Data Protection (Educational instance)

This page provides information on the collection and processing of personal data for the documentation and management of laboratory data and the use of an ELN in teaching as part of the service ELN@RWTH.
Service
Collection and processing of personal data for the documentation of laboratory data and the use of an electronic lab notebook (ELN) in teaching as part of the service ELN@RWTH.
Description of the Service
The service "ELN@RWTH" utilizes the product eLabFTW by Deltablot, a web-based electronic lab notebook system that facilitates and teaches users to record data in compliance with GRP (Good Research Practice). The system is provided by Deltablot as Software-as-a-Service (SaaS) for RWTH Aachen University and is supported by the IT Center, for example, regarding onboarding new user groups, answering user questions about the software, and serving as a contact point for Deltablot.
Name and Address of the Responsible Party
The responsible party within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of member states, as well as other data protection regulations, is:
Rector of RWTH Aachen University
Templergraben 55
52062 Aachen (Physical Address)
52056 Aachen (Mailing Address)
Phone: +49 241 80 1
Fax: +49 241 80 92312
Email: rektorat@rwth-aachen.de
Website: www.rwth-aachen.de/rektorat
For implementing the service "ELN@RWTH":
IT Center RWTH Aachen
Seffenter Weg 23
52074 Aachen
Phone: +49 241 80 24680
Email: servicedesk@itc.rwth-aachen.de
Website: www.itc.rwth-aachen.de
Name and Address of the Data Protection Officer
Contact details for the officially appointed Data Protection Officer:
Data Protection Office at RWTH Aachen University:
Templergraben 83
52062 Aachen (Physical Address)
52056 Aachen (Mailing Address)
Germany
Phone: +49 241 80 94114
Email: dsb@rwth-aachen.de
Subject Matter and Purpose of Processing Personal Data
The following mentioned data serves in teaching to learn practical laboratory work and apply digital documentation processes (e.g., in practical laboratory courses), as well as to evaluate performance and attribute recorded information to individual students. Furthermore, it is used to manage access rights to the service "ELN@RWTH."
If exports of data from the ELN take place in any form, e.g., for archiving entries and/or storing them on other platforms, the personal data mentioned below will generally also be exported. This can occur via the user interface or through the REST API. Systems and platforms outside of the ELN that utilize these exported data will thus store this personal data.
Type of Personal Data Concerned / Special Categories of Personal Data
For the service "ELN@RWTH," processing and storage occur for the following personal data:
- Master Data: including first name(s), last name, initials, email address, account creation date, last login date, organization ID, ORCID ID (the latter being voluntary)
- Metadata: including IP address, timestamp when entry changes
- Research/Data Content: name, first name referring to collaboration partners; depending on research project (e.g., interview data)
Recipients of Data
1. Deltablot
116 AV de Paris
94800 Villejuif
France
Registration No.: 922 205 109 R.C.S. Créteil
Email: contact@deltablot.email
Website: deltablot.com
A contract processing agreement has been concluded with Deltablot.
2. The IT Center at RWTH Aachen
3. The respective RWTH institution
Legal Basis
The aforementioned master data (including name, email address) are processed for students according to Art. 6 para. 1 sentence 1 lit. e), para. 3 GDPR in conjunction with §3 para. 1 HG NRW; for teachers (employees at RWTH) according to Art. 6 para. 1 sentence 1 lit. e), para. 3 GDPR in conjunction with §18 para.1 DSG NRW.
Metadata (including log files, timestamps, IP addresses) are processed according to Art. 6 para. 1 sentence 1 lit. e), para. 3 in conjunction with §3 para.1 DSG NRW in conjunction with §3 para.1 HG NRW.
Content data (if personal) are processed according to Art. 6 para. 1 sentence 1 lit. a) GDPR upon consent or based on Art. 6 para. 1 sentence 1 lit. e), para. 3 GDPR in conjunction with §3 paras. 1 & 3 DSG NRW concerning their tasks regarding study programs offered as well as §2 Abs .1 Basic Order RWTH Aachen and §3 Abs. 1 E-Learning Regulations RWTH Aachen.
Data Deletion and Storage Duration
Art. 5 para. 1 lit. e) GDPR requires that a storage period bound to fulfilling each purpose must be specified after which deletion must take place.
Entries and attached files collected for evaluating an exam performance will be exported after completion of a course and archived for ten years as part of examination records.
Data stored in the ELN will be stored in the ELN for a maximum of 3 years but at least 1 year after the completion of the respective course and made available to students for review by course instructors.
After three years all associated teams, including master, meta, and content data will be deleted from the ELN.
Additionally, personal master data (name and email address) can be anonymized through SysAdmins upon request.
Rights Of The Affected Person
If personal data concerning the user are processed, they are a data subject within the meaning of the GDPR and have the following rights vis-à-vis the controller.
In accordance with Articles 15 et seq. GDPR, and subject to the conditions defined therein, the data subject has the right of access to the personal data concerned, as well as the right to rectification or erasure, or to restriction of processing, the right to object to processing, and the right to data portability.
They also have, pursuant to Article 77 GDPR, the right to lodge a complaint with the data protection supervisory authority if the data subject believes that the processing of personal data concerning them infringes this regulation.
If the processing is based on the data subject’s consent (see Art. 6(1)(a), Art. 9(2)(a) GDPR), they also have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal; such withdrawal takes effect only for the future.
To exercise the aforementioned rights, the users sends an email to the IT-ServiceDesk.