National Aerospace University «Kharkiv Aviation Institute»

Regulations on Personal Data Protection

Regulations on Personal Data Protection
at National Aerospace University
«Kharkiv Aviation Institute»

Approved by:
The Academic Council of
National Aerospace University
«Kharkiv Aviation Institute»
Minutes No. 10 dated April 22, 2026

Enacted by Order No. 187 dated April 22, 2026

 

QMS KhAI-UV-P/001:2026

Date of Enactment: April 22, 2026

Edition No. 1

1. General Provisions

1.1. These Regulations on Personal Data Protection (hereinafter — Regulations) govern the legal and organizational foundations of personal data processing and protection at National Aerospace University «Kharkiv Aviation Institute» (hereinafter — University), establishing the procedure for their collection, storage, use, dissemination, and protection. The Regulations define a set of organizational and technical measures aimed at preventing illegal access to personal data, their loss, unlawful use, or dissemination during the University's educational, scientific, personnel, financial, economic, and other activities.

1.2. These Regulations have been developed in accordance with:

- the Constitution of Ukraine;

- the Law of Ukraine «On Personal Data Protection»;

- the Law of Ukraine «On Education»;

- the Law of Ukraine «On Higher Education»;

- the Law of Ukraine «On Information»;

- the Law of Ukraine «On Access to Public Information»;

- the Law of Ukraine «On Electronic Documents and Electronic Document Management»;

- the Law of Ukraine «On Electronic Identification and Electronic Trust Services»;

- the Model Procedure for Personal Data Processing, approved by Order of the Ukrainian Parliament Commissioner for Human Rights dated 08.01.2014 No. 1/02-14;

- the EU General Data Protection Regulation (GDPR) — regarding the processing of personal data of international students and partners from European Union countries, as well as during the implementation of international grant programs;

- the University Charter;

- other regulatory acts of Ukraine and the University in the field of information and personal data protection.

In case of changes in the legislation of Ukraine, the norms of these Regulations shall apply to the extent that they do not contradict current legislation.

1.3. These Regulations apply to all structural units of the University, its employees, higher education applicants (students), as well as other persons whose personal data are processed by the University. These Regulations are mandatory for execution by all University employees who process personal data or have access to them.

1.4. In these Regulations, terms are used in the meanings specified in the Law of Ukraine «On Personal Data Protection», namely:

- Personal data database — a named set of ordered personal data in electronic form (in particular, in EDEBO, internal EDMS) and/or in the form of card indexes (personal files).

- Responsible person — a person appointed by order of the Rector who organizes personal data protection work and monitors compliance with these Regulations at the University.

- Controller of personal data — the University represented by the Rector, who determines the purpose of personal data processing, establishes the composition of these data and the procedures for their processing.

- Consent of the personal data subject — voluntary expression of will of an individual (subject to being informed) to grant permission for the processing of their personal data. Consent may be provided in written or electronic form (using QES, electronic identification systems, in particular via the «Diia» portal/application).

- Depersonalization of personal data — removal of information that directly or indirectly allows identifying a person (used when responding to requests for public information or publishing statistical data).

- Processing of personal data — any action or set of actions, such as collection, registration, accumulation, storage, adaptation, alteration, renewal, use, and dissemination (distribution, realization, transfer), depersonalization, or destruction of personal data, including through the use of the University's information (automated) systems.

- Personal data (PD) — information or a set of information about an individual who is identified or can be specifically identified, which, in accordance with the legislation of Ukraine and the Regulations on the procedure for storing and distributing information constituting commercial secrets and other confidential information of the University, is classified as confidential information about an individual and is subject to protection, and its processing is permitted exclusively on the grounds and in the manner prescribed by law.

- Personal data security breach (leakage) — destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed by the University.

- Processor of personal data — a physical or legal entity granted the right by the personal data controller or by law to process these data on behalf of the controller.

- Personal data subject — an individual whose personal data are processed by the University (student/applicant, employee, applicant for admission, contractor, etc.).

- Third party — any person (except for the personal data subject, controller, processor, and the Ukrainian Parliament Commissioner for Human Rights) to whom personal data are transferred by the University in accordance with the law (in particular, the Ministry of Education and Science of Ukraine (MESU), the National Agency for Higher Education Quality Assurance (NAQA), Territorial Centers of Recruitment and Social Support (TCR and SS), law enforcement agencies, banks, etc.).

- Authorized persons — University employees who, in accordance with their job duties, have the right of access and carry out personal data processing in relevant structural units (personnel department, accounting department, dean's offices, etc.).

1.5. Processing of personal data at the University is carried out on the basis of:

- legality and fairness;

- targeted purpose and limitation of processing purpose;

- proportionality and data minimization;

- accuracy and relevance of personal data;

- limitation of storage periods;

- ensuring an adequate level of personal data protection.

