Protection of your personal data
This privacy statement provides information about the processing and the protection of your personal data.
Processing operation
European Student Card Router
Data Controller
European Commission's Directorate-General for Education, Youth, Sport and Culture, Unit B1 Higher Education
Record reference: DPR-EC-18409.2
1. Introduction
The European Commission (hereafter ‘the Commission’) is committed to protecting your personal data and to respecting your privacy. The Commission collects and further processes personal data pursuant to Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data (repealing Regulation (EC) No 45/2001).
This privacy statement explains the reason for the processing of your personal data, the way we collect, handle and ensure protection of all personal data provided, how that information is used and what rights you have in relation to your personal data. It also specifies the contact details of the responsible Data Controller with whom you may exercise your rights, the Data Protection Officer and the European Data Protection Supervisor.
The information in relation to processing operation: the European Student Card Router undertaken by the Commission's Directorate-General for Education, Youth, Sport and Culture, Unit B1 Higher Education is presented below.
2. Why and how do we process your personal data?
Purpose of the processing operation: the Commission's Directorate-General for Education, Youth, Sport and Culture (hereafter ‘DG EAC’) collects and uses your personal information for the following purposes:
- Registration and access to the European Student Card Router (hereafter ‘ESC-R’) by higher education institutions (hereafter HEIs) and public authorities
- Upload of the student data to issue the European Student Cards
- Update and deletion of the European Student Cards
- Migration of personal data to the European Commission’s cloud, and
- Management and maintenance of the ESC-R
DG EAC processes personal data jointly with the HEIs and public authorities registered to the ESC-R for the following processing operations: 2. Upload of the student data to issue the European Student Cards and 3. Update and deletion of European Student Cards.
Public authorities may issue student cards in some countries or regions depending on the legislation and specific arrangements of the higher education sector. Public authorities are hence considered as potential users of the ESC-R and Joint Controllers.
Please be aware that DG EAC is a Joint Controller exclusively with regard to the processing operations involving the upload of the student data to issue European Student Cards and the update and deletion of the European Student Cards. With regard to the processing operations involving the registration and access to the ESC-R, migration of personal data to the Commission’s cloud and management and maintenance of the ESC-R, DG EAC defines alone the purposes and means of the data processing and will act as an Independent Data Controller.
Your personal data will not be used for automated decision-making operations, including profiling.
3. On what legal ground(s) do we process your personal data?
We process your personal data based on the following sub-paragraph of Article 5(1) of Regulation (EU) 2018/1725:
- (a) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Union institution or body. In particular, the legal basis for the processing of personal data by the European Commission in the context of the European Student Card Initiative is established by Regulation (EU) 2021/817 establishing Erasmus+ and the corresponding Commission Decision C(2021) 7862.
The ESC-R data processing operation does not entail any special categories of data.
4. Which personal data do we collect and further process?
In order to carry out the processing operations outlined under section 2, DG EAC collects and further processes the following data from representatives of HEIs or representatives of public authorities, as well as representatives of third-party processors:
- First name
- Last name
- Email address
DG EAC jointly collects and processes with HEIs or public authorities registered in the ESC-R the following data from students registered in the student or card management systems of said HEIs or public authorities:
- First name
- Last name
- European Student Identifier (ESI)
- Email address
- European Student Card Number (ESCN)
5. How long do we keep your personal data?
The Joint Controllers and the third-party processors only keep the data for the time necessary to fulfil the purpose of collection or further processing.
Personal data related to students (e.g., first name, last name or card-related data such as the European Student Card Number or the European Student Identifier) will be kept for up to two years from the expiration date of a student card or the removal of the card from the ESC-R by the HEI, public authority or their third-party processor. The validity of the European Student Card is linked to the validity of the student’s card issued by the HEI or public authority, and it ranges from 1 to 5 years.
Personal data linked to the representatives of HEIs, public authorities or third-party processors will be kept for as long as the representative is responsible for the European Student Card in their respective HEI, public authority or third-party processor organisation, and will be kept for up to two years thereafter.
