Privacy Notice

This Privacy Notice is based on the EU’s General Data Protection Regulation (2016/679, “GDPR”), namely on the obligation to inform the data subjects (GDPR Articles 12–14) and the data controller’s obligation to maintain a record of processing activities under its responsibility (GDPR Article 30), as well as on the obligations set out in the Finnish Data Protection Act (1050/2018) supplementing the GDPR.

Additionally, this Privacy Notice has been prepared with the aim of making it accessible in accordance with the requirements of the EU’s Web Accessibility Directive (Directive (EU) 2016/2102 of the European Parliament and of the Council on the accessibility of the websites and mobile applications of public sector bodies) and the Finnish Act on the Provision of Digital Services (306/2019) supplementing it.

1 Name of the register

Name of the register
Personal data register for the student selection cooperation between Universities of Applied Sciences (UASs), the use of the Finnish National University of Applied Sciences Digital Entrance Examination (UAS Exam), the use of the International University of Applied Sciences Digital Entrance Examination (International UAS Exam) and the provision of the Entrance Exam Ecosystem (joint register between several universities of applied sciences)

In this Privacy Notice, this register will be referred to as:
Personal data register for the student selection cooperation between UASs, the use of the UAS Exam, the use of the International UAS Exam and the provision of the Entrance Exam Ecosystem (joint register between several UASs)

2 Data controllers

Names of the joint data controllers:

Ab Yrkeshögskolan vid Åbo Akademi, Novia University of Applied Sciences
Centria University of Applied Sciences Ltd
Diaconia University of Applied Sciences Ltd
Haaga-Helia University of Applied Sciences Ltd
Humak University of Applied Sciences Ltd
Häme University of Applied Sciences Ltd
JAMK University of Applied Sciences Ltd
South-Eastern Finland University of Applied Sciences Ltd
Kajaani University of Applied Sciences Ltd
Karelia University of Applied Sciences Ltd
LAB University of Applied Sciences Ltd
Lapland University of Applied Sciences Ltd
Laurea University of Applied Sciences Ltd
Metropolia University of Applied Sciences Ltd
Oulu University of Applied Sciences Ltd
Satakunta University of Applied Sciences Ltd
Savonia University of Applied Sciences Ltd
Seinäjoki University of Applied Sciences Ltd
Tampere University of Applied Sciences Ltd
Turku University of Applied Sciences Ltd
Vaasa University of Applied Sciences Ltd
Arcada University of Applied Sciences Ltd

Contact details of the joint data controllers:

Ab Yrkeshögskolan vid Åbo Akademi, Novia University of Applied Sciences (business ID: 2059910-2)
Postal address: PO Box 6, 65201 Vaasa
Visiting address: Wolffskavägen 31, 65200 Vaasa
Tel. (switchboard): +358 6 328 5000
Email: hakijapalvelut@novia.fi

Centria University of Applied Sciences Ltd (business ID: 1097805-3)
Postal address: Talonpojankatu 2, 67100 Kokkola
Tel. (switchboard): +358 6 868 0200
Email: info@centria.fi

Diaconia University of Applied Sciences Ltd (business ID: 0115776-3)
Postal address: PO Box 12, 00511 Helsinki
Visiting address: Kyläsaarenkuja 2, 00580 Helsinki
Tel. (switchboard): +358 29 469 6000
Email (registry office): kirjaamo@diak.fi

Haaga-Helia University of Applied Sciences Ltd (business ID: 2029188-8)
Visiting address: Ratapihantie 13, 00520 Helsinki
Tel. (switchboard): +358 9 229 611
Email (registry office): kirjaamo@haaga-helia.fi

Humak University of Applied Sciences Ltd (business ID: 1474763-1)
Visiting address: Ilkantie 4, 00400 Helsinki
Tel. (switchboard): +358 20 762 1391
Email: humak@humak.fi

Häme University of Applied Sciences Ltd (business ID: 2617489-3)
Postal address: PO Box 230, 13101 Hämeenlinna
Visiting address: Visamäentie 35, 13100 Hämeenlinna
Tel. (switchboard): +358 3 6461
Email: hamk@hamk.fi

