1. Definitions and Abbreviations used in the Personal Data Processing and Protection Policy in the Federal State Autonomous Educational Institution of Higher Education "Immanuel Kant Baltic Federal University"
1.1 Personal Data (PD) — any information related to directly or indirectly specified individual (personal data subject).
1.2 Personal Data Processing — any action (operation) or a series of actions (operations) performed towards personal data with or without use of the software, including collection, recording, systematization, accumulation, storage, update and alteration, extraction, use, transfer (distribution, presentation, provision), depersonalization, blocking, deleting and destruction of personal data.
1.3 Personal Data Distribution — any actions aimed at the disclosure of Personal Data to an indefinite set of persons.
1.4 Personal Data Provision — any actions aimed at disclosing Personal Data to a certain person or a certain set of persons.
1.5 Personal Data Blocking — temporary Personal Data Processing suspension (unless processing is necessary to clarify Personal Data).
1.6 Personal Data Destruction — any actions making it impossible to restore Personal Data volume in the Personal Data information system and/or resulting in the elimination of tangible media.
1.7 Personal Data Depersonalisation — any actions making it impossible to identify Personal Data as related to a certain data subject without involving additional information.
1.8 Personal Data Information System (PDIS) — a set of Personal Data included into Personal Data databases, as well as the software and tools used for their processing
1.9 Information — information (messages, data), regardless of the form of its presentation.
2. General Provisions
2.1 This document determines the Policy of the Federal Autonomous Educational Institution of Higher Education "Immanuel Kant Baltic Federal University" (hereinafter — the University) in relation to the Personal Data Processing and Protection.
2.2. Personal Data Processing and Protection Policy of the University (hereinafter — the Policy) determines:
The legal framework for ensuring the safety of PD;
Principles and purposes of PD Processing;
Lists of PD subjects and processed by PD;
Operations performed with PD, and terms of their processing;
Rights and obligations of the subjects and employees of the University when Processing PD;
The measures taken by the University to protect PD;
Control and supervision of PD Processing.
2.3. The Policy is based on the Federal Law No. 152-FZ "On Personal Data", Chapter 2, Article 18.1 dated July 27, 2006 and taking into account the requirements of the Constitution of the Russian Federation, legislative and other regulatory legal acts of the Russian Federation on personal data protection.
2.4. The purpose of this Policy is to determine the procedure for Processing Personal Data of citizens; ensuring the protection of the rights and freedoms of a person and a citizen in Personal Data Processing, including the protection of the privacy rights, personal and family confidentiality, as well as establishing the responsibility of officials who have the access to citizens Personal Data for non-compliance with the requirements and standards governing Personal Data Processing and Protection.
2.5. This Policy applies to all Personal Data processed at the University, received before and after signing of this Policy.
2.6. This Policy applies to Personal Data processed with both the use of automatic equipment and without them.
2.7. This Policy applies to all processes in which the processing of Personal Data of the PD subjects of all categories, as well as officials involved in these processes.
2.8. The main provisions of the document can also be extended to divisions of other organizations and institutions that interact with the University as suppliers and consumers (users) of information.
3. Legal Basis of Personal Data Processing
3.1 The Policy is based on the following regulatory legal acts of the Russian Federation:
Civil Code of the Russian Federation;
Tax Code of the Russian Federation;
Labour Code of the Russian Federation;
Federal Law of the Russian Federation No. 273-FZ "On Education in the Russian Federation" dated December 29, 2012;
Federal Law No. 323-FZ "On the Fundamentals of Protecting the Health of Citizens in the Russian Federation" dated November 21, 2011;
4. Personal Data processed at the University
4.1 The PD transferred to the University concern the following categories of data subjects:
Employees;
Students;
Applicants;
Patients;
4.2 List of PD of employees processed at the University:
Full name;
4.3 The List of PD of Students Processed at the University:
Full name;
4.4 List of PD of Applicants Processed at the University:
Full name;
4.5 List of PD of patients processed at the University:
Full name;
5. Operations Performed with Personal Data
Personal Data Processing Terms
5.1 The University collects, records, organizes, accumulates, stores, clarifies (updates, changes), extracts, uses, transfers (distributes, provides, accesses), depersonalizes, blocks, deletes, destroys PD.
5.2 For biometric PD, the transfer (distribution, provision, access) is not carried out, except as provided for by the Federal Law.
5.3 The term for processing PD of the employees, including biometric Personal Data, is during the term of the employment contract and 75 subsequent years after its expiration, unless a different period of archival storage is established in accordance with the current legislation.
5.4 The term of PD processing of students, including biometric PD during the period of studying, and 75 subsequent years after its completion, unless another period of archival storage is established in accordance with the current legislation.