1.6. The University is the controller of personal data of higher education applicants (students), employees, applicants for admission, and other persons whose personal data are processed in connection with the execution of its statutory activities.

The University provides:

- determination of the purpose of personal data processing;

- establishment of the composition and procedures for personal data processing;

- implementation of organizational and technical personal data protection measures;

- appointment of a responsible person (structural unit) for personal data protection issues.

1.7. These Regulations are subject to publication on the official website of the University and are brought to the attention of employees and higher education applicants by another available method.

1.8. The University guarantees that personal data processing is carried out openly and transparently using means and methods consistent with the defined purposes of such processing. Interference in the personal and family life of personal data subjects is prohibited. The University does not collect or process information on the racial or ethnic origin of employees (higher education applicants), their political, religious, or philosophical beliefs, membership in political parties, or information concerning sex life.

1.9. Consent to personal data processing, as well as the Non-Disclosure Obligation regarding personal data, may be provided by subjects both in paper and electronic form. The electronic form is implemented by applying a qualified electronic signature (QES), using the «Diia.Signature» service, other electronic trust services in accordance with the legislation of Ukraine, or by ticking a checkbox on the official web resources and information and communication systems of the University. Electronic documents and authorization logs are stored in the University's information systems and have the same legal force as paper counterparts.

1.10. University employees who process personal data in connection with the performance of their job duties act on behalf of the University as the controller and are not processors of personal data. The University has the right to entrust the processing of personal data of higher education applicants, employees, and other subjects to a Processor (a third-party legal entity or individual) based on a written agreement, which must specify the purpose of processing, the scope of data, and the Processor's obligations to ensure their protection and confidentiality.

1.11. Primary trade union organizations operating at the University independently ensure the protection of information provided by employees / higher education applicants who are trade union members, and are considered controllers of such personal data.

2. Categories of Subjects and Composition of Personal Data

2.1. The University processes personal data (hereinafter — PD) of the following categories of subjects:

- higher education applicants (students, postgraduate students, doctoral students), applicants for admission, students of the preparatory department and courses, and graduates;

- University employees (full-time employees, part-time employees, employment candidates, former employees);

- persons related to higher education applicants (parents or other legal representatives of higher education applicants and applicants for admission, as well as payers under agreements for paid educational services for a higher education applicant, if they do not pay independently);

- individual entrepreneurs, individuals performing work under civil law contracts, as well as representatives, managers, founders, and employees of legal entities that are contractors of the University: partners, stakeholders, internship locations, etc.;

- visitors, users of infrastructure, and participants in University events (who are not higher education applicants or University employees);

- potential applicants for admission (persons participating in career guidance, marketing, and introductory events of the University).

2.2. Composition of personal data of higher education applicants and applicants for admission:

- identification data: surname, first name, patronymic, date and place of birth, gender, citizenship;

- passport data and Registration Number of the Taxpayer's Account Card (RNTRC);

- contact information (registered and actual residence address, telephone number, email);

- information on previous education (educational documents, NMT/ZNO/EVI/EFVV test results);

- information on the progress of the educational process (academic performance, student movement orders, information on individual educational trajectory);

- military registration data (paper military registration documents, electronic military registration documents (e-VOD) with a QR code generated via the «Reserve+» application or the «Diia» portal/application, as well as data from the Unified State Register of Conscripts, Persons Obliged for Military Service, and Reservists «Oberih»);

- data on parents or other legal representatives (surname, first name, patronymic, residence address, telephone number, place of work) — for contact in emergency cases and informing about the educational process (for minor applicants);

- health status details (medical certificates and conclusions required for admission to certain specialties according to the Admission Rules; for accommodation and living in a dormitory, exemption from physical education classes; granting academic leave for medical reasons; confirmation of entitlement to special exam conditions, as well as medical documents necessary to ensure inclusive learning conditions), sick leave certificates, MSEK disability certificates, as well as information on mandatory preventive vaccinations or medical examination results — exclusively in cases where providing such information is directly required by the legislation of Ukraine for admission to the educational process, performance of job duties, or residence in a dormitory);

- information on belonging to preferential categories (documents confirming the right to social scholarships, preferential accommodation, state grants);

- financial details (bank account numbers for paying scholarships or refunding funds);

- photo images.

