In this privacy notice, we explain how we process your personal data in connection with your studies. For additional information on how we handle your data, please see the privacy notice on our website:https://www.rwu.de/kontakt/datenschutz
Name and Address of the Data Controller
Data controller within the meaning of Article 4(7) of the GDPR:
Ravensburg-Weingarten University of Applied Sciences
Doggenriedstraße 70
D - 88250 Weingarten
Represented by: Rector Professor Dr.-Ing. Thomas Spägele
Tel: 0049 (0) 751/501-9344
Email: info@rwu.de
Website: https://www.rwu.de/
External Data Protection Officer
Our external data protection officer can be reached at:
Name: Benedict Lenz
Email: dsb@rwu.de
Website: https://www.exacon-gmbh.de
Information on Data Processing
Nature and Purpose of Processing
The university processes your personal data to the extent necessary to fulfill its legal obligations, provided that no legitimate interests of the data subjects conflict with this. Processing is carried out in particular for the purposes of student administration, the conduct of academic programs, and examination procedures. In this context, the university processes personal data both in paper form and electronically using the administrative and information systems in place. Data processing encompasses the following purposes in particular:
- Conducting the application and admission process, including verifying admission requirements and making selection decisions
- Enrollment and administration of student status (e.g., academic semesters, semesters of leave, withdrawal)
- Organizing and administering the course of study, including courses, internships, student projects, and other study-related activities
- Conducting examination procedures, including exam registration, exam withdrawal (e.g., due to illness), grade evaluation, recognition procedures, appeal procedures, and the administration of examination records
- Preparation of academic and examination certificates as well as graduation documents (e.g., transcripts, diplomas, supplementary documents)
- Compliance with statutory documentation, verification, and reporting requirements, e.g., under the State Higher Education Act, the Higher Education Statistics Act, BAföG regulations, or health insurance law, as currently in effect
- Management of university IT accounts, including the provision of email accounts and access to learning platforms and university IT systems
- Ensuring the operation of the university’s infrastructure, in particular the IT systems on which your data is processed
- Quality assurance, evaluation, and statistical analysis, to the extent required by law
- Archiving, to the extent required by law or arising from documentation obligations
- Conducting legally or organizationally required training sessions, in particular safety, laboratory, machinery, or occupational safety training, including documentation of participation and certification
- General administrative and organizational processes necessary for the administration of academic programs and to ensure the proper operation of the university (e.g., room usage, scheduling, access controls, management of access permissions)
- To the extent necessary, personal data is also processed to ensure technical and organizational operational processes, IT and information security, and compliance with legal requirements in public higher education operations.
The university uses your personal data to communicate with you in connection with your affiliation with the university. We will contact you regarding all aspects of your studies in writing, by phone, or by email—depending on the contact information you have provided to the university—without requiring separate consent.
Data Categories
Only data necessary for the conduct of your studies, the administration of your student status, and the fulfillment of the university’s legal obligations is processed. In the context of your studies, the processing of the following data or data categories is required:
- Identity data (e.g., name, former names, date of birth, place of birth, gender, nationality)
- Address and contact information
- Data regarding eligibility for university admission and previous education and study periods
- Application and admission data
- Academic and enrollment data (e.g., degree program, semester, leaves of absence, withdrawal)
- Information regarding student health insurance in accordance with the currently applicable Student Health Insurance Registration Ordinance (SKV-MV)
- Proof of payment and fees (e.g., semester tuition, other fees)
- Data related to participation in courses and mandatory training sessions
- Exam and academic performance data (e.g., exam registrations, results, course credit recognition, decisions in appeal proceedings)
- Administrative and communication data
- Data regarding the use of university IT systems, including user IDs and student ID cards
- Data that must be transmitted in accordance with statutory reporting requirements (e.g., under the Higher Education Statistics Act, BAföG, health insurance)
- IT, communication, and access data (user IDs, system and security logs, communication metadata, and data required for IT security and the detection and handling of security incidents). There is no monitoring of academic performance or conduct.