5.5 The term of PD processing of applicants in case of enrollment in Federal State Autonomous Educational Institution of Higher Education 'Immanuel Kant Baltic Federal University' (IKBFU) During the period of studying, and 75 subsequent years after its completion, unless another period of archival storage is established in accordance with the current legislation. In case of non-enrollment in IKBFU — until the end of the last month of the current year.
5.6 The term for processing the PD of patients is during the period of medical care, and 25 subsequent years after, unless a different period of archival storage is established in accordance with the current legislation.
5.7 The term of processing PD of individuals in contractual relations with the University, including biometric PD, during the term of the contract, and 5 subsequent years, unless a different period of archival storage is established in accordance with the current legislation.
5.8. The University uses cookies to identify the user. Cookies are text files available to the University, used to process information about the user's activity, including information about which pages the user visited and the time the user spent on the page. The user can disable the use of cookies in the browser settings.
5.9. The University website uses the Yandex Metric web analytics service provided by YANDEX LLC, 119021, Moscow, 16 Leo Tolstoy St.
The information collected by the cookies cannot identify the user, but it can help improve the performance of the university website. Information on the use of the University website by the user, collected using cookies, is transferred to Yandex and stored on the Yandex server in the EU and the Russian Federation. Yandex processes this information to evaluate the user's use of the site, to compile reports for the University on the activities of the University site, and to provide other services. Yandex processes this information in the manner prescribed in the Yandex Metrica Terms of Use.
The user can refuse the use of cookies by selecting the appropriate settings in the browser. The user can also use the tool — https://yandex.ru/support/metrika/general/opt-out.html. However, this may affect some features of the site. By using this site, the user agrees to the processing of data on him/her by Yandex in the manner and for the purposes specified above.
6. Objectives and Principles of PD Processing
6.1 The purposes of PD processing at the University are
To ensure compliance with the Tax Legislation of the Russian Federation, maintain personnel and accounting records, ensure compliance with laws and other regulatory legal acts, assist employees in employment, obtain education and promotion, ensure the personal safety of employees, control the quantity and quality of work performed, and ensure the safety of property;
6.2 PD processing is carried out on the basis of the following principles:
PD processing is carried out on a legal and fair basis;
6.3 PD processing is carried out from the moment of their receipt by the University and is terminated:
By achieving the purposes of PD processing;
7. Rights and Obligations of the Subject of Personal Data
7.1 In accordance with Paragraph 3 of Article 14 of the Federal Law No. 152-FZ "On Personal Data", the PD subject has the right to receive information regarding the processing of the PD.
7.2 Information relating to the processing of PD of the subject, provided to the subject, shall not contain PD relating to other subjects of PD, unless there are legal grounds for disclosing such data.
7.3 The PD subject has the right to require the University to clarify the processed PD, block or destroy them if they are incomplete, outdated, inaccurate, illegally obtained or are not recognized as necessary for the stated purpose of processing, as well as take measures provided for by law to protect the rights.
7.4 The right of the PD subject to access PD may be limited in accordance with the Federal Laws.
8. Personal Data Confidentiality
8.1. The University and other persons who have obtained access to the PD are obliged not to disclose it to third parties and not to distribute Personal Data without the consent of the PD subject, unless it is provided by the Federal law.
9. Receipt and Transfer of Personal Data to Third Parties
9.1 The University in the course of its activities has the right to receive from third parties and transfer PD to third parties in the interests and with the consent of PD subjects, and without the consent of the PD subject in cases stipulated by the Federal Law.
10. Publicly Available Sources of Personal Data
10.1 To provide information to the University, publicly available sources of Personal Data of PD subjects — employees and students of the University, may be created, directories and address books are among others. The publicly available sources of personal data may include PD of the employee with the written consent of the PD subject.
10.2 Information on the PD subject shall be excluded from publicly available sources of personal data at any time upon the request of the PD subject, by the authorised body for the protection of the rights of PD subjects or by a court.
11. Delegation of Personal Data Processing to Another Person
11.1 The University shall have the right to entrust the processing of PD to another person on the basis of a contract concluded with the University only with the consent of the data subject, unless otherwise provided by the Federal Law. A person who processes PD on behalf of the University is obliged to comply with the principles and rules for the processing of Personal Data provided for by the Federal Law “On Personal Data” and this Policy.
12. Rights and Obligations of the University Employees Authorized to Process Personal Data
12.1 Employees authorized to process PD are obliged to:
Be aware of and comply with the requirements of the PD protection legislation;
12.2 Employees are prohibited from processing personal data:
Use of information containing PD for non-official purposes, as well as for official purposes — when negotiating over the telephone network, in open correspondence, articles and speeches;
12.3 Employees Authorized to Process PD are Entitled to:
Provide PD to third parties with the consent of the subject of PD, as well as in other cases stipulated by the current legislation;
13. Measures to Protect Personal Data
13.1 When processing PD, the University takes all the necessary legal, organizational and technical measures to protect it from unauthorized or accidental access, destruction, alteration, blocking, copying, provision, distribution, as well as from other illegal actions.
