Information security and data protection for students
Student digital security
Information security and data protection are part of responsible studying. As a student, you handle your own data and, in many study contexts, also the personal data of others — including research materials, surveys, recordings, and shared documents.
Information security in brief
Practices that protect the confidentiality, integrity, and availability of information. In everyday student life, this means using a strong password, enabling MFA, logging in securely, recognising suspicious messages, and storing data in the right services without sharing it unnecessarily.
Data protection in brief
Protects people’s privacy when personal data is processed. Personal data includes names, email addresses, photos, audio, video recordings, student numbers, and any other information from which a person can be identified directly or indirectly.
Information security
Information security is an important part of student life. During your studies you use many digital services and handle data related to studying and personal information. Protecting this data properly supports safe and smooth studying.
Digital services are essential for studying, working, and managing everyday tasks. At the same time, they carry risks such as data loss, scam attempts, and privacy breaches. Safe behaviour online requires attention, judgement, and good practices that help prevent problems and protect against threats. This is not just about technical solutions — it is also about recognising risks and knowing how to act wisely in different situations.
Information security covers all handling of information, regardless of whether it is in electronic, written, or verbal form. Students are expected to act carefully and follow guidelines. Humak supports safe practices in accordance with applicable legislation and instructions.
Tip: Cyber Weather
To stay informed about current cybersecurity threats and incidents, we recommend the Finnish National Cyber Security Centre’s Kybersää service, which provides up-to-date information on the general cyber threat situation.
Information security refers to the technical measures and organisational procedures that ensure a safe operating environment when using information technology. It covers all processing, storage, and transfer of information, regardless of whether this takes place electronically, verbally, or in writing.
Information security work involves planning and implementing the measures needed to maintain and achieve security. This includes methods, tools, and actions to protect data, the resources allocated, and the equipment involved.
Humak manages information security in accordance with national and international legislation and regulations on information security and data protection, following good governance principles and the guidelines and recommendations issued for the Finnish public administration..
Information security principles define the goals, responsibilities, obligations, and means of implementation for information security at Humak. Information security is an integral part of ensuring and developing all activities, and must be present in the everyday work of both staff and students.
The aim of information security work is to ensure the uninterrupted operation of manual and automated information processing systems and networks that are critical to Humak’s operations; to prevent unauthorised use of data and systems; and to prevent accidental or deliberate destruction or corruption of data, while minimising any resulting damage.
Information security work takes into account Humak’s structure as a networked university of applied sciences, and the increasing shift of teaching to the digital campus, online courses, and remote working.
Data, systems, and services are protected through legislation, regulations, and administrative, technical, and other measures. The goal is to maintain a good level of information security both nationally and internationally.
Everyone who handles Humak’s data is obliged to take care of information security and to comply with Humak’s principles, practices, terms of use, and guidelines relating to information security and data protection. Anyone who handles data is also obliged to report any violations or breaches they observe.
Before receiving a username, you must read, understand, and accept Humak’s terms of use for IT services for students. Acceptance takes place via the Suomi.fi service. Your username is then sent to the email address you provided in opintopolku.fi.
The IT terms apply to everyone who holds a Humak-issued username and password. Their purpose is to protect the confidentiality, integrity, and availability of all users’ data and to provide a reliable and secure environment for information processing. The terms apply to information systems under Humak’s administration or responsibility.
Personal use must not conflict with the guidelines provided or with Finnish law and regulations. Use for commercial or political purposes is generally prohibited. Users are personally responsible for protecting and backing up their own files. Humak’s IT administration backs up files regularly but is not responsible for lost files. The IT administration manages the prevention of malware and spam, but users must also do their part and must not act in ways that compromise information security.
Phishing refers to attempts to obtain a person’s confidential information — such as usernames, passwords, or payment details — through deception. Scams are typically carried out via emails, text messages, or websites designed to look trustworthy and official.
The aim of phishing is to get the recipient to act in the scammer’s favour — for example, by clicking a link, entering their details on a fake website, or downloading a malicious attachment. Scams exploit a sense of urgency, fear, or enticing promises to prevent the recipient from assessing the authenticity of the message.
Phishing is one of the most common cybersecurity threats, and it also targets students. Messages may be sent in the name of educational institutions, resembling login requests or study-related notifications. Careful handling of messages and following guidelines help prevent the risks caused by phishing.
