Personal Data Processing Policy

1. Definitions and Abbreviations used in the Personal Data Processing and Protection Policy in the Federal State Autonomous Educational Institution of Higher Education "Immanuel Kant Baltic Federal University
«

1.1 Personal Data (PD) — any information related to directly or indirectly specified individual (personal data subject).

1.2 Personal Data Processing — any action (operation) or a series of actions (operations) performed towards personal data with or without use of the software, including collection, recording, systematization, accumulation, storage, update and alteration, extraction, use, transfer (distribution, presentation, provision), depersonalization, blocking, deleting and destruction of personal data.

1.3 Personal Data Distribution — any actions aimed at the disclosure of Personal Data to an indefinite set of persons.

1.4 Personal Data Provision — any actions aimed at disclosing Personal Data to a certain person or a certain set of persons.

1.5 Personal Data Blocking — temporary Personal Data Processing suspension (unless processing is necessary to clarify Personal Data).

1.6 Personal Data Destruction — any actions making it impossible to restore Personal Data volume in the Personal Data information system and/or resulting in the elimination of tangible media.

1.7 Personal Data Depersonalisation — any actions making it impossible to identify Personal Data as related to a certain data subject without involving additional information.

1.8 Personal Data Information System (PDIS) — a set of Personal Data included into Personal Data databases, as well as the software and tools used for their processing

1.9 Information — information (messages, data), regardless of the form of its presentation.


2. General Provisions

2.1 This document determines the Policy of the Federal Autonomous Educational Institution of Higher Education «Immanuel Kant Baltic Federal University» (hereinafter — the University) in relation to the Personal Data Processing and Protection.

2.2. Personal Data Processing and Protection Policy of the University (hereinafter — the Policy) determines:

The legal framework for ensuring the safety of PD;

Principles and purposes of PD Processing;

Lists of PD subjects and processed by PD;

Operations performed with PD, and terms of their processing;

Rights and obligations of the subjects and employees of the University when Processing PD;

The measures taken by the University to protect PD;

Control and supervision of PD Processing.

2.3. The Policy is based on the Federal Law No. 152-FZ «On Personal Data», Chapter 2, Article 18.1 dated July 27, 2006 and taking into account the requirements of the Constitution of the Russian Federation, legislative and other regulatory legal acts of the Russian Federation on personal data protection.

2.4. The purpose of this Policy is to determine the procedure for Processing Personal Data of citizens; ensuring the protection of the rights and freedoms of a person and a citizen in Personal Data Processing, including the protection of the privacy rights, personal and family confidentiality, as well as establishing the responsibility of officials who have the access to citizens Personal Data for non-compliance with the requirements and standards governing Personal Data Processing and Protection.

2.5. This Policy applies to all Personal Data processed at the University, received before and after signing of this Policy.

2.6. This Policy applies to Personal Data processed with both the use of automatic equipment and without them.

2.7. This Policy applies to all processes in which the processing of Personal Data of the PD subjects of all categories, as well as officials involved in these processes.

2.8. The main provisions of the document can also be extended to divisions of other organizations and institutions that interact with the University as suppliers and consumers (users) of information.


3. Legal Basis of Personal Data Processing

3.1 The Policy is based on the following regulatory legal acts of the Russian Federation:

  • Civil Code of the Russian Federation;

  • Tax Code of the Russian Federation;

  • Labour Code of the Russian Federation;

  • Federal Law of the Russian Federation No. 273-FZ «On Education in the Russian Federation» dated December 29, 2012;

  • Federal Law No. 323-FZ «On the Fundamentals of Protecting the Health of Citizens in the Russian Federation» dated November 21, 2011;

