Utah Valley University GDPR Privacy Notice

1. Purpose

Utah Valley University (“UVU”) is committed to respecting and protecting the privacy rights of persons in the European Economic Area (“EEA”), comprised of the European Union (“EU”) and the countries of Iceland, Norway, and Lichtenstein, pursuant to the EU General Data Protection Regulation (“GDPR”). This GDPR Privacy Notice describes UVU’s commitment to the privacy of persons in the EEA, and supplements the Utah Valley University Privacy Statement for certain persons in the EEA.

2. Does This GDPR Privacy Notice Apply to Me?

This GDPR Privacy Notice applies to you if:

  • You are a “Person” or “Data Subject”—meaning a natural person, not a corporation, partnership, or other legal entity—who is physically present in the EEA;
  • It is with respect to your “Personal Information”—meaning any information relating to an identified or identifiable person—that is provided while you are physically present in the EEA;
  • Such Personal Information is not earlier or later provided to UVU while you are outside the EEA; and
  • Such Personal Information is provided to UVU:
    • During the course of UVU offering you goods or services;
    • While UVU is monitoring your behavior; or
    • While you are associated with any of UVU’s programs in the EEA.

Please note that information pertaining to current, former, or prospective employment with UVU in the United States is not considered “Personal Information” and is excluded from this GDPR Privacy Notice.

3. What Personal Information Does UVU Process?

A. General Categories

Depending on the specific purpose for processing Personal Information, UVU may process the following general categories of Personal Information: 

  • Names
  • Addresses
  • Telephone numbers
  • Email addresses
  • Identification numbers, including but not limited to social security numbers and driver’s license numbers
  • UVU identification numbers
  • Personal identification numbers
  • Usernames
  • Passwords
  • Demographic information
  • Education history and transcripts
  • Entrance exam scores
  • Background check information
  • Personal references
  • Emergency contact information
  • Financial information, including but not limited to credit and debit card numbers, tax information, and financial aid information
  • Transaction history
  • Business information
  • Passport and visa information
  • Work history
  • Medical history
  • Donation history
  • Insurance information
  • Military service
  • IP addresses
  • Location information
  • Device information
  • Metadata
  • Education records, including but not limited to coursework, correspondence, evaluations, disciplinary complaints, and other records, and files maintained by UVU as part of the educational process
  • Any requests for accommodations or leave

B. Special Categories

In order to fulfill certain of the purposes identified in the table below, UVU may need to request special categories of Personal Information—information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic data; biometric data for the purpose of uniquely identifying a natural person; data concerning health; or data concerning a natural person’s sex life or sexual orientation.  

Before UVU processes your special category Personal Information or your criminal conviction Personal Information, if any, UVU will ask for your affirmative consent unless UVU has another legal basis for the processing, in which case UVU will inform you of that basis.

4. Why UVU Processes Your Personal Information

UVU requires Personal Information only when necessary. The table below describes the Personal Information and Sensitive Personal Information that we may collect, why we may collect it, and our potential legal basis for processing it.

Personal Information and Sensitive Personal Information collection details.

Purpose of Processing

Categories of Personal Information

Legal Basis

As part of the admissions process, we collect applicant Personal Information to evaluate applications. We also may obtain Personal Information from third parties, such as other schools, references, family members, and education as part of an application package.

Name, address, contact details, race/ethnicity, demographic information, educational history, reference letters, emergency contacts, and other relevant information as part of the application package.

Contract: Personal Information collected through the UVU application is necessary for the performance of a contract to provide you education services or to take steps at your request prior to entering into a contract to provide you education services.

Legitimate Interest: Personal Information collected through the UVU application is necessary to evaluate candidates for admissions and for our internal statistical and analytics purposes.

To support course registration

Name, UVU ID, contact information.

Contract: Personal Information collected through the UVU course registration sites is necessary for the performance of a contract to provide you education services.

Legitimate Interest: Personal Information collected for matriculated students, staff, faculty and members of the public, as appropriate for the course, to register in courses or classes.

To evaluate and determine whether financial aid opportunities are available to an applicant

Name, address, contact details, demographic information, salary history, tax forms and other relevant information to evaluate financial aid eligibility and opportunities.

Legitimate Interest: Personal Information collected through the financial aid application is necessary to evaluate whether the applicant is eligible to receive financial aid and for our internal statistical and analytics purposes.

Contract: Personal Information collected through the financial aid application is necessary for the performance of a contract to provide you financial aid or to take steps at your request prior to entering into a contract to provide you financial aid.

To provide online training and educational programs

Name, UVU ID, contact information, demographic information.

Contract: Personal Information collected through the UVU application is necessary for the performance of a contract to provide you education services or to take steps at your request prior to entering into a contract to provide you education services.