2.3. Composition of personal data of employees:

- identification and passport data, Registration Number of the Taxpayer's Account Card (RNTRC);

- data on education, academic degrees, academic titles, professional development;

- information from employment record books (including electronic ones) or employment history details from the register of insured persons;

- military registration data (paper military registration documents, electronic military registration documents (e-VOD) with a QR code generated via the «Reserve+» mobile application or the «Diia» portal/application, as well as data from the Unified State Register of Conscripts, Persons Obliged for Military Service, and Reservists «Oberih»);

- health status details (results of mandatory preliminary and periodic psychiatric and medical examinations upon employment and during employment activities; data from personal medical (sanitary) record books for specified job categories; medical conclusions (MSEK) on establishing disability to ensure proper working conditions and apply tax benefits; electronic and paper sick leave certificates, as well as information on mandatory preventive vaccinations or medical examination results — exclusively in cases where providing such information is directly required by the legislation of Ukraine for admission to the educational process, performance of job duties, or residence in a dormitory);

- financial data (salary amount, bank details, tax accounting data);

- marital status and presence of children (for exercising rights to leave and social benefits);

- digital identifiers (logins in corporate systems, digital signatures);

- photo images.

2.4. Composition of personal data of persons related to higher education applicants (parents, adoptive parents, guardians, or other legal representatives*, as well as customers / payers under an agreement for paid educational services):

* if the legal representative of a higher education applicant is not a customer / payer under an agreement for paid educational services for the higher education applicant, only data marked with * in this point are collected in respect of them

- identification data: surname, first name, patronymic*;

- contact information: registered and actual residence address, telephone number, email address — for official correspondence under the agreement, contact in emergency cases, and informing about the educational process (for minor applicants)*;

- information on family ties and belonging to social/preferential categories: copies of birth certificates, decisions of guardianship authorities, Combatant (UBD) certificates, IDP certificates, death certificates, etc., are processed exclusively within the scope necessary to confirm the representative's authority, as well as to process benefits, social scholarships, and state grants for higher education applicants*;

- documentary and tax data: details of an identity document (passport / ID card) and Registration Number of the Taxpayer's Account Card (RNTRC) — collected when concluding educational service agreements or dormitory residence agreements where the person acts as the Customer / payer, as well as for tax accounting purposes;

- financial data, bank details (IBAN accounts) — collected in case of making payments, the need to refund tuition / accommodation fees, or performing financial reconciliations;

- signature samples: handwritten signature or certificate data of qualified electronic signature (QES / Diia.Signature) when signing agreements, supplementary agreements, and service acceptance acts.

2.5. Composition of personal data of individual entrepreneurs (FOP), persons under civil law contracts, and representatives of legal entities (contractors, partners of internship locations):

- identification data (surname, first name, patronymic);

- position and place of work;

- contact information (work phone, email address);

- information on the authority of the signatory (data contained in extracts from the USR, charters, appointment orders, or powers of attorney, which may include passport data and RNTRC of the manager/representative);

- identification data of individual entrepreneurs and persons under civil law contracts (passport data, RNTRC, bank details, registered address);

- signature samples (including certificate data of qualified electronic signatures — QES).

2.6. Composition of personal data of visitors, infrastructure users, and participants in University events (who are not higher education applicants or University employees):

- identification data and access control data: surname, first name, patronymic, details of identity documents, entry/exit time, as well as information about the person being visited (collected exclusively for the purposes of access control, property security, issuing temporary passes, library/subscriber cards, and making entries in visitor logbooks of academic buildings and dormitories);

- contact information: telephone number, email address (for event registration, sending conference materials, communication with library or sports complex users);

- professional and academic information: place of work or study, position, academic degree, academic title (collected during the registration of invited guests and participants in educational, scientific, and other events, conferences, symposiums, etc.);

- health status details: standard medical certificates (collected exclusively for visitors to sports complexes, swimming pools, etc., if providing such a certificate is a mandatory condition for access according to sanitary norms and visitation rules);

- financial data: information on payments made (in case of paying registration fees for participation in conferences, paying for services of using sports infrastructure, or other paid services of the University).

2.7. Composition of personal data of potential applicants for admission (participants in career guidance events)*:

- identification data: surname, first name, patronymic, date of birth or age (collected for the purpose of verifying that the subject has reached the age from which independent consent to personal data processing is allowed);

- contact information: telephone number, email address, profiles in messengers (Telegram, Viber, etc.) and social networks, locality/region of residence (for invitations to regional offline events);

- academic interests: information on the educational institution where the person studies (school, college), grade/year, graduation year, and desired specialties for admission.

* Collection of passport data, RNTRC, exact home address, or other excessive data from this category of subjects is prohibited.

2.7.1. Procedure for obtaining mandatory consent to PD processing of potential applicants for admission:

Collection of the specified data is carried out exclusively on the basis of explicit, voluntary, and informed consent of the subject (or their legal representative, if the person has not reached 14 years of age). Consent is obtained in the following ways:

- during online registration (via websites, electronic forms, in particular Google Forms, etc.): by the subject independently placing a check mark (tick) in the checkbox «I consent to the processing of my personal data for marketing and career guidance purposes». The checkbox must not be pre-activated (checked) by default. Next to the checkbox, a link to the text of these Regulations or a short privacy notice shall be placed.