  • Federal Law No.326-FZ «Compulsory Medical Insurance in the Russian Federation» dated November 29, 2010;
  • Federal Law No.167-FZ «On Mandatory Pension Insurance in the Russian Federation» dated December 15, 2001;
  • Federal Law No.27-FZ «On Individual (personal) Registration in the System of Compulsory Pension Insurance» dated April 1, 1996;
  • Federal Law No.59-FZ «On the Procedure for Considering of Appeals by Citizens of the Russian Federation» dated May 2, 2006;
  • Federal Law No.125-FZ «On Archiving in the Russian Federation» dated October 22, 2004;
  • Federal Law No. 402-FZ «On Accounting» dated December 6, 2011
  • Administrative Regulations of the Ministry of Internal Affairs of the Russian Federation for the provision of public services for the implementation of migration registration of the Russian Federation citizens in the Russian Federation Russian Federation to the place of stay and at place of residence within the Russian Federation Federal Law (approved by No.984 the Ministry of Internal Affairs of the Russian Federation dated December 31, 2017)
  • Federal Law No. 115-FZ «On the Legal Status of Foreign Citizens in the Russian Federation» dated July 25, 2002;
  • Federal Law No.114-FZ «On the Procedure for Exit from the Russian Federation and Entry into the Russian Federation» dated August 15, 1996;
  • Federal Law No.109-FZ «On Migration Registration of Foreign Citizens and Stateless Persons in the Russian Federation» dated 18.07.2006 dated 18 July, 2006;
  • Order of the Ministry of Internal Affairs of Russia No. 856 «On the approval of the administrative regulations of the Ministry of Internal Affairs of the Russian Federation for the provision of public services for the implementation of migration registration of foreign citizens or stateless persons in the Russian Federation, forms of application for registration of a foreign citizen or stateless person at the place of residence, notifications of the arrival of a foreign citizen or stateless person to the place of stay, notes on the registration of a foreign citizen or state of law at the place of residence, marks on confirmation of the execution by the receiving party and a foreign citizen of the actions necessary for registration at the place of stay, affixed, among others, by the Multifunctional Center for Provision of State and Municipal Services» dated December 10, 2020 No. 856;
  • Order of the Ministry of Internal Affairs of the Russian Federation No. 907 «On approval of Administrative regulations of the Ministry of Internal Affairs of the Russian Federation on provision of the state service in registration, issue, prolongation of effective period and recovery of visas to foreign citizens and stateless persons» dated December 4, 2019;
  • Decree of the Government of the Russian Federation No.9 «On the Procedure for Migration Registration of Foreign Citizens and Stateless Persons in the Russian Federation» dated January 15, 2007;
  • Federal Law No.63-FZ «On Electronic Signature» dated April 6, 2011;
  • Decree of the Government of the Russian Federation No. 1802 On approval of the Rules for posting on the official website of an educational organization on the Internet and updating information about the educational organization, as well as on the invalidation of some acts and certain provisions of some acts of the Government of the Russian Federation dated October 20, 2021;
  • Order of the Ministry of Education and Science of Russia No. 1076 «On Approval of the Procedure for admission to study under educational programs of higher education — Undergraduate programs, Specialty programs, Master's programs» dated August 21, 2020;
  • Federal Law No. 53-FZ «On Military Duty and Military Service» dated March 28, 1998 and «Provision on Military Registration» approved by the Decree of the Government of the Russian Federation No. 719 dated November 27, 2006;
  • Charter of Federal State Autonomous Educational Institution of Higher Education Immanuel Kant Baltic Federal University;
  • License for educational activities No.1797 dated December 3, 2015;
  • Licenses for medical activities No. FS-39-01-000812 dated September 21, 2016;
  • Consent of the Personal Data subject;
  • Executing an agreement to which the personal data subject is a party.


4. Personal Data processed at the University

4.1 The PD transferred to the University concern the following categories of data subjects:

  • Employees;

  • Students;

  • Applicants;

  • Patients;

  • Parties: persons or entities engaged in contractual arrangements with the University.

4.2 List of PD of employees processed at the University:

  • Full name;