6. How do we protect and safeguard your personal data?
All personal data in electronic format (e-mails, documents, databases, uploaded batches of data, etc.) are stored either on the servers of the Commission or of its contractor for this service acting as a third-party processor (NTT DATA Belgique Private Company (SPRL), Rue de Spa 8, 1000 Brussels, Belgium, hereafter ‘NTT Data’). All processing operations are carried out pursuant to the Commission Decision (EU, Euratom) 2017/46 of 10 January 2017 on the security of communication and information systems in the European Commission.
The Commission’s processors, and the Commission’s partners (i.e. joint controllerships in the specific processes of personal data) are bound by a specific contractual clause for any processing operations of your data on behalf of the Commission, and by the confidentiality obligations deriving from the transposition of the General Data Protection Regulation in the EU Member States (‘GDPR’ Regulation (EU) 2016/679).
In order to protect your personal data, the Commission has put in place a number of technical and organisational measures. Technical measures include appropriate actions to address online security, risk of data loss, alteration of data or unauthorised access, taking into consideration the risk presented by the processing and the nature of the personal data being processed. Organisational measures include restricting access to the personal data solely to authorised persons with a legitimate need to know for the purposes of this processing operation.
7. Who has access to your personal data and to whom is it disclosed?
Access to your personal data is provided to the staff of the Commission and its contractor NTT Data acting on behalf of DG EAC as a data processor, responsible for carrying out this processing operation and to authorised staff according to the “need to know” principle. Such staff abide by statutory, and when required, additional confidentiality agreements.
HEIs and public authorities are joint controllers with DG EAC when it comes to their students' data. Representatives of HEIs and of public authorities have access only to the students’ data they upload to the ESC-R. This includes first and last name, ESI, email address and ESCN.
Third-party data processors acting on behalf of the HEIs and public authorities have limited access with regards to the student data, according to the processing arrangement concluded with the HEI or public authority.
8. What are your rights and how can you exercise them?
You have specific rights as a ‘data subject’ under Chapter III (Articles 14-25) of Regulation (EU) 2018/1725, in particular the right to access your personal data and to rectify them in case your personal data are inaccurate or incomplete. Where applicable, you have the right to erase your personal data, to restrict the processing of your personal data, to object to the processing, and the right to data portability.
You have the right to object to the processing of your personal data, which is lawfully carried out pursuant to Article 5(1)(a) of Regulation (EU) 2018/1725 on grounds relating to your particular situation. We do not process your information for any automated decision-making operation, including profiling.
You can exercise your rights by contacting the Data Controller, or in case of conflict the Commission’s Data Protection Officer. If necessary, you can also address the European Data Protection Supervisor. Their contact information is provided under section 9 below.
For requests related to issuing, updating or deleting your European Student Card, you should contact the HEI or public authority in charge of issuing your European Student Card.
Where you wish to exercise your rights in the context of one or several specific processing operations, please provide their description (i.e. their Record reference(s) as specified under section 10 below) in your request.
9. Contact information
The Data Controller
If you would like to exercise your rights under Regulation (EU) 2018/1725, or if you have comments, questions or concerns, or if you would like to submit a complaint regarding the collection and use of your personal data, please feel free to contact the Data Controller at: EAC-ESCI-PERSONAL-DATA@ec.europa.eu.
The Data Protection Officer (DPO) of the Commission
You may contact the Data Protection Officer (DATA-PROTECTION-OFFICER@ec.europa.eu) with regard to issues related to the processing of your personal data under Regulation (EU) 2018/1725.
The European Data Protection Supervisor (EDPS)
You have the right to have recourse (i.e. you can lodge a complaint) to the European Data Protection Supervisor (edps@edps.europa.eu) if you consider that your rights under Regulation (EU) 2018/1725 have been infringed as a result of the processing of your personal data by the Data Controller.
10. Where to find more detailed information?
The Commission Data Protection Officer publishes the register of all processing operations on personal data by the Commission, which have been documented and notified to him. You may access the register here.
This specific processing operation has been included in the DPO’s public register with the following Record reference: DPR-EC-18409.2.