Legitimate Interest: To facilitate provision of on-line education courses to matriculated students, staff, faculty and members of the public, as appropriate for the course

To process employment applications

Name, UVU ID (if available), demographic information, resumes

Legitimate Interest: For individuals interested in employment opportunities, processing applications

To receive donations

Name, contact information, payment information

Legitimate Interest: To collect and process donations/gifts and donor information

To purchase tickets to events

Name, UVU ID (if available), contact information

Contract: To process ticket payment for a variety of events

For event registration

Name, UVU ID (if available), contact information

Legitimate Interest: To process registration for sports, cultural, educational and other UVU events

To purchase parking passes and permits

Name, UVU ID, contact information

Contract: To facilitate payments for parking passes and permits

To submit requests for services (e.g., IT, help desk, help line, CAPS, etc.)

Name, UVU ID, contact information

Legitimate Interest: To process service requests from students, staff and faculty 

Contract: If there is a contract that governs your use of such services, Personal Information is processed pursuant to that contract

Travel sites

Name, UVU ID, contact information, passport number, loyalty membership information, emergency contacts

Legitimate Interest: To facilitate travel arrangements and coordination for students and affiliated travelers through UVU programs. 

Contract: If there is a contract that governs your use of travel sites, Personal Information is processed pursuant to that contract.

Emergency situations

Name, personal health information, emergency contacts

Vital Interest: Our processing of your Sensitive Personal Information is to protect an interest that is essential to your life or the life of someone else

5. How Does UVU Receive Your Personal Information

A. From You, the Data Subject:

UVU may receive your Personal Information when you visit UVU websites, apply for or attend UVU classes or programs, apply for or take online courses with UVU, travel with UVU to a location in the EEA, attend events sponsored by UVU in the EEA, or otherwise interact with UVU in the EEA.

B.   From Third Parties:

UVU may also receive your Personal Information from third parties. Examples include college entrance exam scores received from testing agencies, and online course registration information received from third parties that administer online courses.

6. Who Processes Your Personal Information? 

A.   UVU Personnel:

Your Personal Information may be processed by UVU trustees and employees, including faculty, researchers, medical professionals, financial aid counselors, human resources professionals, law enforcement officers, and others, as may be necessary to carry out the purposes for processing the information and UVU activities.

B.   UVU Related Organizations:

UVU may share your Personal Information with UVU related organizations, such as the Utah Valley University Foundation.

C.   Third Parties:

UVU may share your Personal Information with third parties, such as: educational platform providers and course partners to further the purposes for processing the information and UVU activities; U.S. and foreign government entities to fulfill regulatory obligations (e.g., visa processing) and to facilitate access to funding sources (e.g., financial aid); partner institutions to facilitate study abroad activities; and vendors to provide services related to your affiliation with UVU (e.g., print diplomas, arrange housing) and to improve UVU outreach efforts.   

Please note that UVU may provide anonymized data developed from Personal Information to third parties, such as government entities and research collaborators, and that such anonymized data is outside the scope of this GDPR Privacy Notice.

7. How Long Does UVU Keep Your Personal Information?

UVU keeps your Personal Information as required by law or our policies to perform our legitimate interests, contracts, and substantial public interests. Many of our record retention schedules can be found at the Utah Division of Archives and Record Services’ website. View our retention schedules.

View retention schedules for the State of Utah which apply if we do not have a retention schedule for the type of records in our retention schedules.

8. What Are Your Rights as a Data Subject?

As a Data Subject pursuant to the GDPR, you have certain rights.  This GDPR Privacy Notice summarizes what these rights under the GDPR involve and how you can exercise these rights.  More detail about each right, including exceptions and limitations, can be found in Articles 15-21 and 77 of the GDPR.

Please note:   Nothing in this GDPR Privacy Notice is intended by UVU to waive sovereign immunity or any other defenses or immunities afforded by any or all U.S. federal law, Utah state law, and EU law.

The Right of Access

You have the right to request that UVU confirm whether it is processing your Personal Information.  If UVU is processing your Personal Information, you have the right to access that Personal Information, and UVU will provide you with a copy of that Personal Information unless prevented by applicable law.

The Right of Correction

You have the right to request that UVU correct any inaccurate Personal Information that it maintains about you.  You also have the right to request that UVU complete any incomplete Personal Information that it maintains about you, which could be accomplished by incorporating a supplementary statement that you submit.  If UVU concurs that the Personal Information is incorrect or incomplete, UVU will promptly correct or complete it. 

The Right to Erasure

You have the right to request the erasure of Personal Information that UVU maintains about you in certain circumstances.  These circumstances are identified in Article 17 of the GDPR and include that the Personal Information is no longer necessary in relation to the purpose(s) for which it was collected.

Subject to applicable U.S., state, and EU law and UVU policies, including but not limited to its Privacy Statement, and provided that there are no overriding legitimate grounds for UVU to retain the Personal Information, UVU will comply with the request and will take reasonable steps to inform any third parties with whom the Personal Information was shared.

The Right to Restrict Processing of Personal Information

You have the right to request that UVU restrict the processing of your Personal Information where one of the reasons identified in Article 18 of the GDPR apply.  These reasons include that the Personal Information is inaccurate, the processing is unlawful, or UVU no longer needs the Personal Information.

