1) Brief presentation of Studentweb
Studentweb is a web application that allows students to perform a number of study administration tasks, such as semester registration and registration for lectures and examinations. Studentweb also gives you access to the data Norwegian School of Sport Sciences has stored about you in the study administration system Common Student System (FS), such as contact information, examination results and data forwarded to the Norwegian State Educational Loan Fund.
3) What is considered personal data?
The term personal data includes any data, information and assessment that can be linked to you as an individual, cf. GDPR Article 4 no. 1. The determining factor in whether data is considered personal information, is whether it is fit to identify a specific person.
In some cases, data which, on its own, cannot be linked to an individual person, may constitute personal data if it is used in combination with other data.
4) The purpose of and legal basis for the processing of personal data in Studentweb
The purpose of the processing of personal data in Studentweb is to enable you to administer your studies at Norwegian School of Sport Sciences.
Data processing is authorized under the provisions of the Act Relating to Universities and University Colleges. Data processing is also necessary for Norwegian School of Sport Sciences to be able to perform its contract with you as a student. Certain types of processing, e.g. approving registrations for lectures and examinations, are necessary in the exercise of official authority.
5) Which kinds of personal data are processed in Studentweb, and how long to we store your personal data?
Currently, no sensitive personal data about you is stored or processed in Studentweb.
The following personal data may be processed in Studentweb: profile information (including your name, national identity number/D-number/S-number (11 digits)), sex, contact information, information about your background, native language, photograph, application information, consents you have given, criminal records certificate where relevant, semester registration data, billing information and information about programmes and courses of study.
We store information about your actions in Studentweb, as well as your IP address. We do this in order to be able to document the data you register. This type of personal data is stored in FS and erased after a period of 12 months.
Your personal data may come from:
- You, submitted via Studentweb
- Administrative officers at Norwegian School of Sport Sciences
- You, submitted via Studentweb
Registration of personal data in Studentweb is voluntary, but without your personal data, we may not be able to process your applications. In Studentweb you can register information about yourself and link it to your application to a programme of study (information about your background, enrolment in classes and registration for exams, applications for recognition, etc.) and any documents you upload. This information may be necessary for us to process your applications and for you to study at Norwegian School of Sport Sciences.
Information registered without your express consent
- Administrative officers at Norwegian School of Sport Sciences
In certain circumstances, it is necessary for administrative staff at Norwegian School of Sport Sciences to register information about you in connection with your studies. Examples of this includes assessments linked to applications for admission, explanations for grades and appeals against grading, registrations linked to study completion. These types of data are only sent to Studentweb so that you can have access to your data.
6) In some cases, we process cases automatically
When use Studentweb at Norwegian School of Sport Sciences, a number of processes related to your studies will be performed automatically, either entirely or in part. Automatic processing is used in the following circumstances:
- calculation of eligibility for courses
- registration for lectures and examinations
- creation of invoices
- explanation of grades/complaints against grading in connection with examinations
- various applications for recognition/approval
7) We disclose your personal data to third parties
Disclosure or export of data is defined as any transfer of data save for use in the controller’s own systems/processing or to the data subject itself or any other party receiving data on the data subject’s behalf.
Norwegian School of Sport Sciences may disclose or export data including personal data to other systems, i.e. external data processors, whenever it is deemed necessary.
Your personal data will not be disclosed to countries outside of the EU/EEA, or to any international organizations.
Your personal data may be disclosed to the following parties/agencies:
1) Unit – The Norwegian Directorate for ICT and Joint Services in Higher Education and Research
Studentweb is developed by Unit. Unit staff who need to access your personal data as part of their job will be granted such access. They need this access in order to provide user support and, if relevant, correct errors as part of their duties.
2) University Center for Information Technology (USIT) at the University of Oslo (UiO)
Studentweb is operated by USIT at UiO. USIT staff who need to access your personal data as part of their job will be granted such access.
3) UNINETT AS
It is possible to log in to Studentweb using the log-in solution FEIDE. FEIDE is developed and provided by UNINETT AS. UNINETT AS staff may access your FEIDE user name and IP address, provided they need such access in order to perform their duties. They need this access in order to provide user support and, if relevant, correct errors as part of their duties. Your personal data will be erased from FEIDE after six months.
4) Agency for Public Management and eGovernment (Difi)
It is possible to log in to Studentweb using the log-in services MinID, BankID, Buypass and Commfides through ID-porten. The Agency for Public Management and eGovernment (Difi) is the data controller for any and all personal data processed in ID-porten, as well as for personal data used in the administration of MinID.