- during offline events (exhibitions, open house days, career fairs): by placing the personal signature of the subject on a paper questionnaire/card containing a clause on consent to PD processing, or by scanning a QR code with a transition to an electronic consent form.

Each electronic message (email mailing, SMS, in messengers) sent to such subjects must contain a simple and clear mechanism for withdrawing consent («Unsubscribe» button or instructions for opting out of the mailing). Upon withdrawal of consent, the subject's PD are subject to immediate deletion from the relevant personal data databases of the University.

2.8. General data collected regarding all categories of personal data subjects without exception during their physical or digital interaction with the University:

- video images: photo and video data recorded by video surveillance systems during the stay of any persons on the territory, at checkpoints, and in common areas of the University* (collected exclusively for the purpose of ensuring public order, the safety of participants in the educational process, protection of University property, and prevention of offenses);

* relevant warning information signs must be placed in prominent places in video surveillance zones

- network and digital identifiers: IP addresses, device MAC addresses, cookies (when visiting University websites or using University Wi-Fi networks for the purpose of ensuring cybersecurity);

- access control system data (in case of their implementation): electronic entry/exit logs recorded by automated access control systems (PACS) when crossing control points on the territory or in the premises of the University;

- audio data (in case of using relevant technical means): recordings of telephone conversations during inquiries to official hotlines or information services of the University (carried out exclusively subject to prior automatic voice warning to the caller about such recording).

3. Purpose and Legal Grounds for Personal Data Processing

3.1. The purpose of personal data processing at the University is:

- ensuring the implementation of relations in the field of education and science (organization of the admissions campaign, educational process, issuance of higher education documents, provision of inclusive education, maintenance of EDEBO);

- ensuring labor relations (maintaining personnel records, payroll calculation, monitoring the health status of employees in accordance with occupational health and safety requirements);

- conclusion and performance of agreements on the provision of educational services, provision of other services, lease/accommodation agreements, and other contracts with counterparties;

- conducting career guidance work, marketing research, informing potential applicants for admission about admission rules, open house days, preparatory courses, and other University events (exclusively subject to obtaining prior consent of the subject);

- carrying out accounting and tax accounting, administration of state grants, scholarships, and social benefits;

- ensuring military registration of conscripts, persons obliged for military service, and reservists in accordance with the legislation of Ukraine;

- ensuring access control, security, and property protection on the territory of the University Campus;

- implementation of international academic mobility programs and grant projects;

- ensuring the protection of rights and freedoms of individuals, in particular the right to privacy, in connection with the processing of their personal data.

3.2. Processing of personal data is carried out on the following legal grounds:

- consent of the PD subject (or their legal representative) to the processing of PD;

- authorization for PD processing granted to the University in accordance with the law exclusively for the exercise of its powers (in particular, the Laws of Ukraine «On Higher Education», «On Military Duty and Military Service», the Labor Code of Ukraine, the Tax Code of Ukraine, etc.);

- conclusion and execution of a legal transaction (contract) to which the PD subject is a party;

- necessity to fulfill an obligation of the PD controller provided for by law.

4. Procedure for Collection, Processing, and Storage of Personal Data

4.1. Collection and consent procedure.

PD are collected directly from the subjects by providing paper copies of documents, transmitting electronic copies of digital documents via the «Diia» and «Reserve+» applications, as well as (with the consent of the subject or upon requirement of the law) through electronic information interaction with state registers (EDEBO, USRCPOMSR «Oberih», PFU registers) via the «Trembita» system.

PD processing is carried out after the subject provides explicit and voluntary consent. Consent is granted in writing or in electronic form using a qualified electronic signature (QES) or electronic identification systems. Consent forms for various categories of personal data subjects for PD processing are given in the Appendix to these Regulations.

In cases provided for by Article 11 of the Law of Ukraine «On Personal Data Protection», PD processing is carried out without obtaining consent (as part of fulfilling direct statutory requirements, for example, regarding military or tax registration).

4.2. Processing and storage procedure.

PD are processed in the form of card indexes (personal files) and/or in electronic form (in EDEBO, electronic document management systems (EDMS), corporate information systems).

Hard-copy paper documents (especially those containing sensitive data on health status or military registration) are stored in specially equipped premises or in metal cabinets/safes, to which only University employees or authorized persons (processors) have access.

Processing of personal data concerning health status (information on disability, temporary disability, presence of medical contraindications, etc.) is carried out exclusively by authorized persons (employees of the human resources department, accounting department, dean's offices) within the scope necessary to implement the labor, social, and educational rights of subjects in accordance with the law. Such persons are obliged to adhere to an enhanced confidentiality regime and use these data strictly for their intended purpose, ensuring enhanced confidentiality measures in accordance with the requirements of Article 7 of the Law of Ukraine «On Personal Data Protection».

Electronic PD are stored on secure University servers or in cloud storages that meet information protection requirements.

