University and District Library
LEA Data Protection Declaration
General information
The entity responsible for data processing on this website is Bonn-Rhein-Sieg University of Applied Sciences, represented by its president Prof. Dr. Hartmut Ihne. The following contact options are available:
Hochschule Bonn-Rhein-Sieg
Grantham-Allee 20
53757 Sankt Augustin
Tel.: +49 2241 865 0
Fax: +49 2241 865 609
Contact information for the official data protection commissioner:
Datenschutzbeauftragte der Hochschule Bonn-Rhein-Sieg
Grantham-Allee 20
53757 Sankt Augustin
e-Mail: datenschutzbeauftragte@h-brs.de
https://www.h-brs.de/de/datenschutzbeauftragter
Information on the rights of data subjects
According to Art. 15 of the EU General Data Protection Regulation (GDPR), data subjects are entitled to free information as to whether their personal data is being processed, and if so, which personal data is involved. In general, the data subject can request a copy of this data as long as no legal exception applies. If the data is incomplete or incorrect, the data subject is entitled to have his/her data rectified in accordance with Art. 16 GDPR.
Other rights to which data subjects are entitled include the following:
Art. 17 GDPR: Erasure of personal data if any of the grounds for erasure specified exist.
Art. 18 GDPR: Restriction on processing of personal data if any of the grounds specified exist.
Art. 20 GDPR: The data subject is entitled to transfer his/her own personal data to a controller if it is to be processed on the basis of a declaration of consent or contract.
Art. 21 GDPR: The data subject can object to the otherwise legal processing of his/her personal data on grounds relating to his/her own particular situation.
Art. 22 GDPR: Assigns special rights to data subjects in individual cases involving automated decision-making and profiling.
Right to complain
Data subjects have the right to complain to the supervisory authority responsible for Bonn-Rhein-Sieg University of Applied Sciences.
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestr. 2-4
40213 Düsseldorf
Information on individual forms of data processing
Processing log data (access data): When using this website, information is collected about the pages accessed, whether they were accessed successfully, the time at which they were accessed, the data volume transmitted, and the IP address of the computer sending the request. The purpose of this is to identify errors. This data is only processed internally and on the basis of Art. 6 no. 1 f) GDPR, the legitimate interest being the identification of errors. The log data stored is deleted automatically after 52 calendar days.
Account
Use of the learning platform (LEA), e.g. access to the courses accompanying the lectures or the self-study material, is only possible with a user account.
Students at Bonn-Rhein-Sieg University of Applied Sciences
Students are given a user account when they matriculate. When creating an account, the following data is taken from the central student register of Bonn-Rhein-Sieg University of Applied Sciences as specified in the enrolment regulations: salutation, full name, SIS name (user ID), matriculation number, library user number, matriculation status, department, study programme, university e-mail address, date of birth and postal address(es). The credentials for LEA are the MIA credentials.
For reasons of data protection, data may only be inspected by the e-learning team. By default, only your username und full name. Every student has the option to release additional data, to add further information to your personal profile and make it accessible to other users.
The account is deleted 48 months after the student leaves the university or when the former student expressly asks for the account to be deleted.
Staff, visiting lecturers, guest students at Bonn-Rhein-Sieg University of Applied Science and guest platform users (e.g. project partners)
The following personal data is essential when creating accounts: salutation, surname, first name, e-mail address and DIAS name (user ID) in the case of staff, or the matriculation number in the case of guest students from cooperating universities. An initial password is provided; however, this must be replaced by a password chosen by the user the first time he/she is authenticated.
For reasons of data protection, data may only be inspected by the e-learning team. By default, only your username und full name are visible to other LEA users. Every user has the option to release additional data, to add further information to your personal profile and make it accessible to other users.
The account is deleted when the user expressly asks for the account to be deleted or 48 months after leaving the university. Access for visiting lecturers and guests is limited to the period of their activity at the university.
A user account cannot be created if this data is not provided in full, in which case it will not be possible to use the learning platform’s non-public functions. The legal basis for the processing of this data is Art. 6 no. 1 e) GDPR, the purpose being to restrict access to non-public, protected parts of Bonn-Rhein-Sieg University of Applied Science’s website to registered users.
Right to data portability / data information
You can view your saved personal data at any time by contacting the e-learning team, who will also print it out on request. Data that is incomplete or incorrect can be rectified by agreement.
Cookies
This application uses cookies, i.e. small text files that facilitate technical processing. You will not be able to use all the functions of this app without cookies, e.g. if they have been deactivated in the browser. A list of these cookies follows.
