Search the site

Privacy and Personal Data Protection

The University for Foreigners of Perugia recognises the importance of personal data protection and, as data controller, is committed to processing such data appropriately and transparently in relation to the data subject, i.e., the individual to whom the personal data refer.

Privacy notices are among the tools we use to ensure transparency, as they provide a comprehensive overview of data processing activities, their purposes, and the methods by which they are conducted. These notices are updated whenever new services or purposes are introduced, so we encourage you to review the notices published in this section regularly.

It is important to note that the University for Foreigners of Perugia, hereafter referred to as the “University,” established by Royal Decree-Law of 29 October 1925, no. 1965, is a public institution of higher learning with special status pursuant to Law of 17 February 1992, no. 204. It promotes and organises educational and scientific research activities aimed at advancing and disseminating knowledge of the Italian language, culture, and civilisation, fostering intercultural dialogue, communication, and international cooperation, in collaboration with local, national, and international institutions with similar aims (Art. 1 of the Statute). In carrying out its functions, the University is regarded as equivalent to public administrations (Art. 1, paragraph 2, of Legislative Decree 30 March 2001, no. 165).

For these reasons, data processing carried out by the University may be, in accordance with Article 6, paragraph 1 of the General Data Protection Regulation (“EU Regulation 679/2016” or GDPR):

  • processing necessary for the performance of a contract to which the data subject is party, or to take steps at the request of the data subject prior to entering into a contract (letter b)
  • processing necessary for compliance with a legal obligation (letter c)
  • processing necessary for the performance of a task carried out in the public interest (letter e)
  • processing based on the University’s legitimate interests, provided these do not override the interests, rights, and fundamental freedoms of the data subject, especially if a minor (letter f)

If data processing does not fall within these legal bases—including those established by University regulations or calls for applications—such processing may only take place with the data subject’s consent (Art. 6, para. 1.a). Exceptionally, in cases of specific emergencies, the University may process personal data acquired in any manner if necessary to protect the vital interests of the data subject or another natural person (Art. 6, para. 1.d).

Use of Artificial Intelligence Systems

As part of certain institutional, administrative, educational, and informational services, the University utilizes artificial intelligence systems.

The use of these technologies complies with data protection regulations and is guided by principles of transparency, security, data minimization, and human oversight.

For information on the main systems used by the University, their purposes, and the measures implemented, please refer to the section Artificial Intelligence at the University for Foreigners of Perugia.

Main data processing activities carried out by the University for Foreigners of Perugia

  • Processing for university guidance purposes (including for minors)
  • Processing for the administration of entrance tests or verification of admission requirements
  • Processing for the provision of educational programmes and management of academic careers (from enrolment to graduation, including academic activities, administrative procedures, management of tuition fees and refunds)
  • Processing for the dissemination of the final thesis or related elements
  • Processing for the provision of student support services and benefits
  • Processing for curricular and extracurricular internship activities
  • Processing for research activities in which the data subject is involved
  • Processing for job placement activities
  • Processing for statistical surveys and evaluation of teaching
  • Processing for tutoring, student support, and social inclusion services
  • Processing for fundraising activities, institutional communication and information, and community development
  • Processing for the management of active and passive electoral rights for representation in university bodies
  • Processing for safety within university premises and insurance coverage
  • Cross-cutting processing or processing linked to crosscutting activities (listed below)

  • Processing for the purpose of conducting competitive examinations/selections
  • Processing for the management of employment relationships
  • Processing of personal data for training and professional development purposes
  • Processing of personal data for the management of the educational offer and assignment coverage
  • Processing of personal data necessary for the management of research projects
  • Processing of personal data to ensure research monitoring and evaluation
  • Processing of personal data within the scope of technology transfer activities
  • Processing necessary for welfare policies and the provision of benefits
  • Processing for health and safety in the workplace
  • Processing of personal data related to the provision of fixed and mobile telephony services
  • Processing of data for staff evaluation
  • Processing of data related to disciplinary proceedings
  • Cross-cutting or related processing activities (listed below)

  • Data processing in the management of spaces, including by means of video surveillance systems
  • Processing of personal data for the management of workstations, access, and use of university services, including online services
  • Data processing for the management of governing bodies and institutional positions
  • Data processing for the management of accidents
  • Data processing for the use of library services
  • Data processing within the protocol services and document preservation
  • Processing of data for the procurement of goods and services, contract execution, debt collection, and dispute management
  • Data processing within email services and collaboration tools
  • Processing of personal data in the context of federated service delivery

Further information

The data collected will be retained for the period necessary to achieve the purposes for which they were collected, as established by current legislation or University regulations.

In particular, please note that personal data related to academic records will be retained indefinitely, in compliance with legal obligations regarding record-keeping and archiving as required by current regulations.

The regulation grants numerous rights to the individual to whom the data refers:

  • right of access to personal data
  • right to rectification
  • in cases provided for by law and in the absence of overriding legitimate interests of the University, the right to erasure of data (so-called right to be forgotten)
  • in cases provided for by law, the right to restriction of processing
  • in cases provided for by law and if processing is based on consent, the right to data portability
  • in cases provided for by law and if processing is based on consent, the right to object to processing activities
  • in the case of processing based on consent, the possibility to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal

To exercise these rights, you may submit a request to the Data Controller at rettore@unistrapg.it, or via PEC at protocollo@pec.unistrapg.it, and to the Data Protection Officer at rpd@unistrapg.it, or again to protocollo@pec.unistrapg.it using the specific form.

