Privacy Notice for Faculty
Privacy Notice for Faculty
This privacy notice outlines how and why the American University in Bulgaria (AUBG) collects, uses, and stores your personal data, and your rights in relation to the personal data we hold. We may modify or amend this Privacy Notice. The most current version will always be available on our website and, where appropriate, notified to you by email. If you have any questions about such matters, you can contact us at email@example.com.
What personal data do we collect?
The personal information we collect from you is the following:
- details you provided through your job application (CV, cover letter, and a list of references), any supporting documents requested and additional details provided by any referees and recorded following any interview process;
- contract of employment and any amendments to it;
- correspondence with or about you; for example, letters to you about a pay rise or, at your request, a letter to your mortgage company confirming your salary;
- information needed for payroll, benefits, and expenses purposes;
- contact and emergency contact details;
- records of holiday, sickness, and other absences;
- records relating to your career history, such as training records, appraisals, and other performance measures;
- your student evaluations, grade tapes, sabbatical requests and reports, annual report form, and evaluation related letters (incl. peer reviews; DET and/or FET letters, provost’s and president’s letters, your response letters, external reviewers’ letters in case of promotion), and,
- disciplinary and grievance records.
How do we collect your personal data?
You will have provided much of the information we hold about you, but some may come from other internal sources, such as your manager, or in some cases, external sources, such as referees.
The basis for processing your information and how we use it
As your employer, AUBG needs to keep and process information about you for normal employment purposes. The information we maintain and process will be used for our management and administrative use only. We will keep and use it only to enable us to operate the University business and manage our relationship with you effectively, lawfully, and appropriately during the recruitment process, while employed with us, at the time when your employment ends, and after you have left. This basis includes using the information to enable us to comply with the employment contract, to comply with any legal requirements, pursue the legitimate interests of the University, and protect our legal position in the event of legal proceedings. If you do not provide this data, we may be unable in some circumstances to comply with our obligations, and we will inform you about any implications of that decision.
We will not use your personal information to carry out any wholly automated decision-making that affects you.
We will process your personal information for a range of contractual obligations including the following:
- to communicate effectively with you by post, email, and phone, including the distribution of relevant newsletters and circulars;
- to assess your suitability for a particular role or task (including any relevant right to work checks);
- to administer remuneration, payroll, pension, and other standard employment functions;
- to administer HR-related processes, including those relating to performance/absence management, disciplinary issues, and complaints/grievances;
- to support your training, health, safety, and welfare;
- to help you during the regular evaluation process;
- to deliver facilities (e.g., library), services and staff benefits to you, and where appropriate to monitor your use of those facilities in accordance with University policies.
We will process your personal information for a range of legal obligations including the following:
- to fulfill and monitor our responsibilities under equalities, immigration and public safety legislation;
- to fulfill governance, audit, regulation and quality assurance arrangements and obligations.
We will process your personal information for the university’s legitimate interest including the following:
- to ensure safety and security within the university;
- to compile statistics and conduct surveys and research for internal and statutory reporting purposes;
- to monitor and evaluate the performance and effectiveness of the university;
- to maintain and improve the academic, corporate, financial, estate and human resource management of the university;
- to promote equality and diversity throughout the university.
We may also process your personal data where:
- it is necessary for your health, which could include reasons for absence and GP reports and notes. This information will be used in order to comply with our health and safety and occupational health obligations – to consider how your health affects your ability to do your job and whether any adjustments to your job might be appropriate. We will also need this data to administer and manage statutory and company sick pay, health insurance or life insurance policies, as applicable;
- it is necessary to protect your or another person’s vital interests; and,
- we have your explicit consent to do so, wherever and if necessary.
Control and care over your data
We, as an institution with one of the highest rankings in Bulgaria, are striving to improve and upgrade our control systems to include pseudonymization of the collected and processed data, access controls, defined within the university, and, most importantly, applied due care by our staff and faculty members. All measures are implemented against inadvertent or deliberate manipulation, loss, or destruction, and access by unauthorized persons. Access to your personal data is limited to the academic administration, faculty serving on evaluation committees, and HR staff who use it to perform their job obligations.
Whom we share your data with
Your data may be shared with public authorities, such as Bulgarian Ministry of Education, National Agency for Evaluation and Accreditation, Ministry of Foreign affairs (for visa purposes), National Revenue Agency, National Social Security Institute, Ministry of Internal Affairs, external audit companies, etc. as part of our legal obligations. AUBG may transfer your personal data if and when it finds it appropriate to use subcontractors, i.e. external payroll administration, work health and safety provider, marketing companies for internal and external surveys, evaluation and performance measurement, internal and external auditors, insurance companies etc. In cases we need to transfer your personal data to third parties, you will be notified, and asked for consent, if the data transfer process requires us to do so. In any case, we will share your personal data with high attention to the third parties’ level of technical and organizational ability to manage personal data as required by the GDPR standards.
How long we keep it
We store your personal information as part of your staff record for the duration of your employment (and it may be used as part of our assessment of any future application you make for further employment at AUBG). After you leave, certain records pertaining to your employment are retained indefinitely so that the details of your employment can be confirmed and for statistical or historical research.
Your rights in relation to the personal data we hold:
- to request access to your personal data we hold;
- to receive copies of your personal data in a machine-readable and commonly-used format, known as the right to data portability;
- to rectify or erase your personal data;
- to restrict or object to the processing of your data, where applicable;
- to request data transfer to other parties, in certain cases;
- to object a decision based solely on automated decision-making using your personal data;
- to withdraw consent at any time, in certain cases, without affecting the lawfulness of processing based on consent before its withdrawal; and,
- to lodge a complaint with the supervisory authority – Commission for Personal Data Protection, address - 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592.
You may address your concerns or inquiries to our Data Protection Officer (DPO) – Margarita Petkova, email: firstname.lastname@example.org; tel.: +359 73 888 337.
Please visit AUBG Internal Rules for Data Protection for more information.