PD storage periods are determined in accordance with the University's Nomenclature of Files and archives legislation. PD are destroyed (or anonymized) after the expiration of their storage period, upon reaching the purpose of processing, or upon the lawful request of the subject by drawing up a corresponding destruction act.

4.3. Organization of employee access.

University employees are permitted to process PD only after signing a Non-Disclosure Obligation regarding personal data. The form of the Non-Disclosure Obligation regarding personal data is given in the Appendix to these Regulations.

The Non-Disclosure Obligation regarding personal data remains in force even after the employee's dismissal or termination of the performance of their relevant duties.

Access to electronic databases is granted to employees exclusively to the extent necessary to perform their job duties, using individual authentication means.

4.4. Provision of personal data upon request of law enforcement bodies, courts, attorneys, or other third parties is carried out exclusively in cases provided for by law, on the basis of a written and reasoned request containing a clear reference to the legal ground, the purpose of the request, and the list of required data. Unfounded or overly broad requests are subject to rejection.

5. Rights and Obligations of Personal Data Subjects

5.1. According to Article 8 of the Law of Ukraine «On Personal Data Protection», a PD subject has the right:

- to know about the sources of collection, location of their PD, and the purpose of their processing;

- to receive information regarding the conditions for granting access to PD to third parties;

- to access their personal data;

- to submit a reasoned request objecting to the processing of their PD or a request for their modification or destruction, if these data are processed illegally or are inaccurate;

- to protection of their PD against unlawful processing and accidental loss;

- to withdraw consent to PD processing (except cases where processing is a mandatory non-alternative legal requirement);

- to lodge complaints regarding the processing of their personal data with the Ukrainian Parliament Commissioner for Human Rights or with a court.

5.2. Procedure for exercising rights

Within 10 working days from the date of receipt of the request, the University notifies the subject whether their request will be satisfied. The overall timeframe for resolving issues raised in the request cannot exceed 30 calendar days.

5.3. A personal data subject is obliged:

- to provide accurate personal data in the scope necessary to achieve the processing purpose;

- to timely (within the deadlines specified by internal rules or legislation) notify the University of changes in their personal data (in particular, changes of surname, address, updates to military registration documents or medical conclusions affecting the educational/working process).

5.4. Consequences of withdrawing consent or requesting the destruction of personal data

If a PD subject requests the destruction of their personal data or withdraws consent to their processing, and these data are necessary for maintaining the educational process, conducting military or tax accounting, calculating payroll/scholarships, or fulfilling other obligations of the University provided for by the legislation of Ukraine, the University explains to the subject the consequences of such a request.

If further processing of such PD is an indispensable condition for maintaining a person's status as a higher education applicant or employee, satisfying the request for destruction of PD or termination of their processing entails the impossibility of further performance by the University of its obligations.

In such a case, the impossibility of processing mandatory personal data constitutes grounds for terminating the relevant legal relationship (expulsion of a higher education applicant, dismissal of an employee, or termination of a commercial contract) due to the impossibility of the parties fulfilling their obligations.

The above does not apply to cases of withdrawing consent to PD processing collected exclusively for marketing, career guidance purposes, or for providing additional services not directly related to compliance with educational or labor legislation requirements.

6. Transfer of Personal Data to Third Parties

6.1. General conditions of transfer

Transfer of PD to third parties is carried out exclusively with the consent of the PD subject or in cases directly provided for by law.

Transfer of PD for commercial purposes is prohibited.

6.2. Mandatory transfer of PD by law:

The University transfers PD (within the scope established by legislation) without additional consent to the following institutions:

- Ministry of Education and Science of Ukraine (in particular, through EDEBO);

- Territorial Centers for Recruitment and Social Support — for ensuring military registration;

- State Tax Service authorities, Pension Fund of Ukraine;

- National Agency for Higher Education Quality Assurance (NAQA);

- State Treasury Service of Ukraine;

- State Audit Service of Ukraine;

- Employment Centers;

- Banking institutions (for servicing payroll and scholarship projects under contracts);

- Medical and preventive care institutions that carry out mandatory medical examinations.

6.3. Transfer of PD upon request:

Provision of PD upon request of law enforcement bodies, courts, and state enforcement service authorities is carried out only upon a written and reasoned requirement with reference to specific provisions of the law.

Provision of PD in response to requests for access to public information or attorney requests is carried out with mandatory anonymization (redaction) of PD, except in cases where disclosure of such data is required by law.

6.4. Cross-border transfer of PD:

Transfer of PD to foreign entities (foreign educational institutions, grant foundations) is carried out within international mobility programs or international partnerships exclusively with the consent of the PD subject or on the basis of an international treaty of Ukraine.

Cross-border transfer is permitted to states that ensure an adequate level of PD protection (in particular, according to GDPR standards).

