DATA PROTECTION POLICY: PROCESSING OF PERSONAL DATA AND RETENTION OF STUDENT INFORMATION
| Policy number | EULER-QA-DP-2025-01 — Data Governance, v1.0 |
| Approved by | University Foundation Governing Board and University Executive and Academic Board |
| Effective date | 06/25/2026 |
| Next scheduled review | [Effective date + 2 years]; compliance review annually |
| Policy owner | Global Executive Chairman, with the designated Data Protection Coordinator |
| Responds to | AAC Expert Report (June 12, 2025), Standard 7, Condition 1 (Condition 23 of 34) |
| Related instruments | Crisis Management and Data-Breach Plan (Condition 24); Recording Consent (Condition 25); the University’s published Privacy and Safety policy, which this instrument consolidates and supersedes where they overlap |
| Publication | University website (Policies pages), student agreements by reference, and EGNYTE — “Current and Active Policies” |
1. Purpose
This policy governs the processing of personal data by EULER and states, explicitly and by category, how long student information is retained. It directly responds to AAC Condition 23 (Standard 7, Condition 1):
“Data Protection Policy: The institution must develop and implement a comprehensive policy addressing the processing of personal data, clearly outlining the duration for which student information is retained in accordance with relevant data protection regulations.”
2. Regulatory Basis and Scope
EULER processes personal data in accordance with the data protection legislation applicable in Curaçao (the National Ordinance on the Protection of Personal Data — Landsverordening bescherming persoonsgegevens) and, as institutional best practice for a globally enrolled student body that includes residents of the European Union, the principles of the EU General Data Protection Regulation (GDPR). This policy applies to all personal data processed by the University — of applicants, students, alumni, faculty, staff, and contractors — across all systems: the student records system (CMS), the learning platform (LMS), the document repository (EGNYTE), the governance platform, survey and communication tooling, and contracted processors.
3. Roles and Definitions
| Term / role | Meaning at EULER |
| Controller | The Euler-Franeker Memorial University (the University Foundation), which determines the purposes and means of processing |
| Data Protection Coordinator (DPC) | The designated officer responsible for this policy’s operation: maintains the processing register and retention schedule, answers data-subject requests, coordinates with processors, and reports annually to the Boards |
| Processors | Service providers processing data on the University’s instructions under contractual safeguards — including the joint EULER–EUCLID academic infrastructure, Pressidium (managed hosting of the LMS), Sucuri (security and backup services for the CMS), EGNYTE (document repository), Grammarly (writing support), proctoring and video-conference platforms, and survey tooling |
| Personal data / processing | Any information relating to an identified or identifiable person, and any operation performed on it (collection, storage, use, disclosure, erasure) |
4. Principles
All processing observes: lawfulness, fairness, and transparency; purpose limitation (data collected for stated purposes only); data minimization (only what the purpose requires); accuracy (with student self-service correction through the CMS); storage limitation (the retention schedule of Section 6); integrity and confidentiality (Section 7); and accountability (the DPC’s register and the annual review).
5. What the University Processes, and Why
| Data subjects | Categories processed | Purposes / basis |
| Applicants | Identity, contact, qualifications and transcripts, WHED verification logs, English evidence, references (PhD) | Admission decisions under the adopted admission policies; legitimate educational administration |
| Students | Enrollment and roadmap data, coursework (papers, quizzes), grades, examination records and recordings (with consent), supervision and support logs, feedback responses, payment records | Delivery and certification of education; contract with the student; legal and accreditation obligations |
| Alumni | Conferral records, transcript data, contact details (with consent for alumni relations) | Permanent registry function; alumni network (consent-based) |
| Faculty / staff | Appointment records, performance records, survey responses (aggregated) | Employment/engagement administration; quality assurance under the employee-perspective policy |
The University does not sell personal data, does not use it for third-party marketing, and discloses it only to processors under safeguards, to authorities where legally required, and to the AAC in anonymized or aggregate form.