Name: PHPSESSID / authchallenge
Content (example): randomly generated alphanumerical string
Purpose: to authenticate the user
Valid until: end of session
Remark: can only be accessed through server-side scripting; can only be accessed via secure connections
Name: sessionID
Content (example): randomly generated alphanumerical string
Purpose: to authenticate the user
Valid until: end of session
Remark: can only be accessed through server-side scripting; can only be accessed via secure connections
Name: ilClientId
Content (example): "db_040811"
Purpose: contains client ID of ILIAS instance
Valid until: end of session
Remark: can only be accessed through server-side scripting; can only be accessed via secure connections
Name: iltest
Content (example): "cookie"
Purpose: used to check whether session cookies are possible
Valid until: end of session
Remark: can only be accessed through server-side scripting; can only be accessed via secure connections
Along with its name and value, each cookie contains information about the domain sending it (domain: "lea.hochschule-bonn-rhein-sieg.de"), and specifies that the cookie may only be read by the transmitting domain (HostOnly : true), whether the cookie can only be accessed through secure connections (usually HTTPS) (Secure : false / true), whether the cookie can be read by browser scripts (httpOnly : true / false), and where the cookie is stored (Path : "/" ).
Data collected when using LEA
Description: first name(s)
Field: forename
Usergroup: students, other users
Purpose: to identify the individual
Remark: visible to all LEA users, can only be modified on request
Description: surname(s)
Field: lastname
User group: students, other users
Purpose: to identify the individual
Remark: visible to all LEA users, can only be modified on request
Description: title
Field: title
User group: students, other users
Purpose: to make contact
Remark: visibility optional, can only be modified on request
Description: user ID (SIS/DIAS name)
Field: id
User group: students, staff
Purpose: to identify the individual
Remark: visible to all LEA users, cannot be modified
Description: other user ID
Field: login
User group: other users
Purpose: to identify the individual
Remark: visible to all LEA users, cannot be modified
Description: matriculation number
Field: matriculationnumber
User group: students, guest students from cooperating universities
Purpose: to identify the individual
Remark: only visible to e-learning team
Description: e-mail
Field: email1
User group: students, other users
Purpose: to make contact
Remark: visibility optional, can be modified by LEA users themselves
Description: e-mail
Field: email2
User group: students
Purpose: to make contact
Remark: only visible to e-learning team
Description: street
Field: street1
User group: students
Purpose: to make contact
Remark: only visible to e-learning team
Description: house number
Field: housenr1
User group: students
Purpose: to make contact
Remark: only visible to e-learning team
Description: zip code
Field: postalcode1
User group: students
Purpose: to make contact
Remark: only visible to e-learning team
Description: city
Field: city1
User group: students
Purpose: to make contact
Remark: only visible to e-learning team
Description: street (secondary address)
Field: street2
User group: students
Purpose: to make contact
Remark: only visible to e-learning team
Description: house number (secondary address)
Field: housenr2
User group: students
Purpose: to make contact
Remark: only visible to e-learning team
Description: zip code (secondary address)
Field: postalcode2
User group: students
Purpose: to make contact
Remark: only visible to e-learning team
Description: city (secondary address)
Field: city2
User group: students
Purpose: to make contact
Remark: only visible to e-learning team
Description: salutation
Field: sex
User group: students, other users
Purpose: to identify the individual
Remark: visibility optional, can be modified by LEA users themselves
Description: department
Field: department
User group: students, other users
Purpose: to make contact / e-learning support
Remark: visibility optional, can be modified by LEA users themselves
Description: password
Field: password
User group: students, other users
Purpose: to authenticate the user
Remark: encrypted; modification possible for students via MIA; other users can make changes in LEA directly
Description: matriculation status
Field: immatriculated
User group: students
Purpose: for the conditional deletion of user data
Remark: only visible to e-learning team
Description: study programme
Field: program1
User group: students
Purpose: to make contact / e-learning support
Remark: only visible to e-learning team
Description: secondary study programme
Field: program2
User group: students
Purpose: to make contact / e-learning support
Remark: only visible to e-learning team
All user groups: the following information is processed or can be provided voluntarily to supplement profiles:
Description: account status (unlimited, limited in time with limitation period)
Field: access
Purpose: authorisation of access / operational e-learning support
Remark: only visible to e-learning team
Description: activity status (active, inactive)
Field: active
Purpose: authorisation of access / operational e-learning support
Remark: only visible to e-learning team
Description: general interests
Field: general interests
Purpose: supplementary profile information
Remark: user can complete and disclose voluntarily