- Where applicable, health data, to the extent that it is necessary for decisions regarding admission to the program, the granting of accommodations for students with disabilities, for decisions regarding examinations, leaves of absence, waivers and deferrals of tuition fees, as well as for the conduct of practical study semesters and applications for study abroad programs.
Further details are set forth in the “University Bylaws on the Obligation to Provide Personal Data and on the Processing of Personal Data to Fulfill the University’s Tasks,” which comprehensively regulates the relevant data categories and collection requirements.
Legal Basis
Your personal data is processed to fulfill the university’s statutory obligations in connection with your studies and the administration of your student status. The legal basis is Article 6(1)(e) of the GDPR and Section 4 of the Baden-Württemberg State Data Protection Act (LDSG) in conjunction with Section 12(1) of the Baden-Württemberg State Higher Education Act (LHG). Additional legal bases apply to specific processing activities, in particular:
- State Higher Education Act
- Study and Examination Regulations of Ravensburg University, as currently in force
- Higher Education Statistics Act
- Student Health Insurance Registration Ordinance (SKV-MV)
- BAföG / Regulations of the Offices for Educational Assistance
- Other special statutory provisions, if applicable
To the extent that health data is collected, this is done in accordance with Section 12(2) of the Baden-Württemberg Higher Education Act (LHG BW)
To the extent that individual data processing operations are based on consent (e.g., voluntary disclosures or the use of certain services), the legal basis is Article 6(1)(a) of the GDPR. In such cases, you will be informed separately.
The relevant obligations regarding the provision of personal data, as well as the permitted data processing activities, are also set forth in the “University Bylaws on the Obligation to Provide Personal Data and on the Processing of Personal Data for the Purpose of Fulfilling the University’s Tasks.”
Recipients and Transfers to Third Countries
In the context of conducting academic programs, administering student status, and complying with legal requirements, your personal data will be disclosed only to those entities that require it to perform their duties or are legally obligated to do so. These include, in particular:
Internal Recipients
- Student Affairs and Admissions Office
- Exam Administration and Examination Boards
- Faculties, program directors, and faculty members
- Internship offices or departments that oversee internship semesters
- University representatives (e.g., Equal Opportunity Officers, Disability Services Officers, Quality Management Officers, International Office), to the extent necessary to fulfill their duties
- University IT and Data Center
- Library
- Administrative units responsible for payments, fees, tuition, or collections
- Departments and relevant offices involved in specific procedures (e.g., appeals, examination regulations)
External recipients
- Student Services Organizations, to the extent necessary to fulfill statutory or statutory-based duties
- Health insurance providers within the framework of the Student Health Insurance Registration Ordinance (SKV-MV)
- Offices for Educational Assistance (BAföG)
- German Pension Insurance (e.g., for enrollment or withdrawal notifications)
- State Statistical Office within the framework of statutory reporting obligations under the Higher Education Statistics Act
- Where applicable, foreign universities, cooperation partners, or partner universities within the framework of exchange programs or internship semesters (only to the extent necessary for the implementation of the respective program)
- Where applicable, government agencies in accordance with statutory obligations to provide information
Data processors pursuant to Art. 28 of the GDPR
To provide certain services, the university engages carefully selected data processors. These processors handle personal data exclusively in accordance with documented instructions and on the basis of a data processing agreement. This includes, in particular, providers and service providers in the following areas:
- IT infrastructure, system administration, and data center operations
- Software and cloud services (e.g., human resources management systems, training or communication platforms, Microsoft 365, HISinOne hosting)
- Electronic archiving, document management, and data destruction
- Video conferencing and communication systems
Personal data will only be disclosed to other recipients if there is a legal basis for doing so or if you have given your prior consent.
The processing of personal data outside the European Union (EU) or the European Economic Area (EEA) may occur on a case-by-case basis, particularly in connection with the use of IT systems or cloud services. In such cases, a transfer will only take place if the specific requirements of Articles 44 et seq. of the GDPR are met. This means that either an adequacy decision by the European Commission exists for the country in question (e.g., for the United Kingdom, Switzerland, or Canada), or an adequate level of data protection is ensured through the adoption of EU Standard Contractual Clauses and, if necessary, supplementary safeguards.
