandatory and the consequences of failing to provide such data
  5. if consent for processing specific categories of data has been requested, the existence of the right to withdraw consent and the procedures and conditions for exercising that right
  6. the ways in which data will be processed, whether profiling is involved (fully automated decision-making based on certain data), the data retention period or retention criteria applied
  7. whether data may also be processed by other public administrations or external companies, transferred outside the European Union, and the safeguards implemented by the Controller
  8. the rights exercisable (detailed above), how and whom to contact to submit a request, and the right to lodge a complaint with the supervisory authority

In certain cases, processing involves obligations to exchange or disclose personal data to other Public Administrations, while some processing activities are carried out with the support of specialized companies that act as external data processors: these processing methods are also specified in the privacy notices.

We acknowledge that, due to its thoroughness, the full privacy notice may take time to read, so in some cases a simplified notice is provided, which refers to the full version for more in-depth information.

Updated Privacy Notices

(currently being published)

Personal data may be processed by technical-administrative staff, academic staff, or collaborators of the Data Controller who, acting under the direct authority of the Controller, are authorized to process the data or are designated as external data processors, having received appropriate training and operational instructions relevant to the activities involved in their respective processing tasks.

Personal data may also be disclosed to other public administrations, should these require such data to carry out institutional proceedings within their competence. In certain cases, the University may engage external companies for the provision and management of specific services. These entities may gain access to personal data solely for the purpose of providing the requested service and, as such, will be designated as external data processors, contractually bound to the Controller to ensure the processing of personal data in compliance with the procedures outlined by the GDPR.

Personal data may also be disclosed to public authorities or private entities where teaching, research, or internship activities related to the chosen course of study or employment may take place, as well as to judicial authorities upon their request.

For research and teaching purposes, personal data may be transferred abroad to other universities or research institutions, or within the framework of international mobility programs. The safeguards provided by the Data Controller will comply with Chapter V of the GDPR, the relevant provisions issued by the Ministry of Education, University and Research (Miur), or sector-specific regulations.

Below are links to documents that may be of interest for further information on personal data processing:

A personal data breach should be considered any violation of the security of IT systems or personal data processing that accidentally or unlawfully results in the access, destruction, loss, alteration, or unauthorized disclosure of personal data stored, transmitted, or otherwise processed by the University.

In the event of a suspected and/or confirmed personal data breach, it is extremely important to ensure that it is addressed immediately and correctly, in order to minimize its impact and prevent recurrence. For instance, in cases involving unauthorized access to email accounts or restricted areas, one of the immediate measures to be taken is to change the password for these services.

If a breach has occurred or you become aware of a suspected personal data breach, you must complete a form and submit it to databreach@unistrapg.it as soon as possible, taking into account the following two scenarios:

Use of the form is mandatory in order to provide the University with immediate access to the necessary information to adequately assess the resulting risk situation.

Breaches may occur for a wide range of reasons, including:

  • loss or theft of data or devices (laptops, smartphones, USB keys, etc.) on which data are stored or made accessible
  • viruses, malware, or other attacks targeting your work computer, IT system, or the university network
  • disclosure of confidential data to unauthorized individuals (for example, via attachments sent to incorrect recipients by email, or accessed through a compromised mailbox)
  • loss or theft of paper documents containing confidential personal data
  • unauthorized or unlawful access to IT systems, hacking
  • databases used in the work environment being tampered with, rendered unusable, or destroyed without authorization
  • violation of physical security measures aimed at protecting archives containing confidential information
  • compromise of security regarding university service access credentials, through phishing or awareness by third parties

When such a breach may result in a risk to the rights and freedoms of individuals, the Data Controller (the University) is required to notify the breach to the Data Protection Authority within no more than 72 hours from becoming aware of it. The University is also required to inform the data subject under the terms set out in Article 34 of Regulation (EU) 679/2016.

Back to top