Privacy Notice

Article 1 – Information on the Collection of Personal Data

(1) General information

This privacy notice provides information on the processing of personal data in connection with the use of this application portal for the application, admission and selection procedure for the Applied Data Science M.Sc. programme at Georg-August-Universität Göttingen, as well as the subsequent transfer of relevant application records for University administration following enrolment.

"Personal data" means any information relating to an identified or identifiable natural person within the meaning of Art. 4 para. 1 of the General Data Protection Regulation (GDPR).

(2) Controller

The Controller pursuant to Art. 4 para. 7 of the EU General Data Protection Regulation (GDPR) is:

Georg-August-Universität Göttingen Stiftung öffentlichen Rechts
(excluding University Medical Center Göttingen)
represented by the President, Prof. Dr. Axel Schölmerich
Wilhelmsplatz 1
37073 Göttingen
Germany
Phone: +49 (0)551 39-21000
Email: praesident@uni-goettingen.de

(3) Responsible unit

The unit responsible for conducting the application and selection procedure is the Selection Committee for Applied Data Science at the Institute of Computer Science, Faculty of Mathematics and Computer Science.

Institute of Computer Science
Faculty of Mathematics and Computer Science
Georg-August-Universität Göttingen
Goldschmidtstraße 7
37077 Göttingen
Germany

(4) Data Protection Officer

The Data Protection Officer of Georg-August-Universität Göttingen can be contacted at:

Ass. iur. Florian Hallaschka
Georg-August-Universität Göttingen
Goßlerstraße 5/7
37073 Göttingen
Germany
Email: datenschutz@uni-goettingen.de

Article 2 – Scope and Purposes of Processing

(1) Scope of processing

Personal data are processed through the application portal to the extent necessary for the administration and examination of applications and for carrying out the applicable admission and selection procedure for the Applied Data Science M.Sc. programme.

(2) Categories of personal data

Personal data are processed from the creation of an applicant account and during the preparation, submission, examination and assessment of an application.

Depending on the applicable degree programme and application procedure, the following categories of personal data may be processed in particular:

(3) Purposes of processing

Personal data are processed for the purposes of:

(4) Further processing

Where the University intends to further process personal data for a purpose other than that for which the data were collected, the University will provide the applicant, before that further processing takes place, with information on that other purpose and any further information required under Art. 13 para. 3 GDPR.

(5) Contact by email

Where an applicant contacts the University by email in connection with the application, admission or selection procedure, the personal data contained in the communication are processed to the extent necessary to handle and respond to the enquiry or request.

Such correspondence is retained only for as long as required for the respective purpose and in accordance with the applicable statutory and University retention and deletion requirements.


Article 3 – Rights of Data Subjects

(1) Rights under the GDPR

You have the following rights under the General Data Protection Regulation (GDPR) with regard to personal data concerning you, subject to the respective statutory requirements:

Where applicable, you have the right to data portability in accordance with Art. 20 GDPR. This right does not apply where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the University (Art. 20 para. 3 sentence 2 GDPR).

(2) Withdrawal of consent

Where processing is based on consent, you have the right to withdraw your consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. Processing or retention that is required or permitted on another legal basis remains unaffected.

(3) Right to lodge a complaint

You also have the right to lodge a complaint with a supervisory authority in accordance with Art. 77 GDPR.

The competent supervisory authority for Georg-August-Universität Göttingen is:

Der Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
Germany
Phone: +49 (0)511 120-4500
Email: poststelle@lfd.niedersachsen.de


Article 4 – Collection of Data when Using the Application Portal

(1) Technical and security data

When the application portal is accessed, technical data are processed as necessary to establish the connection, deliver the requested content and ensure the secure and reliable operation of the portal. Such data may include the IP address, date and time of the request, requested page or resource, HTTP status information and technical information transmitted by the browser.

The application portal also records limited security and audit information for selected account, authentication, security and administrative events. Depending on the event, these records may include the date and time, event type and outcome, user account identifier, IP address, browser information and limited event-related metadata.

These technical, security and audit data are processed for the provision, administration and protection of the application portal, including the detection and investigation of errors, misuse and security incidents. They are not used for advertising, behavioural analysis or profiling.

(2) Cookies

The application portal uses cookies that are technically necessary for authentication, session management, form security and the secure operation of the portal.

Cookies are small text files stored on the user's device and associated with the browser being used. They enable the portal to maintain a secure session and to recognise related requests from the same browser.

The application portal does not use analytics, advertising or tracking cookies.

(3) Session and authentication cookies

A session cookie is used to associate requests with the user's session and, after login, with the authenticated user account. This allows the portal to provide access to the corresponding application and other protected functions.