JAMK University of Applied Sciences Ltd (business ID: 1006550-2)
Postal address: PO Box 207, 40101 Jyväskylä
Visiting address: Rajakatu 35, 40200 Jyväskylä
Tel. (switchboard): +358 14 449 9694
Email (registry): kirjaamo@jamk.fi

South-Eastern Finland University of Applied Sciences Ltd (business ID: 2472908-2)
Postal address: PO Box 68, 50101 Mikkeli
Visiting address: Patteristonkatu 3 D, 50101 Mikkeli
Tel. (switchboard): +358 40 655 0555
Email (registry office): kirjaamo@xamk.fi

Kajaani University of Applied Sciences Ltd (business ID: 2553600-4)
Postal address: PO Box 52, 87101 Kajaani
Visiting address: Ketunpolku 1, 87100 Kajaani
Tel. (switchboard): +358 8 618 991
Email: kajaanin.amk@kamk.fi

Karelia University of Applied Sciences Ltd (business ID: 2454377-1)
Postal address: PO Box 256, 80101 Joensuu
Visiting address: Tikkarinne 9, 80200 Joensuu
Tel. (switchboard): +358 13 260 600
Email: info@karelia.fi

LAB University of Applied Sciences Ltd (business ID: 2630644-6)
Postal address: PO Box 214, 15101 Lahti
Visiting address: Mukkulankatu 19, 15210 Lahti
Tel. (switchboard): +358 29 446 5000
Email: asiakirjat@lab.fi

Lapland University of Applied Sciences Ltd (business ID: 2528792-5)
Visiting address: Jokiväylä 11 C, 96300 Rovaniemi
Tel. (switchboard): +358 20 798 6000
Email (registry office): kirjaamo@lapinamk.fi

Laurea University of Applied Sciences Ltd (business ID: 1046216-1)
Postal address: Ratatie 22, 01300 Vantaa
Visiting address: Ratatie 22, 01300 Vantaa
Tel. (switchboard): +358 9 8868 7150
Email: rehtorintoimisto@laurea.fi

Metropolia University of Applied Sciences Ltd (business ID: 2094551-1)
Postal address: PO Box 4000, 00079 Metropolia
Visiting address: Myllypurontie 1, 00920 Helsinki
Tel. (switchboard): +358 9 7424 5000
Email (registry office): kirjaamo@metropolia.fi

Oulu University of Applied Sciences Ltd (business ID: 2509747-8)
Postal address: PO Box 222, 90101 Oulu
Visiting address: Yliopistokatu 9, 90570 Oulu
Tel. (switchboard): +358 20 611 020
Email (registry office): kirjaamo@oamk.fi

Satakunta University of Applied Sciences Ltd (business ID: 2388924-4)
Postal address: PO Box 1001, 28101 Pori
Visiting address: Satakunnankatu 23, 28130 Pori
Tel. (switchboard): +358 2 620 3000
Email (switchboard): kirjaamo@samk.fi

Savonia University of Applied Sciences Ltd (business ID: 2629463-3)
Postal address: PO Box 6, 70201 Kuopio
Visiting Address: Microkatu 1, 70210 Kuopio
Tel. (switchboard): +358 17 255 6000
Email (registry office): savonia@savonia.fi

Seinäjoki University of Applied Sciences Ltd (business ID: 2539767-3)
Postal address: PO Box 412, 60101 Seinäjoki
Visiting address: Kampusranta 11, 60320 Seinäjoki
Tel. (switchboard): +358 20 124 3000
Email (registry office): kirjaamo@seamk.fi

Tampere University of Applied Sciences (business ID: 1015428-1)
Visiting address: Kuntokatu 3, 33520 Tampere
Tel. (switchboard): +358 029 45222
Email: tamk@tuni.fi

Turku University of Applied Sciences Ltd (business ID: 2528160-3)
Visiting address: Joukahaisenkatu 3, 20520 Turku
Tel. (switchboard): +358 2 263 350
Email (switchboard): kirjaamo@turkuamk.fi

Vaasa University of Applied Sciences (business ID: 2267669-3)
Postal address: PO Box 509, 65101 Vaasa
Visiting address: Wolffintie 30, 65200 Vaasa
Tel. (switchboard): +358 20 766 3300
Email: info@vamk.fi

Arcada University of Applied Sciences Ltd (business ID: 0200099-5)
Visiting address: Jan-Magnus Janssons plats 1, 00560 Helsinki
Tel. (switchboard): +358 20 769 9699
Email (registry office):registrator@arcada.fi