  • Previous surname, name, patronymic/middle name (if any);
  • Date, place and reason for the change (in case of change in legislation);
  • Date and place of birth;
  • Data of the identity document (series, number, when and where issued, subdivision code);
  • Address of permanent registration and residence;
  • Citizenship;
  • Gender;
  • Email;
  • Contact phone number (office, home, mobile);
  • Marital status;
  • Family composition: degree of kinship, full name, date of birth of close relatives;
  • Tax payer ID;
  • Code of the insurance certificate of the Pension Fund of the Russian Federation (SNILS);
  • Information on military registration;
  • Information on the Federal State Civil Service (Municipal Service);
  • Information on education, advanced training, and professional retraining;
  • Information on the academic degree, academic ranks;
  • Information on foreign language proficiency, level of proficiency;
  • Job position;
  • Data on seniority, including previous workplaces, employment records, dismissal, transfer;
  • Information on scientific research, publications, results of scientific research;
  • Information about state awards, other awards, honours, incentives;
  • Details of the civil registration certificate;
  • Information on payroll accruals;
  • Data on tax deductions;
  • Information on social benefits provided for by the Russian Federation Legislation;
  • Bank account number, bank name;
  • Information on health insurance;
  • Information on the state of health;
  • Information on vaccination;
  • Information on the presence/absence of a criminal record (including terms and grounds);
  • Photography;
  • Face image (biometric personal data).

4.3 The List of PD of Students Processed at the University:

  • Full name;

  • Date and place of birth;
  • Passport data (series, number, when and where issued, subdivision code);
  • Address of permanent registration and residence;
  • Email;
  • Gender;
  • Citizenship;
  • Registering number;
  • Medical examination report details (number and date of issue);
  • Information on health/disability (disability group, health group, medical group for physical education);
  • Social conditions;
  • Preferential training conditions;
  • Enrolment date;
  • University orders (date, number, reason for transfer);
  • Information on the educational activities of students;
  • Information on the expulsion (reason, grounds, number and date of the order);
  • Information on training (major, group, course, level, qualification, form of training and basis);
  • Information on the accrual of scholarship and other payments;
  • Contact phone number;
  • Photography;
  • Information on legal representatives (full name, place of work, phone number);
  • Information on the results of the United State Examination;
  • Face image (biometric personal data).

4.4 List of PD of Applicants Processed at the University:

  • Full name;

  • Date and place of birth;
  • Gender;
  • Citizenship;
  • Address of permanent registration and residence;
  • Data of the identity document (series, number, when and where issued, subdivision code);
  • Information on legal representatives (full name, place of work, phone number);
  • Results of entrance examinations (USE, etc.);
  • Information on previous education (qualification, major, level of mastery);
  • Information on the medals received and participation in the Olympiads;
  • Information on special rights/benefits;
  • Information on individual achievements;
  • Insurance number of individual personal account (SNILS);
  • Email;
  • Phone number;
  • Photography;
  • Information on the previously attended educational institutions (city, name, type, year of graduation);
  • Information of the education document (type, series, number, date of issue);
  • Information on the language being studied;
  • Information on grades from the educational certificate (subjects and grades);
  • Information on the submitted applications (major, level, qualification, form of training and basis);
  • PD of legal representatives: full name; address of permanent registration and residence; place of work; data of an identity document (series, number, when and where issued, subdivision code);
  • Phone number.

4.5 List of PD of patients processed at the University:

  • Full name;

  • Date of birth;
  • Gender;
  • Citizenship;
  • Address of permanent registration and residence;
  • Data of the identity document (series, number);
  • Insurance number of individual personal account (SNILS);
  • Information on health insurance;
  • Data on the selected insurance medical organization;
  • Date of registration as an insured person;
  • Status of the insured person (employed, unemployed);
  • Types, conditions, terms, volumes and cost of medical care provided;
  • Information on the state of health, including diagnosis;
  • Records of medical services;
  • Phone number.
4.6 The list of PD of parties: persons or entities engaged in contractual arrangements with the University who are in contractual relations with the University, processed at the University:
  • Full name;
  • Date and place of birth;
  • Passport data (series, number, when and where issued, subdivision code);
  • Address of permanent registration and residence;
  • Citizenship;
  • Gender;
  • Contact phone number;
  • Information on the presence/absence of a criminal record;
  • Photography;
  • Tax payer ID;
  • Information of the document confirming registration in the system of individual (personalized) accounting, including the insurance number of the individual personal account (SNILS);
  • Information on education, advanced training, and professional retraining;
  • Information on the academic degree, academic ranks;
  • Information on foreign language proficiency, level of proficiency;
  • Information on military registration;
  • Information on employment and seniority;
  • Information on monetary remuneration;
  • Bank account number, bank name;
  • Information on health insurance;
  • Medical report on the state of health;
  • Face image (biometric personal data).
  • Information on military registration;
  • Marital status;
  • Data on children (full name, date of birth);
  • Next of kin (full name, status, date of birth);
  • Data on tax deductions;

5. Operations Performed with Personal Data

Personal Data Processing Terms

5.1 The University collects, records, organizes, accumulates, stores, clarifies (updates, changes), extracts, uses, transfers (distributes, provides, accesses), depersonalizes, blocks, deletes, destroys PD.

