Privacy Policy on the processing of personal data for Library services

Article 13 Reg. EU/2016/679

Foreword

Luiss, Libera Università Internazionale degli Studi Sociali Guido Carli (hereinafter, “Luiss” or the “Data Controller”), is an independent university that offers an advanced educational model.

This policy describes the characteristics of the processing carried out by Luiss on the personal data of users who make use of the Library's services, including through dedicated IT platforms and applications, such as the Alma cloud platform, highlighting the rights granted to data subjects by Regulation (EU) 2016/679 (hereinafter, the “GDPR”) and by applicable law.

This notice is periodically updated to ensure compliance with current legislation or new methods of processing personal data.

What personal data do we collect?

The Data Controller collects and processes the following personal data:

  • identification data of the data subject (first name, last name, tax code, student ID number, and institutional ID);
  • contact details (address, email and telephone number);
  • type of user (e.g. faculty, students, staff and external parties);
  • data relating to the account and authorization to use Library services;
  • data relating to the use of library services, such as requests, reservations, loans, renewals, returns, late returns, suspensions and any amounts associated with the services;
  • technical data and usage logs necessary for the security, operation and support of the platforms used;
  • content of support requests, reports, complaints, suggestions, and communications exchanged with the Library.

The Alma platform is not intended for the collection of special categories of personal data pursuant to Article 9 of the GDPR or of any other information not necessary for the provision of library services. The user is therefore asked not to enter special categories of personal data in the free-text fields or in support requests.

For what purposes do we collect your data, and why is the processing lawful?

The Data Controller collects and processes the Data Subject’s personal information for the following purposes:

  • to manage the relationship with the user from an administrative standpoint (the legal basis is: performance of the relationship with the data subject and, where applicable, performance of the University’s institutional tasks).
  • to manage, including through the Alma platform, the user’s personal data, authorization and authentication for library services (the legal basis is: performance of the relationship with the data subject and, where applicable, performance of the University’s institutional tasks).
  • to manage the use and circulation of paper and electronic materials, including requests, reservations, loans, renewals, returns, late returns, suspensions and any amounts related to the services (the legal basis is: performance of the relationship with the data subject).
  • to create and manage the personal account for accessing Library services (the legal basis is: performance of the relationship with the data subject).
  • to send communications that are strictly necessary for the management of Library services (the legal basis is: performance of the relationship with the data subject).
  • to allow and manage the submission of reports, complaints and suggestions (the legal basis is: performance of the relationship with the data subject).
  • to allow requests for manuals, essays, articles and periodicals (the legal basis is: performance of the relationship with the data subject).
  • to assist the user in using the services and to handle requests for assistance, purchase or search for monographs and periodicals (the legal basis is: performance of the relationship with the data subject).
  • to assist the user in the provision of inclusion services (the legal basis is: performance of the relationship with the data subject and, if special categories of data are processed, the explicit consent of the data subject or another appropriate condition provided for in Article 9 GDPR).
  • to allow the reservation of computer workstations dedicated to the Library’s services (the legal basis is: performance of the relationship with the data subject).
  • to ensure the security, business continuity, maintenance, and technical support of the platforms used (the legal basis is: the Data Controller's legitimate interest in the security and proper functioning of the systems, with due regard for the fundamental rights and freedoms of the data subjects, as well as compliance with applicable legal obligations).

How does the Data Controller process your personal data, and for how long does it retain them? 

The Data Subject’s personal data are processed in paper and electronic form, using servers, cloud databases, application software, and dedicated platforms. The processing is carried out using appropriate technical and organizational measures to ensure the security, confidentiality, integrity and availability of the data.

Account data and data necessary for managing the relationship with the Library are retained for the period during which the user is authorized to use library services and, subsequently, for the time necessary to complete any pending transactions, handle any disputes and comply with legal obligations. The history of library operations is retained according to the timeframes defined in the University’s retention plan and, where possible, deleted or anonymized when no longer necessary. Technical data and security logs are retained for the period strictly necessary for the security and management of the service.

Information collected for the provision of inclusive library services is retained for 12 months, unless a different period is necessary to comply with legal obligations, protect a right, or respond to a request from the data subject.

To whom do we disclose your personal data?

  • Internal disclosure

Only University employees and collaborators who need to access the data subject’s personal data in order to provide the requested services may do so, and only to the extent of the relevant and necessary information. These individuals are authorized to process data and are adequately informed and trained in the field of personal data protection.

  • External disclosure

The Data Controller shares personal data with suppliers that assist it in providing and managing the Library’s services, appointed, where necessary, as Data Processors pursuant to Article 28 GDPR. These include, by way of example, EasyStaff S.r.l., Formstack, and Ex Libris Italy S.r.l., companies of the Clarivate Group.

For the management of the Alma platform, Ex Libris Italy S.r.l. processes data on behalf of Luiss as a data processor. The Data Processor may use affiliated companies and other suppliers, appointed as sub-processors, for activities such as hosting, maintenance, technical support, security, backup, and business continuity, in compliance with the instructions given by Luiss and the obligations set forth in applicable law.

The data may also be disclosed to public entities, administrative or judicial authorities, and other recipients in cases provided for by law or when disclosure is necessary to establish, exercise, or defend a right. The data are not disclosed.

Are your data transferred abroad?

As part of the provision of library services, some personal data may be processed or made accessible by companies belonging to the group of suppliers or by their sub-processors established in countries outside the European Economic Area. Such transfers are carried out in compliance with Articles 44 et seq. of the GDPR, on the basis of an adequacy decision by the European Commission or, where necessary, by means of standard contractual clauses approved by the European Commission and the adoption of any additional measures.

Are automated decisions envisaged?

The processing operations described in this notice do not involve decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect the data subject.

What are your rights as a data subject, and how can you exercise them?

The GDPR grants specific rights to the data subject. In the cases and within the limits provided for by law, the Data Subject may exercise:

  • the right to access their personal data and to obtain a copy thereof;
  • the right to obtain the rectification of inaccurate data and the integration of incomplete data;
  • the right to erasure of personal data;
  • the right to restrict processing;
  • the right to object to the processing, where applicable;
  • the right to data portability, where applicable;
  • the right to withdraw any consent given at any time, without affecting the lawfulness of the processing carried out prior to the withdrawal;
  • the right to obtain information on the safeguards applied to any transfers of data to third countries;
  • the right to lodge a complaint with the Italian Data Protection Authority, pursuant to Article 77 of the GDPR, or to take legal action.

Data subjects may exercise their rights by sending an email, without any particular formalities, to privacy@luiss.it or by writing to the Data Controller, Luiss Guido Carli, ref. Privacy – DPO, Viale Pola 12 – 00198 Rome, specifying their request and providing the information necessary to identify them.

The contact information for the Data Protection Officer (DPO) is as follows: dpo@luiss.it.