Person responsible for the content of the register:

Name: Tuomas Orama
Position: Research and Development Manager, Metropolia University of Applied Sciences Ltd
Address: Metropolia University of Applied Sciences Ltd, PO Box 4000, FI-00079 METROPOLIA
Email: tuomas.orama@metropolia.fi

Contact details of the contact person for the register:

Name: Marko Borodavkin
Position: Project Manager, Metropolia University of Applied Sciences Ltd
Address: Metropolia University of Applied Sciences Ltd, PO Box 4000, FI-00079 METROPOLIA
Email: marko.borodavkin@metropolia.fi

Data Protection Officers of the joint data controllers:

Ab Yrkeshögskolan vid Åbo Akademi, Novia University of Applied Sciences: Data Protection Officer Roald von Schoultz
Email: dataskyddsansvarig@novia.fi
Centria University of Applied Sciences Ltd: Data Protection Officer Rainer Björk
Email: rainer.bjork@centria.fi

Diaconia University of Applied Sciences Ltd: Data Protection Officer Liisa Leppänen
Email: tietosuojavastaava@diak.fi; liisa.leppanen@diak.fi

Haaga-Helia University of Applied Sciences Ltd: Data Protection Officer Ilkka Valve
Email: ilkka.valve@haaga-helia.fi

Humak University of Applied Sciences Ltd: Data Protection Officer Ari Savander
Email: security@humak.fi; ari.savander@humak.fi

Häme University of Applied Sciences Ltd: Data Protection Officer Kari Kataja
Email: tietosuojavastaava@hamk.fi; kari.kataja@hamk.fi

JAMK University of Applied Sciences Ltd: Data Protection Officer Annukka Akselin
Email: tietosuoja@jamk.fi; annukka.akselin@jamk.fi

South-Eastern Finland University of Applied Sciences Ltd: Data Protection Officer, Project Manager Markus Häkkinen
Email: tietosuojavastaava@xamk.fi; markus.hakkinen@xamk.fi

Kajaani University of Applied Sciences Ltd: Data Protection Officer
Email: tietosuojavastaava@kamk.fi

Karelia University of Applied Sciences Ltd: Data Protection Officer Mika Kettunen
Email: tietosuoja@karelia.fi

LAB University of Applied Sciences Ltd: Data Protection Officer, Legal Counsel Anne Himanka
Email: tietosuoja@lab.fi

Lapland University of Applied Sciences Ltd: Data Protection Officer Pirjo Kärki-Koskinen
Email: tietosuoja@lapinamk.fi; pirjo.karki-koskinen@lapinamk.fi

Laurea University of Applied Sciences: Data Protection Officer Marjo Valjakka
Email: marjo.valjakka@laurea.fi

Metropolia University of Applied Sciences Ltd: Data Protection Officer Tuulia Aarnio
Email: dpo@metropolia.fi

Oulu University of Applied Sciences Ltd: Data Protection Officer Ulla Virranniemi
Email: tietosuoja@oamk.fi; ulla.virranniemi@oamk.fi

Satakunta University of Applied Sciences Ltd: Data Protection Officer Osmo Santamäki
Email: tietosuojavastaava@samk.fi; osmo.santamaki@samk.fi

Savonia University of Applied Sciences Ltd: Data Protection Officer Mervi Hätinen
Email: tietosuojavastaava@savonia.fi; mervi.hatinen@savonia.fi

Seinäjoki University of Applied Sciences Ltd: Data Protection Officer Jarmo Jaskari
Email: tietosuojavastaava@seamk.fi; jarmo.jaskari@seamk.fi

Tampere University of Applied Sciences Ltd: Data Protection Officer (Data Protection Officer of the Tampere universities community)
Email: dpo@tuni.fi

Turku University of Applied Sciences Ltd: Data Protection Officer Jaani Kuusela
Email: tietosuoja@turkuamk.fi; jaani.kuusela@turkuamk.fi

Vaasa University of Applied Sciences Ltd: Data Protection Officer Sami Olmari
Email: security@vamk.fi; sami.olmari@vamk.fi

Arcada University of Applied Sciences Ltd: Data Protection Officer Anna Härmä
Email: tietosuoja@arcada.fi; dataskydd@arcada.fi; anna.harma@arcada.fi