Description: display language used on platform
Field: language
Purpose: changing the display language
Remark: can be selected
Description: appearance of the platform (skin/style)
Field: default skin/style
Purpose: changing the appearance of the platform
Remark: can be selected
Description: when using assessment tools (exercises, tests, wikis): results, assessments, feedback
Field: -
Purpose: measuring learning success
Remark:
Description: when using other elements of the learning platform (forums / blogs / wikis / surveys etc.): the data generated and made visible on the platform
Field: -
Purpose: using the platform's interactive functions
Remark:
Description: when using the internal mailing system: the messages sent and received through the e-mail function
Field: mails
Purpose: contact option on the platform
Remark:
Description: owner of data set
Field: owner
Purpose: controller of data set
Remark: only visible to e-learning team
Description: offering help
Field: offering help
Purpose: supplementary profile information
Remark: user can complete and disclose voluntarily
Description: the authorisations (roles) assigned to the account
Field: role assignment
Purpose: Course participation/group membership and authorisations on the platform
Remark:
Description: ownership of objects
Field: owner
Purpose: visibility of controller or object creator
Remark:
Description: adjustment of hits per page
Field: hits/page
Purpose: changing the hit display
Remark: can be selected
Description: consent to terms of use and date on which consent was given
Field: agreed on
Purpose: declaration of consent to terms of use
Remark: obligatory on initial registration; only visible to e-learning team
Description: interests/hobbies
Field: interests/hobbies
Purpose: supplementary profile information
Remark: user can complete and disclose voluntarily
Description: avatar
Field: avatar
Purpose: supplementary profile information
Remark: user can complete and disclose voluntarily
Description: looking for help
Field: looking for help
Purpose: supplementary profile information
Remark: user can complete and disclose voluntarily
Description: support requests are processed in Microsoft Exchange and stored together with the data provided
Field: -
Purpose: support
Remark:
Description: phone, office
Field: phone, office
Purpose: supplementary profile information
Remark: user can complete and disclose voluntarily
Description: timestamp of account approval or most recent data synchronisation (in the case of students)
Field: approved on
Purpose: identifying problems with synchronization / operational e-learning support
Remark: only visible to e-learning team
Description: timestamp of status change, learning success ("not attempted" / "in progress" / "bearbeitet" / "passed" / "failed")
Field: -
Purpose: measuring learning success
Remark: for course participation and group membership if function activated
Description: timestamp of account creation
Field: created on
Purpose: age of the account / operational e-learning support
Remark: only visible to e-learning team
Description: timestamp of last login
Field: last login
Purpose: collection for anonymised statistics / statistics relating to platform use
Remark: only visible to e-learning team
Learning content/modules integrated into LEA
The central learning platform LEA (“Lernen und Arbeiten online” - Learning and Working Online) utilises learning content and modules that offer users opportunities for interactive supplementary learning. Users are free to use this content; however, it may be classified as a mandatory element of a course delivered by staff or lecturers and be subject to special data protection regulations. The use of information and materials is subject to copyright regulations that the user must comply with (cf. Terms of Use).
Content from Third-Party Providers
- YouTube
- You can embed and open YouTube videos in LEA. When you access a video, your browser establishes a direct connection with YouTube and reloads necessary and unavoidable scripts such as Google Fonts. The reason for and scope of the data acquisition and the further processing and use of data by YouTube, as well as your rights in this context and settings options for protecting your privacy can be found in YouTube's privacy policy. Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, opt-out: https://adssettings.google.com/authenticated.
- H5P
- You can set up and use content via H5P in LEA. When creating and using, necessary and unavoidable scripts are reloaded depending on the library used:
- Branching Scenario: When you create a branching scenario, your browser establishes a direct connection with h5p.com and reloads necessary and unavoidable scripts. The reason for and scope of the data acquisition and the further processing and use of data by h5p.com, as well as your rights in this context and settings options for protecting your privacy can be found in h5p.com’s privacy policy. Provider: H5P Group, Privacy Policy: https://h5p.com/privacy-policy
- Libraries in which YouTube videos are used: When you access a video, your browser establishes a direct connection with YouTube and reloads necessary and unavoidable scripts such as Google Fonts. The reason for and scope of the data acquisition and the further processing and use of data by YouTube, as well as your rights in this context and settings options for protecting your privacy can be found in YouTube's privacy policy. Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, opt-out: https://adssettings.google.com/authenticated.