If the applicant does not select the "Remember me" option when logging in, the authenticated session is configured to expire when the browser is closed. If the "Remember me" option is selected, the authenticated session may remain valid for up to 30 days, unless the user logs out or the session is invalidated earlier.

Logging out terminates the authenticated session.

(4) CSRF protection

The portal uses a technically necessary CSRF cookie to protect forms and other state-changing requests against Cross-Site Request Forgery. This security mechanism is intended to prevent unauthorised requests from being submitted to the portal through another website.

(5) Browser settings and deletion of cookies

Users may delete cookies at any time through their browser settings and may generally configure their browser to restrict or refuse cookies.

Because the cookies used by the application portal are technically necessary, restricting or deleting them may prevent functions such as logging in, remaining authenticated or securely submitting forms from working correctly.

(6) User account and authenticated sessions

Applicants create a user account to access and use the application portal. The portal processes the account and session information necessary to authenticate users, control access to protected information and prevent unauthorised access to applicant data.

Access to applicant data and administrative functions is restricted according to the authenticated user account and the permissions assigned to it.


Article 5 – Application and Selection Data

(1) Examination and assessment of applications

The personal data and documents provided in connection with an application are processed to examine the application, determine whether the applicable entry and admission requirements are fulfilled, and conduct the applicable selection procedure.

Members of the Selection Committee, authorised reviewers and University personnel assisting with the procedure may examine the submitted information and documents and record information necessary for the assessment and documentation of the application.

(2) Automated calculations

The application portal automatically performs calculations required for the applicable selection procedure. Depending on the procedure, these may include the normalisation of grades and the calculation of scores or points.

Where the applicable procedure provides for points to be awarded on the basis of a test ranking, the points assigned to an applicant may depend on the results of other eligible applicants.

These calculations support the examination and selection procedure. The application portal does not make final admission or rejection decisions based solely on automated processing. Final decisions concerning admission or rejection remain the responsibility of the Selection Committee.

(3) Recipients

Personal data processed in connection with the application, admission and selection procedure may be accessed by or disclosed to persons and University units that require the data for the performance of their respective duties. Depending on the applicable procedure, recipients or categories of recipients include:

(4) Retention and deletion

Personal data relating to unsuccessful applicants or applicants who do not proceed to enrolment are generally retained for six months after the allocation of places and are then deleted in accordance with the applicable University retention and deletion requirements.

For successful applicants who enrol, relevant application records are transferred to the Electronic Student File (Elektronische Studierendenakte – ESA). Their subsequent retention, archiving and deletion are governed by the applicable statutory and University requirements for student records.

Where records must be retained for longer, in particular because an administrative or judicial proceeding is pending or because other applicable retention requirements apply, deletion takes place only after the relevant retention requirement has ceased to apply.


Article 6 – Legal Basis and Provision of Data

The collection and processing of personal data required for the application and selection procedure is based on the applicant's informed consent pursuant to Art. 6 para. 1 lit. a GDPR in conjunction with Arts. 7 and 8 GDPR.

Where processing is necessary for compliance with a legal obligation to which the University is subject, the legal basis is Art. 6 para. 1 lit. c GDPR. Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the University, the legal basis is Art. 6 para. 1 lit. e GDPR in conjunction with the applicable statutory and University provisions.

The processing of personal data of applicants and, following successful enrolment, students is also governed by section 17 para. 1 of the Lower Saxony Higher Education Act (Niedersächsisches Hochschulgesetz – NHG) and the University's Regulation on the Collection and Processing of Personal Data of Applicants, Students and Examination Candidates (PersDatO).

Where information or supporting documents submitted in connection with special circumstances contain special categories of personal data within the meaning of Art. 9 para. 1 GDPR, such data are processed only to the extent necessary for the purpose for which the information was provided and only where an applicable legal basis under Art. 9 para. 2 GDPR permits the processing.

The session and CSRF cookies used by the application portal are technically necessary to provide the requested service securely. The storage of and access to information on the user's device for these purposes is carried out in accordance with section 25 para. 2 no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG).

The processing of technical connection, security and audit data necessary for the secure and reliable operation of the application portal is based on the University's legitimate interest in the security and functionality of the service pursuant to Art. 6 para. 1 lit. f GDPR and, where applicable, Art. 6 para. 1 lit. e GDPR in connection with the University's public tasks. The University's interest in protecting the application portal, applicant data and the integrity of the application and selection procedure is considered to outweigh the conflicting interest in the confidentiality of these limited technical and security data.

The provision of personal data for the purpose of applying for the degree programme is voluntary. If an applicant chooses to submit an application, the personal data, information and documents required under the applicable admission regulations and the application procedure must be provided in order for the University to examine and assess the application. Applications that are not submitted are not considered in the application and selection procedure.