- Familiarise yourself with the key guidelines for information security and follow them. If you are unsure about anything, ask IT support for guidance: support@humak.fi. Follow Humak’s approved information security guidelines, keep up with security communications, read the instructions, and participate in any training offered to you. Information security concerns all of us!
- Lock your computer or log out whenever you leave it unattended. Try to use different passwords for different systems. Store passwords and other login credentials carefully. Use data and tools only for your studies or work tasks.
- Be careful not to disclose confidential information to outsiders — whether at your workplace, on public transport, or on social media. Data must be protected at every stage of processing.
- Do not browse suspicious websites. Do not open strange emails or their attachments. Never share your personal username or password with anyone else. Change your password regularly. Remember the data lifecycle.
- Handle and store physical items — such as documents, USB drives, phones, passwords, keys, and access badges — appropriately. Do not let outsiders use your computer. Take care of your information security!
- Lock your workstation whenever you step away from it. At the end of the day, log out of all systems and shut down your computer. Follow the clean desk principle. Do not leave confidential material on your desk.
- Fit your laptop with a privacy screen to prevent shoulder surfing. Do not leave devices unattended in visible places — for example, in a car or hotel room. If you transfer data using external storage, always supervise the transfer personally. Only use unencrypted external storage for non-confidential public information.
- Remember to use end devices safely. Take particular care when working outside Humak’s premises. Prepare in advance for data queries and potential problems.
- Tell your lecturer if you notice any information security violations. Always report information security incidents, threats, and vulnerabilities immediately to your lecturer and to Humak IT support at support@humak.fi. Remember: maintaining information security is an ongoing process!
- Do not panic if something unexpected happens. Reach out to Humak IT support at support@humak.fi. Good behaviour protects your reputation — be mindful of reputational risk!
Data protection
The General Data Protection Regulation (GDPR) is a European Union data protection regulation that has applied since 2018. Its purpose is to protect individuals’ personal data and give them greater control over their own information. The regulation requires organisations to process personal data transparently, securely, and only on lawful grounds.
Everyone has the right to the protection of their personal data. Data protection is a fundamental right that ensures the realisation of the rights and freedoms of data subjects in the processing of personal data. Data protection defines when and under what conditions personal data may be processed. Information security is one means of implementing data protection — its purpose is to protect data and information systems through organisational and technical measures that ensure the confidentiality and integrity of information, the availability of systems, and the realisation of data subjects’ rights.
Humak’s management, employees, students, and external parties in a contractual relationship with Humak are obliged to comply with the data protection policy and other information security and data protection practices, rules, guidelines, and principles. When personal data is processed on behalf of Humak, Humak’s data protection policy applies.
Humak processes personal data to fulfil its statutory mission under the Universities of Applied Sciences Act. Humak processes the personal data of students, staff, and stakeholders. Alumni, marketing, customer, and partner data are processed on the basis of a contract, consent, or a statutory obligation. Personal data is processed to carry out work duties, to enable students to study, and to maintain access rights and information security.
Data protection is everyone’s responsibility — please familiarise yourself with Humak’s data protection practices.
- Tunne tietosuojan toteutumisen kannalta keskeiset ohjeet ja toimi niiden mukaisesti. Epäselvissä ja askarruttavissa asioissa on kysyttävä ohjeistus esihenkilöltä. Selvitä ja noudata Humakin hyväksyttyjä tietosuojaohjeita. Seuraa Humakin julkaisemia tietosuojaan liittyviä tiedotteita, tutustu ohjeisiin ja osallistu sinulle tarjottuun koulutukseen. Toimi saamiesi ohjeiden mukaisesti. Tietosuoja koskee meitä kaikkia!
- Minimoi henkilötietojen käsittely ja rajaa käsittelijöiden piiri mahdollisimman pieneksi. Luokittele käsittelemäsi tieto (julkinen, salainen, arkaluontoinen ym.) ja tunnista riskit. Käytä tietoaineistoja ja työvälineitä opintojen/työtehtäviesi hoitamiseen. Varmista, että henkilötietojen käsittely on oikeutettua ja asianmukaista!
