Search the site

Privacy and Personal Data Protection

The University for Foreigners of Perugia recognises the importance of personal data protection and, in its capacity as data controller, is committed to processing such data appropriately and transparently with regard to the data subject, namely the person to whom the personal data relates.

Privacy notices are one of the instruments of this transparency, as they provide a comprehensive overview of data processing activities, their purposes, and the methods by which they are carried out. Whenever new services or purposes are introduced, these notices are updated; therefore, we invite you to regularly consult the information published in this section.

It is important to note that the University for Foreigners of Perugia, hereinafter referred to as the “University”, was established by Royal Decree-Law of 29 October 1925, No. 1965, and is a public institution of higher education with special status pursuant to Law of 17 February 1992, No. 204. The University promotes and organises educational and scientific research activities aimed at the knowledge and dissemination of the Italian language, culture and civilisation, intercultural dialogue, communication and international cooperation, in close collaboration with its local area and its representative institutions, as well as with national and international institutions pursuing similar objectives (Art. 1 of the Statute). The University is classified as part of the Public Administration for the purposes of its statutory functions (Art. 1, paragraph 2, of Legislative Decree 30 March 2001, No. 165).

For these reasons, the processing activities carried out may, pursuant to Article 6, paragraph 1 of the General Data Protection Regulation “EU Regulation 679/2016” or GDPR, be:

  • processing necessary for the performance of a contract to which the data subject is party, or for the implementation of pre-contractual measures taken at the data subject’s request (point b)
  • processing required for compliance with legal obligations (point c)
  • processing necessary for reasons of public interest (point e)
  • processing necessary for the legitimate interests pursued by the University, provided these do not override the interests, rights and fundamental freedoms of the data subject, especially if the data subject is a minor (point f)

If data processing does not fall under these legal bases, including those provided by University regulations or Calls for Applications, data may only be processed with the explicit consent of the data subject (Art. 6, para. 1.a). In exceptional circumstances, such as specific emergencies, the University may process personal data that has been obtained, in order to safeguard the vital interests of the data subject or another natural person (Art. 6, para. 1.d).

Use of Artificial Intelligence Systems

As part of certain institutional, administrative, educational, and informational services, the University employs artificial intelligence systems.

The use of these technologies complies with data protection regulations and follows principles of transparency, security, data minimisation, and human oversight.

For information on the main systems used by the University, their purposes, and the safeguards in place, please refer to the section Artificial Intelligence at the University for Foreigners of Perugia.

Main Processing Activities Carried Out by the Università per Stranieri di Perugia

  • Processing for university guidance purposes (also addressed to minors)
  • Processing for the administration of entrance tests or verification of admission requirements
  • Processing for the provision of the educational pathway and career management (from enrolment to graduation, including teaching delivery, administrative procedures, management of fees and refunds)
  • Processing for the dissemination of the final thesis or related materials
  • Processing for the provision of student services and benefits for the right to education
  • Processing for curricular and extracurricular internship activities
  • Processing for research activities in which the individual is involved
  • Processing for job placement activities
  • Processing for statistical surveys and evaluation of teaching activities
  • Processing for tutoring, support, and social inclusion services
  • Processing for fundraising activities, institutional communication and information, and community development
  • Processing for the management of voting rights and representation in the University’s governing bodies
  • Processing for safety on University premises and insurance coverage
  • Cross-cutting processing or processing connected to cross-cutting activities (listed below)

  • Processing for the conduct of competitive examinations/selection procedures
  • Processing for employment management purposes
  • Processing of personal data for training and professional development
  • Processing of personal data for the management of educational provision and allocation of roles
  • Processing of personal data required for research project management
  • Processing of personal data to enable the monitoring and evaluation of research
  • Processing of personal data within technology transfer activities
  • Processing necessary for welfare policies and access to benefits
  • Processing for health and safety at the workplace
  • Processing of personal data in the provision of landline and mobile telephony services
  • Processing of data for staff appraisal
  • Processing of data related to disciplinary proceedings
  • Cross-functional processing or processing linked to cross-functional activities (detailed below)

  • Data processing in the management of spaces, including through video surveillance systems
  • Processing of personal data for the management of workstations, access to and use of University services, including online services
  • Processing for the management of governing bodies and institutional offices
  • Processing for the management of accidents
  • Processing for the use of library services
  • Data processing within protocol and document archiving services
  • Processing for the procurement of goods and services, contract stipulation, debt collection, and management of disputes
  • Data processing within email services and collaboration tools
  • Processing of personal data within the context of federated service provision

Further information

The data collected will be retained for the period necessary to achieve the purposes for which they were collected and as established by current legislation or the University’s regulations.

In particular, please note that personal data related to academic records will be stored indefinitely, in accordance with record-keeping and archiving obligations set out by current legislation.

The regulation recognises a number of rights for the individual to whom the data refer:

  • right to access personal data
  • right to rectification
  • in cases provided for by law and in the absence of overriding legitimate interests of the University, the right to erasure (so-called right to be forgotten)
  • in cases provided for by law, the right to restriction of processing
  • in cases provided for by law and where processing is based on consent, the right to data portability
  • in cases provided for by law and where processing is based on consent, the right to object to processing activities
  • in the case of processing based on consent, the possibility to withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal

To exercise these rights, you may submit a request to the Data Controller at rettore@unistrapg.it or, via certified email (PEC), protocollo@pec.unistrapg.it, and to the Data Protection Officer at rpd@unistrapg.it, or also to protocollo@pec.unistrapg.it using the dedicated form.

