Processing of Personal Data in the Student Union of the University of Jyväskylä

This privacy policy describes the processing of personal data within the Student Union of the University of Jyväskylä (JYY) and its various activities.

Data Controller:

The Student Union of the University of Jyväskylä (JYY)

Keskussairaalantie 2
40600 Jyväskylä
jyy(a)jyy.fi
+358 504306747 

Data Protection Officer: tietosuojavastaava@jyy.fi

You can find information about the processing of personal data in this privacy policy based on the specific group of individuals you are looking for. It is possible for a person to belong to several groups simultaneously: for instance, someone might be both a resident of a property we rent out and a participant in a training session we organize, and they might also use the gym services designated for our residents. In such cases, the descriptions for all these groups apply to the individual. However, this grouping facilitates finding relevant information, as often only specific processing activities may be of interest.

Additionally, this privacy policy outlines the rights applicable to everyone, explains how we protect personal data, and provides the contact information of the supervisory authority in case someone needs to submit their matter for official review.

Legislation

The Student Union complies with the Administrative Procedure Act (434/2003) when performing public administrative duties. The public access to the activities of the Student Union is governed by the provisions of the Act on the Openness of Government Activities (621/1999) concerning the transparency of activities carried out by public authorities as defined in Section 4(1) of the Act.

Hallintolaki (434/2003): Administrative Procedure Act (434/2003)

Laki viranomaisten toiminnan julkisuudesta (621/1999): Act on the Openness of Government Activities (621/1999)

The Student Union of the University of Jyväskylä – Processing of Student Data

Other Activities of the Student Union and Alumni

The Council of Representatives’ Registries

Registries on Soihtu Business Unit of JYY and other registries

Principles of Register Security

The data in the register is stored in databases protected by firewalls, passwords, and other necessary technical measures, such as encryption.

Access to systems containing personal data of students or our stakeholders is restricted to designated employees of the Student Union of the University of Jyväskylä, who need such access to perform their duties. All employees have ongoing access to guidelines for the secure and lawful handling of personal data and other information entrusted to us.

Paper-based and digital materials are disposed of securely to ensure data protection.

Risk Management for Data Subjects

Efforts are made to minimize risks to data subjects in the processing of personal data. Risk management measures include regular risk assessments and impact assessments related to personal data processing.

In the event of a data breach, the controller will urgently assess and mitigate potential risks to the data subject. If it is likely that the breach poses a high risk to the data subject’s rights and freedoms, the controller will notify the data subject of the breach.

Data Subject Rights and How to Exercise Them

Individuals have certain rights regarding the personal data we process. This section provides a general overview of those rights. Exceptions to these rights may apply depending on the legal basis for the processing. Details about such exceptions can be found in the descriptions of specific groups of individuals earlier in this document.

If you wish to exercise your rights, please contact the designated contact person mentioned at the beginning of this statement. To expedite the process, specify whether you are a student, a resident in one of our rental properties, or if your request concerns participation in events or services at the Student Union building. If your request pertains to a specific period, providing these details will significantly speed up the process. Supplying identifiers such as your student number or other relevant details can also facilitate a quicker response.

Rights can generally be exercised free of charge once per calendar year. If multiple requests are made by the same individual within a calendar year, an administrative fee may be applied based on the scope of the request. You will be informed of the estimated cost in advance.

Right to Access Personal Data

Data subjects have the right to obtain a copy of their personal data in a commonly used electronic format and review their information.

Right to Rectification

Data subjects have the right to have inaccurate or incorrect data rectified. This right can be exercised by notifying the data controller and providing the correct information. Individuals can request the correction of inaccurate or incomplete data.

Right to Erasure

Anyone has the right to request the deletion of their data. Deletion can be carried out, for example, in the following cases:

You withdraw your consent, and there is no other basis for processing the personal data.

You object to the processing of your personal data, and there is no overriding reason to continue processing.