5.2 For biometric PD, the transfer (distribution, provision, access) is not carried out, except as provided for by the Federal Law.

5.3 The term for processing PD of the employees, including biometric Personal Data, is during the term of the employment contract and 75 subsequent years after its expiration, unless a different period of archival storage is established in accordance with the current legislation.

5.4 The term of PD processing of students, including biometric PD during the period of studying, and 75 subsequent years after its completion, unless another period of archival storage is established in accordance with the current legislation.

5.5 The term of PD processing of applicants in case of enrollment in Federal State Autonomous Educational Institution of Higher Education 'Immanuel Kant Baltic Federal University' (IKBFU) During the period of studying, and 75 subsequent years after its completion, unless another period of archival storage is established in accordance with the current legislation. In case of non-enrollment in IKBFU — until the end of the last month of the current year.

5.6 The term for processing the PD of patients is during the period of medical care, and 25 subsequent years after, unless a different period of archival storage is established in accordance with the current legislation.

5.7 The term of processing PD of individuals in contractual relations with the University, including biometric PD, during the term of the contract, and 5 subsequent years, unless a different period of archival storage is established in accordance with the current legislation.

5.8. The University uses cookies to identify the user. Cookies are text files available to the University, used to process information about the user's activity, including information about which pages the user visited and the time the user spent on the page. The user can disable the use of cookies in the browser settings.

5.9. The University website uses the Yandex Metric web analytics service provided by YANDEX LLC, 119021, Moscow, 16 Leo Tolstoy St.

The information collected by the cookies cannot identify the user, but it can help improve the performance of the university website. Information on the use of the University website by the user, collected using cookies, is transferred to Yandex and stored on the Yandex server in the EU and the Russian Federation. Yandex processes this information to evaluate the user's use of the site, to compile reports for the University on the activities of the University site, and to provide other services. Yandex processes this information in the manner prescribed in the Yandex Metrica Terms of Use.

The user can refuse the use of cookies by selecting the appropriate settings in the browser. The user can also use the tool — https://yandex.ru/support/metrika/general/opt-out.html. However, this may affect some features of the site. By using this site, the user agrees to the processing of data on him/her by Yandex in the manner and for the purposes specified above.


6. Objectives and Principles of PD Processing

6.1 The purposes of PD processing at the University are

  • To ensure compliance with the Tax Legislation of the Russian Federation, maintain personnel and accounting records, ensure compliance with laws and other regulatory legal acts, assist employees in employment, obtain education and promotion, ensure the personal safety of employees, control the quantity and quality of work performed, and ensure the safety of property;

  • To ensure compliance with the Legislation of the Russian Federation in education, carry out scientific, literary or other creative activities, conducting research, carry out educational, research, financial and economic activities;
  • To ensure compliance with the Legislation of the Russian Federation in health care, provision of medical services;
  • Preparation, entering into and execution of a Civil Law contract;
  • To inform visitors of information resources about the staff, events and activities of the University;
  • To inform visitors of information resources via the contact forms;
  • To provide access to the services contained on the website via the use of a personal account;
  • To issue a bank card for making payments and other remuneration;
  • To ensure compliance with the Russian Federation's Defence Legislation, military records keeping;
  • Organization of access control to the operator's territory to ensure security and counter-terrorism.

6.2 PD processing is carried out on the basis of the following principles:

  • PD processing is carried out on a legal and fair basis;

  • PD processing is limited to the achievement of specific, predetermined and legitimate purposes;
  • PD processing incompatible with the purposes when collecting PD is not allowed;
  • It is not allowed to combine databases containing PD, the processing of which is carried out for purposes incompatible with each other;
  • PD that are only used for the purposes of their processing are the subject of the processing;
  • The content and volume of PD processed corresponds to the stated purposes of processing;
  • The PD, its accuracy, processing efficiency and, where appropriate, its relevance to the purposes of the PD processing are ensured;
  • When storing personal data, the personal data operator is obliged to use databases located in the territory of the Russian Federation, in accordance with Chapter 4 of Article 18 of the Federal Law «On Personal Data» to the extent provided by law.