7. Organizational and Technical Personal Data Protection Measures

7.1. Organizational protection measures

7.1.1. The University applies a decentralized management model for personal data protection. Responsibility for organizing PD protection work is assigned directly to the heads of structural subdivisions and working bodies of the University (human resources department, accounting department, dean's offices, admissions committee, scholarship committee, military mobilization unit, etc.) within their functional duties and with respect to the data arrays they process.

7.1.2. The organization of PD protection at the University, coordination, and methodological guidance are carried out by a responsible person appointed by order of the Rector. The responsible person advises heads of structural subdivisions and monitors the existence of signed Consents to the collection and processing of personal data and Non-Disclosure Obligations regarding personal data, as well as coordinates the provision of responses to requests of personal data subjects.

Direct processing of PD in structural subdivisions (human resources department, accounting department, dean's offices, etc.) is carried out by authorized employees who have access to these data in accordance with their job duties and have signed Non-Disclosure Obligations regarding personal data.

7.1.3. Heads of relevant structural subdivisions independently organize the PD processing workflow in their areas of work, conduct briefings for subordinate employees who have access to them, and exercise continuous monitoring over their compliance with the requirements of legislation and these Regulations. Distribution of personal data databases and assignment of responsibility for their maintenance and preservation to specific structural subdivisions is carried out in accordance with orders of the Rector and Regulations on the relevant structural subdivisions.

7.1.4. The University (represented by the heads of structural subdivisions) maintains records of employees who have been granted access to PD for the performance of their job duties. All such employees are required to provide a written (or electronic with an applied QES) Non-Disclosure Obligation regarding personal data.

7.1.5. Internal transfer of PD of higher education applicants, employees, and counterparties to structural subdivisions or authorized officials of the University for conducting claim and litigation work (preparation of lawsuits, claims, responses to court requests) is carried out in accordance with the procedures and on the grounds specified by the Regulations on the procedure for conducting claim and litigation work of the University. Employees who obtain such access are obliged to use the data strictly for their intended purpose and provide a written Non-Disclosure Obligation regarding personal data.

7.2. University employees who are granted access to PD:

7.2.1. Must be familiar with the requirements of the Law of Ukraine «On Personal Data Protection» (see link: https://zakon.rada.gov.ua/laws/show/2297-17%2523Text) and these Regulations.

7.2.2. Are obliged:

- to use PD only in accordance with professional, official, or labor duties, to prevent loss of PD or their unlawful use;

- to prevent disclosure of PD in any manner that was entrusted to them or became known in connection with the performance of professional, official, or labor duties (except cases provided for by law), provided that such obligation remains in force after termination of their activities related to PD, except cases established by law;

- to urgently notify the immediate supervisor in case of loss or accidental destruction of PD media, loss of keys to premises, safes, cabinets where PD are stored, if authentication data for logging into any of the automated systems became known to other persons (with the exception of the University system administrator), or upon detection of an attempted unauthorized access to personal data;

- upon dismissal from work or transfer to another position, to timely hand over to the head of the structural subdivision or another employee designated by the University management information media containing PD that were received or created personally or jointly with other employees during the performance of job duties.

7.3. Technical measures and cybersecurity:

Access to electronic PD databases (internal EDMS, EDEBO, accounting and human resources software) is carried out exclusively using individual user accounts (logins and passwords), multi-factor authentication (where technically feasible), and/or qualified electronic signatures (QES).

Transfer of logins, passwords, and media containing QES from one employee to another is prohibited.

The University ensures the deployment of licensed antivirus software, firewall systems, and cryptographic information security tools during the transmission of PD over open networks.

In order to prevent data loss, regular backup of electronic PD databases is carried out.

7.4. Procedure of action in case of leak or unauthorized access to PD

In case of detecting a fact of unauthorized access to PD, their leak, loss, or a cyberattack on University servers, the employee who detected such fact is obliged to immediately notify their immediate supervisor and/or the University management.

The University takes urgent measures to block unauthorized access, eliminate vulnerabilities, and minimize consequences.

If a data leak carries a high risk to the rights and freedoms of PD subjects, the University notifies the Ukrainian Parliament Commissioner for Human Rights of this incident within the timeframes established by law, as well as, where possible, the PD subjects themselves.

8. Retention Periods and Procedure for Destruction of Personal Data

8.1. Retention periods

PD are stored at the University no longer than necessary for the purpose of their processing, unless otherwise provided for by legislation.

Retention periods for documents containing PD (student personal files, personnel orders, accounting records) are determined in accordance with the List of Standard Documents Created in the Course of Activity of State Authorities and Local Government Bodies, approved by the Ministry of Justice of Ukraine on 12.04.2012 No. 578/5 (as amended).

Video recordings from the University's video surveillance systems are stored for no more than 30 calendar days, after which they are subject to automatic cyclical overwriting, except in cases where a video recording serves as evidence in the investigation of offenses.