If you believe that the processing does not comply with the applicable regulations, you may contact the Data Protection Officer at rpd@unistrapg.it and/or file a complaint with the competent supervisory authority, which for Italy is the Italian Data Protection Authority. Alternatively, you may file a complaint with the Supervisory Authority in the EU Member State where you reside or habitually work, or where the alleged violation occurred.

In the case of minors, before sharing data with the University, the privacy notices must be carefully read together with parents or legal guardians. Parents or legal representatives of underage users may exercise rights as indicated in the previous section.

The privacy notice, prepared in accordance with Art. 13 EU Regulation 679/2016, contains extensive information as outlined below:

  1. The data and contact details of the Data Controller and the Data Protection Officer, which for the University for Foreigners of Perugia are as follows:
    1. the Data Controller is the Università per Stranieri di Perugia, represented by the Rector as legal representative
    2. the Data Controller’s contact: rettore@unistrapg.it or, via PEC, protocollo@pec.unistrapg.it
    3. the Data Protection Officer’s contact: rpd@unistrapg.it, tel. 075 57 46 1
  2. the purposes and legal basis of the processing of personal data, and whether there is a legitimate interest on the part of the Controller
  3. the nature (personal/sensitive) and type of data processed (personal details, contact data, etc.)
  4. whether providing data is mandatory and the consequences of not providing data
  5. if consent has been requested for the processing of particular data, the existence of the right to withdraw consent and how and under what conditions this right can be exercised
  6. the methods by which processing will be carried out, whether it involves profiling (fully automated decision-making processes based on the data subject’s data), the data retention period or retention criteria applied
  7. whether data may be processed by other public administrations or external companies, transferred outside the European Union, and which safeguards have been implemented by the Controller
  8. the rights that can be exercised (as detailed above), how and where to submit requests, and the right to lodge a complaint with the supervisory authority

In certain cases, processing entails specific obligations to transmit or share personal data with other Public Administrations, while some processing is carried out with the support of specialized companies that serve as external data processors: these processing methods are also specified in the privacy notices.

Given the comprehensive nature of the privacy notice, reading it may take some time; therefore, in some cases, a simplified notice is provided, referring to the extended version for those interested in further details.

Updated Privacy Notices

(currently being published)

Personal data may be processed by technical-administrative staff, academic staff, or collaborators of the Data Controller who, operating under the direct authority of the Controller, are authorized to process such data or are appointed as external data processors. These individuals receive appropriate training and operational instructions according to the specific activities related to the data processing for which they are responsible.

Personal data may also be shared with other public administrations, should they need to process the data as part of their own institutional procedures. In some cases, the University uses external companies to provide and manage certain services. Such companies may have access to personal data solely for the purpose of carrying out the requested services and will therefore be designated as external data processors, contractually bound to the Data Controller to ensure that personal data is processed in accordance with GDPR requirements.

Personal data may also be communicated to public authorities or private entities where teaching activities, research, or internships related to the chosen study program or employment may take place, as well as to judicial authorities upon request.

For research and educational purposes, personal data may be transferred abroad to other universities or research institutions, or in the context of international mobility projects. The safeguards provided by the Data Controller will comply with Chapter V of the GDPR, relevant provisions established by the Ministry of Universities and Research, and applicable sector regulations.

Below are links to documents that may be of interest for further information on personal data processing:

A personal data breach must be considered any security incident affecting IT systems or personal data processing that results, accidentally or unlawfully, in access, destruction, loss, alteration, or unauthorized disclosure of personal data stored, transmitted, or otherwise processed by the University.

In the event of a suspected and/or confirmed personal data breach, it is vital to ensure that the breach is addressed immediately and appropriately, in order to minimize its consequences and prevent its recurrence. For example, in cases where unauthorized access to email accounts or restricted areas may be involved, one of the immediate measures to take is to change the access password for such services.

If a personal data breach has occurred or if you are aware of a suspected breach, you must complete a form and submit it to databreach@unistrapg.it as soon as possible, considering the two different scenarios:

The use of the form is mandatory in order to provide the University with key information needed to properly assess the resulting risk situation.

Breaches may occur for a wide range of reasons, including:

  • loss or theft of data or devices (laptops, smartphones, USB sticks, etc.) on which data is stored or accessible
  • virus, malware, or other attacks on your work computer, IT system, or the University network
  • disclosure of confidential data to unauthorized persons (for example, data included in attachments forwarded by email to the wrong recipient, or accessed following an email account breach)
  • loss or theft of paper documents containing confidential personal data
  • unauthorized or otherwise unlawful access to IT systems, hacking
  • work-related databases being altered, rendered unusable, or destroyed without authorization
  • breach of physical security measures protecting archives containing confidential information
  • compromise of University service access credentials, due to phishing or exposure to third parties

When such a breach may pose a risk to the rights and freedoms of natural persons, the Data Controller (the University) is required to notify the Data Protection Authority within no more than 72 hours from when it becomes aware of the incident. The University is also required to inform the data subject of the breach, in accordance with the terms set out in Article 34 of Regulation (EU) 679/2016.

Back to top