If UVU grants your request to restrict processing, UVU will only process that Personal Information with your consent, for the protection of the rights of another natural or legal person, for reasons of important public interest, for the establishment, exercise or defense of legal claims, or as otherwise required by applicable U.S., state, or EU law.

The Right to Data Portability

Where the basis for processing is either consent or performance of a contract between you and UVU, and where the processing is carried out by automated means, you have the right to receive your Personal Information that you have provided to UVU. UVU will provide the Personal Information in a structured, commonly used, and machine-readable format.  Where technically feasible and upon your request, UVU will transmit the Personal Information directly to another entity. 

The Right to Withdraw Consent

If the basis for processing your Personal Information is consent, you may revoke your consent at any time.  Upon receipt of your notice withdrawing consent, and if there are no other legal grounds for the processing, UVU will stop processing the Personal Information unless the processing is necessary for the establishment, exercise, or defense of legal claims.  Revoking consent does not affect the lawfulness of processing that occurred before the revocation.

The Right to Object to Processing

In certain situations, you may have the right to object to processing of your Personal Information

  • Public Interest or Legitimate Interests. If the basis for processing your Personal Information is public interest or legitimate interests, you have the right to object to processing the Personal Information. UVU will cease processing unless UVU demonstrates overriding legitimate grounds for processing or the processing is necessary for the establishment, exercise, or defense of legal claims.
  • Direct Marketing. If UVU is using your Personal Information for direct marketing purposes such as fundraising, you have the right to object at any time, and UVU will stop using your Personal Information for that purpose .

The Right to File a Complaint

You have the right to submit a complaint with an EU supervisory authority, in particular the one in the EU Member State of your habitual residence, place of work, or place of the alleged violation, if you believe that UVU’s processing of your Personal Information violates the GDPR. 

For more information on the process for submitting a complaint, consult the relevant EU supervisory authority.

How to Exercise Your Rights

In order to exercise any of these rights, except the right to file a complaint with an EU supervisory authority, you should submit your request to UVU’s Information Systems Department:

Email:  compliance@uvu.edu

Telephone:  +1 (801) 863-8245

Address:
Utah Valley University Information Technology
800 West University Parkway, MS 130
Orem, UT 84058
Attn: GDPR Compliance

At that time, you will be asked to:

  • Identify yourself
  • Provide information to support that the GDPR applies to you (see Section 2, above)
  • Identify the specific information or data that you are concerned about
  • State what right(s) you wish to exercise

To expedite processing your request, please identify the data collection location (e.g., the website where your Personal Information was collected), if known.

10. How Does UVU Respond to Requests for Personal Information?

In addition to the rights provided by the GDPR, you may also have rights with respect to your Personal Information pursuant to U.S. federal law, state law, or UVU policy.  When you submit a request to UVU to exercise your rights, UVU will respond in accordance with existing UVU policies and procedures that implement the relevant privacy law(s). These include, but are not limited to, policies pertaining to student education records and policies pertaining to certain health records that UVU maintains.

11. Existence of Automated Individual Decision-Making

UVU may use automated decision-making, including profiling, to help identify prospective UVU supporters and its activities. The logic takes an all-factor approach to assessing a possible donor’s propensity to support UVU and may result in a prospective donor being contacted to explore support opportunities.

You will not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless the decision is necessary for entering into or performing a contract or unless you explicitly consent.

12. Transfer of Personal Information outside the EEA

UVU is based in the U.S. and is subject to U.S. and Utah law.  Personal Information that you provide to UVU will generally be hosted on U.S. servers.  To the extent that UVU needs to transfer your information either (a) from the EEA to the U.S. or another country or (b) from the U.S. to another country, UVU will do so on the basis of either (i) an “adequacy decision” by the European Commission; (ii) EU-sanctioned “appropriate safeguards” for transfer such as model clauses, a copy of which you may request, if applicable, by contacting UVU as set forth in Section 9; (iii) your explicit and informed consent; or (iv) it being necessary for the performance of a contract or the implementation of pre-contractual measures with UVU, in which case UVU will inform you of the intent to transfer the Personal Information.  Please note that the U.S. is not currently considered a safe harbor country under the GDPR. 

13. How Do I Contact UVU, the Data Controller?

UVU is the data controller.  If you have any questions about anything contained in this GDPR Privacy Notice, please contact UVU’s Information Systems Department:

Email: compliance@uvu.edu

Telephone: +1 (801) 863-8245

Address:
Utah Valley University Information Technology
800 West University Parkway, MS 130
Orem, UT 84058
Attn: GDPR Compliance

14. GDPR

If you are interested in reviewing an English version of the GDPR, please see the Regulation document.

15. Updates to GDPR Privacy Notice

UVU may update this GDPR Privacy Notice from time to time.  Any changes will become effective upon posting of the revised GDPR Privacy Notice.