- Varo paljastamasta luottamuksellisia tietoja sivullisille työpaikalla tai sen ulkopuolella esimerkiksi sosiaalisessa mediassa tai puhelimessa. Säilytä henkilötietoja sisältävä materiaali aina suojatussa tilassa. Tietoja tulee suojata sen kaikissa käsittelyvaiheissa. Huolehdi henkilötietojen oikeasta käsittelystä ja dokumentoinnista!
- Lähetä henkilötietoja sähköpostitse vain suojattuna ja vain jos vastaanottaja on aidosti tunnistettu. Muista tietojen elinkaari. Tuhoa vanhentuneet ja tarpeettomat tiedot!
- Säilytä henkilötiedot turvallisesti. Lähetä henkilötietoja sähköpostitse yhteistyötaholle vain salattuna ja vain kun vastaanottaja on luotettu taho. Laita samalla tietosuoja kuntoon!
- Luovuta arkaluonteisia tietoja vain sellaisten sähköisten palveluiden kautta, jotka vaativat vastaanottajilta vahvan tunnistautumisen. Hävitä tietosuojattava jäte asianmukaisesti. Noudata ns. puhtaan pöydän periaatetta. Älä säilytä työpöydällä salassa pidettävää aineistoa. Kartoita sopimukset ja huolehdi, että niissä on sovittu henkilötiedoista!
- Tulosta henkilötietoja vain, kun se on perusteltua ja vain tulostimille, jotka ovat suojattuja. Henkilötietoja sisältävät tulosteet on säilytettävä suojatussa tilassa. Huolehdi etätyössä ja matkoilla mobiililaitteiden ja niiden kautta käytettävien salassa pidettävien tietojen suojaamisesta. Mikäli siirrät aineistoa ulkoisen muistin avulla, valvo siirtoa aina henkilökohtaisesti. Käytä ulkoisia muistivälineitä ilman salausohjelmaa vain julkisen tiedon kuljettamiseen. Hanki kannettavaan tietokoneeseen suojakalvo, joka estää sivulta tapahtuvan salakatselun. Huolehdi, että asia otetaan vakavasti!
- Muista kunnioittaa muiden yksityisyyttä. Henkilötietojen käsittelijä on aina vaitiolovelvollinen käsittelemistään tiedoista. Näin ylläpidät luottamusta.
- Ilmoita aina tietosuojaan liittyvistä ongelmatilanteista ja havaitsemistasi uhkista ja suojauspuutteista välittömästi lehtorille ja Humakin tietosuojan tukeen, security@humak.fi Muista, että tietosuojan ylläpito on jatkuva prosessi!
- Älä hätäänny tai hölmöile, jos jotain poikkeavaa tapahtuu. Ota rohkeasti yhteyttä Humakin tietosuojan tukeen, security@humak.fi. Paranna hyvällä toiminnalla imagoa – huomioi maineriski!
Rights of the data subject
GDPR Articles 15, 16, 17, 18, and 20.
The data subject provides the personal data required in each situation and is responsible for its accuracy. Providing personal data is a necessary prerequisite for handling matters in many of Humak’s processes.
The data subject has the right to know what personal data about them is being processed and what information has been stored. The data subject also has the right to request restriction of processing, rectification or erasure of data, or to transfer data from one system to another. Using their Humak username, the data subject can access and view their own information in many systems.
If a data subject wishes to exercise their rights in another way, they should submit a data request to Humak’s registry office (kirjaamo@humak.fi). Humak will provide the information as soon as possible and without undue delay, at the latest within one month of receiving the request.
If the request is complex and requires, for example, a legal interpretation, the deadline may be extended by two months. Information is provided free of charge as a rule. If the data subject requests multiple copies, a fee based on administrative costs may be charged. If a request is manifestly unfounded or excessive, or if the data subject submits requests repeatedly, Humak may charge for the administrative costs of providing the information or refuse to provide it entirely — in which case Humak will justify its decision.
If Humak does not provide the information or does not act as requested by the data subject, the data subject will be given a written explanation. This will also include information about their rights, such as the right to lodge a complaint with the supervisory authority.
Download, complete, save, and submit the personal data access request form to Humak’s registry office at kirjaamo(at)humak.fi.