PD of potential applicants for admission (collected during career guidance events) are stored until the completion of the relevant admissions campaign or until consent is withdrawn by the subject.

8.2. Procedure for destruction (deletion)

PD are subject to destruction in case of:

- expiration of their retention period established by legislation;

- termination of legal relations between the PD subject and the University (unless legislation requires further archival retention);

- entry into legal force of a court ruling regarding the seizure or destruction of PD;

- withdrawal of consent by the PD subject (if there are no other legal grounds for processing).

Destruction of documents containing PD on paper media is carried out by shredding or incineration, which is documented with a corresponding Act on Destruction of Documents.

Destruction of PD in electronic form is carried out by their permanent deletion from databases and backup copies without the possibility of recovery.

9. Liability for Violations

9.1. University employees who have access to PD bear personal

responsibility for compliance with the requirements of Ukrainian legislation in the field of personal

data protection and the provisions of these Regulations.

9.2. For violations of legislation on PD protection (unlawful collection, storage, use, destruction, dissemination of confidential information about a person), as well as non-compliance with the established procedure for PD protection, guilty persons are subject to:

- disciplinary liability (reprimand, dismissal);

- administrative liability (fines according to Art. 188-39 of the Code of Ukraine on Administrative Offenses);

- criminal liability (according to Art. 182, 361, 362 of the Criminal Code of Ukraine);

- civil liability (compensation for material and moral damage).

10. Final Provisions

10.1. These Regulations are approved by the Academic Council of the University and put into effect by an order of the Rector.

10.2. Amendments and additions to these Regulations are introduced in the manner established for their adoption in the event of changes in current legislation of Ukraine, implementation of new information technologies, or changes to the organizational structure of the University.

Appendix A1

Form 1: For higher education applicants and prospective students

To be completed at the admissions office or dean's office upon enrollment

Appendix A2

Form 2: For employees (candidates for positions, current and dismissed employees)

To be completed at the HR department upon employment or data updates.

Signed in paper form by hand or in electronic form using an EDS (QES or Diia.Signature)

Appendix A3

Form 3: For persons associated with applicants for education (parents, legal representatives, customers / payers under contract)

Signed in paper form by hand or in electronic form using an EDS (QES / AES or Diia.Signature) or by checking a checkbox

This form is completed and signed personally by parents or payers EXCLUSIVELY in cases of their direct participation in concluding contracts or during personal submission of documents for applying for benefits. If details about parents (full name, phone, address) are provided by the applicant for education solely as contact information, this form is not completed by parents - the obligation regarding the lawfulness of transferring this data and informing the parents is assumed by the applicant for education themselves upon signing Form 1

Appendix A4

Form 4: For sole proprietors (FOP), persons under civil law contracts (GPC/GPC), and representatives of legal entities (counterparties, partners, practical training bases)

Signed in paper form by hand or in electronic form using an EDS (QES or Diia.Signature)

If a full written contract is concluded with a sole proprietor (FOP) or a person under a civil law contract, a separate consent does not need to be signed, provided that the relevant contract clause or confidentiality clause is included directly into the text of such contract; sample text of this clause is given below *

Appendix A5

Form 5: For visitors, infrastructure users (library, sports complex), and event participants

Depending on the format of interaction with the subject, the University uses one of the following options for obtaining consent:

Option 5.1: Full written form

Used for issuing library cards, passes to the sports complex/pool, or during registration for large-scale events with organizational fees

Option 5.2: Logbook form (for security checkpoints and dormitories)

Printed out and pasted onto the cover page of the Visitor Logbook at the entrance of academic buildings and dormitories. Individual forms are not filled out

Option 5.3: Electronic checkbox (for registration for conferences and events)

Placed under online registration forms on the University website or Google Forms. Checkbox must not be checked by default

Appendix A6

Form 6: For prospective students (participants in career guidance events)

Depending on the event format, an electronic checkbox or a short paper questionnaire is used

Appendix B1

Form 7: For persons granted the right of access to personal data and their processing (employees, committee members, system administrators, persons under civil law contracts)

This obligation is signed prior to actually granting the person access to personal data databases (upon employment, inclusion in the admissions committee, or prior to issuing logins/passwords to EDEBO, Mentor systems, etc.) and is kept in the personal file or with the secretary of the working body

Signed in paper form by hand or in electronic form using an EDS (QES or Diia.Signature)

Appendix B2

Register of Personal Data Non-Disclosure Obligations

Appendix C

Liability for Violation of Legislation in the Field of Personal Data Protection

Employees of National Aerospace University «Kharkiv Aviation Institute», as well as other persons who obtained access to personal data in connection with the performance of their professional, official, or contractual duties, are obliged to prevent disclosure in any manner of personal data that was entrusted to them or became known to them.

For violation of legislation on personal data protection and internal normative acts of the University, guilty persons are subject to disciplinary, administrative, criminal, civil-law, and material liability in accordance with the legislation of Ukraine.

