Services

Art. 13 of EU Regulation 2016/679 - General Data Protection Regulation

This privacy notice is provided pursuant to Articles 13 and 14 of EU Regulation 2016/679 (General Data Protection Regulation, hereinafter EU Regulation), in relation to the personal data that the University of Padua, acting as Data Controller, acquires for the conclusion and performance of contracts and agreements between the University of Padua and third parties and for the conduct of any tender procedures, starting from the authorisation and registration of companies on the University Electronic Marketplace (hereinafter Me.Unipd) and on the University procurement portal, including the activities of preserving administrative and technical documentation and the related further obligations.

The processing of personal data is based on the principles of fairness, lawfulness, transparency, and protection of confidentiality and of all the rights of data subjects, as specified in the following information.

The Data Controller is the University of Padua (hereinafter the University), with registered office at Via VIII Febbraio n. 2, 35122 - Padua
(certified email: amministrazione.centrale@pec.unipd.it).

At the University, there is a Data Protection Officer, appointed pursuant to Art. 37 of the EU Regulation. The Data Protection Officer may be contacted at privacy@unipd.it.

The personal data that may be processed by the data controller for the purposes indicated in point 4 are specified below.

  1. Personal data provided directly by the data subject, relating to the data subject and to its employees and collaborators (including, by way of example, legal representatives, shareholders, attorneys-in-fact, employees, delegates and related parties). Ordinary personal data, such as personal details, tax identification code (of employees or clients), identity document details (driving licence/ID card/passport no.), contact details (certified email (PEC), email, telephone contacts), credentials, personal identification code (Customer ID), economic/financial and tax data, bank details, credit card details and transactions.
  2. Personal data, including special categories of personal data and judicial data, obtained from public administrations and judicial authorities. Judicial data contained in the criminal records register, in the register of administrative sanctions arising from criminal offences and the related pending charges, or information concerning the status of accused person or suspect, parole, prohibition or obligation of residence, and alternatives to detention. Judicial data, namely personal data relating to criminal convictions and offences or related security measures, are processed in compliance with Article 10 of the EU Regulation and Article 2-octies of Legislative Decree No. 196 of 30 June 2003 (the so-called Privacy Code).

The data collected are processed for the conclusion and performance of contracts and agreements between the University and third parties and for the conduct of any procurement procedures, starting from the qualification and registration of companies in the University Electronic Marketplace (hereinafter Me.Unipd) and in the University procurement portal, including the activities of preserving the administrative and technical documentation and the related further fulfilments.

In particular, the data are processed for the following purposes:

  1. verification of all the general and specific requirements of the contracting party concerned, required in fulfilment of specific legal obligations and of the procurement documentation;
  2. management of participation in and use of the Electronic Marketplace by authorised interested parties and administrations. Within the scope of this purpose, for example, the data of authorised interested supplier parties, as well as commercial information relating to products and contained in the catalogues (products offered, price, and so on), are published on the Electronic Marketplace platform and made visible and accessible to Ordering Points, in the manner and within the limits necessary for the proper use of the Electronic Marketplace; suppliers’ data are acquired by the Ordering Points for the purposes of the contractor selection procedure, the subsequent conclusion and performance of the Contract, including the related legal, tax and accounting fulfilments and the relevant economic and administrative management and performance;
  3. conclusion of the contract or agreement;
  4. performance of the contract or agreement and of any amendments also subsequently concluded with the interested parties;
  5. management of judicial disputes or debt recovery procedures;
  6. any market research, economic and statistical analyses, dissemination of services, sending of information material and updates on University initiatives and programmes, for purposes related to consumption monitoring and expenditure control, as well as for the analysis of further achievable savings in expenditure, for the exercise of information activities with other Public Administrations and for the further purposes related and connected to the implementation of the public spending rationalisation programme.

