The University for Foreigners of Perugia recognises the importance of personal data protection and, as data controller, is committed to processing such data appropriately and transparently in relation to the data subject, i.e., the individual to whom the personal data refer.
Privacy notices are among the tools we use to ensure transparency, as they provide a comprehensive overview of data processing activities, their purposes, and the methods by which they are conducted. These notices are updated whenever new services or purposes are introduced, so we encourage you to review the notices published in this section regularly.
It is important to note that the University for Foreigners of Perugia, hereafter referred to as the “University,” established by Royal Decree-Law of 29 October 1925, no. 1965, is a public institution of higher learning with special status pursuant to Law of 17 February 1992, no. 204. It promotes and organises educational and scientific research activities aimed at advancing and disseminating knowledge of the Italian language, culture, and civilisation, fostering intercultural dialogue, communication, and international cooperation, in collaboration with local, national, and international institutions with similar aims (Art. 1 of the Statute). In carrying out its functions, the University is regarded as equivalent to public administrations (Art. 1, paragraph 2, of Legislative Decree 30 March 2001, no. 165).
For these reasons, data processing carried out by the University may be, in accordance with Article 6, paragraph 1 of the General Data Protection Regulation (“EU Regulation 679/2016” or GDPR):
- processing necessary for the performance of a contract to which the data subject is party, or to take steps at the request of the data subject prior to entering into a contract (letter b)
- processing necessary for compliance with a legal obligation (letter c)
- processing necessary for the performance of a task carried out in the public interest (letter e)
- processing based on the University’s legitimate interests, provided these do not override the interests, rights, and fundamental freedoms of the data subject, especially if a minor (letter f)
If data processing does not fall within these legal bases—including those established by University regulations or calls for applications—such processing may only take place with the data subject’s consent (Art. 6, para. 1.a). Exceptionally, in cases of specific emergencies, the University may process personal data acquired in any manner if necessary to protect the vital interests of the data subject or another natural person (Art. 6, para. 1.d).
Use of Artificial Intelligence Systems
As part of certain institutional, administrative, educational, and informational services, the University utilizes artificial intelligence systems.
The use of these technologies complies with data protection regulations and is guided by principles of transparency, security, data minimization, and human oversight.
For information on the main systems used by the University, their purposes, and the measures implemented, please refer to the section Artificial Intelligence at the University for Foreigners of Perugia.
Main data processing activities carried out by the University for Foreigners of Perugia
- Processing for university guidance purposes (including for minors)
- Processing for the administration of entrance tests or verification of admission requirements
- Processing for the provision of educational programmes and management of academic careers (from enrolment to graduation, including academic activities, administrative procedures, management of tuition fees and refunds)
- Processing for the dissemination of the final thesis or related elements
- Processing for the provision of student support services and benefits
- Processing for curricular and extracurricular internship activities
- Processing for research activities in which the data subject is involved
- Processing for job placement activities
- Processing for statistical surveys and evaluation of teaching
- Processing for tutoring, student support, and social inclusion services
- Processing for fundraising activities, institutional communication and information, and community development
- Processing for the management of active and passive electoral rights for representation in university bodies
- Processing for safety within university premises and insurance coverage
- Cross-cutting processing or processing linked to crosscutting activities (listed below)
- Processing for the purpose of conducting competitive examinations/selections
- Processing for the management of employment relationships
- Processing of personal data for training and professional development purposes
- Processing of personal data for the management of the educational offer and assignment coverage
- Processing of personal data necessary for the management of research projects
- Processing of personal data to ensure research monitoring and evaluation
- Processing of personal data within the scope of technology transfer activities
- Processing necessary for welfare policies and the provision of benefits
- Processing for health and safety in the workplace
- Processing of personal data related to the provision of fixed and mobile telephony services
- Processing of data for staff evaluation
- Processing of data related to disciplinary proceedings
- Cross-cutting or related processing activities (listed below)
- Data processing in the management of spaces, including by means of video surveillance systems
- Processing of personal data for the management of workstations, access, and use of university services, including online services
- Data processing for the management of governing bodies and institutional positions
- Data processing for the management of accidents
- Data processing for the use of library services
- Data processing within the protocol services and document preservation
- Processing of data for the procurement of goods and services, contract execution, debt collection, and dispute management
- Data processing within email services and collaboration tools
- Processing of personal data in the context of federated service delivery
During the provision of IT services to University users, secondary personal information is collected and processed. This information can be linked to personal data but is not collected directly from the individual; rather, it is gathered to enable IT processes (e.g., the user ID or the IP address of the device used to access the service).