1. Disciplinary Liability

For non-performance or improper performance by a University employee of their labor duties regarding the processing and protection of personal data, violation of the requirements of the Regulations on Personal Data Protection and non-disclosure obligations, disciplinary measures may be applied to the employee in accordance with the Labor Code of Ukraine (LCU):

Reprimand (Art. 147 of the LCU).

Dismissal (Art. 147, para. 3 of Art. 40 of the LCU — for systematic failure to perform duties, or under other relevant articles in case of detecting a gross violation).

2. Administrative Liability

According to Art. 188-39 of the Code of Ukraine on Administrative Offenses (CUAO), violation of legislation in the field of personal data protection entails imposition of fines on officials and citizens (employees). Such offenses, in particular, include:

- Failure to notify or untimely notification of the Ukrainian Parliament Commissioner for Human Rights (or another supervisory authority determined by law) about personal data processing that presents a special risk, or about changes to such data, which resulted in unlawful access to them or violation of rights of the personal data subject (for example, leaving open access to a database, loss of media containing a personal data database).

Sanction: a fine on citizens from 1,700.00 to 3,400.00 UAH, on officials — from 3,400.00 to 6,800.00 UAH.

- Evasion of execution of lawful demands of the Commissioner or their representatives regarding elimination of violations of legislation.

Sanction: a fine on citizens from 3,400.00 to 5,100.00 UAH, on officials — from 5,100.00 to 17,000.00 UAH.

- Failure to observe the procedure established by legislation for personal data protection, which resulted in unlawful access to them or violation of rights of the personal data subject.

Sanction: a fine on citizens from 1,700.00 to 8,500.00 UAH, on officials — from 5,100.00 to 17,000.00 UAH.

Note. Payment of an administrative fine does not release the guilty person from the obligation to compensate for damages caused.

3. Criminal Liability

In case of intentional actions that led to severe consequences, guilty persons are brought to liability in accordance with the Criminal Code of Ukraine (CCU):

Article 182 of the CCU («Violation of Privacy»): Unlawful collection, storage, use, destruction, dissemination of confidential information about a person or unlawful modification of such information (for example, database leak or its transfer to third parties without consent).

Sanction (part 1): a fine from 8,500.00 to 17,000.00 UAH, or correctional labor for a term up to 2 years, or arrest for a term up to 6 months, or restriction of liberty for a term up to 3 years.

Sanction (part 2 — the same actions committed repeatedly, or if they caused substantial damage): arrest for a term from 3 to 6 months, or restriction or deprivation of liberty for a term from 3 to 5 years.

Article 361 of the CCU («Unauthorized Interference in the Operation of Information (Automated), Electronic Communication Networks»): If data leakage occurred as a result of intentional hacking of University databases, bypassing security systems, or transmitting access passwords to unauthorized persons, which led to leakage, loss, or falsification of information.

Sanction (part 1): a fine from 17,000.00 to 51,000.00 UAH, or deprivation of the right to hold certain positions or engage in certain activities for a term up to 2 years, or restriction of liberty for a term up to 3 years.

Article 362 of the CCU («Unauthorized Actions with Information Processed in Computers, Automated Systems...»): Theft, damage, falsification, or blocking of information by a person who has lawful access to it (for example, an employee of the admissions committee or dean's office intentionally modified or deleted data in EDEBO or internal registers of the University).

Sanction (part 1): a fine from 34,000.00 to 68,000.00 UAH or correctional labor for a term up to 2 years.

Sanction (part 2): deprivation of liberty for a term up to 3 years with deprivation of the right to hold certain positions or engage in certain activities for the same term.

Sanction (part 3 — the same actions, if they caused significant damage): deprivation of liberty for a term from 3 to 6 years with deprivation of the right to hold certain positions for a term up to 3 years.

4. Civil-Law Liability

Compensation for damage to the personal data subject.

Higher education applicants, employees, or other persons who suffered property and/or moral damage as a result of unlawful processing of their personal data or violation of requirements for their protection, have the right to compensation for this damage in accordance with the Civil Code of Ukraine.

5. Material Liability

Material liability of an employee to the University.

If, as a result of an employee's actions (data leak, loss of information media, violation of cybersecurity instructions), direct actual property damage was caused to the University (for example, the University was forced to pay fines by decision of supervisory authorities or compensate damage to victims), such employee bears material liability in accordance with Chapter IX of the LCU.

6. Procedure for Documenting Violations

In case of detecting a fact of personal data security violation (leak, unauthorized access, loss), a commission is established at the University to conduct an internal investigation. The Responsible Person is ex officio an obligatory member of such commission. Based on the results of the investigation, an Act is drawn up, which serves as grounds for bringing guilty persons to liability or transferring materials to law enforcement agencies.