Privacy notice: Processing of Student Personal Data

(EU General Data Protection Regulation 2016/379, Articles 13 and 14)

In this notice, we provide detailed information about the purpose for which we collect your personal data and how we process it. Personal data includes any information by which you can be directly or indirectly identified.

What is the basis for processing your personal data?

The processing of your personal data is based on Vaasa University of Applied Sciences’ legal obligation and the legitimate interest of students to pursue their studies and utilize study-related benefits and services.

The processing is based on the following laws and regulations:

  • Universities of Applied Sciences Act (L932/2014)
  • Government Decree on Universities of Applied Sciences (A1129/2014)
  • Act on the National Registers of Education Records, Qualifications and Degrees (L884/2017)
  • Act on the Openness of Government Activities (L621/1999)
  • EU General Data Protection Regulation (2016/679)
  • Data Protection Act (L1050/2018)

If your data is to be used for purposes other than those based on law or legitimate interest, we will request your consent.

For what purpose do we process your personal data?

We process your personal data for the following purposes:

  • To organize teaching and implement your right to study
  • To manage student information
  • For study-related counseling, guidance, and support
  • For managing study achievements and completed degrees
  • For educational development
  • To enable physical and information security in the study environment
  • To fulfill statutory monitoring, reporting, and statistical obligations

Additionally, we may use your data:

  • For scientific research (through a separate research approval process)
  • For marketing communication if you have provided consent

What personal data do we process?

We process your personal data to provide high-quality study, guidance, and education services. Keeping up-to-date information ensures students’ legal protection and the realization of the university’s official data collection. We process only necessary personal data for the purposes of our tasks.

We process the following information:

  • Student identification, contact, and background information
  • Study-related information (e.g., education, degree, study duration, semester registrations, semester fee obligation)
  • Registrations for exams and courses, as well as information related to participation in teaching
  • Study achievements and their assessments
  • Personal study plan information and details related to guidance and support
  • Internships and information related to international mobility
  • Thesis and related information
  • Information related to scholarships and grants
  • Graduation information
  • Feedback and career and placement surveys
  • Information related to paid education and payments
  • Information related to electronic exam surveillance
  • Information required for organizing digital services

Study-related information, which may include sensitive personal data (special categories of data):

  • Information related to personal study arrangements and support for studies and well-being
  • Information about extending or returning study rights
  • Investigations into exceptional study situations and their consequences (e.g., decisions related to dishonest conduct or disciplinary actions)

Where do we obtain your personal data?

We obtain the personal data from you and from the following sources:

  • The Studyinfo portal (Opintopolku), maintained by the Finnish National Agency for Education (EDUFI).
  • The enrolment and registration service (OILI), maintained by the Finnish National Agency for Education (EDUFI)
  • Updates from teachers regarding studies
  • Through registration and online payment services
  • From international application systems and foreign universities

Name and contact information may be updated from public directories, such as the population information system or directory services.

The data may also include information observed and derived from the use of university-provided IT services and devices or collected by administrative and monitoring services used by the university (e.g., camera surveillance).

To whom do we disclose your personal data?

In accordance with the law, we may disclose your personal data directly or through the national VIRTA study information service to the following parties:

  • Finnish National Agency for Education
  • Ministry of Education and Culture
  • National authority for collecting and compiling statistics (Tilastokeskus)
  • Social Insurance Institution of Finland (KELA)
  • Finnish National Supervisory Authority for Welfare and Health (VALVIRA)
  • Employment authorities and funds
  • Career monitoring surveys
  • Finnish Student Health Service (YTHS)
  • EXAM Consortium (electronic exams)
  • Finnish Immigration Service (MIGRI) for non-EU students

Your personal data may be disclosed for marketing purposes if you have provided consent. Data disclosures for research purposes always occur through a separate research approval process.

Do we transfer your data outside the EU or EEA?

Data is not generally transferred.

Data transfer may be necessary for the implementation of essential IT services for studies or for organizing student exchanges or internships outside the EU or the European Economic Area.

Transfer of personal data outside the EU and EEA is carried out in accordance with the requirements of the data protection regulation.

How long do we retain your personal data?

Retention periods are determined in accordance with legal requirements, decisions of the National Archives of Finland, and Vaasa University of Applied Sciences’ records management plan.

In our information systems, the following data is retained permanently:

  • Student selection criteria
  • Student’s identifying information
  • Documentary information related to the correction procedure of student selection
  • Information on study rights, registration, degrees, studies, and study achievements, degree certificates
  • Attendance and absence information
  • Information related to the appeal procedure for assessment of study achievements
  • Matters processed by the Degree Committee
  • Opinions on the thesis, student self-assessments, and grade proposals

Theses are retained permanently in the Theseus publication archive.

How do we protect your personal data?

We always ensure the protection of your privacy and that your data is stored in accordance with the law. The confidentiality obligations specified in employment contracts bind the staff.

Manual material

  • Manual materials are stored and protected in a way that prevents outsiders from viewing them and prevents accidental destruction, alteration, disclosure, transfer, or other unlawful processing.
  • Employees have the right to access only student information that they need for their job duties.
  • Documents containing personal data are destroyed by shredding or as confidential waste.

Electronically processed data

  • The responsibility for maintaining server equipment lies with the controller’s IT department. Networks and servers are adequately protected.
  • Access rights are restricted by user groups. Visibility and update rights to the system are determined by user role.
  • Only authorized personnel have access to the system. Access to the system is determined by a person’s job duties or student status.

Do we use automated decision-making?

There is no automated decision-making in the processing of personal data.

Data subject’s rights

When we process your personal data, you have a right to:

  • receive information about the processing
  • view and verify your data
  • request that your data be rectified
  • demand that your data be erased (not applicable to statutory duties)
  • demand limitations to the processing of your personal data
  • oppose the processing of your personal data
  • request that the personal data you have submitted be transferred from one controller to another
  • withdraw your consent, if the processing of your personal data is based on consent
  • avoid being subject to automated decision-making.

Requests regarding the verification, rectification and erasure of data should be sent to VAMK’s data protection officer. The contact details can be found below.

You have a right to submit a complaint to the national Office of the Data Protection Ombudsman if current data protection legislation has been violated while processing your personal data.

Contact information of the data controller

Data controller: 
Oy Vaasan ammattikorkeakoulu – Vasa yrkeshögskola Ab
Wolffintie 30
65200 Vaasa
Phone +358 207 663 300

Representative of the data controller: 

Henkilön tunnistetta ei löydy. Tarkista lyhytkoodi.

Responsible person for processing student personal data: Sanna Eronen, Director, Education (, +358 207 663 626)

Contact person for processing of student personal data: Juha Vierola, Head of Student Services (, +358 207 663 604)

Data protection officer:

Henkilön tunnistetta ei löydy. Tarkista lyhytkoodi.

This privacy notice has been updated on 8 August 2023.