3 Data Protection Officer

Data Protection Officer:
Tuulia Aarnio, Metropolia’s Data Protection Officer

Contact details of the Data Protection Officer:
Tel: +358 40 844 0690
Email: dpo@metropolia.fi

4 Purpose and lawful basis of the processing of personal data

Purpose of the processing of personal data:

The personal data register for the student selection cooperation between UASs, the use of the UAS Exam, the use of the International UAS Exam and the provision of the Entrance Exam Ecosystem (joint register between several UASs) is used to process personal data for carrying out student selections by the UASs. It is a joint register operated by several higher education institutions. The Finnish National University of Applied Sciences Digital Entrance Examination (UAS Exam) is used for selecting students in Finland for UAS studies leading to a Finnish-language or Swedish-language degree. The International University of Applied Sciences Digital Entrance Examination (International UAS Exam) is used for selecting students in Finland for UAS studies leading to an English-language degree.

Both the UAS Exam and the International UAS Exam are implemented in the Exam System. In addition, a Management System has been put in place for processing the applicants’ personal data. The Management System is used for identifying applicants and as an aid in the practical arrangements for the exams.

Since autumn 2019, the UAS sector has used a joint Digital Entrance Examination, managed by several UASs that are contracting parties and joint data controllers. As of spring 2022, the UAS sector will use a joint International UAS Exam for education leading to an English-language UAS degree.

Under the student selection cooperation between the UASs, all of the UASs listed in section 1 of this Privacy Notice use the UAS Exam when selecting students for education leading to a Finnish-language or a Swedish-language degree. The UAS Exam is used by all faculties, with the exception of the faculty of culture. The degree programmes under the faculty of culture may, however, choose to use the UAS Exam in the future. In addition to what is described above, under the student selection cooperation between the UASs, all of the UASs listed in section 1 of this Privacy Notice (excluding Satakunta University of Applied Sciences, SAMK) use the International UAS Exam to select students for education leading to an English-language degree.

The International UAS Exam is also used by all faculties, with the exception of the faculty of culture. However, the degree programmes under the faculty of culture may, in the future, choose to use the International UAS Exam to select students for education leading to an English-language UAS degree.

All the UASs participating in the student selection cooperation are committed to the Finnish National Entrance Examination Cooperation when using the UAS Exam and/or the International UAS Exam. The Entrance Examination Cooperation means that the results of the UAS Exam and/or International UAS Exam are accepted in accordance with the principles governing these exams in all the UASs or fields of study that use them.

The Exam System owned by Metropolia University of Applied Sciences (Entrance Exam Ecosystem) is utilised in the provision of the UAS Exam and International UAS Exam described in this Privacy Notice. Personal data are processed throughout the UAS student selection cooperation as well as when the Exam System is used.

In connection with the implementation of the activities described above, the UASs process personal data in such a way that a joint controllership exists between them, as referred to in Article 26 of the EU’s General Data Protection Regulation (EU 2016/679). The UASs have entered into an agreement on joint controllership specifying their actual roles, responsibilities and relations with regard to the data subjects.

Lawful basis for the processing of personal data:

The processing of the personal data contained in the personal data register for the student selection cooperation between UASs, the use of the UAS Exam, the use of the International UAS Exam and the provision of the Entrance Exam Ecosystem (including the use of the Management System related to the aforementioned) and the provision of the Entrance Exam Ecosystem is based on Article 6(1)(c) and (e) of the EU’s General Data Protection Regulation.

Personal data are processed in the student selection cooperation in order to carry out the student selections. Personal data are also processed in order to identify the persons participating in the UAS Exam and the International UAS Exam and to manage their identification.

Article 6(1)(c) of the EU’s General Data Protection Regulation: The processing of personal data is based on the Universities of Applied Sciences Act (932/2014) and the Act on the National Registers of Education Records, Qualifications and Degrees (884/2017).

According to the Universities of Applied Sciences Act, education, tuition and the issuing of degrees are part of the statutory duties of a UAS. The licence granted to a UAS specifies which degrees and related degree titles the UAS must issue (educational provision). According to the Universities of Applied Sciences Act, the students are accepted by the UAS. (Universities of Applied Sciences Act, sections 4, 7–8 and 25–28.)