A specific privacy notice has been prepared for the processing of data of those who browse the University web portal. This notice is provided in the section below.
Further information
The data collected will be retained for the period necessary to achieve the purposes for which they were collected, as established by current legislation or University regulations.
In particular, please note that personal data related to academic records will be retained indefinitely, in compliance with legal obligations regarding record-keeping and archiving as required by current regulations.
The regulation grants numerous rights to the individual to whom the data refers:
- right of access to personal data
- right to rectification
- in cases provided for by law and in the absence of overriding legitimate interests of the University, the right to erasure of data (so-called right to be forgotten)
- in cases provided for by law, the right to restriction of processing
- in cases provided for by law and if processing is based on consent, the right to data portability
- in cases provided for by law and if processing is based on consent, the right to object to processing activities
- in the case of processing based on consent, the possibility to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal
To exercise these rights, you may submit a request to the Data Controller at rettore@unistrapg.it, or via PEC at protocollo@pec.unistrapg.it, and to the Data Protection Officer at rpd@unistrapg.it, or again to protocollo@pec.unistrapg.it using the specific form.
If you believe that the processing does not comply with the applicable regulations, you may contact the Data Protection Officer at rpd@unistrapg.it and/or file a complaint with the competent supervisory authority, which for Italy is the Italian Data Protection Authority. Alternatively, you may file a complaint with the Supervisory Authority in the EU Member State where you reside or habitually work, or where the alleged violation occurred.
In the case of minors, before sharing data with the University, the privacy notices must be carefully read together with parents or legal guardians. Parents or legal representatives of underage users may exercise rights as indicated in the previous section.
The privacy notice, prepared in accordance with Art. 13 EU Regulation 679/2016, contains extensive information as outlined below:
- The data and contact details of the Data Controller and the Data Protection Officer, which for the University for Foreigners of Perugia are as follows:
- the Data Controller is the Università per Stranieri di Perugia, represented by the Rector as legal representative
- the Data Controller’s contact: rettore@unistrapg.it or, via PEC, protocollo@pec.unistrapg.it
- the Data Protection Officer’s contact: rpd@unistrapg.it, tel. 075 57 46 1
- the purposes and legal basis of the processing of personal data, and whether there is a legitimate interest on the part of the Controller
- the nature (personal/sensitive) and type of data processed (personal details, contact data, etc.)
- whether providing data is mandatory and the consequences of not providing data
- if consent has been requested for the processing of particular data, the existence of the right to withdraw consent and how and under what conditions this right can be exercised
- the methods by which processing will be carried out, whether it involves profiling (fully automated decision-making processes based on the data subject’s data), the data retention period or retention criteria applied
- whether data may be processed by other public administrations or external companies, transferred outside the European Union, and which safeguards have been implemented by the Controller
- the rights that can be exercised (as detailed above), how and where to submit requests, and the right to lodge a complaint with the supervisory authority
In certain cases, processing entails specific obligations to transmit or share personal data with other Public Administrations, while some processing is carried out with the support of specialized companies that serve as external data processors: these processing methods are also specified in the privacy notices.
Given the comprehensive nature of the privacy notice, reading it may take some time; therefore, in some cases, a simplified notice is provided, referring to the extended version for those interested in further details.
Updated Privacy Notices
(currently being published)
- Privacy notice for candidates admitted to the qualifying test, held online, for the formation of a ranking list of external experts for the correction of DILS-PG scripts
- Privacy notice for members of the DILS-PG exam committee for online sessions
- Privacy notice for the processing of personal data during the epidemiological emergency period related to Covid-19
- Privacy notice for additional processing of personal data for the resumption of in-person teaching activities – phase 3
- Privacy notice regarding processing related to the conclusion of procurement contracts
- Privacy notice regarding processing related to the conclusion of freelance contracts
- Privacy notice for the processing of personal data of candidates in competitions for research fellowships
- Privacy notice for the processing of personal data of participants in the "Treno della memoria" initiative
- Privacy notice for the processing of personal data of teaching and research staff
- Privacy notice for the processing of personal data of technical-administrative staff and CEL with a permanent employment contract
- Privacy notice for the processing of personal data for the verification of compliance with the vaccination obligation for teaching and research staff and technical-administrative staff
- Privacy notice for the processing of personal data during audio recordings of sessions of the Academic Senate and the Board of Directors of the University for Foreigners of Perugia
- Privacy notice for enrolled and graduated students as well as users intending to register for degree courses at the University for Foreigners of Perugia
- Privacy notice for video surveillance systems installed at the facilities of the University for Foreigners of Perugia
- Privacy notice for the processing of personal data related to the production of video, photographic, multimedia, journalistic, promotional, and informational materials