13.2. The safety of PD is provided, in particular, in the following ways:
13.2.1 Appointment of a person responsible for the organization of PD processing.
13.2.2 The implementation of internal control and audit compliance of Personal Data Processing with the Federal Law No. 152-FZ "On Personal Data" dated July 27, 2006 and regulatory legal acts adopted in accordance with it, as well as with the requirements for the protection of personal data and local acts.
13.2.3 Acquaintance of the University employees directly involved in the processing of PD with the provisions of the Russian Federation legislation on PD, as well as with the requirements for the protection of PD and local acts regarding the processing of PD.
13.2.4 Definition of threats to the safety of PD when processed in Personal Data System.
13.2.5 The use of organizational and technical measures to ensure the safety of PD when it is processed in PD System is necessary to meet the requirements for PD protection.
13.2.6 PD carriers listing.
13.2.7 Identification of unauthorized access to personal data and the adoption of appropriate measures.
13.2.8 Recovery of PD, modified or erased due to unauthorized access to them.
13.2.9 Establishment of rules for access to PD processed in the PD System, as well as ensuring that all actions performed with personal data are recorded in the PD System.
13.2.10 Control of measures taken to ensure the safety of PD and the level of PD System security.
13.2.11 Application of the information security protection measures passed the procedure of conformity assessment in the prescribed manner.
14. Control and supervision of personal data processing
14.1 The duties of officials responsible for monitoring the processing and protection of PD, as well as their responsibility, are defined in the Instruction of the person responsible for organizing the PD processing and in the Instruction of the Information Security Administrator of PD Systems.
14.2 The person in charge of organising the processing of PD and the information security officer for personal data systems and the Administrator are appointed by order of the Rector from among the persons authorised to process PD.
14.3 The authorised body for the protection of the rights of data subjects, which is entrusted with ensuring the control and supervision of the compliance of the processing of personal data with the requirements of the Federal Law No. 152-FZ "On Personal Data" dated July 27, 2006, is the federal executive body for control and supervision in the sphere of communications, information technology and mass communications (The Federal Service for Supervision of Communications (Roskomnadzor)).
14.4 The competent authority for the protection of the rights of the PD subjects shall consider the appeals of the data subject on the conformity of the contents of the PD and the methods of their processing with the purposes of their processing and shall take the appropriate decision.
14.5 The Federal Service for Supervision of Communications, Information Technology, and Mass Media in the Kaliningrad Region:
Address: 236008, Kaliningrad, 4 Kommunalnaya St.
Phone number for enquiries: (4012) 45-15-50
Fax: (4012) 93-00-82
Email: rsockanc39@rsoc.ru
Website: http://39.rsoc.ru/
14.6 Employees of the University authorised to process PD found guilty of violating the requirements of the legislation regarding the protection of PD, including those who authorised the disclosure of PD, shall bear the personal civil, criminal, administrative, disciplinary and other liability provided for by law.
15. Information on the University
Federal State Autonomous Institution of Higher Education 'Immanuel Kant Baltic Federal University'
Legal address (location) for sending requests/complaints by personal data subjects and their representatives regarding inaccuracy of personal data, unlawfulness of its processing, withdrawal of consent and access by the data subject to the data: 236016, Kaliningrad, 14 A. Nevskogo, building 1, office 115.
Email address for sending requests/complaints by personal data subjects and their representatives regarding inaccuracy of personal data, unlawfulness of their processing, withdrawal of consent and access of the personal data subject to their data: post@kantiana.ru
16. Final Provisions
16.1 This Policy is approved by the order of the Rector.
16.2 All the University staff involved in the processing of PD are required to review and comply with this policy.
16.3 The term of the Policy is unlimited.
16.4 Pursuant to Part 2 of Article 18.1. This policy is published on the website of the University in accordance with the Federal Law No. 152-FZ "On Personal Data" dated July 27, 2006.
16.5 The University reserves the right to amend this Policy. The date of the last update of the revision is displayed when the name of the Policy is changed. The new version of the Policy is effective upon posting on the Site, unless the latest version of the Policy provides otherwise.
16.6 Other local University regulations governing the procedure for the protection and processing of PD shall be issued in accordance with this Policy and the personal data legislation.
16.7 Compliance with the policy is monitored by the Rector of the University.
Личный кабинет для
Личный кабинет для cтудента
Даю согласие на обработку представленных персональных данных, с Политикой обработки персональных данных ознакомлен
Подтверждаю согласие