Services

Art. 13 of EU Regulation 2016/679 - General Data Protection Regulation

This privacy notice is provided pursuant to Art. 13 of EU Regulation 2016/679 (General Data Protection Regulation, hereinafter EU Regulation), in relation to the personal data of professors, including contract professors, researchers, technical and administrative staff, research grant holders and collaborators in any capacity (hereinafter, data subjects), which the University of Padua (hereinafter, University) comes into possession of as a result of the establishment of an employment relationship and for every related fulfilment.

The processing of personal data is based on the principles of fairness, lawfulness, transparency, and protection of confidentiality and of all the rights of the data subjects, in accordance with the information set out below.

The Data Controller is the University of Padua, with registered office at Via VIII Febbraio n. 2, 35122 - Padua (certified email: amministrazione.centrale@pec.unipd.it).

The Data Controller has appointed a Data Protection Officer pursuant to Article 37 of the EU Regulation. The Data Protection Officer can be contacted at the following email address: privacy@unipd.it.

The personal data that may be processed exclusively for the purposes indicated in point 4 are:

  1. personal details (first name, surname, date of birth, sex), contact details, residence details, data relating to qualifications held and income conditions;
  2. special categories of data, such as health data, the processing of which is carried out only if authorised by an express provision of law, for the pursuit of purposes of substantial public interest, or by the data subject’s consent given at the same time as contingent needs arise (such as, for example, a possible injury);
  3. data relating to criminal convictions and offences.

The University processes the personal data provided at the time the employment relationship is established, during its course or at the time of its termination, relating to the data subject and their family members, exclusively for the purposes of complying with the legal and contractual requirements relating to the employment relationship, including those connected with the management of tax and social security obligations.
In particular, the processing concerns the pursuit of the following purposes:

I. Management of the employment relationship and organisation

  1. management of legal career progression, internal and external mobility, assessment of the professional’s work activity, salary progression and career advancement;
  2. management of staff records and publication of contact details and further publication obligations pursuant to the law;
  3. monitoring and management of attendance, including by means of badges or other electronic methods;
  4. use of exemptions, leave, absences, career breaks, concessions and/or benefits recognised by law and collective bargaining;
  5. management of training and professional development (enrolment in training courses, any certificates of attendance for courses), including abroad;
  6. authorisation to carry out extra-institutional assignments;
  7. payroll processing and complementary and ancillary operations;
  8. verification of fitness for service for disabled persons;
  9. management of insurance and social security procedures, welfare benefits, injury reports and claims;
  10. management of measures supporting parenthood;
  11. management of activities against discrimination in the workplace and protection of gender equality and the enhancement of organisational well-being;
  12. prevention and management of cases of workplace bullying and sexual harassment;
  13. management of remote working;
  14. disciplinary proceedings and out-of-court procedures, conciliation procedures and legal proceedings before all administrative and judicial authorities relating to the data subject.

II. Teaching and research

  1. management of teaching activity registers;
  2. participation, subject to voluntary enrolment, in research projects;
  3. management of research projects and technology transfer activities;
  4. management of national and international mobility.

III. Internal organisation

  1. management of the organisational structure and human resources (organisational positions, skills profiles, corporate knowledge repository, remuneration policies);
  2. management of the University’s agreements, conventions and contracts;
  3. management of governing bodies and institutional offices;
  4. application of safety measures in the workplace in accordance with the provisions of Legislative Decree 81/2008;
  5. video surveillance in University facilities;
  6. statistical surveys and internal evaluations within the University in order to improve services;
  7. promotion of degree courses and of informational and cultural events organised or sponsored by the University or by the teaching and research facilities.

The personal data of the data subject are processed with the support of electronic and paper-based means.

The University adopts appropriate organisational and technical measures to protect the personal data in its possession, through security measures suitable to guarantee the confidentiality and security of personal data, in particular against the loss, theft, as well as the unauthorised use, disclosure or modification of personal data.

The Data Controller does not make use of automated decision-making processes, including profiling, relating to the rights of the data subject, in compliance with the safeguards provided for by Article 22 of the EU Regulation.

Any processing of special categories of personal data, referred to in point 3), letter b), will also be carried out in compliance with the “Regulations on the processing of the University’s sensitive and judicial data”, available on the General interest regulations page.

The institutional email account assigned to staff at the time the employment relationship is established is the communication tool between the worker and the University, through which all official communications and information relating to the management of the relationship and the pursuit of all the purposes referred to in point 4 will be sent.

Personal identification and common personal data (point 3, letter a) are processed pursuant to Article 6(1) of the EU Regulation on the basis of at least one of the following lawful conditions:

  1. for the performance of a contract or pre-contractual measures to which the data subject is a party;
  2. for compliance with a legal obligation;
  3. for the performance of tasks carried out in the public interest.

