Definition and scope
The UTAD General Privacy Policy (PGP_UTAD), as an essential foundation for transparency and privacy protection, aims, on the one hand, to inform about the purpose, means of collection, and manner in which personal data under its responsibility are processed and protected, and, on the other hand, to inform data subjects on how they can exercise all their privacy and protection rights.
As a commitment to safeguarding data, UTAD, under a principle of proactive accountability, is committed to protecting the privacy and personal data of the respective data subjects and to processing such data in compliance with all principles and rules governing data protection, thereby ensuring maximum security and confidentiality.
The PGP_UTAD is based on the General Data Protection Regulation (GDPR), REGULATION (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, and Law No. 58/2019 of 8 August, which ensures its execution in the Portuguese legal order.
Provided that compliance is ensured, this privacy and security policy does not preclude the possibility of special privacy policies applicable to specific UTAD services or organizational units, subject to due and prior recognition under special circumstances.
This privacy policy does not apply to any third-party platform or system, even if hyperlinks exist from any UTAD channel.
Nature of personal data
For the purposes hereof, any information that identifies or allows, directly or indirectly, the identification of a natural person shall be considered personal data.
As a practical measure, each organizational unit or service of UTAD shall carry out a diagnosis and inventory of data processing operations, whether based on IT systems or not, which include, in particular, one of the following categories of personal data:
- Name;
- Identification numbers BI/CC/NIF/ADSE/CGA, driving licence or passport/visa or residence permit;
- Identification and location addresses, physical or electronic;
- Photograph/image;
- Family status or academic and professional qualifications;
- Biometric data/physical characteristics;
- Health/physical or mental condition;
- Professional data;
- Economic, cultural and social data;
- Religious and political beliefs.
Data processing
Operations or sets of operations, whether automated or not, performed on personal data or sets of personal data to be processed under the responsibility of UTAD or through a processor or third party, shall comply, in particular, with the following principles:
-
Principle of lawfulness
Data may only be processed based on one of the following grounds: consent; a contractual relationship; compliance with a legal obligation; the protection of vital interests of the data subject or another natural person; the performance of a task carried out in the public interest or in the exercise of official authority; and the existence of legitimate interests pursued by the controller or by a third party. -
Principle of purpose limitation
Subject to the terms initially established, data may only be collected/processed for specified, explicit, and legitimate purposes. -
Principle of data minimisation
Only data that are adequate, relevant, and necessary in relation to the established purpose may be processed. -
Principle of accuracy
Data shall be processed accurately and kept up to date, erased, or rectified without delay. -
Principle of storage limitation
Data storage shall be limited to the period strictly necessary for the purposes for which they are processed. -
Principle of integrity and confidentiality
Data shall be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
On its digital platforms and systems, UTAD may collect technical information from users through cookies to provide a personalized service and enable safer, more effective interaction, without prejudice to its external use for purely statistical purposes.
The processing of personal data by a third party who is neither the controller nor a processor is subject to proper authorization and adherence to the principles established herein.
Data subject rights
Data subjects may exercise their rights of access, rectification, objection, restriction, and erasure of personal data concerning them in the possession of UTAD through one of the following means:
- In person, upon presenting their Citizen Card, at the Human Resources Services, if an employee, or at the Academic Services, if a student.
- Directly on UTAD's digital platforms, whenever admissible.
-
By registered mail, accompanied by proof of identity, a copy of an official photo identification document, and contact details, namely phone or mobile number and email address, to:
Balcão Integrado de Informação
Universidade de Trás-os-Montes e Alto Douro
Quinta de Prados
5000-801 Vila Real
Data Protection Officer (DPO) and National Data Protection Commission (CNPD)
To ensure continuous monitoring of compliance with the General Data Protection Regulation (GDPR) and other applicable laws, as well as to act as a contact point between UTAD, data subjects, and the data protection authority, a Data Protection Officer is designated, who can be contacted via epd@utad.pt or by post at:
Encarregado de Proteção de Dados da UTADEdifício da Reitoria
Quinta de Prados – Folhadela
5000-801 Vila Real
Regarding the appointment of the DPO, Rectoral Order No. 25/2025, of 28 May, is currently in force.
Complaints may also be lodged with the supervisory authority: Comissão Nacional de Proteção de Dados (CNPD), Rua de São Bento, n.º 148-3, 1200-821 Lisboa, or at www.cnpd.pt.
Security policy
Within the framework of the policies and procedures of its data center, UTAD has implemented appropriate security measures to protect User personal data against destruction, loss, alteration, disclosure, unauthorized access, or any other form of accidental or unlawful processing.
However, it is the User's responsibility to ensure and guarantee that the device being used is adequately protected against harmful software, computer viruses, worms, and/or malware.
Disclosure
The PGP_UTAD and any special privacy policies of UTAD, whenever they exist, must be made public, namely on their respective digital platforms, and may be made available through one of the means provided in Section IV.
July 2025