Wireless network privacy notice
Information you need to know:
The IT Services department is part of Liverpool John Moores University. See further information on the institution.
Liverpool John Moores University is the Data Controller.
Our Data Protection Officer can be contacted at DPO@ljmu.ac.uk
LJMU takes your privacy very seriously. This privacy notice explains how we use your personal information and your rights regarding that information. We will always use your data as set out in the principles of the General Data Protection Regulation (GDPR) and all current Data Protection Legislation. We are committed to being transparent about how we collect and use your data and to meeting our data protection obligations.
For information about how the wider University uses personal data please see the Privacy Notice section of our website.
What information are we collecting?
Whenever you connect to a wireless network at LJMU, we will collect log information that includes your username, date/time, location and IP address. This information can be cross referenced with logs from other systems that can be used to identify what systems/web-sites you have connected to.
Why are we collecting your data and what is the legal basis for this?
LJMU will collect personal data from you for several reasons, and will at all times do so in compliance with the principles of the GDPR, and for one of the legal basis set out in Article 6 of the Regulation.
We are processing your information in order to provide technical support. It may also be used to investigate who has visited certain web-sites, e.g. a Phishing site.
The lawful basis is Article 6 (F) - that LJMU have legitimate interests in collecting this data.
Who has access to this data?
Your personal data will be used only by relevant LJMU staff where the data is necessary for them to undertake their designated role.
This is limited to LJMU IT Services technical support staff. We may also provide information to Police if requested to do so.
How does the University protect your data?
The University takes Data Protection very seriously and at all times your personal data will be handled in line with the University’s Information Security Policy.
For how long does the University keep your data?
We will keep your information for no longer than two years in accordance with our Records Retention Schedule.
As a data subject, you have a number of rights. You can:
- Access and obtain a copy of your data on request, this could be in a portable electronic format;
- Require the University to change incorrect or incomplete data if you think that it is inaccurate or out of date
- Require the University to delete or stop processing your data, for example where the data is no longer necessary or legally required for the purposes of processing
If you would like to exercise any of these rights, please contact the Data Protection Officer DPO@ljmu.ac.uk
What if you do not provide data?
We are unable to respond to your request if you do not provide us with sufficient contact details. If you would like to seek access to your own records then for security reasons we will not be able to disclose this to you without verification of your identity.
We can extract specific data from the logs for you, in which case we would require your username, date and time for the information that you require.
Please note that if you require this information for a large range of time, it will be difficult to collate and will take time. We will be able to advise you when you request the information approximately how long it will take to provide.
Transfers of data outside the UK
Generally, we do not send your personal data outside the UK. However, in some specific cases, we may transfer the personal data we collect to countries outside the UK in order to perform our contract with you/or a contract with another organisation that requires your personal data i.e. a collaboration agreement with a university based outside of the UK. Where we do this, we will ensure that your personal information is protected by way of an ‘adequacy regulation’ with the UK or by putting alternative appropriate measures in place to ensure that your personal information is treated by those third parties in a way that is consistent with and which respects the UK laws on data protection. For example model contractual clauses, data sharing/data processing agreement and binding corporate rules (where applicable).
Automated decision making
We will not make any decisions about you automatically using a computer, based on your personal data. All decisions affecting you will be taken by a human.
How to complain to the Information Commissioner’s Office?
You have the right to complain to The Information Commissioner if you believe that our processing of your personal data does not meet our data protection obligations. The Information Commissioner can be contacted:
Post: Information Commissioners Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK95AF.
Telephone: 0303 123 1113.
Email: contact can be made by accessing www.ico.org.uk