Privacy and Personal Data Protection Policy

Privacy and Personal Data Protection Policy of the Nursing School of Coimbra

Nursing School of Coimbra
The Nursing School of Coimbra is a public higher education institution whose mission involves the fields of higher education, research, and provision of services to the community. It is a nonprofit organization with social interests. As an institution that processes personal data on a daily basis, the Nursing School of Coimbra is committed to the regulations and obligations imposed by the European legislation on data protection, namely Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, hereinafter referred to as GDPR, as well as national legislation, namely Law no. 58/2019 of 8 August, ensuring the implementation of Regulation (EU) 2016/679 of the European Parliament and of the Council. The Nursing School of Coimbra is strongly committed to the protection of personal data for which it is responsible and implements effective technical and organizational measures for compliance with the principles of data protection, taking into account the nature, scope, context, and purposes of data processing, as well as the risks of failure in the protection of the rights and freedoms of natural persons, including those resulting from the exposure of personal data in the cyberspace. The regulation of the Legal Regime for Cyberspace Security and the adoption of procedures in the field of information security call for this revision of the Privacy and Personal Data Protection Policy, with the purpose of reinforcing its commitment and the respect for the privacy and protection of personal data. Therefore, this privacy and personal data protection policy applies to all operations carried out by the Nursing School of Coimbra.

Personal data
Personal data means any information relating to an identified or identifiable natural person, both directly and indirectly.

Data controller
The Nursing School of Coimbra is a public higher education institution and collective person of public law with taxpayer no. 600081583 and headquarters at the Avenida Bissaya Barreto. It establishes the types of personal which are subject to the processing, the purposes and means of the processing, and the storage periods.

Type of personal data
The Nursing School of Coimbra, within the scope of its activity, collects and processes personal data necessary for the pursuit of its mission and responsibilities, in accordance with the Legal Framework for Higher Education Institutions (Law no. 62/2007, of 10 September) and its Statutes (approved by Legislative Decree 50/2008, DR. no. 185, 2nd Series, of 24 September). Furthermore, the Nursing School of Coimbra processes the personal data necessary for the management of human resources, including staff, faculty, and other service providers, including the necessity for the performance of a contract or compliance with the legal obligations arising therefrom. The Nursing School of Coimbra may also process personal data aimed at the protection of persons and property.

Collection of personal data
The Nursing School of Coimbra collects personal data in person, in writing, or through computer systems. Personal data are processed by both non-automated (e.g., manual files) and automated means, in compliance with the personal data protection law, and stored in specific databases created for that purpose. Personal data will not be processed for a purpose other than that for which consent has been given by the data subject or when required by law.

Lawfulness of personal data processing
In the Nursing School of Coimbra, the processing of personal data depends on the fair and lawful conditions for that processing, as well as the compliance with the principle of proportionality. Therefore, personal data will be processed at the Nursing School of Coimbra only if: - it is necessary for the performance of a contract or for compliance with a legal obligation to which the Nursing School of Coimbra is subject; - it is necessary for reasons of public interest as a public higher education institution; - it is necessary for the pursuit of other purposes legitimized by the unambiguous consent of the data subject; - it is necessary in order to protect the vital interests of the data subject or of another natural person; - It is necessary for the purposes of the legitimate interests pursued by the controller or by a third party to whom the data are disclosed, after an assessment of the necessity and proportionality of the processing, without overriding the interests and rights or freedoms of the data subject; - it is necessary for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, in accordance with the legal framework in force.

Purposes of personal data processing
The Nursing School of Coimbra respects the right to privacy and does not collect information other than personal data that is provided voluntarily through forms or other legitimate means. When collecting personal data, the Nursing School of Coimbra provides the data subject with the necessary information on how the data will be processed lawfully, fairly, and in a transparent manner in accordance with the privacy and data protection policy and ensured them that these personal data will only be processed for the purposes for which they were collected. Where the processing of personal data by the Nursing School of Coimbra is based on the data subject’s consent, information will be provided about the specified, explicit, and legitimate purposes of data collection. Where personal data is processed for purposes other than those for which they were collected, the Nursing School of Coimbra will request explicit consent for that further processing, except for cases in which data processing is lawful without consent, in accordance with the legislation in force. The personal data processed by the Nursing School of Coimbra can be legitimately transmitted to a third party whenever there is compliance with the purposes directly related to the legitimate functions of the data subject or the data controller.

