Information security when the agreement or right to study ends
Information security and data protection when access rights expire
Expiry of the right to access electronic resources
You will no longer have access to University-provided electronic resources after:
- you have finished your studies,
- your employment contract ends,
- your role changes so that you no longer meet the requirements for accessing e-resources
- your other affiliation with the University providing you with access to e-resources ends, or
- your fixed-term access rights expire
Your user account will be closed 7 days after your right to access our electronic resources expires.
The student's user account is valid for 14 days after the end of the user rights.
User responsibilities upon the expiry of access rights
Make sure you take copies of any files and emails you may need in the future before your TUNI user account is disabled and you lose access to them. Departing employees (and non-employees with a similar status as employees) must consult their supervisor to identify the person to whom they must transfer important knowledge relating to their job to ensure the continuity of operations. This also applies, for example, to students who have been members of a research group.
All users who leave the University must install any software, which was made available to them based on their student/employee status, from their home computer.
Data Stored in Cloud Services and Storage Systems When Employment Ends
- Employees are primarily responsible for providing their supervisor with any necessary files before their employment ends. The supervisor is responsible for agreeing on the practical arrangements.
- Materials that must remain available to an entire team should be stored in a shared group directory (S: drive) or an O365 collaborative workspace (TUNI Groups). Shared directories and workspaces always have a designated owner responsible for managing access rights.
- TUNI does not maintain separate backups of OneDrive data.
- When employment ends, the O365 account is closed and a 30-day retention period begins.
- During the 30-day period:
- The supervisor is granted access to the employee's OneDrive data and receives a notification that they have 30 days to retrieve any necessary files. For this reason, it is essential that users remove their personal data before employment ends.
- After 30 days, the OneDrive data is permanently deleted.
- If the employee returns to employment within the 30-day period, OneDrive access is restored to them and the supervisor's access rights are removed.
- No exceptions are granted to these rules except in criminal investigation cases. An account cannot be reopened after the 30-day period has elapsed.
- As a rule, no data is released from storage systems after employment has ended.
- In exceptional circumstances, the contents of a folder specifically marked as personal may be retrieved. Exceptions are decided by the Provost.
- Email is not released to the supervisor. Separate rules apply to email, under which messages may be retrieved only for specific justified reasons.
- As a rule, individuals themselves are not granted access to their email after employment ends, as messages may contain personal data or other confidential information.
- Messages are not reviewed individually to separate personal and work-related content.
- In special cases, information specifically marked as personal may be retrieved from a mailbox together with the individual concerned. At the university, the decision is made by the Provost.
Handling Information Assets in Case of Death
These instructions describe the handling of information assets after the death of a holder of access rights to the Universities Community's information systems (student or employee). The instructions apply to information assets left behind by the deceased user.
The university's and university of applied sciences' devices and systems are intended for study and work purposes. They may contain confidential information and sensitive personal data. Due to data protection requirements, materials stored on a student's or employee's devices or systems are not released after their death.
Emails are not released because they may contain confidential personal data and are protected by the secrecy of communications.
Information stored in cloud services cannot be recovered after user data has been deleted.
1. Disabling User Accounts and Deleting Stored Data
Information entered into the student information system or HR system regarding the end of studies or employment automatically initiates the deletion of user accounts and stored data in accordance with normal user account management processes and retention periods.
2. Release of Other Information Assets in Exceptional Cases
The administrator of the deceased person's estate may request the release of materials for justified reasons. A written request, including justification, must be addressed to the Universities Community's Data Protection Officer (dpo [at] tuni.fi), who records the request.
As a rule, only specifically identified material subject to copyright legislation, or other material separately agreed upon in writing, may be released. Decisions on release are made by:
- the Provost at the university; and
- a member of the TAMK Management Group at the university of applied sciences who is authorized to decide on the use of materials outside TAMK's data repositories.
Requests must be submitted without delay, as the deletion of user data and stored information occurs automatically and a death is treated in the same manner as the normal end of studies or employment. Restoration of data afterward is not technically possible.
The file directories of a deceased employee and their contents are classified, where necessary, under copyright regulations as either employer-owned or privately owned. Private material should be stored in a folder named Private/Henkilökohtainen or otherwise clearly marked as private.
Only copyright-protected material that has been explicitly marked as personal and stored in a dedicated personal folder may be released to an external party.
All information assets of a deceased student are classified as private. As a rule, they are not released and are deleted according to normal account management procedures.
Material belonging to the employer is transferred to the supervisor or to a location designated by the supervisor. The supervisor is responsible for arranging and reviewing the information within the applicable retention periods.
3. Preservation of Email
The Universities Community's email service is hosted in a cloud-based storage environment and is not separately backed up by the university or university of applied sciences. No special backups are created in the event of a death. Emails cannot be restored from the cloud storage environment after their automatic deletion.
The right of the university or university of applied sciences to search a deceased employee's email for messages belonging to the employer is governed by the Act on the Protection of Privacy in Working Life (759/2004).
Any email of a deceased employee that is not work-related is considered private and is generally not disclosed to external parties. The emails of a deceased student are considered private and are not released. Materials related to membership in a working group, governing body, or similar function are handled separately when necessary.
4. Work Equipment Provided by the Universities Community and Related Data
If the university or university of applied sciences has provided the person with work equipment, such as a work computer or communication devices, the estate must return them, together with any other employer-owned property and the information contained therein, without delay.
Any employer-owned information assets located on privately owned computers or devices must also be returned. Returned information assets are processed as described above.
In the case of a student, information is generally destroyed according to standard procedures. An exception applies to project materials covered by a resource agreement and stored on university or university of applied sciences equipment. Such materials may be preserved for the project upon request from the responsible supervisor for further processing.
5. Applying a Retention Hold to Cloud-Stored Data
In exceptional cases, deletion of data stored in cloud services may be postponed for up to six months by applying a retention hold to the user's account.
The retention hold must be applied while the account is still active and must be based on a justified request, such as:
- a request from an authority;
- the supervisor being unable to act; or
- another reason preventing timely action.
Requests for a retention hold should be directed to the Data Protection Officer at dpo [at] tuni.fi.