Processing of Personal Data
Your personal privacy is important to us, and the university follows the EU's General Data Protection Regulation (GDPR) and supplementary legislation for all our processing of personal data. Here we provide an overview of the personal data processing for which we are responsible.
What is personal data?
Personal data is any kind of information that can be directly or indirectly linked to a living person. This can include names, contact information, or personal identification numbers. Even photos of individuals are considered personal data.
Certain personal data is particularly sensitive, such as personal identification numbers, salary information, and social conditions. Some personal data is classified as sensitive, such as information about health, political opinions, and sexual orientation.
What is personal data processing?
Personal data processing means handling personal data in some way and includes any action that can be taken with personal data. Examples of processing include collection, registration, storage, processing, disclosure, dissemination, merging, or destruction of personal data.
Data Controller
MDU is responsible for the processing of personal data for which the university determines the purpose and means. The university processes personal data, among other things, in its case management, during admissions to studies at the university, in the administration of studies, within the university's alumni activities, in administrative management, and during various types of events and arrangements organized.
Organization number: 202100–2916
Our Data Protection Officer
The Data Protection Officer works with issues related to MDU's compliance with the General Data Protection Regulation. If you want to exercise any of the rights under the General Data Protection Regulation or if you have questions about the processing of your data, you can contact the university's Data Protection Officer.
Email: dso@mdu.se
How MDU processes personal data
MDU processes personal data to fulfill its mission as a state authority and institution of higher education, as well as to finance and conduct research.
The university processes personal data to comply with legislation that the university is subject to, for statistical purposes, archival purposes, and to develop and follow up on activities.
Inquiries and contact with MDU
If you contact us, we will process your personal data to communicate with you and handle the matter that has been submitted. The data processed is usually contact information (name, email address) and any additional personal data that you have provided in your contact with us. The legal basis for the processing is a task of public interest.
Social media
The university uses several different social media platforms, such as Facebook, LinkedIn, Instagram, and Twitter. There, we publish interviews and photos from our activities, for example, of our researchers, which means that we process, for example, images and names. On social media, personal data processing also occurs when you interact with MDU's posts and pages in various ways (likes, comments, visits).
The purpose of personal data processing on social media is to inform about our activities and communicate with our target audience. The legal basis for personal data processing is public interest.
MDU removes inappropriate content from social channels, such as in comment fields. Read about social media guidelines.
Website
The university has several official websites, such as mdu.se, where information about the university's activities is published. On these websites, the university is responsible for personal data that is published on the site, such as names and contact information, and the purpose is to inform about our activities. The legal basis for the processing is public interest.
MDU's website also uses cookies. The purpose of the cookies is to improve the website for you as a visitor and to develop the website.
Alumni network
MDU has an alumni network that is intended for everyone who has studied at Mälardalen University (formerly college). When you choose to join the alumni network by registering, your personal identification number is processed to verify your identity. You can also provide contact information and information about your employer and LinkedIn profile so that the alumni network can send you information about lectures, newsletters, and your program or subject area. When you join the network and register for activities and events or otherwise show interest in participating in the activities, the legal basis is consent.
For other alumni activities, the legal basis is public interest. The processing is carried out to collaborate with the surrounding community and inform about the university's activities, as well as to ensure that research results from the university are utilized.
Students
If you are a student at MDU, we process your personal data, such as name, personal identification number, and information about study results and other information related to your studies at the university.
The personal data you provide when applying for admission is registered in the national admissions system for universities (NyA). If you are admitted to a program, the personal data is transferred to the university's study documentation system (Ladok), which is used to document students' results and compile statistics for both internal use and for Statistics Sweden (SCB).
The university is responsible for handling applicants' and students' personal data in the aforementioned registers. The handling is regulated by the ordinance on the reporting of studies, etc., at universities and colleges (1993:1153).
For admission, examination, and credit transfer of courses, the legal basis is that the processing of personal data is a necessary step in the university's exercise of authority. For other personal data processing necessary for you to be a student at MDU, the legal basis is public interest.
MDU processes your personal data as long as you are a student at the university. When you are no longer a student at the university, your personal data is processed as required by law.
Conferences, Courses, and Events
When registering for conferences, lectures, and other events organized by the university, we process your personal data to manage the activity and conduct follow-ups. The university process contact information such as name, email address, and any dietary requirements. Our processing is necessary to perform a task in the public interest (Article 6.1 e GDPR). Personal data is deleted after the event has been completed.
During these activities, we may also take photographs and record videos. The visual material captured will be used for marketing purposes to promote our activities and operations. This material may be featured on various platforms such as LinkedIn, Facebook, and Instagram. Our processing of this visual material, where you may appear, is necessary to perform a task in the public interest (Article 6.1 e GDPR). Clear signage will be in place to indicate that audio and/or video recording is taking place during these activities.
Research
MDU conducts research as part of the university's mission as a research institution. If you participate in a research study, you will receive specific information from the responsible researcher about how and why your personal data is processed in connection with your participation. Your personal data will be processed as long as necessary to ensure ongoing research.
Job Application
MDU processes personal data in connection with job applications. The personal data is processed to enable MDU to administer the applications and fill the position. The processing for filling the position is part of MDU's exercise of authority and other processing is to perform a task of public interest. Data is stored for at least two years to fulfill legal obligations according to the Discrimination Act.
