Privacy and Data Processing Policy
Effective from: 1 September 2024
I. Introduction
The „Bod Péter” Pedagogical High School (hereinafter: Controller or Institution) is a public educational institution operating at its headquarters at 525400 Târgu Secuiesc, 20 Ady Endre Street. In processing personal data, the Institution acts in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: GDPR), Romanian Law No. 190/2018 on measures implementing the GDPR, Law No. 365/2001 on information society services, and Law No. 677/2001 (applicable provisions).
This policy aims to inform visitors to the Institution's website, persons using its services (students, parents, legal representatives, visitors) about the processing of their personal data, their rights, and the means of exercising those rights.
II. Data of the Controller
| Name of Institution: | „Bod Péter” Pedagogical High School |
| Headquarters: | 525400 Târgu Secuiesc, 20 Ady Endre Street, Covasna County |
| Phone: | +40 267 360 670 |
| E-mail: | bodpeter@bodpetertk.ro |
| Website: | http://192.168.1.1 |
Data Protection Officer (DPO)
Pursuant to Article 37 of the GDPR, since the Institution operates as a public authority, it has appointed a Data Protection Officer (DPO). The contact details of the Data Protection Officer are:
- E-mail: bodpeter@bodpetertk.ro (subject: Data Protection Officer)
- Postal address: 525400 Târgu Secuiesc, 20 Ady Endre Street.
III. Definitions
- Personal data:
- Any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Processing:
- Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Controller:
- The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processor:
- A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- Data subject:
- A natural person whose personal data are processed.
- Consent:
- Any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
IV. General principles of data processing
When processing personal data, the Institution follows the following principles:
- Lawfulness, fairness and transparency: Personal data are processed lawfully, fairly and in a transparent manner in relation to the data subject.
- Purpose limitation: Personal data are collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.
- Data minimisation: Only personal data which are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed are collected.
- Accuracy: The Institution takes every reasonable step to ensure that inaccurate personal data are erased or rectified without delay.
- Storage limitation: Personal data are kept only for the period necessary for the fulfilment of the purpose.
- Integrity and confidentiality: Personal data are processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
- Accountability: The Institution is responsible for compliance with the above principles and is able to demonstrate such compliance.
V. Purpose and legal basis of processing
1. Operation of the website and contact
| Purpose of processing: | Operation of the website, informing visitors, handling enquiries received through the contact form. |
| Legal basis: | Consent of the data subject (Article 6(1)(a) of the GDPR). |
| Data processed: | Name, e-mail address, telephone number, content of the message. |
| Retention period: | 1 year from the conclusion of the enquiry. |
2. Newsletter (if applicable)
| Purpose of processing: | Informing about the Institution's news, events and programmes. |
| Legal basis: | Consent of the data subject (Article 6(1)(a) of the GDPR). |
| Data processed: | Name, e-mail address. |
| Retention period: | Until withdrawal of consent (unsubscription). |
3. Educational activities (student data)
| Purpose of processing: | Establishment, maintenance and termination of the student's legal relationship with the school; teaching and examination activities; management of diplomas, class registers and matriculation records; preparation of school statistics. |
| Legal basis: | Compliance with a legal obligation (Article 6(1)(c) of the GDPR) – under the Romanian Education Law and related legislation. Performance of a task carried out in the public interest (Article 6(1)(e) of the GDPR). |
| Data processed: | Student's name, place and date of birth, personal identification number (CNP), home address, name and contact details of parents/legal representatives, academic progress data, grades, examination results. |
| Retention period: | As provided by law (generally 50 years from the termination of the student's legal relationship for matriculation records and diplomas). |
4. Photographs and video recordings
| Purpose of processing: | Documentation of school events and programmes, display on the website and social media channels. |
| Legal basis: | Consent of the data subject (or of the legal representative in case of minors) (Article 6(1)(a) of the GDPR). |
| Data processed: | Photographs and video recordings. |
| Retention period: | Until withdrawal of consent, but no longer than 5 years. |
VI. Use of cookies
What are cookies?
Cookies are small text files that are stored on your device when the website loads in your browser. These cookies help the website function properly, enhance security, and provide a better user experience.