Confidentiality
Personal data will be processed by the Nursing School of Coimbra for the purposes for which they were collected or for the compliance of legal obligations. Personal data will be processed in a confidential manner and accessed by a restricted number of workers/collaborators of the Nursing School of Coimbra to carry out their professional duties, within the limits applicable.

Personal data storage period
The storage period varies according to the purpose of the processing. The Nursing School of Coimbra stores personal data for as long as it is required for any liability arising from legal relationships, the performance of a contract, or the implementation of pre-contractual measures. If there are no specific legal requirements, data will be stored for as long as it may be necessary to fulfill the purposes for which the data were collected and processed or for a period of time authorized by the Control Authority, after which time the data will be deleted. The Nursing School of Coimbra may store personal data for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, without prejudice to the protection of the rights and freedoms of the data subject, in accordance with the applicable law. Those safeguards involve the implementation of technical and organizational measures to ensure, among others, compliance with the principle of data minimization.

Rights of data subjects
In accordance with the legal framework on Personal Data Protection, the Nursing School of Coimbra ensures that data subjects have the right to access, update, rectify or erasure their personal data, in accordance with the legislation in force, upon a written request addressed to the data protection officer. The data subject has the right to withdraw his or her consent at any time. The withdrawal of consent will not affect the lawfulness of the processing based on consent before its withdrawal. Furthermore, the data subject has the right to be notified in case of a personal data breach, in accordance with the GDPR. The data subject’s right of access should be limited when it adversely affects the rights and freedoms of others.

Information security - Data protection
The Nursing School of Coimbra will implement the necessary technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction. The Nursing School of Coimbra has defined, approved, and implemented a Security Plan under the Information Security and Cybersecurity Policy, which includes the security, integrity, availability, and privacy of the personal data collected and processed by the Nursing School of Coimbra. The Security Plan aims to establish, implement, and continuously improve a set of policies, rules, practices, security measures and controls, monitoring and auditing interventions to ensure the implementation of the commitments made by Nursing School of Coimbra toward the management of Information Security and Cybersecurity.

Data Protection Officer
The Nursing School of Coimbra has designated a Data Protection Officer, who is responsible, among other aspects, for monitoring this Privacy Policy, clarifying the rules for personal data processing, and communicating with the supervisory authorities, ensuring that all those who entrust the Nursing School of Coimbra with their personal data are aware of their rights and of how it processes their personal data.

Collection of technical/anonymous information
The websites of the Nursing School of Coimbra collect anonymous information about its visitors which is made available by browsers and web servers, such as browser type, language preference, referring site, pages visited, time spent on the website, date and time of each visit, search terms. The Nursing School of Coimbra will not intentionally collect personally identifiable information. This information helps to understand how our users use the website to improve the quality and usefulness of the services provided.
Notwithstanding the anonymous information collected and processed on our Web Analytics platform, technical information may be collected about your visit(s) by the technological infrastructure that supports the system. The Nursing School of Coimbra will not share this information with third parties, without prejudice to the legal requirements imposed by the legislation in force (that is, this information may be shared with the competent public authorities, in compliance with the Portuguese and European legislation).

Cookies
When you use the websites of the Nursing School of Coimbra, cookies (small text files) are stored on your end device that allow us to, for example, understand whether you intend to contribute with anonymous information to our Web Analytics platform or whether you are logged in. Functional and analytical cookies do not include personal data and are transferred securely. Third-party cookies are not managed by our system so they may have their own cookies and privacy policy, outside the scope of this policy. Our system will not send any personal data intentionally to external services. Cookies can be blocked or disabled. Please check your browser settings for more information.

Changes to this Policy
The Nursing School of Coimbra reserves the right to adjust or update this Privacy Policy. Any changes will be published.

Questions and suggestions
To learn more about how the Nursing School of Coimbra processes your personal data or to clarify any doubts, please contact us.

Contacts
Escola Superior de Enfermagem de Coimbra
Av. Bissaya Barreto, S/N
3000-075 Coimbra
esenfc@esenfc.pt

Data Protecion Officer
epd@esenfc.pt


Revision Approval Date: 27/07/2023