6.3 PD processing is carried out from the moment of their receipt by the University and is terminated:

  • By achieving the purposes of PD processing;

  • Due to the absence of the need to achieve the previously stated purposes of PD processing;
  • By withdrawing consent to process PD;
  • By the expiration of the consent;
  • By detection of unlawful processing of Personal Data.

7. Rights and Obligations of the Subject of Personal Data

7.1 In accordance with Paragraph 3 of Article 14 of the Federal Law No. 152-FZ «On Personal Data», the PD subject has the right to receive information regarding the processing of the PD.

7.2 Information relating to the processing of PD of the subject, provided to the subject, shall not contain PD relating to other subjects of PD, unless there are legal grounds for disclosing such data.

7.3 The PD subject has the right to require the University to clarify the processed PD, block or destroy them if they are incomplete, outdated, inaccurate, illegally obtained or are not recognized as necessary for the stated purpose of processing, as well as take measures provided for by law to protect the rights.

7.4 The right of the PD subject to access PD may be limited in accordance with the Federal Laws.


8. Personal Data Confidentiality

8.1. The University and other persons who have obtained access to the PD are obliged not to disclose it to third parties and not to distribute Personal Data without the consent of the PD subject, unless it is provided by the Federal law.


9. Receipt and Transfer of Personal Data to Third Parties

9.1 The University in the course of its activities has the right to receive from third parties and transfer PD to third parties in the interests and with the consent of PD subjects, and without the consent of the PD subject in cases stipulated by the Federal Law.


10. Publicly Available Sources of Personal Data

10.1 To provide information to the University, publicly available sources of Personal Data of PD subjects — employees and students of the University, may be created, directories and address books are among others. The publicly available sources of personal data may include PD of the employee with the written consent of the PD subject.

10.2 Information on the PD subject shall be excluded from publicly available sources of personal data at any time upon the request of the PD subject, by the authorised body for the protection of the rights of PD subjects or by a court.


11. Delegation of Personal Data Processing to Another Person

11.1 The University shall have the right to entrust the processing of PD to another person on the basis of a contract concluded with the University only with the consent of the data subject, unless otherwise provided by the Federal Law. A person who processes PD on behalf of the University is obliged to comply with the principles and rules for the processing of Personal Data provided for by the Federal Law “On Personal Data” and this Policy.


12. Rights and Obligations of the University Employees Authorized to Process Personal Data

12.1 Employees authorized to process PD are obliged to:

  • Be aware of and comply with the requirements of the PD protection legislation;

  • Maintain the confidentiality of the PD, report breaches of the PD processing procedure and attempts to gain unauthorised access to the PD;
  • Comply with the rules for the use of PD, the order in which they are accounted for and stored, in order to prevent access by unauthorised persons;
  • Process only PD that is accessed due to the performance of official duties.

12.2 Employees are prohibited from processing personal data:

  • Use of information containing PD for non-official purposes, as well as for official purposes — when negotiating over the telephone network, in open correspondence, articles and speeches;

  • Transmission of PD via unprotected communication channels (teletype, fax communication, email) without using certified means of cryptographic protection of information.

12.3 Employees Authorized to Process PD are Entitled to:

  • Provide PD to third parties with the consent of the subject of PD, as well as in other cases stipulated by the current legislation;

  • Reasonably refuse to the PD subject (or their representative) to satisfy the request for information concerning the PD processing of the subject, if there are grounds provided by the legislation of the Russian Federation.

13. Measures to Protect Personal Data

13.1 When processing PD, the University takes all the necessary legal, organizational and technical measures to protect it from unauthorized or accidental access, destruction, alteration, blocking, copying, provision, distribution, as well as from other illegal actions.

13.2. The safety of PD is provided, in particular, in the following ways:

13.2.1 Appointment of a person responsible for the organization of PD processing.

13.2.2 The implementation of internal control and audit compliance of Personal Data Processing with the Federal Law No. 152-FZ «On Personal Data» dated July 27, 2006 and regulatory legal acts adopted in accordance with it, as well as with the requirements for the protection of personal data and local acts.