If you log in through ID-porten, Difi’s user support and administrative staff may, if necessary, access your national identity number and contact information, as well as a limited log-in history.
This need arises when Difi is asked to provide user support or troubleshoot/correct errors in the service.
Providers of electronic IDs (BankID, Buypass and Commfides) are data controllers for any and all personal data required for the administration of their log-in solutions.
5) Other parties
8) Personal data safety
Norwegian School of Sport Sciences regularly perform risk and vulnerability analyses to protect your personal data in Studentweb. In addition, various security measures have been implemented, such as access control, to keep the number of people who have access to your personal data as low as possible.
9) Your rights
Right to information and access
You also have the right to view/access any and all personal data registered about you at Norwegian School of Sport Sciences. You also have the right to request a copy of the personal data registered about you if you so wish.
Right to correction
You have the right to have corrected any and all incorrect personal data about you. You also have the right to supplement any and all incomplete data registered about you. Please contact us if you believe we have registered incorrect or incomplete personal data about you. It is important that you justify and, if relevant, document why you believe the personal data registered is incorrect or incomplete.
Right to limit processing
In certain circumstances, you have the right to demand limited processing of your personal data. Limiting the processing of personal data means that your personal data will still be registered, but the opportunities for further processing are limited.
If you believe that personal data about you is incorrect or incomplete, or you have filed a complaint against the processing of your data (read more about this below), you have the right to demand to demand that the processing of your personal data be limited temporarily. This means that processing will be limited until, if relevant, we have rectified your personal data, or until we have been able to assess whether your complaint is justified.
In other circumstances you may also demand a more permanent limitation on the processing of your personal data. In order to qualify for the right to limit processing of your personal data, the conditions established by the Personal Data Act and Article 18 of the GDPR must be met. If we receive a request from you to limit processing of your personal data, we will assess whether the statutory conditions have been met.
Right to erasure
In certain circumstances you have the right to demand that we erase your personal data. The right to erasure is not unconditional, and whether this applies to your situation must be assessed in light of relevant privacy legislation, i.e. the Personal Data Act and GDPR. Please contact us if you want to have your personal data erased. It is important that you justify why you want the personal data erased, and, if possible, that you also specify which personal data you want erased. We will den consider whether the conditions for erasure, as established by law, have been met. Please be advised that the law allows for us to make exceptions to your right to erasure. For example, we may need to store personal data for the purpose of performing a task in compliance of the Act Relating to Universities and University Colleges, or for reasons of public interest, such as archiving, research and statistics.
Right to object
You may have the right to file an objection against the processing, i.e. object to the processing, on grounds that you have a specific need to stop the processing, e.g. if you have a need for protection, have a secret address, etc. The right to object is not unconditional, and it is contingent upon the legal basis for the processing, and on your particular circumstances. The conditions are established by Article 21 of the GDPR. If you object to processing of your personal data, we will consider whether the conditions for filing an objection have been met. If we find that you have the right to object to the processing and that your objection is justified, we will discontinue processing, and you will have the right to demand erasure of the data. Please be advised that we, under certain circumstances, may make exceptions from erasure, e.g. if we have to store your personal data for the purpose of performing a task in compliance with the Act Relating to Universities and University Colleges, or for reasons of public interest.
Right to file complaint against processing
If you believe we processed your personal data incorrectly or unlawfully, or if you believe we failed to protect your rights, you have the right to file a complaint against processing. Please see item 10 below for how to contact us.
If we dismiss your complaint, you may file your complaint with the Norwegian Data Protection Authority (DPA). The DPA is responsible for making sure Norwegian enterprises comply with the provisions of the Personal Data Act and the GDPR in their processing of personal data.
10) Contact information
Norwegian School of Sport Sciences is the data controller of personal data in Studentweb, cf. GDPR Article 4 no. 7.
If you wish to exercise your rights as established in item 9 above, please contact us at email@example.com. We will process your request as soon as possible and within 30 days at the latest.
Data protection office
Norwegian School of Sport Sciences has appointed a data protection officer whose responsibility it is to protect the personal data interests of both students and staff at Norwegian School of Sport Sciences. You may contact the data protection officer about the administrative processing of personal data at Norwegian School of Sport Sciences via e-mail: firstname.lastname@example.org .
Unit – The Norwegian Directorate for ICT and Joint Services in Higher Education and Research is the provider of Studentweb. This means that Unit develops and maintains Studentweb, and Unit is also responsible for the day-to-day operation of Studentweb. As part of this task, a select few of Unit’s staff have access to all personal data registered in Studentweb.
Contact information for Unit: email@example.com