- Privacy notice on the processing of non-primary information in the context of IT services, in accordance with the General Data Protection Regulation
- Privacy notice on the processing of personal data of students with disabilities or Specific Learning Disorders (SLD) who intend to access tutoring, assistance, and social inclusion services
- Privacy notice on the processing of personal data for enrolled and graduated students of the University for Foreigners of Perugia who participate in the Erasmus+ mobility programme
- Privacy notice on the processing of personal data for enrolment in courses and exams of the CVCL
- Privacy notice on the processing of data collected during initiatives promoted by the University for Foreigners of Perugia
- Privacy notice for students participating in the public selection for “150 hours” student work positions
- Privacy notice for candidates in teaching and research staff recruitment procedures
- Privacy notice for candidates in remote DILS-PG exams
- Privacy notice on the processing of data provided through the online form for information on courses requested by the University
- Privacy notice on the processing of personal data of institutional users of the University Library and Documentation System (SBDA)
- Privacy notice on the processing of personal data of candidates for competitions and selections for technical-administrative staff and language experts/collaborators
- Privacy notice on the processing of personal data of members of committees for competitions or selections relating to technical-administrative staff and CEL
- Privacy notice on the processing of personal data of individuals reporting violations pursuant to Legislative Decree 24/2023 (Art. 13, EU Regulation 2016/679 - GDPR)
- Privacy notice on the processing of personal data for access to a postgraduate course at the University for Foreigners of Perugia
- Privacy notice on the processing of data provided through online registration forms for University events
- Privacy notice for users of the University’s web portal
Personal data may be processed by technical-administrative staff, academic staff, or collaborators of the Data Controller who, operating under the direct authority of the Controller, are authorized to process such data or are appointed as external data processors. These individuals receive appropriate training and operational instructions according to the specific activities related to the data processing for which they are responsible.
Personal data may also be shared with other public administrations, should they need to process the data as part of their own institutional procedures. In some cases, the University uses external companies to provide and manage certain services. Such companies may have access to personal data solely for the purpose of carrying out the requested services and will therefore be designated as external data processors, contractually bound to the Data Controller to ensure that personal data is processed in accordance with GDPR requirements.
Personal data may also be communicated to public authorities or private entities where teaching activities, research, or internships related to the chosen study program or employment may take place, as well as to judicial authorities upon request.
For research and educational purposes, personal data may be transferred abroad to other universities or research institutions, or in the context of international mobility projects. The safeguards provided by the Data Controller will comply with Chapter V of the GDPR, relevant provisions established by the Ministry of Universities and Research, and applicable sector regulations.
Below are links to documents that may be of interest for further information on personal data processing:
A personal data breach must be considered any security incident affecting IT systems or personal data processing that results, accidentally or unlawfully, in access, destruction, loss, alteration, or unauthorized disclosure of personal data stored, transmitted, or otherwise processed by the University.
In the event of a suspected and/or confirmed personal data breach, it is vital to ensure that the breach is addressed immediately and appropriately, in order to minimize its consequences and prevent its recurrence. For example, in cases where unauthorized access to email accounts or restricted areas may be involved, one of the immediate measures to take is to change the access password for such services.
If a personal data breach has occurred or if you are aware of a suspected breach, you must complete a form and submit it to databreach@unistrapg.it as soon as possible, considering the two different scenarios:
- notification of breach of service access credentials
to be used if the breach involves the disclosure or misuse of University service access credentials by third parties - notification of personal data breach
for reporting any breach not included in the previous scenario
The use of the form is mandatory in order to provide the University with key information needed to properly assess the resulting risk situation.
Breaches may occur for a wide range of reasons, including:
- loss or theft of data or devices (laptops, smartphones, USB sticks, etc.) on which data is stored or accessible
- virus, malware, or other attacks on your work computer, IT system, or the University network
- disclosure of confidential data to unauthorized persons (for example, data included in attachments forwarded by email to the wrong recipient, or accessed following an email account breach)
- loss or theft of paper documents containing confidential personal data
- unauthorized or otherwise unlawful access to IT systems, hacking
- work-related databases being altered, rendered unusable, or destroyed without authorization
- breach of physical security measures protecting archives containing confidential information
- compromise of University service access credentials, due to phishing or exposure to third parties
When such a breach may pose a risk to the rights and freedoms of natural persons, the Data Controller (the University) is required to notify the Data Protection Authority within no more than 72 hours from when it becomes aware of the incident. The University is also required to inform the data subject of the breach, in accordance with the terms set out in Article 34 of Regulation (EU) 679/2016.