In accordance with the Act on the National Registers of Education Records, Qualifications and Degrees, when a UAS carries out student selections, it must store the following data, among others, on each data subject: name of the applicant, national learner ID and personal identity code or other similar identification information, nationality, gender, native language and the necessary contact details; information on the applicant’s education and completed degrees;

information on the application for education and the justifications for selection in the case of each applicant; information on the outcome of the selection, acceptance of the study place and enrolment at the educational institution. (Act on the National Registers of Education Records, Qualifications and Degrees, sections 17–27.)

Article 6(1)(e) of the EU’s General Data Protection Regulation: personal data are processed in the UAS student selection cooperation on the basis of the exercise of official authority.

5 Legitimate interests of the data controller or a third party

The lawful basis for the processing of personal data in the register is not “legitimate interest”. Therefore this section does not apply.

6 Description of the groups of data subjects and personal data categories

The following are the groups of data subjects in the personal data register for the student selection cooperation between UASs, the use of the UAS Exam, the use of the International UAS Exam and the provision of the Entrance Exam Ecosystem:

- Applicants participating in the student selection process of the UASs (applicants for education leading to Finnish-language and Swedish-language degrees at the 22 UASs that are parties to the agreement; applicants for education leading to English-language degrees at the 21 UASs that are parties to the agreement)

- The staff of the UASs who use the Management System for identifying applicants

The following data are stored by personal data category in the personal data register for the student selection cooperation between UASs, the use of the UAS Exam, the use of the International UAS Exam and the provision of the Entrance Exam Ecosystem:

Background information on the applicant related to the implementation of the Entrance Exam Ecosystem

(processing of applicant information before the Entrance Examination in the Opintopolku.fi service and during the Entrance Examination as well as after the result of the exam has been established)

- Basic information on the applicant: forenames, call name, surname, national learner ID, personal identity code, email, telephone number;

- Application ID;

- Entrance Examination content identifiers;

- Information on the location and time of the Entrance Examination

The personal data processed in the Entrance Exam Ecosystem (and in the Management System related to it and in the International UAS Exam) are retrieved by Metropolia University of Applied Sciences from the Opintopolku.fi service through a technical interface.

The personal data of each applicant are processed in the Entrance Exam Ecosystem in order to enable the creation of individualised content for the Entrance Examination and enable the completion of the Entrance Examination.

There is a Management System connected to the Exam System. The Management System generates a unique identifier in the form of a QR code and information on the Entrance Examination for the applicant. The applicant’s unique QR code is used together with a personal identity document for performing strong identification of the applicant before the exam.

The UASs create spaces in the Management System and place applicants in different spaces. An applicant may also be granted additional time and special arrangements for health-related reasons; the applicant’s exam performance may be rejected or the applicant may be transferred to another exam event. The reasons for the special arrangements are not stored in the register.

Information on the applicant’s exam answers (UAS Exam and/or International UAS Exam)

(the answers given personally by the applicant in the system during the Entrance Examination)

- Answers given in the Entrance Examination (saved only on a server of Metropolia University of Applied Sciences);

- Log data related to the answers given in the Entrance Examination (incl. precise time each answer is saved; the data are saved only on a server of Metropolia University of Applied Sciences);

The applicant personally gives the answers to the Entrance Examination questions when completing the exam. The UAS Exam and/or International UAS Exam include several sections for each applicant, covering areas such as reasoning skills and language and communication skills. The degree programmes the applicant is applying for determine the sections selected for the Entrance Examination.

Scores obtained by the applicant in the Entrance Examination (UAS Exam and/or International UAS Exam)

(data processed at the end of the Entrance Examination and the information transferred by Metropolia University of Applied Sciences to the Opintopolku.fi service of the Finnish National Agency for Education through a technical interface)

- Scores obtained by the applicant in the Entrance Examination

The applicant’s answers are given scores in the Exam System. The applicant’s section-specific exam scores are transferred to the Opintopolku.fi service via a technical interface.

Information on the Management System connected to the Entrance Exam Ecosystem and on the UAS staff using it

- Haka IDs of the UAS staff

- Email addresses of the UAS staff   The Haka IDs and email addresses of the staff of the UASs using the Management System are stored in the system.