- You can set up and use content via H5P in LEA. When creating and using, necessary and unavoidable scripts are reloaded depending on the library used:
- Media portal H-BRS
The media portal is available to all LEA users for the processing, managing and distributing video content for research and teaching purposes. Data processing is carried out by VIMP GmbH Munich. In LEA, videos can be uploaded to the media portal or integrated and accessed from it. The reason for and scope of the data acquisition and the further processing and use of data in the media portal as well as your rights in this context and setting options for protecting your privacy can be found in the media portal's privacy policy: https://www.h-brs.de/en/bib/privacy-statement-medienportal-h-brs
Educast.nrw
The educast.nrw service is available to all LEA users for processing, managing and distributing video content for research and teaching purposes. Thereby an order data processing takes place. The following personal data is processed by the "educast.nrw consortium", represented by the Westfälische Wilhelms-Universität Münster, in the following process procedures:
- Access control / identity control
- Video upload / broadcast live stream
- video upload and administration of videos from the Customer´s learning management systems (ILIAS or Moodle)
- Video upload and administration within the administrative user interface
- upload of recordings from recording devices that are compatible to Opencast
- recording personal videos via Opencast Studio
- Editing and administration of videos
- film editing of uploaded videos
- processing of uploaded videos in preparation of distribution
- Distributing videos and live streamings
- distributing uploaded videos within the Customer´s learning management systems (ILIAS or Moodle)
- distributing videos to another website (outside of ILIAS or Moodle)
- annotating with Opencast Annotation Tool
- Access to anonymized user statistics
- Provided Service Support to the persons in charge at the university
1. Access control / Identity control (DFN-AAI)
Type of Data: account data / DFN-AAI attributes (concerns attributes that are required at least. Additional attributes might be processed in the event of a participating university requiring a different configuration): eduPersonPrincipalName, displayName or cn or gn + sn, e-mail, eduPersonAffiliation. (Moredetails to DFN-AAI attributes: https://doku.tid.dfn.de/de:common_attributes)
Data Subject: end-user
Source of Data: participation university
Nature and purposes of the processing: collecting, recording, storing, read out, retrieval, usage, synchronization, linkage
2. Video upload / broadcast live stream
Type of Data: audiovisual content
Data Subject: individuals on screen
Source of Data: end-user
Nature and purposes of the processing: collecting, recording, organizing, structuring, storing, read out, retrieval, usage, disclosure by transmission, dissemination or otherwise making available, synchronization, linkage
Type of Data: account data (see no. 1)
Data Subject: individuals uploading videos
Source of Data: participating university
Nature and purposes of the processing: collecting, recording, storing, read out, retrieval, usage, synchronization, linkage
Type of Data: name (first name + last name)
Data Subject: individuals on screen (for guests if there is no account data available)
Source of Data: participating university
Nature and purposes of the processing: collecting, recording, storing, read out, retrieval, usage, synchronization, linkage
Type of Data: location-based data (information about geographic position at the time a lecture recording is/was made or a livestream is broadcasted.)
Data Subject: individuals on screen
Source of Data: participating university
Nature and purposes of the processing: collecting, recording, organizing, structuring, storing, read out, retrieval, usage, disclosure by transmission, dissemination or otherwise making available, synchronization, linkage
3. Editing and administration of videos
Type of Data: audiovisual content
Data Subject: individuals on screen
Source of Data: end-user
Nature and purposes of the processing: organizing, structuring, storing, read out, retrieval, usage, disclosure by transmission, dissemination or otherwise making available, synchronization, linkage
Type of Data: account data (see no. 1)
Data Subject: acting individuals
Source of Data: participation university
Nature and purposes of the processing: collecting, recording, storing, read out, retrieval, usage, synchronization, linkage
4. Distributing videos and live streamings
Type of Data: audiovisual content
Data Subject: individuals on screen
Source of Data: end-user
Nature and purposes of the processing: read out, retrieval, usage, disclosure by transmission, dissemination or otherwise making available
Type of Data: name (first name + last name)
Data Subject: individuals on screen
Source of Data: participating university
Nature and purposes of the processing: read out, retrieval, usage, disclosure by transmission, dissemination or otherwise making available
Type of Data: location-based data (information about geographic position at the time a lecture recording is/was made or a livestream is broadcasted.)
Data Subject: individuals on screen
Source of Data: participation university
Nature and purposes of the processing: read out, retrieval, usage, disclosure by transmission, dissemination or otherwise making available
Type of Data: log data about user’s activities stating the IP address and anonymized web tracking data
Data Subject: individuals watching video or live stream
Source of Data: end-user
Nature and purposes of the processing: collecting, recording, storing
5. Access to anonymized user statistics
Type of Data: account data (see no. 1)
Data Subject: acting individuals
Source of Data: participating university
Nature and purposes of the processing: collecting, recording, storing, read out, retrieval, usage, synchronization, linkage
Type of Data: log data about user’s activities stating the IP address and anonymized web tracking data
Data Subject: individuals watching video or live stream
Source of Data: end-user
Nature and purposes of the processing: aggregating, usage
6. Provided Service Support to the persons in charge at the university
Type of Data: contact details (name, e-mail)
Data Subject: support requesting individuals
Source of Data: immediately from Data Subject
Nature and purposes of the processing: collecting, recording, storing, read out, retrieval, usage, synchronization
_
Further information is available from the e-learning team: https://www.h-brs.de/en/bib/lea-support