PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA PURSUANT TO ARTICLES 13–14 OF THE GDPR
Welcome to Erasmus Student Network Milano Bocconi.
In order to proceed with your registration and participation in our activities, we need to process certain personal data relating to you. This notice explains how we do so.
1. Data Controller
The Data Controller is Erasmus Student Network Milano Bocconi – ETS, with its registered office at Viale Marche No. 21 – 20125 – Milan (MI), Italy.
You may contact us regarding any privacy-related matter at: milano_bocconi@esn.it
2. What Personal Data We Process
In order to manage your membership, we collect:
Identification and Contact Data: first name, last name, date of birth, nationality, address, email address, and telephone number.
Academic Data: home university and host university (required to verify your Erasmus/International student status).
Browsing Data: access logs relating to the Jupiter platform.
Images and Videos (optional): photographs and video recordings taken during events, only if you provide your specific consent.
Health Data (Article 9 GDPR): exclusively in relation to specific trips and events, we may ask you to provide information regarding food intolerances or allergies in order to ensure your safety during the event. Such data will be deleted once the event has ended.
3. Why We Process Your Data (Purposes of Processing and Legal Basis)
a) Membership Registration (Mandatory): to register you in the members' register, issue your digital and/or physical ESNcard, and activate the mandatory insurance coverage.
Legal Basis: Performance of the membership agreement (Article 6(1)(b) GDPR).
b) Management through Jupiter (Mandatory): your personal data are recorded on the Jupiter/Galaxy platform, shared with ESN International and ESN Italy, in order to allow you to use your ESNcard throughout Europe.
Legal Basis: Performance of the agreement, necessary for the provision of the ESNcard service (Article 6(1)(b) GDPR).
c) Event Coordination – WhatsApp/Telegram: we will provide you with a link allowing you to voluntarily join messaging groups used for logistical coordination and safety during the events for which you register.
Legal Basis: Legitimate interest of the Association in ensuring the safe management of its activities (Article 6(1)(b) GDPR).
d) Promotional Communications: we may send you emails regarding future events similar to those in which you have participated and publish photographs and videos on the Association's website and social media channels in order to document and promote its activities.
Legal Basis: Consent of the data subject (Article 6(1)(a) GDPR), which may be withdrawn at any time.
e) Event Safety Management (health data relating to food intolerances).
Legal Basis: Explicit consent of the data subject (Article 9(2)(a) GDPR).
4. Source of the Data and Categories of Recipients
Your personal data may initially be provided to us by public institutions with which the Data Controller actively cooperates, such as universities and entities affiliated with them.
Your personal data (or the personal data of the individual(s) for whom you act as legal representative or guardian) will not be disclosed. However, they may be communicated to public and private entities, organisations, and institutions for the purposes specified above and in the cases provided for by law or regulations.
In particular, your personal data may be communicated to:
The ESN Network: ESN Italy and ESN AISBL (Brussels) for the management of the central database;
The ESN Network (ESN Italy and ESN International): for example, for the management of the central Jupiter database;
ESN Italy, acting as Joint Data Controller;
Insurance companies: for the activation of accident and third-party liability insurance coverage;
Public authorities, only where required by law (e.g. Police Headquarters for accommodation registration, anti-terrorism lists).
5. Transfer of Personal Data Abroad
Your personal data are not transferred outside the territory of the European Union.
However, they may be transferred outside the European Economic Area where this is necessary for the management of your relationship with the Data Controller, for example through the use of platforms located in the United States, such as Google Drive. In such cases, the transfer shall take place in compliance with the EU-U.S. Data Privacy Framework or by means of Standard Contractual Clauses.
In such cases, recipients of the personal data will be subject to protection and security obligations equivalent to those guaranteed by the Data Controller.
In any event, only the personal data strictly necessary to pursue the purposes described above will be communicated, and, where required, all safeguards applicable to transfers of personal data to third countries will be implemented.
6. Methods of Processing and Data Retention Period
Your personal data are processed lawfully and fairly, in compliance with the provisions of Articles 5 and 6 of the GDPR, for the purposes described above and in accordance with the fundamental principles established by the applicable legislation.
The processing of personal data may be carried out by means of manual, electronic and telematic tools, always under the protection of appropriate technical and organisational measures designed to ensure their security and confidentiality, particularly in order to reduce the risks of destruction or loss, including accidental loss, unauthorised access, or processing that is unlawful or incompatible with the purposes for which the data were collected.
Personal data will be processed by the Data Controller only for the time necessary to provide the requested services. As a general rule, personal data will be retained for 10 years, unless a longer retention period is required by laws, regulations or European Union legislation, or for the establishment, exercise or defence of legal claims or judicial proceedings.
Where personal data are processed for promotional purposes, and without prejudice to the data subject's right to withdraw consent at any time, such data will be retained for 2 years.
7. Nature of the Provision of Personal Data
The provision of your personal data is mandatory where it is necessary to perform pre-contractual or contractual measures with the Data Controller, or to comply with legal obligations incumbent upon the Data Controller, such as accounting and invoicing obligations.
Failure to provide such personal data will make it impossible for the Data Controller to provide the requested services.
Where the provision of personal data is based on consent, the provision of such data is optional, and failure to provide consent shall not affect the contractual relationship.
8. Your Rights
You may exercise, at any time, the rights granted to you under the GDPR, including the right to:
a) access your personal data and obtain information regarding the purposes pursued by the Data Controller, the categories of personal data processed, the recipients to whom the data may be disclosed, the applicable retention period, and the existence of any automated decision-making processes;
b) obtain, without undue delay, the rectification of inaccurate personal data concerning you;
c) obtain the erasure of your personal data, where the conditions provided for by law are met;
d) obtain the restriction of processing, where applicable;
e) request the portability of the personal data you have provided to specifically designated third parties, or receive such data in a structured, commonly used and machine-readable format, including for the purpose of transmitting those data to another Data Controller without hindrance, whenever this is required by law;
f) lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
The exercise of the above rights is subject to the limitations, rules and procedures laid down in Regulation (EU) 2016/679, with which the Data Subject is required to comply.
In accordance with Article 12(3) of the GDPR, the Data Controller shall provide the Data Subject with information on the action taken in response to the request without undue delay and, in any event, no later than 30 days from receipt of the request.
Where necessary, taking into account the complexity and number of requests, this period may be extended by a further 60 days.
The Data Controller shall inform the Data Subject of any such extension and of the reasons for the delay within 30 days of receiving the request.
To exercise these rights, it is sufficient to submit a written request to the Data Controller or to the Data Protection Officer, where appointed, using the contact details indicated below and the appropriate forms available at the registered office or on the institutional website.
9. Data Protection Officer (DPO)
The Data Controller has not appointed a Data Protection Officer (DPO), as it is not required to do so under the applicable legislation.
This form is intended to regularise your status as an Ordinary Member of ESN Milano Bocconi, in compliance with the GDPR and Italian Copyright Law. Completion of this form is required in order to receive your operational credentials.
A) Privacy Section
I declare that I have received and read the Privacy Notice for Ordinary Members provided by ESN Milano Bocconi, acting as the Data Controller, that I understand my personal data will be processed for the management of the Association's activities (including the use of platforms such as Jupiter and organisational WhatsApp groups), and that I am aware of my rights.