7 Regular sources of personal data

Personal data of the applicant

The personal data are obtained from the Opintopolku.fi service maintained by the Finnish National Agency for Education with regard to participation in the UAS Exam and/or International UAS Exam.

The answers given in the UAS Exam and/or International UAS Exam are obtained from the data subjects themselves in the exam situation.

Metropolia University of Applied Sciences saves the scores obtained by the applicant in the UAS Exam and/or International UAS Exam.

Personal data of the staff of the UASs

The personal data of the staff of the UASs are partly obtained from the data subjects themselves when they applied for employment at the UAS, and partly the data (such as the Haka ID) are created for them by their employer. The staff of the UASs create spaces in the Management System and place applicants into different spaces. An applicant may also be granted additional time and special arrangements for health-related reasons; they may also be transferred to another exam event, which is technically performed by the UAS staff.

8 Information systems used in the processing of personal data

The personal data processed in the Entrance Exam Ecosystem are retrieved using a technical interface from the Opintopolku.fi service maintained technically by the Finnish National Agency for Education. The applicant’s exam answers are given scores directly in the Exam System by Metropolia University of Applied Sciences. The section-specific exam scores the applicant obtains in the UAS Exam and/or International UAS Exam are transferred by Metropolia University of Applied Sciences at the end of the process via an interface to the Opintopolku.fi service of the Finnish National Agency for Education.

Metropolia University of Applied Sciences owns the Entrance Exam Ecosystem used in the joint selections of the UASs and the Management System connected to it, both of which enable the UAS Exam and International UAS Exam to be provided to the entire UAS sector.

Open source Nextcloud server software is used in the execution of UAS Exam and International UAS Exam. Nextcloud on-premise software is used for sharing files, organizing exam situation rooms and saving backups.

9 Data recipients or recipient groups and regular disclosures

Access to the personal data contained in the register will be given, where necessary, in the systems listed below. (For the purpose of repairing a technical fault, for example, access will be given with administrator rights to the system provider or to the maintenance personnel of a measurement device.) All system/software providers used (the companies behind them) can be deemed to be recipients of personal data.

With respect to the systems used by the register, personal data processing agreements in accordance with Article 28 of the GDPR have been concluded with the following cooperation partners:

Finnish National Agency for Education; Opintopolku.fi service

Metropolia University of Applied Sciences retrieves the personal data processed in the Exam System from the Opintopolku.fi service via a technical interface. The data on the applicants are disclosed from the Opintopolku.fi service to Metropolia University of Applied Sciences for the implementation of the UAS Exam and International UAS Exam. The Opintopolku.fi service is technically maintained by the Finnish National Agency for Education.

Metropolia University of Applied Sciences can be deemed a recipient of data disclosures from the Opintopolku.fi service maintained by the Finnish National Agency for Education. The disclosures are governed by an agreement (data services agreement) between Metropolia University of Applied Sciences and the Finnish National Agency for Education.

Metropolia University of Applied Sciences provides the Entrance Exam Ecosystem and the Management System connected to it using an external service provider (a personal data processor acting on its behalf). Personal data processor acting on behalf of Metropolia University of Applied Sciences:

Eduix Oy

Since Eduix Oy, which provides and develops the Entrance Exam Ecosystem together with Metropolia University of Applied Sciences, has access to the data in the Exam System, including personal data, Eduix Oy can be deemed to be a recipient of personal data in connection with the Entrance Exam Ecosystem and the Management System related to it. Metropolia University of Applied Sciences and Eduix Oy have entered into a personal data processing agreement in accordance with Article 28 of the EU’s General Data Protection Regulation. Metropolia University of Applied Sciences has provided written instructions to the personal data processor acting on its behalf, as required by Article 28 of the EU’s General Data Protection Regulation.

Data from the personal data register for the student selection cooperation between UASs, the use of the UAS Exam, the use of the International UAS Exam and the provision of the Entrance Exam Ecosystem may be disclosed for scientific and historical research purposes.

Upon the consent of the data subject (research subject), data from the personal data register for the student selection cooperation between UASs, the use of the UAS Exam, the use of the International UAS Exam and the provision of the Entrance Exam Ecosystem are disclosed to thepersonal data register for research material on participants in the Entrance Examination.  

