General Data Protection Regulation (GDPR) Policy
About this document
This privacy notice explains how Palm Beach Atlantic University ("we", "our", "us")
collects, uses and shares your personal data, and your rights in relation to the personal
data we hold. This privacy notice concerns our processing of personal data of past,
present and prospective students of Palm Beach Atlantic University ("you", "your").
Palm Beach Atlantic University is the data controller of your personal data and is
subject to the Data Protection Act 1998 ("DPA") and to the General Data Protection
Regulation (the "GDPR").
Any questions or concerns regarding Palm Beach Atlantic University privacy and data
protection practices can be directed to the Data Protection Officer at DPO@pba.edu
Whose data does the GDPR protect?
The GDPR covers personal information of all natural persons—that is, people, but not
legal entities like corporations or nonprofits—within the EU ("EU data subjects").
The GDPR makes no distinctions based on individuals' permanent places of residence
or nationality. The GDPR applies to all such individuals' personal data.
Protection of Your Personal Information
Palm Beach Atlantic University takes reasonable and appropriate measures to protect
Personal Data from loss, misuse, unauthorized access, disclosure, alteration, and
destruction, taking into account the risks involved in the processing and the nature
of the Personal Data.
How we collect your information
We may collect your personal data in a number of ways, for example:
- From the information you provide to us when you interact with us before joining, for
example when you express your interest in studying at Palm Beach Atlantic University;
- When you apply to study at Palm Beach Atlantic University and complete enrolment forms
and when you complete other admissions processes and procedures;
- Information collected through disciplinary and grievance procedures;
- Information collected through the administration of student housing; and
- Information collected through surveys and feedback mechanisms.
- When you communicate with us by telephone, email or via our website, for example in
order to make inquiries or raise concerns;
- In various other ways as you interact with us during your time as a student of Palm
Beach Atlantic University.
- From third parties, for example from your previous or current school, college, university
or employers who may provide a reference about you or who may sponsor your studies.
Types of Data Collected
We may collect the following types of personal data about you:
- Your name, and contact information such as address, email address and telephone number,
as well as your date of birth, social security number (or other tax identification
number) and your passport number or national identity card details, country of residence
and your nationality. We will also allocate you a unique student number
- Information relating to your education and employment history, the school(s) and other
colleges or universities you have attended and places where you have worked, the courses
you have completed, dates of study and examination results. We will also keep records
relating to assessments of your work, details of examinations taken, your predicted
and actual examination grades and other information in your student record
- Information about your family or personal circumstances, and both academic and extracurricular
interests, for example where this is relevant to the assessment of your suitability
to receive aid or in order to provide you with appropriate care
- Sensitive personal data and information about criminal convictions and offences, including:
- Information concerning your health and medical conditions (e.g. disability and dietary
- Certain criminal convictions (e.g. for students on nursing programs, following completion
of a background check)
- Information about your racial or ethnic origin; religion or similar beliefs
- Payment data necessary to process your payment if you make purchases, such as your
payment instrument number (credit card number).
- Records related to your use of our facilities and services
- Photographs from events and CCTV footage
- Information about your involvement, activities, and awards
The basis for processing your information and how it is used
Palm Beach Atlantic University may process your personal data as it is necessary for
the performance of a contract with you or in order to take steps at your request prior
to entering into a contract. In this respect, we use your personal data for the following:
- To interact with you before you are enrolled as a student, as part of the admissions
process (e.g. to send you a prospectus or answer enquiries about our courses)
- To address any concerns or feedback you may have
- For any other purpose for which you provide us with your personal data.
We also may process your Personal Information because it is necessary for our legitimate
interests. In this respect, we may use your Personal Information for any of the following:
- To provide you with educational services which may not be set out in our Student Handbook
but which are nevertheless a part of our academic and educational mission
- To monitor and evaluate the performance and effectiveness of the university, including
by training our staff or monitoring their performance
- To maintain and improve the academic, corporate, financial, estate and human resource
management of the University
- To promote equality and diversity throughout the University
- To seek advice on our rights and obligations, such as where the University requires
- To recover funds owed to the university
- For fundraising purposes
We may also process your personal data for our compliance with our legal obligations.
