The EU General Data Protection Regulation (GDPR) (2016/679), Articles 13 and 14.
Created 22 May 2018, last updated 16 June 2026.
1. Name of the register
The customer register of the Tritonia Academic Library
2. Data controller
University of Vaasa / Tritonia Academic Library (Business ID: 0209599-8)
Wolffintie 34, 65200 Vaasa
Tel. 029 449 800, tietosuoja@uwasa.fi
3. Representative of the controller and contact information
Director Anne Lehto
Wolffintie 34, 65200 Vaasa
Tel. 029 449 8500, anne.lehto@uwasa.fi
4. Contact information of the data protection officer
Tel. 029 449 8000, tietosuojavastaava@uwasa.fi
5. Names of the registers
The customer register of the library system of the Tritonia Academic Library
6. Purpose of processing personal data
The Tritonia Academic Library is the library of the following universities and universities of applied sciences:
- University of Vaasa
- Vaasa University of Applied Sciences
- Yrkeshögskolan Novia (units in Vaasa and Jakobstad)
- Centria University of Applied Sciences (Jakobstad campus)
Tritonia uses the customer register of the library system to manage the library’s customer relationships.
7. Legal basis for processing personal data
- GDPR 6(1)(e): A task carried out in the public interest
8. Data content and storage times
The following data is stored in the register:
- the customer’s name, personal identification number, address, phone number and email address;
- customer group data for borrowing purposes;
- statistic group identifier for statistical calculation of borrowing;
- library card number;
- PIN code for authentication;
- material borrowed by the customer;
- material reserved by the customer;
- customer’s fees; and
- outdated contact information, possible letter of authorisation and measures taken because of unreturned loans and unpaid fees.
Personal identification number: The personal identification number is processed for the unambiguous identification of the customer and the management of activities (e.g. borrowing rights, collection of unreturned loans). The processing is based on the public interest task (GDPR 6(1)(e)) and is necessary for the reliable identification of the data subject.
Mandatory provision of information: Providing customer information (name, personal identification number, contact details) is necessary for the use of library services. If the information is not provided, the library card cannot be issued and the services cannot be used.
The library card is valid for five years. Expired library cards are removed from the library system. Inactive customers are removed from the system within three years. The card for exchange students is valid for one year. Paper forms are stored for three years (archive guidelines of the University of Vaasa).
9. Where the personal data for processing is obtained from
The data sources include:
- information reported and stored in the data system by the customer;
- public address and phone number services;
- data stored during library activities; and
- the population information system.
- In cases of debt collection, the data controller can check the customer’s up-to-date address information from the population information system of the Digital and Population Data Services Agency in order to fulfil the controller’s legal obligations related to outstanding debts.
The customer is responsible for informing about changes.
10. Transfer and disclosing of data
Personal data may be disclosed to the following categories of recipients:
- debt collection and billing services (processing of outstanding debts);
- IT service providers and system suppliers (technical maintenance of systems);
- security and infrastructure service providers (servers, authentication services);
- statistics and reporting services (non-personal statistical information); and
- the Tritonia Finna search service (customer logs in to the service).
We disclose data only if it is necessary to carry out the legal tasks of the library or to ensure technical operation.
11. Data transfer outside EU or EEA
Personal data is not transferred outside the EU or EEA countries.
12. Principles of protecting personal data
The university as the data controller uses appropriate technical and organisational measures to protect personal data from unauthorised or unlawful processing as well as damage or loss of personal data.
- Manual material
- The customer data forms filled in by customers are stored for three years in a locked room.
- Automatically processed data
- The staff of Tritonia’s universities working in Tritonia as well as the IT designers responsible for maintaining the library system can access the customer register with personal IDs to the extent required by their work tasks. The server containing the customer register is in controlled facilities of the IT Center for Science (CSC). The maintenance staff have access rights to the server.
Library staff are bound by confidentiality.
13. Automated decision-making
Automated decisions are not made.
14. Rights of the data subject
The data subject has the right to:
- obtain information on the processing of their personal information and have access to their data.
- have incomplete personal data completed and demand the rectification of inaccurate and incorrect personal data concerning them without unnecessary delay.
- the erasure of their personal data and be forgotten without undue delay provided that
- the personal data is no longer necessary for the purposes for which they were collected or otherwise processed;
- the data subject withdraws consent on which the processing is based and there is no other legal ground for the processing;
- the personal data has been unlawfully processed; or
- the personal data must be erased for compliance with a legal obligation in European Union or national law.
- restrict the processing of data if
- the accuracy of the personal data is contested by the data subject;
- the processing is unlawful and the data subject opposes the erasure of the personal data;
- the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims; or
- the data subject has objected to the processing in accordance to Article 21(1) pending the verification whether the legitimate grounds of the controller override those of the data subject.
- withdraw consent if the processing activity is based on consent (e.g. voluntary communication), but most of the processing is based on a legal/public task of the library (GDPR 6(1)(e)), in which case consent is not a legal basis.
The data subject has also the right to complain to the supervisory authority: The Office of the Data Protection Ombudsman, P.O. Box 800, 00531 Helsinki.
The data subject may also have the right to transfer their personal data from one system to another, if the right is applicable to the data in question.
For advice and guidance on the rights of the data subject, contact the data protection officer.
15. Other data
The use of the service generates log entries that are used to ensure the data security of the service, develop the service technically and detect, prevent and resolve malfunctions (Information Society Code (917/2014), sections 138, 141, 144 and 272). The logs are kept for the time required for these purposes and are not used for any other purpose.
16. Changing the privacy policy
The University of Vaasa/Tritonia Academic Library is constantly developing its operations and reserves the right to update this privacy policy. Alterations may also be based on changes in legislation.
We recommend that you check this policy from time to time.
If significant alterations, where our privacy policy changes drastically, occur, we may also notify you in other ways before the change takes effect.