10 Transfer of information outside the EU or EEA or to international organisations

Data included in the personal data register for the student selection cooperation between Universities of Applied Sciences (UASs), the use of the Finnish National University of Applied Sciences Digital Entrance Examination (UAS Exam), the use of the International University of Applied Sciences Digital Entrance Examination (International UAS Exam) and the provision of the Entrance Exam Ecosystem (joint register between several universities of applied sciences) are, in principle, not transferred to outside the EU or EEA or to international organisations.

For clarity purposes, it is noted that it is possible that, as part of the student selection cooperation between Universities of Applied Sciences (UASs), the e-mail system of each participating UAS may be used as part of data processing. The e-mail system of Metropolia University of Applied Sciences is run on a private server in Metropolia Myllypuro machine room (it is not part of Microsoft O365 cloud service solution). When the e-mail system of a University of Applied Sciences is run on a private server (different from cloud service solution) the situation does not involve possible transfer of personal data to outside the EU or EEA.

However, it is possible that e-mail solutions of some Universities of Applied Sciences participating in student selection cooperation between UASs are run on the Microsoft O365 cloud service solution. These situations may involve transfer of personal data to outside the EU or EEA.

Parties committed to student selection cooperation between UASs are noted, in principle, to have accepted the situation described above. Each party participating in the student selection cooperation between UASs is obliged to engage their contractors, by contracts, in adhering to the terms of the contract on data transfer. The contract on data transfer shall include the Standard Contractual Clauses (SCC) approved by the European Commission. In addition, the parties shall assess and follow the data protection level of the target country of data transfer and, when necessary, take additional technical and organisational protective measures to secure the data transfer. The data transfer can also be conducted by using another procedure, approved in writing by the parties.

11 Personal data retention times

The data saved in the Exam System are retained for one (1) year as of the date on which the decision concerning student selections is issued.

The data in the admission register concerning admission to a UAS are retained for five (5) years from the date on which the student selection is made. However, the data concerning the acceptance of a study place, which are included in the application register of the UASs, are retained permanently. (Act on the National Registers of Education Records, Qualifications and Degrees, section 22.)  

12 Rights of the data subject

The data subjects have the right to receive confirmation from the data controller of whether their personal data are being processed. Furthermore, the data subjects have the right of access to their personal data and the right to inspect their personal data stored in the register and to receive copies of them. Under the GDPR, the data controller(s) must respond to requests by the data subjects to exercise their rights within one month of receiving such a request.
A. Right of access to personal data
The data subjects have the right to check whether their personal data are stored in the personal data register. The data subject may submit a data request to the UAS that they have primarily applied to (by following the instructions provided for the data subjects on the public website of the UAS). When submitting the request, the data subject must prove their identity in a reliable manner (for example by presenting an official personal identity document or driving licence to the student affairs office or the data protection officer of the UAS). The UAS to which the applicant has primarily applied will contact Metropolia University of Applied Sciences if, for example, it needs information on the data technically saved in the Entrance Exam Ecosystem. In such a case, Metropolia University of Applied Sciences will deliver this information to the requesting UAS.
B. Right to rectify personal data and to restrict processing
The data subjects have the right to request the data controller to restrict the processing of their personal data in the following cases:
  • the data subject disputes that their personal data are correct (right to rectify personal data), in which case processing will be restricted until the data controller can ascertain that the data are correct;
  • processing is unlawful and the data subject objects to the erasure of their personal data, instead requesting that the processing of the data be restricted;
  • the data controller no longer needs the personal data for the purposes of the processing, but the data subject needs them in order to establish, exercise or defend a legal claim.
A request for rectifying personal data or for restricting processing can be submitted to the UAS to which the applicant has primarily applied. The data subject must prove their identity in a reliable manner when submitting the request.  
C. Right to data portability (transfer of data from one system to another)
Not applicable to this register.
D. Right to not be subjected to a personal data breach
The data subject has the right to not be subjected to a personal data breach, as referred to in Article 33 of the EU’s General Data Protection Regulation, due to the data controller’s negligence in data protection and/or data security matters or due to negligence on the part of a data processor used by the controller in data protection and/or data security matters. The data subject has the right to be informed without undue delay if a personal data breach is likely to pose a high risk to the rights and freedoms of natural persons.