Contractors and Suppliers
In order to administer contractual relationships and fulfill agreements, MDU processes personal data about contractors and suppliers. The personal data processed includes names, contact information, and financial information necessary for making payments or invoicing. The legal basis is the contract. Personal data that appears in public records is stored according to applicable archival regulations. Other data is deleted when the contract ends
How Your Data is Protected
MDU ensures that all processing of personal data is protected by appropriate organizational and technical measures. These measures are designed to ensure a level of security appropriate to the risks associated with the processing.
Your personal data will be protected by security infrastructure, access control, and, if necessary, encryption or storage in specially protected areas. Personal data in IT systems is regularly backed up.
Who Can Access Your Personal Data?
MDU is a public authority, and as such, much of the information at the university is public records. If your personal data appears in a public record, those who request the record can access your personal data, unless confidentiality according to the Public Access to Information and Secrecy Act (2009:400) prevents this.
In addition, your data may be disclosed to partners in research projects, suppliers, and other parties who need access to the data due to agreements between the university and you, due to a task of public interest, as part of the exercise of authority, or due to a legal obligation that the university has. If the university plans to disclose information about you to other organizations, you will be informed about it. MDU will not disclose personal data to other parties without legal support.
Storage Period
The university retains your personal data as long as the purpose and processing require it, or as long as required by applicable legislation.
Mälardalen University is a public authority, and as such, the starting point according to archival legislation is that the authority should preserve public records. This also includes public records that contain personal data. Public records are managed in accordance with current archival legislation (1990:782), the Freedom of the Press Act (1949:105), and the regulations of the National Archives. Disposal of public records is carried out in accordance with the university's document management plans and disposal decisions.
Personal data that is not part of a public record and that does not need to be further processed for archival purposes is retained and processed only as long as necessary for the purpose for which it is processed.
Transfer of Personal
Data to Third Countries Transfer to third countries means that personal data is transferred outside the EU/EEA. MDU may transfer personal data outside the EU/EEA in connection with student exchanges and international research projects. In these cases, you will be informed that a transfer to a third country is taking place when you provide your data to the university.
MDU takes all reasonable legal, organizational, and technical measures necessary to achieve an adequate level of protection for your personal data, whether processed within the EU or in third countries.
Your Rights as a Data Subject
The General Data Protection Regulation gives you several rights as an individual. You can read more about them on the website of the Swedish Authority for Privacy Protection. If you want to exercise your rights, you can submit your request via the link at the bottom of this page. If you have questions regarding the processing of your data, you can contact the university's Data Protection Officer at dso@mdu.se.
Right of Access
You have the right to request information on whether the university processes personal data about you. You also have the right to receive a free copy of the personal data being processed. If you request extracts repeatedly, MDU will charge a fee to cover administrative costs for this. When handling a request for a register extract, the university will also provide information about the processing, purpose, legal basis for the processing, and anticipated storage periods.
Right to Information
You have the right to receive information about the processing of personal data when your personal data is collected or at the first point of contact if it is collected from someone else. You have the right to be informed in clear and plain language about, among other things, why your personal data is being processed, how long it will be stored, and, where applicable, who will have access to your data.
Right to Rectification
If you believe that the personal data concerning you is incorrect or incomplete, you can request to have the data corrected or supplemented.
Right to be Forgotten
You have the right to have your personal data deleted from the university's systems if the data is no longer needed to fulfill the purpose for which it was collected. If your personal data has been disclosed to another party, the university will take all reasonable steps to inform these parties of your request for deletion.
You also have the right to request the deletion of specific personal data, for example, if you appear in a photo on a webpage managed by the university or if your email address is on a newsletter distribution list.
There may be legal requirements and regulations that require the university to retain your personal data, such as rules on public records or documentation of studies and research. We will evaluate your request to be forgotten against applicable legislation.
Right to Restriction of Processing
You have the right to request that the processing of your personal data be restricted, which means that the university ensures that personal data is only processed for specific purposes. MDU will restrict processing in the following cases:
If you inform us that your personal data is incorrect and the university needs time to verify the accuracy of the data. If the university no longer needs the data, but you request that it continue to be stored because you need it to assert legal claims. If you object to processing carried out by the university. In such cases, the processing will be restricted until a balance has been struck between your reasons for the objection and the university's compelling legitimate reasons.
Right to Object to Processing
You have the right to object to MDU processing your personal data in certain cases, such as in research or educational activities. The university will then cease the processing unless MDU has compelling reasons to continue it, or if the processing is required to assert legal claims.
Right to Data Portability
If MDU processes personal data about you to fulfill a contract, you may, in certain cases, have the opportunity to obtain personal data concerning you to use elsewhere, for example, to transfer the data to another data controller. This right is called data portability.
Comments about the University's processing of your personal data
You have the opportunity to submit comments about the University’s processing of your personal data. You may also send a report to the Swedish Data Protection Authority, which is a supervisory authority. If you wish to claim damages you may submit your claim to the University or initiate proceedings in a public court.
Ärende om rättighet enligt GDPR
Skapa ett ärende om rättighet enligt GDPR för behandlingen av dina personuppgifter
Mälardalen University’s Data Protection Officer
The Data Protection Officer's task is to ensure that the General Data Protection Regulation is followed within the organization.
Contact the Data Protection Officer if you have questions regarding the processing and protection of personal data or if you want to exercise your rights under the General Data Protection Regulation.