If you believe that processing is not compliant with the regulations, you may contact the Data Protection Officer at rpd@unistrapg.it and/or lodge a complaint with the competent supervisory authority, which in Italy is the Garante per la protezione dei dati personali. Alternatively, you may submit a complaint to the Data Protection Authority of the EU Member State in which you reside or work, or where the alleged infringement occurred.

In the case of minors, before providing data to the University, it is necessary for the information notices to be read carefully together with the parents or legal guardians. Parents or other legal representatives of minor users may exercise their rights as outlined in the previous section.

The information notice, issued in accordance with Article 13 of Regulation (EU) 679/2016, contains a wide range of details, as summarised below:

  1. The contact details of the Data Controller and the Data Protection Officer, for the University of Perugia, are as follows:
    1. The Data Controller is the Università per Stranieri di Perugia, represented by the Rector as the legal representative
    2. The Controller’s contact details are: rettore@unistrapg.it or, via PEC, protocollo@pec.unistrapg.it
    3. The Data Protection Officer’s contact details are: rpd@unistrapg.it, tel. 075 57 46 1
  2. The purposes and legal bases for processing personal data and whether a legitimate interest of the Controller exists
  3. The nature (personal/sensitive) and type of data processed (personal details, contact information, etc.)
  4. Whether the provision of data is mandatory and the consequences of failure to provide data
  5. If consent is required for processing special categories of data, the existence of the right to withdraw consent and the procedures and conditions for exercising this right
  6. The processing methods, including whether profiling is carried out (fully automated decision-making based on certain data of the data subject), and information on data retention periods or retention policies applied
  7. Whether data may be shared with other public administrations or external companies, transferred outside the European Union, and the safeguards put in place by the Controller
  8. The rights that may be exercised (as detailed above), the procedures and contact points for submitting requests, and the right to lodge a complaint with the supervisory authority

In certain cases, processing involves obligations to transmit or share personal data with other Public Authorities, while some processing is carried out with the support of specialised companies that act as external data processors; these processing arrangements are also specified in the information notices.

Given the level of detail, reviewing the information notice may require time, so in some cases a simplified notice is provided, with a link to the full version for those wishing to learn more.

Updated Information Notices

(being published)

Personal data may be processed by the University’s Technical and Administrative Staff, academic staff, or by collaborators of the Controller, who—acting under the direct authority of the Controller—are authorised to process data or appointed as external processors. These individuals receive appropriate training and operational instructions in relation to the various activities involved in the relevant processing.

Personal data may also be disclosed to other public authorities if required by them for procedures within their institutional competence. In certain cases, the University engages external companies for the provision and management of specific services. These companies may access personal data solely for the purpose of providing the requested service and, as such, will be designated as external data processors, contractually bound to the Controller to ensure personal data is processed in accordance with the provisions of the GDPR.

Personal data may also be communicated to public authorities or private entities where educational, research, or internship activities related to the chosen study path or employment may take place, as well as to judicial authorities upon request.

Personal data collected for research and teaching purposes may be transferred abroad to other universities or research institutions, or within the framework of international mobility projects. The guarantees provided by the Controller will comply with Chapter V of the GDPR, the provisions of the Ministry of Universities and Research, or relevant sector regulations.

Links to documents that may be of interest for further information on the processing of personal data are provided below:

Any breach of IT system security or personal data processing that accidentally or unlawfully results in access to, destruction, loss, alteration, or unauthorised disclosure of personal data stored, transmitted, or otherwise processed by the University must be considered a personal data breach.

In the event of a suspected and/or confirmed personal data breach, it is of utmost importance that it is addressed immediately and appropriately, in order to minimise the consequences of the breach and to prevent its recurrence. For example, if it concerns unauthorised access to email or restricted areas, one of the immediate actions to take is to change the access password for the relevant services.

If a breach has occurred or you are aware of a suspected personal data breach, a form must be completed and sent to databreach@unistrapg.it as quickly as possible, taking into account the following two scenarios:

Use of the form is mandatory in order to ensure that the University immediately has the necessary information to adequately assess the resulting risk situation.

Breaches may occur for a wide range of reasons, including:

  • loss or theft of data or devices (laptops, smartphones, USB drives, etc.) on which they are stored or made accessible
  • viruses, malware or other attacks on your work computer, on the University’s IT system, or network
  • disclosure of confidential data to unauthorised parties (for example, included in attachments forwarded via email to the wrong recipient, or accessed due to violation of the mailbox containing them)
  • loss or theft of paper documents containing confidential personal data
  • unauthorised access to or misuse of IT systems, hacking
  • workplace databases being altered, rendered unusable, or destroyed without authorisation
  • violation of physical security measures designed to protect archives containing confidential information
  • loss of security of University service access credentials due to phishing or third-party knowledge

When such a breach may pose a risk to the rights and freedoms of natural persons, the University as the Data Controller is required to notify the breach to the Supervisory Authority within no more than 72 hours from when it became aware of it. The University is also obliged to communicate the breach to the data subject, as specified in Article 34 of Regulation (EU) 679/2016.

Back to top