Outdated and unnecessary data is automatically removed whenever possible, without requiring a separate request. However, personal data processed for contractual or billing purposes may need to be retained in compliance with accounting laws or other legal obligations.

Right to Restrict Processing

Data subjects have the right to request the restriction of processing their personal data. This applies, for example, in cases where there is uncertainty regarding the accuracy or lawfulness of the data processing, but retaining the data is necessary to resolve the uncertainty. However, the right to restrict processing does not apply in cases where the law requires data retention. For example, accounting laws mandate retaining financial records for 10 years.

Right to Object

Data subjects have the right to object to the processing of their personal data if it is being processed based on our legitimate interests or for tasks in the public interest (e.g., scientific or historical research, statistical purposes, or direct marketing).

Right to Data Portability

In certain situations, data subjects have the right to transfer the data they have provided to another system. This applies when the processing of personal data is based on consent or a contract. If we cannot transfer personal data automatically, you have the right to receive the data you have provided in a machine-readable format to enable further transfer.

Automated Decision-Making and Profiling

In digital service channels, data provided by the data subject may be automatically assessed, for example, to verify eligibility for a contract.

When automated processing and related decision-making are used, the data subject has the right to object if the procedure is not essential for entering into or executing a contract. In such cases, data subjects will be informed about alternative ways to proceed with their matters through other channels.

Right to Withdraw Consent

Data subjects have the right to withdraw their consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. Withdrawal of consent will not impact the quality or content of the services we provide.

Right to File a Complaint with a Supervisory Authority

If a data subject believes that their data has been processed improperly or unlawfully, we encourage contacting us first so that we can address the issue together. If our response is not satisfactory, you also have the right to lodge a complaint with the relevant supervisory authority.

We encourage you to always contact us first to help resolve any issues as quickly as possible.

Office of the Data Protection Ombudsman

The Data Protection Ombudsman is the national supervisory authority in Finland responsible for monitoring and ensuring compliance with data protection laws. If you believe that your personal data has been processed unlawfully or improperly, you have the right to file a complaint with the Data Protection Ombudsman.

Contact details for the Data Protection Ombudsman:

Website: www.tietosuoja.fi

Email: tietosuoja@om.fi

Postal Address:

Data Protection Ombudsman

P.O. Box 800

00521 Helsinki

Finland

The Ombudsman can help resolve disputes regarding the processing of personal data and provide guidance on your rights.

Data Transfers and Disclosures

The subcontractors we use are always committed to processing data only according to our instructions and for the purposes we have defined. All subcontractors are contractually obligated to this, as well as to maintain confidentiality regarding the personal data they process on our behalf.

Data is not generally disclosed outside of JYY.

If data is transferred to third countries, this will be communicated at the time of data collection. Data processing may involve systems or cloud services that store data outside the EU. If data is transferred outside the European Union or the European Economic Area, such a transfer requires that the country in question ensures an adequate level of data protection, or the data controller provides sufficient safeguards regarding the privacy and rights of individuals through contractual clauses or other means, or the data subject has given explicit consent to the transfer. Transfers to the United States are based on the European Commission’s decision on the adequacy of data protection under Article 45 of the GDPR and the Privacy Shield agreement.

Changes to the Privacy Policy

We update the privacy policy as necessary. If the changes are significant, we aim to inform the individuals affected directly. Any questions or inquiries regarding the privacy policy can be sent to the Data Protection Officer, whose contact details are provided at the beginning of this document.

Document Status and Version

This Privacy Policy was reviewed on June 23rd, 2026, and is currently in the draft stage. The document has not yet been approved by a decision of the Student Union’s competent body.

The draft is not yet final or binding in all respects, and its content may change during the preparation process. The final, approved version will be published separately.

This policy will supersede any previous privacy policies of the organizations and companies mentioned earlier.

Note: This translation is provided for informational purposes only. The content has not been legally reviewed, and the official document is the one in the original language.