Data is processed in a manner that guarantees the highest level of security and confidentiality and may be carried out using manual, IT and telematic tools suitable for storing, managing and transmitting it. Such data may also be matched with that of other subjects on the basis of qualitative, quantitative and temporal criteria identified from time to time within the activities indicated in point 4.

Personal data collected through the platforms published at https://www.unipd.it/portale-appalti is stored on the servers of the CINECA Consorzio Interuniversitario and protected by appropriate IT security measures, in accordance with the indications of the Agid Guidelines.

Automated decision-making processing of the acquired data is excluded.

The processing of personal data is carried out by the University exclusively for the purposes indicated in point 4 and on the basis of one of the following lawful grounds:

  1. performance of a contract to which the data subject is a party or of pre-contractual measures taken at the request of the same pursuant to Art. 6(1)(b) of the EU Regulation;
  2. compliance with a legal obligation to which the Data Controller is subject pursuant to Art. 6(1)(c) of the EU Regulation.

Special categories of personal data are processed for reasons of substantial public interest pursuant to Art. 9(2)(g) of the EU Regulation.

The processing is necessary for the conclusion of the contract or agreement, for the carrying out of tender procedures, as well as for compliance with specific contractual, regulatory and tax obligations incumbent upon the University. The provision of the data is therefore mandatory for the execution of the contract or agreement, for the award and for the purposes of participation in the tender procedures launched by the University and the management of all related obligations.

The data may be disclosed, exclusively for the purposes indicated in point 4, to University staff, self-employed collaborators, professionals, consultants including external consultants, the other parties involved in the contractual relationship, and to data processors and sub-processors that may be appointed for the performance of the contract.

Personal data are also disclosed to the National Anti-Corruption Authority (ANAC) pursuant to Article 213 of Legislative Decree No. 50 of 18 April 2016 (Public Contracts Code), as well as to other interested parties who request access to the documents of the procedure within the limits permitted under Law No. 241 of 7 August 1990 (New rules on administrative procedure).

Within the limits laid down by legal obligations requiring administrative transparency, personal data are published and disseminated through the website www.unipd.it, section “Amministrazione Trasparente”.

The University, without prejudice in all cases to compliance with the rules on the proper processing of data, may transfer data to third countries outside the European Union only where necessary for purposes related to the institution’s institutional functions (for example, reporting activities for international projects).

Personal data are retained for the entire period necessary to carry out the purposes set out in point 4. The retention period, therefore, is directly related to the duration of the procedures and the fulfilment of all legal obligations, including subsequent ones, as well as to the performance of the contract or agreement. Following the termination of the contractual effects and the conclusion of the procedure, the data will be retained in accordance with the rules on the retention of administrative documentation.

Personal data may be retained for a longer period if this is necessary for a legitimate purpose, such as the defence, including in court, of the rights of the University.

The data subject is entitled to the following rights:

  1. the right to access their personal data (Article 15 of the EU Regulation);
  2. the right to rectification or completion of their data (Article 16 of the EU Regulation);
  3. the right to erasure (right to be forgotten), within the limits permitted by Article 17(3) of the EU Regulation;
  4. the right to restriction of processing under the conditions set out in Article 18 of the EU Regulation;
  5. the right to data portability, as provided for in Article 20 of the EU Regulation;
  6. the right to object to processing at any time (Article 21 of the EU Regulation);
  7. the right to lodge a complaint with the Italian Data Protection Authority.

To exercise their rights, the data subject may contact the University by writing to the certified email address amministrazione.centrale@pec.unipd.it or to the email address urp@unipd.it. Alternatively, the data subject may write to: University degli Studi di Padua, via VIII febbraio n. 2, Padua.

The University is required to provide a response within one month of the request, which may be extended up to three months in the event of particular complexity of the request.

Any amendments and additions to this notice are published in the privacy section of the institutional website at www.unipd.it/privacy.

Last updated: 20 May 2020

Privacy data protection

Data Protection Officer  DPO:  Giorgio Valandro

email: privacy@unipd.it