6. Retention Schedule — Student Information
The durations below answer the condition’s central demand. “Enrollment + N” runs from the end of enrollment (graduation or withdrawal). On expiry, records are securely deleted or irreversibly anonymized; anonymized aggregates may be kept indefinitely for quality assurance.
| Record category | Retention | Rationale |
| Academic record of conferral: transcript, grades, degree awarded, diploma supplement | Permanent | The University’s registry function — graduates must be able to verify their degree for life |
| Defended theses and dissertations (published versions) | Permanent | Scholarly record (IRPJ / thesis platform); published with consent |
| Admission file of enrolled students, incl. WHED Verification Logs and equivalency evaluations | Enrollment + 6 years | Accreditation and recognition evidence (Conditions 14/20) |
| Application files of unsuccessful or withdrawn applicants | 2 years, then deleted | Reconsideration window; then no purpose |
| Coursework: Response Papers, quizzes, Major Papers, checklists | 5 years after course completion | Grade substantiation, moderation, and appeals |
| Oral-examination and proctoring recordings (made with consent under Condition 25) | 1 year after the grade becomes final | Verification and appeal window only; then deleted |
| Supervision logs, defense records, degree-checkpoint certifications | Permanent | Substantiation of the conferral (Conditions 9/15) |
| Course feedback — raw survey responses | 2 years | Verification; aggregates (anonymized) kept for QA |
| Learning-support and accommodation records (confidential) | Enrollment + 5 years | Continuity of support; restricted access |
| Financial records (tuition, payments) | 10 years | Fiscal and audit requirements |
| Routine correspondence and platform accounts | Enrollment + 3 years; accounts deactivated at completion | Administration wind-down |
Faculty and staff records are retained for the duration of the appointment plus 5 years (employee-perspective policy); governance and quality records (minutes, audits, KPI reports) are institutional, not personal, records and are kept permanently in anonymized or role-based form. The DPC maintains the authoritative schedule and executes deletions on a scheduled annual cycle, logged.
7. Security Measures
- Access control: role-based access on the CMS, LMS, and EGNYTE; restricted categories (support, accommodation, performance records) limited to named roles; one account per user; strong-password and least-privilege practice.
- Infrastructure: the LMS is operated on Pressidium managed WordPress hosting (hardened environment, encryption in transit, automatic daily backups with retention); the CMS is protected and backed up through Sucuri security services (firewall, malware monitoring, and backups). Restore procedures and continuity are governed by the Crisis Management and Data-Breach Plan (Condition 24).
- Processors: all processors operate under agreements with confidentiality, security, and deletion obligations; the DPC maintains the processor register.
- Transfers: as a fully online institution, data is processed across borders on the safeguarded platforms above; the University applies the same protections to every student regardless of residence.
- Breach response: suspected breaches are handled under the Condition 24 plan — containment, assessment, notification of affected persons and authorities where required, and documented remediation.
8. Rights of Data Subjects
Every applicant, student, alumnus, and staff member may: access the personal data the University holds about them; obtain rectification of inaccurate data (students can maintain contact data directly in the CMS); request erasure of data whose retention is no longer required by the schedule or law; object to processing for non-essential purposes (e.g., alumni communications); and receive a copy of their key records in portable form. Requests go to the Data Protection Coordinator at the published address and are answered within 30 days; refusals are reasoned and reference this policy. No adverse consequence attaches to exercising these rights.
9. Governance, Training, and Review
- The Data Protection Coordinator is designated by the University Executive and Academic Board ([name/role]), maintains the processing register, retention schedule, and processor register, and reports annually to the Boards.
- All staff and faculty with access to personal data complete a short annual data-protection briefing; confidentiality obligations are part of every appointment.
- An annual compliance review (register accuracy, deletion-cycle execution, access-rights audit, processor status) is conducted by the DPC with the QA / IQA Office; results and any corrective actions are minuted and included in the quality assurance update to the AAC.
- Students are informed of this policy at application and enrollment; student agreements reference it together with the recording-consent provisions (Condition 25).
10. Evidence of Compliance
- This approved policy, signed and dated, containing the retention schedule.
- The published policy page and the student-agreement reference.
- The DPC designation, processing register, and processor register (extracts).
- The annual deletion-cycle log and compliance-review minutes.
- Hosting and security arrangements (Pressidium / Sucuri) documentation, shared with the Condition 24 submission.









