Privacy Policy
Personal Data Processing — Commitment to inclusion, equity, and data security
Version aligned with the IGE Self-Assessment Tool (OpenEU project No. 101177241, WP3, ST 3.3.2).
1. Purpose
This Privacy Policy ensures transparency and fairness in personal data processing at Daugavpils Universitāte (DU), in compliance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the Latvian Personal Data Processing Law, and the IGE Self-Assessment Tool (OpenEU project No. 101177241, WP3, ST 3.3.2).
We continuously assess and improve data processing to support inclusion and equity — especially for under-represented groups: women in STEM, rural residents, persons with disabilities, adult learners, and others facing barriers to higher education and lifelong learning.
2. Data Controller & Contact Information
2.1. Data Controller
Daugavpils Universitāte (DU)
Registration No.: 2741000222
Legal Address: Daugavpils, Vienības iela 13, LV-5401, Latvia
Phone: +371 65422180 / +371 65422922
Email: du@du.lv
2.2. Data Protection Officer (DPO)
Aleksandrs Baranovskis
Email: aleksandrs.baranovskis@du.lv
2.3. How to Contact Us
You may contact DU regarding data processing and privacy using the contact details above.
Note: Requests from vulnerable or marginalised individuals (e.g., trauma-affected persons, older users, those with language barriers) are prioritised — we ensure accessible communication channels (e.g., email, phone, in-person with flexible ID verification).
3. Scope of Application
This policy applies to data processing concerning:
- Visitors to DU premises (including those monitored by videomonitoring for security purposes);
- Students (prospective, current, and alumni);
- Staff (current, former, and potential);
- Website users (DU website, e-Studies, DU LIS portal);
- Individuals whose data is processed in social media campaigns supporting DU outreach and inclusion initiatives.
Processing occurs regardless of how data is provided — in person, online, on paper, or via phone.
4. Legal Basis
This Policy is developed in accordance with:
- GDPR (Regulation (EU) 2016/679);
- Latvian Personal Data Processing Law;
- DU internal regulations (e.g., Staff Rules, Study Regulations);
- IGE Self-Assessment Tool (OpenEU project No. 101177241, WP3, ST 3.3.2).
5. Core Principles for Data Processing
DU commits to processing personal data in accordance with:
- Lawfulness, fairness, and transparency — especially avoiding algorithmic bias and discrimination;
- Purpose limitation — data collected only for specified, explicit, and legitimate purposes;
- Data minimisation — only necessary data collected;
- Accuracy — data kept up to date and corrected when needed;
- Storage limitation — data retained only as long as necessary;
- Integrity and confidentiality — robust security using modern technology;
- Accountability — documented processing and regular audits.
6. Purposes of Processing
Personal data is processed to:
- Identify individuals (using accessible identification options for under-represented groups);
- Manage admissions, enrolment, recruitment, and documentation;
- Conclude and execute contracts (study, employment, IT access);
- Manage working and study time;
- Ensure safety and security (videomonitoring used solely for security purposes);
- Support insurance, research, and social programmes;
- Conduct outreach and promotion — including targeted adult education, engagement, and lifelong learning initiatives (OpenEU WP3 objectives);
- Comply with national and EU reporting obligations;
- Maintain service quality and enhance participation — aligned with inclusion and autonomy principles.
7. Legal Basis for Processing
Data processing is based on:
- Consent (GDPR Art. 6(1)(a)) — clear, voluntary, and revocable;
- Contractual necessity (GDPR Art. 6(1)(b)) — execution of study or employment contracts;
- Legal obligation (GDPR Art. 6(1)(c)) — tax, education, or other statutory duties;
- Public interest (GDPR Art. 6(1)(e)) — education, research, and participation enhancement.
Sensitive data (health, disability, ethnicity) is processed only with appropriate legal grounds — e.g., explicit consent or substantial public interest with safeguards.
8. Data Collection & Retention Period
8.1. Data Collection
- Submitting study/enrolment documents;
- Contract conclusion or performance;
- Direct provision by the data subject (e.g., surveys, accessibility needs forms);
- While on DU premises (videomonitoring used solely for security);
- During social media engagement — only with consent and appropriate support.
8.2. Retention Period
Data is retained only as long as at least one of the following applies:
- An active contract is in place;
- A legitimate legal claim or defence period remains open;
- Statutory obligation exists (e.g., archival requirements — 10 years after relationship ends);
- Videomonitoring footage: maximum 30 days, unless required by authorities;
- Valid consent remains (if no other lawful basis).
Once retention periods expire, data is securely deleted or anonymised, especially when sensitive (e.g., disability status, trauma-related data).
9. Automated Decision-Making
DU does not use automated decision-making that produces legal or similarly significant effects (GDPR Art. 22).
10. Data Recipients
Data may be shared with:
- Law enforcement authorities (as required by law);
- DU staff acting within their duties;
- Technical processors — University of Latvia (LIS system maintenance);
- Third parties only to the extent strictly necessary for contracted services;
- Auditors, legal advisors;
- State institutions (CSB, MSIT, SRS) — only as required by law;
- EU institutions — upon legal obligation.
When transfers occur to third countries (outside EEA), DU ensures compliance with GDPR — e.g., via Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework.
11. Data Protection Measures
Daugavpils Universitāte implements:
- IT security tools (antivirus, firewalls, encryption);
- Videomonitoring — security-only, with clear signage;
- Regular security testing and staff training;
- Access controls (smart cards, biometrics only where legally mandated and justified);
- Data Protection Impact Assessments (DPIAs) for high-risk processing.
Note (IGE): Security measures do not undermine accessibility or participation (e.g., alternative verification methods for trauma-affected users).
12. Data Subject Rights
Data subjects have the right to:
- Access their personal data — via DU IES and e-Studies (estudijas.du.lv);
- Rectify inaccurate data;
- Erasure (right to be forgotten) — under GDPR Art. 17;
- Restriction of processing;
- Withdraw consent at any time;
- Data portability — where applicable;
- Lodge a complaint with the Data State Inspectorate or law enforcement.
How to exercise your rights?
- Send a signed request (digitally with qualified e-signature or in person with ID verification);
- DU will verify your identity — accessible options available (e.g., video call with document display);
- Response within one month (extendable to three months for complex cases).
13. Data Controller Responsibilities
As data controller, DU shall:
- Provide clear information before processing (GDPR Arts. 13/14);
- Enable easy data correction;
- Implement organisational and technical security;
- Notify data subjects of breaches without undue delay;
- Ensure data processing is carried out only by authorised personnel;
- Inform data subjects of any purpose changes and obtain new consent if needed.
IGE-aligned: Processing is never used to reinforce bias or exclusion.
14. Data Processors
DU contracts only with processors (e.g., University of Latvia for LIS support) who guarantee GDPR and IGE compliance through binding agreements.
15. Website & Cookies
Cookies may be used on the DU website to improve performance (e.g., faster page loading). These are not used for personal data processing.
Links to third-party websites are provided for convenience only — DU is not responsible for their privacy practices.
16. Updates
DU reserves the right to update this Policy — changes will be published with the latest revision date.
Approved by DU Rector's Order No. 4-4/5, 16 January 2019.
Last updated: IGE Self-Assessment Tool integration (OpenEU project No. 101177241, WP3, ST 3.3.2).
This policy aims to ensure inclusion, security, and equal opportunity for all — regardless of age, disability, gender, ethnicity, or location.