13 Right to object

According to Article 21 of the EU’s General Data Protection Regulation, the data subjects have the right to object, on grounds relating to their particular situation, at any time to the processing of personal data concerning them which is based on Article 6(1)(e) (processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller), such as profiling based on these provisions. The data controller(s) may no longer process the personal data unless they demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.

A request to stop the processing of collected personal data can be submitted to the UAS to which the applicant has primarily applied. The data subject must prove their identity in a reliable manner when submitting the request.

14 Right to withdraw consent

If the processing of personal data is based on the data subject’s consent, the data subject has the right to withdraw their consent for processing at any time without the withdrawal of consent affecting the lawfulness of processing based on consent before its withdrawal.

Not applicable to this register.

15 Right to lodge a complaint with a supervisory authority

Every data subject has the right to lodge a complaint with a supervisory authority if the data subject considers that the processing of their personal data infringes the applicable data protection regulations.

The national supervisory authority in Finland is the Office of the Data Protection Ombudsman. Contact details:

Office of the Data Protection Ombudsman
Street address: Lintulahdenkuja 4
FI-00530 Helsinki, Finland
Postal address: PO Box 800
FI-00531 Helsinki, Finland

Telephone (switchboard): +358 29 56 66700
Registry Office: +358 29 566 6768
Email: tietosuoja@om.fi

16 Principles of data protection in the register

General description of the technical and organisational security measures aiming at protecting the personal data of the data subjects and the personal data registers:  
  • The data controllers and the system providers have agreed on the protection of the register. Where necessary, the responsibilities are described in adequate detail in the appropriate agreements.
  • The employees and other personnel of the data controllers have undertaken to comply with the obligation of secrecy and to keep confidential the information they receive in connection with the processing of personal data.
  • The system providers (personal data processor(s) acting on behalf of the joint data controller(s)) undertake to maintain the register and the personal data relating to it in accordance with good data processing practices and to comply with the obligation to absolute secrecy and confidentiality.
  • The data security of the personal data register maintained by the data controllers and the confidentiality of the data contained therein are ensured with appropriate technical and administrative means in accordance with good data processing practices.
  • The data controllers have restricted user rights and authorisations to data systems, tools and other storage platforms in such a way that data can only be accessed and processed by the persons who are necessary for such processing due to their job duties or position.
  • The system containing personal data may only be used by employees who are entitled to process personal data due to their job duties and/or position. Such employees will be given the appropriate training for their duties.
  • Every user of a tool/system must identify themselves with their personal codes, which are issued when the right to access the tool/system is granted. The right of access will expire once the employee resigns or is transferred from the duties for which they were granted the right.
  • The data are collected in databases that are protected logically and physically.
  • The databases and their back-up copies are located in locked premises, and the data can only be accessed by certain pre-appointed persons

17 Information on whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the data subject is obliged to provide the personal data and of the possible consequences of failure to provide such data (information on the source of the personal data)

Information on whether the provision of personal data for processing in the personal data register for the student selection cooperation between UASs, the use of the UAS Exam, the use of the International UAS Exam and the provision of the Entrance Exam Ecosystem is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the data subject is obliged to provide the personal data and of the possible consequences of failure to provide such data. An account has been given for each register regarding how the personal data were obtained.

The personal data are obtained from the data subjects themselves in connection with their application and participation in the Entrance Examination.

Application for studies at a UAS and participation in the joint Entrance Examination of the UASs is arranged in such a way that, when the applicant begins to enter data through the Opintopolku.fi service, they are informed that the data will be processed by the Finnish National Agency for Education and several different UASs in Finland as joint data controllers. The personal data of the staff of the UASs are partly obtained from the data subjects themselves when they applied for employment at the UAS, and partly the data (such as the Haka ID, work email address) are created for them by their employer based on their employment contract.

The www.ammattikorkeakouluun.fi website has been created for people who intend to apply for studies in Finnish-, Swedish- and English-language degree programmes at the UASs.

For more detailed information on data protection in the UAS student selection cooperation as well as on accessibility is available on the www.ammattikorkeakouluun.fi website, under the Data Protection and GDPR section and the Accessibility section.

18 Automated individual decision-making, including profiling

The data contained in the personal data register for the student selection cooperation between UASs, the use of the UAS Exam, the use of the International UAS Exam and the provision of the Entrance Exam Ecosystem are not used for automatic decision-making or profiling.
Valikko