1. Introduction

Pursuant to Articles 13 and 14 of the Regulation (EU) 2016/679 on the “protection of natural persons with regard to the processing of personal data” (hereinafter also “GDPR”), we are providing the information required on the processing of your personal data ("Data") performed by Università Cattolica del Sacro Cuore (hereinafter also the “University”).

2. Identity and contact details for the Data controller

The Controller of the processing of your Data is Università Cattolica del Sacro Cuore, with registered office in Largo Agostino Gemelli 1, 20123 Milan, telephone (+39) 027234.1.

3. Categories of personal data

The Data processed by the University include, including but not limited to:

  • Common Data: Personal Data, Contact details, work experience, education, qualifications, publications, your picture in digital format;
  • Special categories of personal data pursuant to Art. 9 of the GDPR (e.g. data on the health status, such as protected characteristics), included in the curriculum vitae or other documentation you have submitted to the University;
  • Data concerning criminal convictions and offences pursuant to Art. 10 of the GDPR, that can be inferred from the documentation submitted by the data subject and that will be processed only to the maximum extent permitted by applicable law.


Data provided by you will be processed for the following purposes:

a). Enable you to participate in the call for applications you have applied for and perform related activities;
b). Claim and/or defend the rights of the University in civil, criminal and/or administrative litigation cases.

4. Processing purpose and legal basis

The legal basis of processing is constituted:

  1. For purposes under a):
  • In reference to common Data, by the execution of pre-contractual measures, for example participation in tests and evaluation questionnaires;
  • In reference to special categories of personal data, by your explicit consent.

     2. For purposes under b), by the need to establish, exercise or defend a right in court proceedings.

It is not mandatory to provide your Data, but an eventual refusal to do so and/or to give your explicit consent to the processing of special categories of personal data, will entail the objective impossibility for the University to pursue the purposes illustrated above.

5. Processing methods

Personal data are processed manually, digitally and electronically applying logics strictly connected to the purposes and, in any case, to guarantee the security and confidentiality of the data pursuant to laws in force.

6. Data storage period

The University will process the Data for the time strictly needed to achieve the abovementioned purposes; with no prejudice to any storage terms established by law or regulations.

7. Subject categories that the Data can be communicated to

Your data can be communicated to:

  • Public and private Bodies or competent Authorities;
  • Organisations associated with the University;
  • Banks.

Subjects belonging to the categories that data can be communicated to, will process the Data, based on the case, as Processors specifically appointed by the Controller pursuant to law, or as autonomous Controllers.

8. Transfer of personal data to countries extra EU

Personal data can be transferred to non-EU Countries, in particular for services located outside the European Union (e.g. cloud storage). In that case, the Controller hereto assures that the transfer of data outside the EU will take place pursuant to laws applicable, for example after stipulating the standard contractual clauses adopted by the European Union.

9. Data Protection Officer, D.P.O.

The University has appointed a Data Protection Officer, D.P.O., Mr.Ferdinando Zanatti email

10. Rights of the Data Subject

As Data subject you have the right to:

a). Ask the Controller to access, cancel, rectify if inaccurate, integrated if incomplete your data, and to restrict processing in cases set forth in Art. 18 of the GDPR;

b). Object, at any time, in full or partially, to processing of Data needed for pursuance of the legitimate interest of the Controller;

c). If the conditions for the portability right pursuant to Art. 20 of the GDPR exist, receive in a structured form, commonly used and readable with an automatic device the Data supplied to the Controller and, if technically feasible, transmit it to another Controller without hindrance;

d). Revoke consent given at any time;

e). Lodge a complaint with a supervisory Authority.


Those rights may be exercised by registered mail, addressed to Università Cattolica del Sacro Cuore, Direzione Amministrativa (Office of the General Manager) – Privacy, Largo Agostino Gemelli 1, 20123, Milan, or by email to

Updated on: 20 June 2018