Pursuant to the provisions of Regulation (EU) 2016/679 (“Regulation on the protection of natural persons with regard to the processing of personal data and on the free movement of such data”, hereinafter “the EU GDPR”), we hereby inform you that Study Abroad Italy, Inc., DBA SAI Programs (hereinafter referred to as “SAI”), in its capacity as Data Controller, pursuant to Article 12 of the EU GDPR, of the processing of your personal data and information, is required to provide you with the following information:
1. All personal data you have provided to SAI, as well as any entity from whom personal data are collected, and all the further data provided in order to allow the planning and organization of the SAI study abroad programs with host schools in Europe, and thereof aimed at the performance of the academic services to be provided to you, will be processed and handled by SAI in accordance with its policies and with the aforementioned EU GDPR, and with the principles of fairness, lawfulness, transparency, purpose limitation, accuracy, storage limitation, integrity and confidentiality and accountability, as well as the utmost protection of your privacy; sensitive data processing will only take place in relation to data regarding your health condition (such as diseases, allergies, food intolerances) or judicial data.
2. Data is collected from you, your respective school, and relevant parties upon your request. This data shall be processed exclusively for SAI purposes, connected or related to the activities carried out by SAI, such as study programs in partnership with European schools, the accomplishment of bureaucratic practices for your entry in the EU, the performance of the contractual obligations of SAI in connection with your study abroad stay with host schools in Europe. In particular the data supplied or collected will be processed for the following purposes:
a. to fulfill the obligations established by any applicable law, including the regulations or the European Union Law;
b. to execute the contractual obligations with reference to your enrollment with the SAI study abroad programs organized with host schools in Europe (such as, but not limited to, course enrollment, grades, student health and safety protection);
c. with reference to data provided by public authorities or by hospitals should an accident or aggression occur to the student, in order to take the necessary actions.
Sensitive data regarding your health conditions and food habits will only be processed for the purpose of protecting student safety or of fulfilling the obligations established by law, by regulations or by the European Union Law; sensitive data regarding judicial measures which may have been provided to SAI by public bodies will be processed only for purposes relating to a health or safety emergency and complying with any applicable mandatory provision of local or European Union law.
3. Submittal and processing of personal data is necessary in order to achieve the purposes above specified.
4. Any refusal will make it impossible to carry out the necessary activities and the correct administrative and didactic management of student programs necessary to accomplish the contractual obligations of SAI in connection with your study abroad stay with host schools in Europe, as well as the obligations imposed by law.
5. All personal data, including sensitive data, will be collected and processed automatically and/or manually in compliance with the provisions of the EU GDPR and by adopting the appropriate data protection measures, securing strictly monitored access.
6. Data processing will take place, according to the aforementioned points, within those offices of SAI premises which are exclusively dedicated to SAI study abroad programs; the data will be handled only by the persons who are in charge of and responsible for SAI activities and by other persons working on the same areas as specified in internal communications, and who process data for your course enrollment, posting of grades, and processing of your transcripts by the SAI host school; sensitive data will be handled only within those offices of SAI premises which are exclusively dedicated to SAI study abroad programs, for the purposes above specified, by persons officially appointed to this task. Your personal data you have provided may be transferred overseas pursuant to the terms, conditions and limits specified by Chapter V of the EU GDPR.
7. In particular, your data may be communicated, in compliance with the rules above indicated, to public or private subjects to whom they may be necessary in order to fulfill obligations set forth by local laws, regulations or EU laws; sensitive data may be communicated to public bodies and authorities (such as public hospitals, public safety authorities, police offices, courts, magistrates and the like) and to private subjects (such as private hospitals and clinics, security supervisors, insurance companies) only for purposes relating to health and safety emergency and for the purposes of fulfilling obligations set forth by local laws, regulations and EU laws.
8. The Data Controller, under the law and with particular reference to the safety obligations related to the automatic processing of your data, is SAI.
9. All data will be processed by SAI in its capacity as Data Controller with the supervision of Marco Minuti, Data Manager, who can be reached at the following telephone number/email: +39 371 168 0025 / firstname.lastname@example.org.
10. You will be able to exercise any and all other rights, as applicable, foreseen by Articles from 15 to 22 of the EU GDPR, namely right of access, right to rectification, right to erasure or “to be forgotten”, right to restriction of processing, right to data portability, right to object; you can read Regulation (EU) 2016/679 at: http://ec.europa.eu/justice/data-protection/reform/files/regulation_oj_en.pdf
11. Please be also informed that:
a. the period for which your personal data will be stored will be from now until 20 years after your study abroad program is complete.
b. you can withdraw your consent, if granted below, at any time and even only orally, but this will not affect the lawfulness of processing your personal data based on your consent before withdrawal.
c. you have legal rights and remedies against any breach of your personal privacy according to articles from 77 to 84 of the EU GDPR.