Retention Period
We store your personal data only for as long as is necessary for the respective purposes for which we process it. If we process data for multiple purposes, it will be deleted or stored in a format that does not allow direct identification of you as soon as the last specific purpose has been fulfilled. The following principles apply to individual processing operations:
- Applicant data that does not result in enrollment will be deleted no later than the end of the calendar year following the year of application.
- Student data is generally deleted as soon as it is no longer necessary for the conduct of studies, for examination procedures, or for the administration of student status, and provided that no statutory retention requirements preclude this. Certain categories of data may be stored for longer periods due to requirements related to examinations, archiving, or budgetary regulations.
- Examination-related documents—in particular applications, decisions, certificates, recognition or appeal proceedings, and related correspondence—are retained in accordance with the higher education regulations governing examination files. The retention period begins at the end of the calendar year in which the examination was completed or the examination case was finally closed.
- Data relevant to degree conferral, particularly that required for the issuance and subsequent verification of transcripts, certificates, and degree documents, is retained for a longer period in accordance with statutory or archival retention requirements. This serves to validate issued degree documents and to provide proof of acquired qualifications.
- Data required to defend against or enforce legal claims may be retained by us for as long as a corresponding proceeding could be initiated.
- Data subject to archiving requirements is retained in accordance with the provisions of the Baden-Württemberg State Archives Act or submitted to the responsible archive.
Consequences of Non-Issuance
You are only required to provide the personal data that is necessary for the completion of your degree program, for the administration of your student status, or as required by law. Without this data, the university is generally unable to admit applicants to the program, carry out the necessary student administration procedures, or conduct examination processes. If you refuse to allow your data to be processed in these cases, this may result in your inability to begin, continue, or properly complete your studies. However, providing voluntary or optional data is not mandatory; failure to provide such data in these cases will not result in any adverse consequences.
Automated Decision-Making:
Automated decision-making within the meaning of Article 22 of the GDPR does not take place. Should we use automated decision-making procedures in individual cases in the future, we will provide separate notice of this to the extent required by law.
Your Rights as a Data Subject
Data subjects may contact the data controller or the data protection officer directly with any questions regarding data protection and the processing of their personal data.
Right of Access (Art. 15 GDPR)
You may request information about your stored data.
Right to Rectification (Art. 16 GDPR)
You may have inaccurate data corrected.
Right to erasure (Art. 17 GDPR)
You may request that we erase your data, provided the legal requirements are met.
Right to Restriction of Processing (Art. 18 GDPR)
You may request that the processing of your data be restricted, provided the legal requirements are met.
Right to Data Portability (Art. 20 GDPR)
To the extent technically feasible, you have the right to receive your data in a structured, machine-readable format.
Right to Object (Art. 21 GDPR)
You may object to the processing of your data at any time for reasons arising from your particular situation, provided that the processing is based on Art. 6(1)(e) or (f) of the GDPR.
Right to Withdraw Consent (Art. 7(3) GDPR)
If you have given your consent todata processing, you may withdraw it at any time with future effect. Withdrawal does not affect the lawfulness of processing carried out on the basis of your consent prior to the withdrawal. Please direct your withdrawal to the contact information provided for the Data Protection Officer or the data controller.
Timeframes for Complying with Data Subjects’ Rights
We generally strive to respond to all requests within 30 days. However, this timeframe may be extended for reasons related to the specific data subject right or the complexity of your request.
Competent Supervisory Authority
We take your concerns and rights very seriously. However, if you believe that we have not adequately addressed your complaints or concerns, you have the right to file a complaint with a competent data protection authority:
The State Commissioner for Data Protection and Freedom of Information
P.O. Box 10 29 32
70025 Stuttgart
Phone: 07 11/61 55 41-0
Fax: 07 11/61 55 41-15