Back to Top

Please check the COVID-19 webpage and social media for updates.

General Data Protection Regulation Policy

Purpose

As an institution of higher learning, Western Oklahoma State College Intends to uphold the General Data Protection Regulation (GDPR) of the European Union for all the personal data protected under its scope.

Scope

The GDPR concerns the personal data for for persons whom are in the European Union.

For the purposes of this policy and in the intent of following the GDPR, ‘personal data’ is defined as any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

User Rights

Data subjects that are within the scope of the GDPR are entitled to transparent information, information and Access to personal data (Including data obtained directly from the data subject and data not obtained from the data subject), the right to access by the data subject, the right to rectification, and erasure, the right to restrict processing, right to data portability, the right to object, the right to be excluded in automated decision making including profiling.

Transparent Information

Western Oklahoma State College will take appropriate measures to provide information relating to the processing of personal information to the data subject of that information in a concise, transparent, intelligible and easily accessible form using clear and plain language. This information will be provided to the data subject upon the request of the data subject contingent on positive identification. The information will be made available without undue delay and within 1 to 3 months, depending on the complexity of the request. The information provided by this request covers the information about the modalities of information gathering where the data are provided by the data subject, data are not provided by the data subject, or are communication about the data subject.  This information can be requested using the form available here: GDPR Request Form

Information and Access to personal data (Including data obtained directly from the data subject and data not obtained from the data subject).

Western will provide information to the data subject data that are collected from the data subject, contingent on the data subject being covered by the scope of the GDPR and a positive identification of the requesting data subject.

The following information will be made available:

  • Identity and contact information of data controller
  • Identity and contact information of the data protection officer
  • The purpose for which the personal data are intended
  • The recipients or categories of the personal data, if any
  • The time periods in which the data are stored
  • The data subjects right as contained in the GDPR

This information will be made available without undue delay and within 1-3 months, depending on the complexity of the request and can be requested here: GDPR Request Form

The right to access by the data subject

Western will provide information as to whether or not personal data conserning the data subject are being processed and in the case that they are:

  • The purpose of the processing
  • The categories of the data
  • Recipients of the data
  • Time period in which the data will be stored
  • Rights to that data as contained in the GDPR
  • In the case that the data was not obtained directly from the data subject, the source of the data.
  • The existence of automated decision making made with that data, information about the logic involved and the significance of that data.

This information will be made available without undue delay and within 1-3 months, depending on the complexity of the request and can be requested here: GDPR Request Form

Rectification and erasure

Western will provide the data subject the right to obtain, without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

Western will provide the data subject the right of erasure of personal data where the following conditions apply:

  • The personal data are no longer necessary for the purposes in which it was intended.
  • The data subject withdrawals consent.
  • There are no legitimate grounds for processing according to the GDPR

This service will be made available without undue delay and within 1-3 months, depending on the complexity of the request and can be requested here: GDPR Request Form

Western complies with the Oklahoma Open Records Act which requires the public availability of certain records including data subject’s directory information, unless it is requested by the data subject to withhold that information. This request can be made by select the correct option on the Application for Admission, emailing: admissions@wosc.edu or calling admissions at 580-477-2000.

Western is subject to Oklahoma record retention guidelines specified in the Oklahoma Department of Libraries. Many education records are subject to retention rules that range from two years to permanent  retention. Requested erasure will only be applied to records that are allowed according to the Oklahoma Department of Libraries records disposition schedule.

Right to restrict processing

Western will restrict the processing of records (where allowed by Oklahoma State Statutes and Guidelines) when one of the following conditions apply:

  • Data accuracy are contested by the applicant
  • Data processing is unlawful and data subject opposes the erasure.
  • Western no longer needs the data for processing but is required to retain the records by the data subject for the establishment, exercise or defense of a legal claim.

Where the data processing has been restricted, such data will only resume processing under the request of the data subject or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest.

Processing will be restricted without undue delay and within 1-3 months, depending on the complexity of the request and can be requested here: GDPR Request Form

Notification obligation regarding rectification or erasure of personal data or restriction of processing

Western shall communicate any rectification or erasure of personal data or restriction of processing carried out to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. Western will inform the data subject about those recipients if the data subject requests it.

Right to data portability

The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to Western, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where technically feasible.

Right to object

Western will no longer process personal data unless needed for legitimate overriding interests, rights and freedoms of the data subject, or for the establishment, exercise or defense of legal claims; upon the objection of the data subject.

Where personal data are used for marketing purposes, the data will no longer be used for those purposes.

Processing will be restricted without undue delay and within 1-3 months, depending on the complexity of the request and can be requested here: GDPR Request Form

Restrictions

This policy is subject to all State of Oklahoma, Oklahoma State Regents of Higher Education, Higher Learning Commission and United States of America, US Department of Education and other laws, guidelines and policies.  The GDPR will be upheld to the best of Western’s capability within the restrictions of all the requirements of any Oklahoma state public education institution.

 


 

(5-25-2018)

GDPR REQUEST FORM