Close

Processing of Personal Data in the EXAM System and Exam Room (“Exam Aquarium”)

Controller

Laurea University of Applied Sciences Ltd, Ratatie 22, 01300 Vantaa, Finland
Contact person for the register: Technical main user of the system, Suvi Valsta, dcell@laurea.fi
Data Protection Officer: Marjo Valjakka, tietosuoja@laurea.fi

Purpose and Legal Basis for Processing Personal Data

The purpose of processing personal data is to enable the booking, completion, supervision, and assessment of electronic examinations conducted in Laurea’s EXAM system.
The purpose of the camera surveillance system in the designated examination room (“exam aquarium”) is to ensure the personal safety of students taking exams, protect property, prevent or investigate situations endangering safety or property, and investigate potential misconduct during examinations.

The processing of personal data is based on a legal obligation under the Universities of Applied Sciences Act (932/2014) and the performance of a task carried out in the public interest.

No automated analysis, decision-making, or profiling is carried out in the EXAM examination process

Categories of Personal Data and Sources of Data

The following personal data are processed concerning students of Laurea and partner higher education institutions taking EXAM examinations

  • Basic personal data: Last name and first name, Email address, User ID, Student number or personal identification number, User role
  • Data related to examinations: Information about the course being examined, exam booking details (time, location, computer used), exam answers, Assessment data and grades
  • Data collected through camera surveillance: Video and audio recordings

Basic student data are obtained through integration from the student information system and via HAKA authentication.
Data related to examinations are obtained directly from the students.
Camera surveillance data are recorded by surveillance cameras in the examination room.

Regular Disclosures and Transfers of Data

An external service provider is used to organize electronic examinations. In providing the service, the provider may gain access to personal data contained in the system and processes them as a data processor based on a contract.

In cases of suspected misconduct related to exam visits by students of partner higher education institutions, video surveillance data may be disclosed to representatives of the relevant institution when the case concerns their student.

Video recordings may be disclosed to authorities (e.g. the police) to the extent deemed necessary if the data are related or suspected to be related to damage or a criminal offence.

Personal data are not transferred outside the EU/EEA.

Principles of Data Protection

The processing of personal data complies with Laurea University of Applied Sciences’ information security and data protection policies. Personal data are only accessible to persons who need them to perform their duties.

Processing of personal data is based on job responsibilities. Access restrictions are implemented through personal access rights and technical measures. Use of systems requires a username and password. Access rights are granted by the system’s main user.

System providers acting as data processors are responsible for the technical protection and security of personal data in accordance with contractual agreements.

Data Retention Period

Personal data related to a student’s examination are retained for 6 months after the completion of the assessment.
Video recordings are retained for 30 days from the examination or for the duration of any investigation concerning suspected misconduct or criminal activity.

Rights of the Data Subject

The rights of the data subject are determined in accordance with Articles 15–22 of the EU General Data Protection Regulation (GDPR).

Right of Access

The data subject has the right to inspect and obtain a copy of their personal data. Requests must be submitted in writing to exam@laurea.fi and must specify the data concerned.

Right to Rectification

The data subject has the right to request correction of inaccurate data. Requests must be submitted in writing to exam@laurea.fi and must specify the data concerned.

Right to Erasure

As the processing is based on a legal obligation and public interest, the data subject does not, as a rule, have the right to have their data erased.
However, the data subject has the right to request erasure if:

  • the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
  • the personal data have been processed unlawfully; or
  • the personal data must be erased to comply with a legal obligation under EU or national law.

The data subject has the right to lodge a complaint with the supervisory authority.

Contact Details of the Data Protection Ombudsman
Visiting address: Lintulahdenkuja 4, 00530 Helsinki, Finland
Postal address: P.O. Box 800, 00531 Helsinki, Finland
Telephone (switchboard): +358 29 56 66700
Registry: +358 29 566 6768
Email: tietosuoja@om.fi