In this respect, we may use your personal data for the following:
- To meet our compliance and regulatory obligations
- For the prevention and detection of crime
- In order to assist with investigations (including criminal investigations) carried
out by the police and other competent authorities.
We may also process your personal data where:
- It is necessary for medical purposes (e.g. medical diagnosis, provision of health
or social care or treatment, or a contract with a health professional)
- It is necessary for emergency medical purposes
- It is necessary to protect your or another person’s vital interests or
- We have your specific or, where necessary, explicit consent to do so.
How PBA Uses Current and Prospective Student Information
We may use Personal Information (including Sensitive Personal Data) we collect from
and about you during your association with us for the following purposes:
- Recruit and/or admit you as a student at Palm Beach Atlantic University
- Facilitate academic matters, including for:
- The provision of our core teaching, learning, and research services (e.g. registration,
assessment, attendance, managing progress, academic misconduct investigations, certification,
- Maintaining student records
- Assessing your eligibility for bursaries and scholarships
- Provide library, IT, media, and other information services
- Provide support of our core services in non-academic matters, including:
- Providing support of our core student services in non-academic matters
- Monitoring of equal opportunities
- Safeguarding and promotion of students’ welfare
- Ensuring students’ safety and security
- Managing student employment, assistantships, and internships
- Managing student accommodations
- Managing the use of social media
- Managing facilities on campus, including parking
- Administer finances such as fees, scholarships, federal and state grants, or financial
- Provide other administrative functions, such as:
- Carrying out research and statistical analysis
- Carrying out audits to ensure compliance with our regulatory and legal obligations
- Providing operational information
- Promoting our services
- Preventing and detecting crime
- Dealing with grievances and disciplinary actions
- Dealing with complaints and inquiries
- Provide for archiving and statistical purposes
- Preparing the commencement booklet; and
- Promoting and archiving the ceremony on our website.
Data Retention Timeframe
We will retain your Personal Information for as long as needed to meet compliance
requirements for legal document retention obligations. Even where you have exercised
one or more of the rights (below) with respect to your Personal Information, we will
have the right to retain your Personal Information for compliance with legal obligations,
for the performance of a task carried out in the public interest, for archiving purposes
in the public interest, for scientific or historical research purposes, for statistical
purposes, or for the establishment, exercise, or defense of legal claims.
Your Rights with Respect to Your Personal Information
Under the General Data Protection Regulations (GDPR), you have the following rights:
- To obtain access to the Personal Information that we hold about you
- To object on grounds relating to your particular situation to our processing activities
where you feel they have a disproportionate impact on your interests, rights, and
- If you believe that your Personal Information that we possess is, or has become, incorrect
or is incomplete, you may request to review, revise, correct, or update any of the
Personal Information we may have about you free of charge
- To restrict the processing activities related to your Personal Information (and, where
our processing is based on your consent, you may withdraw that consent, without affecting
the lawfulness of our processing based on consent before its withdrawal)
- To request that we erase your Personal Information erased
- To have Personal Information, which you have voluntarily provided to us, produced
in a structured, commonly used, and machine-readable format, including for the purpose
of transmitting it to another party; and
- To require us not to send you marketing communication.
Please note that the above individual rights are not absolute, and we may be entitled
to refuse requests where certain exceptions apply. If you have given your consent
and you wish to withdraw it, please contact the Campus Data Protection Officer by
email using the contact information provided at the end of this document. Please note
that where the processing of your personal data relies on your consent and where you
then withdraw that consent, we may not be able to provide all or some aspects of our
services to you and/or it may affect the provision of those services.
Privacy and Children
The Privacy Notice is not directed to “children”, and we do not seek, nor do we knowingly
process, Personal Information from children. Where a prospective or current student
is classified as a child, we will make reasonable efforts to verify that consent is
given or authorized by the holder of parental responsibility over the child, where
Personal Information of the child is to be processed.
Revisions to this Privacy Notice
Palm Beach Atlantic reserves the right, at our sole discretion, to change, modify,
add, remove, or otherwise revise portions of our policies and this Privacy Notice
at any time, consistent with the requirements of applicable law. When we do, we will
post the revision(s) to this page (https://www.pba.edu/general-data-protection-regulation-policy). If this policy is changed in a material way, PBA will provide appropriate notice.