Special categories of personal data (for example, data relating to health, political and trade union opinions or religious beliefs, etc.) and judicial data (point 3, letters b and c) are processed on the basis of at least one of the following lawful conditions provided for by Article 9(2)(b) of the EU Regulation:

  1. to fulfil obligations in the field of employment law and social security and social protection law;
  2. for reasons of substantial public interest on the basis of European Union or national law;
  3. for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes;
  4. to establish, exercise or defend a right in legal proceedings;
  5. on the basis of the explicit consent of the data subject.

Personal data relating to criminal convictions and offences referred to in letter c) of point 3 are processed to the extent strictly necessary for carrying out the purposes indicated in the previous point 4.
The provision of personal data for processing for the purposes indicated in point 4 is mandatory, as it is necessary for the establishment and management of the employment relationship with the University and for compliance with regulatory obligations and purposes of substantial public interest

The recipients of the personal data collected are the natural persons appointed by the University to process the data for the purposes indicated in point 4, including employees and collaborators, including self-employed collaborators, of affiliated bodies.

The recipients of the data also include the Data Processors appointed by the Controller, including CINECA Consorzio Interuniversitario, as the provider of IT services, with registered office at via Magnanelli 6/3 - 40033 Casalecchio di Reno (BO).

In addition, the data provided are disclosed to the following parties:

  1. ESU Di Padova - Regional agency for the right to university education;
  2. the University of Padua's pro-tempore treasury institution
  3. INAIL, public security authorities, the One-Stop Immigration Desk and other authorities provided for by law for the reporting of accidents at work;
  4. insurance bodies for accident claims;
  5. CUN (National University Council) for the institutional functions assigned by law;
  6. INPS, for benefits connected with pension and end-of-service payments;
  7. Committee for the verification of service-related causes and the territorially competent Medical Commission (as part of the procedure for the recognition of service-related causes/fair compensation, pursuant to Presidential Decree 461/2001);
  8. the competent healthcare facilities for medical examinations;
  9. public and private bodies to which the law or the University have entrusted staff training services;
  10. private entities to which the University entrusts services falling within its remit on an outsourcing basis;
  11. Employment Centre or the territorially competent body for recruitment pursuant to Law 68/1999 and subsequent amendments;
  12. trade union organisations for the fulfilments connected with the payment of membership fees and for the management of trade union leave;
  13. Ministry of Finance, as part of the Universities' role as Tax Assistance Centres (CAF), in relation to income tax returns;
  14. public administrations to which employees are seconded, within the framework of worker mobility;
  15. Azienda Ospedaliera di Padova, Istituto Oncologico Veneto and other ULSS companies with reference to staff and collaborators carrying out activities under agreement with the SSN;
  16. public and private bodies for carrying out procedures relating to guaranteed loans through salary-backed assignment and small loans;
  17. State Legal Service, Ministry of Foreign Affairs, Police Headquarters, Embassies, Public Prosecutor's Office in relation to residence permits and the recognition of particular statuses;
  18. judicial authorities and other public authorities in the exercise of their respective inspection and investigation functions.

The data subject's personal data will not be disclosed or transferred outside the national territory, except where necessary for the management of research projects and international mobility.

The determination of the retention period for personal data complies with the principle of necessity of processing. Personal data are therefore retained for the entire period necessary to carry out the purposes indicated in point 4.

The data subject is granted the following rights:

  1. the right to access their personal data (Article 15 of the EU Regulation);
  2. the right to rectify or supplement their data (Article 16 of the EU Regulation);
  3. the right to erasure (right to be forgotten), pursuant to Article 17 of the EU Regulation;
  4. the right to restriction of processing under the conditions set out in Article 18 of the EU Regulation;
  5. the right to data portability, as provided for in Article 20 of the EU Regulation;
  6. the right to object at any time to processing (Article 21 of the EU Regulation);
  7. the right to lodge a complaint with the Garante per la protezione dei dati personali.

To exercise their rights, the data subject may contact the Data Controller by writing to the certified email address amministrazione.centrale@pec.unipd.it or to the email address urp@unipd.it. Alternatively, the data subject may write to: University of Padua, via VIII Febbraio n. 2, Padua.

The Data Controller is required to provide a response within one month of the request, extendable up to three months in cases where the request is particularly complex.

Any changes and additions to this privacy notice are published in the Privacy section of the institutional website www.unipd.it/privacy.

Last updated: 23 July 2019

Privacy and data protection

Data Protection Officer  DPO:  Giorgio Valandro

email: privacy@unipd.it