13.2.3 Acquaintance of the University employees directly involved in the processing of PD with the provisions of the Russian Federation legislation on PD, as well as with the requirements for the protection of PD and local acts regarding the processing of PD.

13.2.4 Definition of threats to the safety of PD when processed in Personal Data System.

13.2.5 The use of organizational and technical measures to ensure the safety of PD when it is processed in PD System is necessary to meet the requirements for PD protection.

13.2.6 PD carriers listing.

13.2.7 Identification of unauthorized access to personal data and the adoption of appropriate measures.

13.2.8 Recovery of PD, modified or erased due to unauthorized access to them.

13.2.9 Establishment of rules for access to PD processed in the PD System, as well as ensuring that all actions performed with personal data are recorded in the PD System.

13.2.10 Control of measures taken to ensure the safety of PD and the level of PD System security.

13.2.11 Application of the information security protection measures passed the procedure of conformity assessment in the prescribed manner.


14. Control and supervision of personal data processing

14.1 The duties of officials responsible for monitoring the processing and protection of PD, as well as their responsibility, are defined in the Instruction of the person responsible for organizing the PD processing and in the Instruction of the Information Security Administrator of PD Systems.

14.2 The person in charge of organising the processing of PD and the information security officer for personal data systems and the Administrator are appointed by order of the Rector from among the persons authorised to process PD.

14.3 The authorised body for the protection of the rights of data subjects, which is entrusted with ensuring the control and supervision of the compliance of the processing of personal data with the requirements of the Federal Law No. 152-FZ «On Personal Data» dated July 27, 2006, is the federal executive body for control and supervision in the sphere of communications, information technology and mass communications (The Federal Service for Supervision of Communications (Roskomnadzor)).

14.4 The competent authority for the protection of the rights of the PD subjects shall consider the appeals of the data subject on the conformity of the contents of the PD and the methods of their processing with the purposes of their processing and shall take the appropriate decision.

14.5 The Federal Service for Supervision of Communications, Information Technology, and Mass Media in the Kaliningrad Region:

Address: 236008, Kaliningrad, 4 Kommunalnaya St.

Phone number for enquiries: (4012) 45-15-50

Fax: (4012) 93-00-82

Email: rsockanc39@rsoc.ru

Website: http://39.rsoc.ru/

14.6 Employees of the University authorised to process PD found guilty of violating the requirements of the legislation regarding the protection of PD, including those who authorised the disclosure of PD, shall bear the personal civil, criminal, administrative, disciplinary and other liability provided for by law.


15. Information on the University

Federal State Autonomous Institution of Higher Education 'Immanuel Kant Baltic Federal University'

Legal address (location) for sending requests/complaints by personal data subjects and their representatives regarding inaccuracy of personal data, unlawfulness of its processing, withdrawal of consent and access by the data subject to the data: 236016, Kaliningrad, 14 A. Nevskogo, building 1, office 115.

Email address for sending requests/complaints by personal data subjects and their representatives regarding inaccuracy of personal data, unlawfulness of their processing, withdrawal of consent and access of the personal data subject to their data: post@kantiana.ru


16. Final Provisions

16.1 This Policy is approved by the order of the Rector.

16.2 All the University staff involved in the processing of PD are required to review and comply with this policy.

16.3 The term of the Policy is unlimited.

16.4 Pursuant to Part 2 of Article 18.1. This policy is published on the website of the University in accordance with the Federal Law No. 152-FZ «On Personal Data» dated July 27, 2006.

16.5 The University reserves the right to amend this Policy. The date of the last update of the revision is displayed when the name of the Policy is changed. The new version of the Policy is effective upon posting on the Site, unless the latest version of the Policy provides otherwise.

16.6 Other local University regulations governing the procedure for the protection and processing of PD shall be issued in accordance with this Policy and the personal data legislation.

16.7 Compliance with the policy is monitored by the Rector of the University.

Личный кабинет для

Личный кабинет для cтудента

Даю согласие на обработку представленных персональных данных, с Политикой обработки персональных данных ознакомлен

Подтверждаю согласие