In certain cases, the data subject may have the right to request that the processing of their personal data be restricted while the legal basis for the data or its processing is being properly reviewed, corrected, or supplemented
Data portability means that the data subject receives the personal data they have provided in a structured, commonly used, and machine-readable format and may transfer that data to another controller without Humak obstructing this. This right may apply only in situations where processing is automated and based on consent or a contract.
Based on their particular personal situation, the data subject has the right at any time to object to the processing of their personal data when the legal basis for processing is the performance of a task in the public interest, the exercise of official authority, or Humak’s legitimate interest. In such cases, data may continue to be processed only if there is a compelling and justified reason that can be demonstrated. The data subject has the right, without special justification, to object at any time to the processing of their personal data for direct marketing purposes.
In situations where the processing of a data subject’s personal data is based solely on consent, the data subject may withdraw that consent. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal. Consent should be withdrawn primarily from the party to whom it was given. If this is not possible, the data subject may contact the person responsible for the register.
A data subject may lodge a complaint with the supervisory authority if they believe that the processing of their personal data violates the EU General Data Protection Regulation (EU 2016/679). In addition, students have the right to use other administrative appeals and legal remedies. A student also has the right to bring an action against the controller’s or processor’s organisation if they believe their rights have been violated because the processing of personal data has not complied with the GDPR.
Humak has an obligation to demonstrate that personal data is processed lawfully and systematically. This requires clear principles defining how data protection is implemented, as well as practical guidelines and procedures to ensure they are followed in daily operations.
The controller must be able to demonstrate compliance with data protection legislation. Accountability is a key principle of the GDPR. If the controller detects a data breach, for example, accountability allows it to show that it has actively sought to identify data protection risks and has implemented the necessary measures to protect personal data.
If the controller cannot demonstrate compliance with the GDPR, this may result not only in reputational risk but also in administrative and financial penalties. The controller must implement the necessary technical and organisational measures to meet the accountability requirements. Accountability also entails a documentation obligation — in practice, carrying out and recording certain measures.
Data protection handbook (Coming soon)
The data protection handbook is a practical guide that brings together the principles of the data protection policy and describes in more detail how the protection of personal data is implemented in everyday practice. It includes descriptions of responsibilities and roles, processes related to the processing of personal data, instructions for implementing data subjects’ rights, data protection impact assessment practices, guidance on responding to data breaches, and links to legislation and internal procedures. The handbook serves as a tool for staff and students to ensure that all data protection obligations are known, followed, and can be demonstrated to external authorities.
Data protection policy (Coming soon)
The data protection policy defines the principles and practices for ensuring the lawful, secure, and transparent processing of personal data. Personal data is collected and used only for predefined, justified purposes and is stored only for as long as necessary. All processing is based on legislation, a contract, consent, or another acceptable legal basis, and the rights of data subjects — such as access, rectification, and erasure requests — are guaranteed. Humak is also committed to training its staff, ensuring technical and organisational safeguards, and continuously developing data protection practices as part of good information management.
Information security and data protection checklist for Online Learning
- Follow communications on data protection and information security published by Humak, read the guidelines, and participate in any training offered. Act in accordance with the instructions you receive. If you have any questions, you can always turn to your lecturer or Humak’s IT security office.
- Use study materials provided by Humak only for your studies. Do not discuss confidential matters on public transport or on social media.
- Use the email address provided by Humak for study-related matters. Do not share confidential or sensitive information by email.
- If you join an online teaching session in a public place or with others present, use a privacy screen on your laptop to prevent shoulder surfing. Do not leave your devices unattended in visible places — for example, in a car, library, or hotel room.
- Before joining an online teaching session, make sure that others cannot see or hear private matters.
- If you join an online session from a location where you cannot be certain of the security of the network connection, use your own phone’s mobile data or Humak’s Eduroam network to connect.
- Keep software and operating system updates on your devices up to date.
- Do not browse suspicious websites. Do not open strange emails or their attachments. Never share your personal username or password with anyone else. Change your password regularly.
- Do not panic if something unexpected happens. Let your lecturer or supervisor know what happened, and they will direct you further if needed.
- Remember to respect the privacy of your fellow students and lecturers. Good behaviour protects your reputation — be mindful of reputational risk! Data protection and information security apply to you too!