Types of cookies used by the Institution
| Type | Purpose | Legal basis |
|---|---|---|
| Essential (necessary) | Required for the basic operation of the website (e.g. session management, security settings). | Legal obligation / legitimate interest of the controller (Article 6(1)(c) and (f) of the GDPR). |
| Statistical | Anonymous collection of traffic data (e.g. number of visitors, most popular pages). | Consent of the data subject (Article 6(1)(a) of the GDPR). |
Managing cookies
Most browsers allow you to change your cookie settings. If you disable or delete cookies, some features of the website may not function properly.
Cookie settings can be modified in the following browsers:
- Google Chrome: Settings → Privacy and security → Cookies and other site data
- Mozilla Firefox: Settings → Privacy and security → Cookies and site data
- Microsoft Edge: Settings → Cookies and site permissions → Cookies and data
- Safari: Settings → Privacy → Block cookies
VII. Processors and data transfer
Processors
The Institution uses the following processors:
| Processor | Activity |
|---|---|
| Web hosting provider | Provision of web hosting services |
| Ministry of Education (SIIIR/SEI systems) | Maintenance of national educational records |
Transfer to a third country
The Institution does not transfer personal data to a third country outside the European Economic Area (EEA) or to an international organisation.
VIII. Rights of the data subject
Under the GDPR, the data subject has the following rights:
1. Right to be informed
The data subject has the right to be informed about the processing of their personal data.
2. Right of access
The data subject has the right to obtain from the Controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the information listed in Article 15 of the GDPR.
3. Right to rectification
The data subject has the right to obtain from the Controller without undue delay the rectification of inaccurate personal data concerning him or her.
4. Right to erasure („right to be forgotten”)
The data subject has the right to obtain from the Controller the erasure of personal data concerning him or her without undue delay where one of the grounds listed in Article 17 of the GDPR applies.
5. Right to restriction of processing
The data subject has the right to obtain from the Controller restriction of processing where one of the conditions set out in Article 18 of the GDPR is met.
6. Right to data portability
The data subject has the right to receive the personal data concerning him or her, which he or she has provided to the Controller, in a structured, commonly used and machine-readable format and has the right to transmit those data to another controller.
7. Right to object
The data subject has the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on Article 6(1)(e) or (f) of the GDPR.
8. Right to withdraw consent
Where processing is based on consent, the data subject has the right to withdraw his or her consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Exercising rights
To exercise the rights set out above, the data subject may contact the Controller at the following contact details:
- E-mail: bodpeter@bodpetertk.ro
- Postal address: 525400 Târgu Secuiesc, 20 Ady Endre Street.
The Controller shall respond within 30 days, but no later than 1 month from receipt of the request. If the data subject considers that the processing infringes the applicable data protection legislation, they may lodge a complaint with the supervisory authority:
- National Supervisory Authority for Personal Data Processing (ANSPDCP – Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal)
- Address: București, B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, cod poștal 010336
- Website: www.dataprotection.ro
- E-mail: anspdcp@dataprotection.ro
IX. Data security measures
To protect personal data, the Institution applies the following technical and organisational measures:
- SSL/HTTPS encryption on the website
- Password-protected administration interfaces
- Regular backups
- Restriction of access rights
- Computers and servers equipped with antivirus and firewall
- Data protection training for employees
X. Handling of personal data breaches
In the event of a personal data breach, the Institution acts in accordance with Articles 33–34 of the GDPR:
- The breach is notified to the ANSPDCP supervisory authority within 72 hours of becoming aware of it.
- If the breach is likely to result in a high risk to the rights and freedoms of data subjects, the Institution informs the data subjects without undue delay.
XI. Contact form
When using the contact form on the Institution's website, we request the following data:
- Name
- E-mail address
- Telephone number (optional)
- Content of the message
These data are used exclusively for the purpose of handling the enquiry and are retained for a maximum of 1 year following contact.
XII. Processing of minors' data
In processing student data, the Institution pays particular attention to the protection of minors' personal data. The data of minor students are processed with the consent of the legal representative (parent/guardian) or on the basis of a legal obligation.
For children under the age of 16, consent must be given by the parent or legal representative.
XIII. Closing provisions
The Institution reserves the right to amend this privacy policy from time to time. Amendments enter into force upon publication on the website. In the case of changes that significantly affect the rights of data subjects, the Institution will send a separate notification.
This policy enters into force on the date of its publication on the website.
Last updated: 1 September 2024.