Skip to main content
European School Education Platform

Data protection notice

The European Education and Culture Executive Agency ('EACEA') is committed to preserving the protection of your personal data. This notice provides information on your rights in relation to data protection and on how your personal data are processed by EACEA in accordance with Regulation (EU) No 2018/1725 on the protection of personal data by the Union institutions, bodies, offices and agencies [1] ('the Data Protection Regulation').

1. Who is responsible for processing your personal data (data controller)?

The controller is EACEA, BE-1049 Brussels.
The person designated as being in charge of the processing operation is the Head of Unit A6 - Platforms, Studies and Analysis.
The contact email address is eacea-eplus-esep@ec.europa.eu

2. For which purpose do we process your data?

The European School Education Platform ('the Platform') is a meeting point for the school education community – school staff, researchers and policymakers – to share news, interviews, publications, practice examples, courses and partners for their Erasmus+ projects. Its eTwinning area is dedicated to eTwinners and their activities.

eTwinners are defined as registered users of the Platform who, following a validation procedure by National Support Organisations (NSOs), are granted access to the restricted eTwinning area and its collaborative functionalities.

A dedicated section of the Platform, called ‘eTwinning’, provides a restricted area for school staff (teachers, head teachers, librarians) based in associated countries to Erasmus+, to collaborate, develop joint projects, share resources, and engage in community activities. Access to the eTwinning area is granted only after users have been validated by the National Support Organisations (NSOs) of their respective countries.

European Schoolnet has been contracted by EACEA to coordinate Platform-related activities (articles, videos, podcasts, online courses, etc.) and to carry out specific tasks supporting the community engagement of users (conferences, workshops, events, etc.).

For the platform, data processing is needed to allow registered users to:

  • Publish posts in the connect area to find project partners
  • Publish courses’ descriptions which will be included in the course catalogue,
  • Apply for online and on-site events organised by the EUN in the context of its project’s task
  • Participate in surveys, self-assessment tools and open calls
  • Participate in online courses managed by EUN and run via the EU Academy
  • Subscribe to newsletters via Newsroom

In addition to the above, for the eTwinning area, data processing is needed to allow eTwinners to:

  • Share information as part of eTwinners’ community engagement and collaborative projects registration and implementation
  • Communicate and collaborate within project activities
  • Involve pupils in the activities taking place in their project’s restricted area (TwinSpace)
  • Facilitate monitoring and research activities run by EUN

Additionally, specific users’ personal data are processed, upon their consent, when publishing articles on the Platform, including pictures, quotes and affiliation.

The data processing is needed to:

  • Allow registrants to participate in online and hybrid events
  • Website statistics, registering browsing experience of the visitor
  • Publish editorial content through both the Platform and eTwinning areas, which includes expert articles that shares experts’ insights, and practical articles that highlight innovative teaching methods and showcase best practices from schools, teachers, and the eTwinning community
  • Enrol the registered users to the EU Academy course selected via the Platform
  • Access to the course in the EU Academy environment
  • Conduct short pedagogical surveys and monitoring report surveys to allow and facilitate monitoring and research activities in relation to the Platform activities
  • Provide individuals with certificates of completion of online courses, as well as with certificates, in digital and print, or trophies, in relation to the eTwinning European prizes, eTwinning School labels, National and European Quality labels
  • Produce and disseminate videos featuring best practices of schools, teachers, users of eTwinning, winners of the eTwinning European prizes
  • Provide support services and respond to helpdesk inquiries
  • Send subscribers updates and relevant information related to the Platform or eTwinning and to inform them of on different topics in the area of services of the EC through the newsletters
  • Manage the Platform/eTwinning social media activities more effectively and efficiently, gather analytics on the Platform social media accounts' audience engagement to assess the impact of communications activities

Your personal data will not be used for an automated decision-making including profiling.

3. Which personal data are processed?

In order to carry out the processing operation, the following data may be processed:

  • personal identification numbers (IDs, passport, etc);
  • data subjects’ contact details (names and addresses (including email addresses);
  • registration data/participation to meeting, etc;
  • physical characteristics of persons: image, voice, video recording, etc;
  • allowances and bank accounts;
  • info concerning the data subject's career;
  • data subjects’ communications via phone, emails etc;
  • geo/localisation, IP address,

Dietary requirements collected for catering at onsite events may, depending on what the data subject chooses to disclose, reveal data concerning health (e.g. allergies, intolerances) or religious or philosophical beliefs (e.g. halal, kosher, vegetarian, vegan). Such data is processed only on the basis of the data subject's explicit consent (Art. 10(2)(a) of Regulation (EU) 2018/1725), is transmitted to the catering vendor in anonymised form, is destroyed immediately after the event and in any case no later than one month after the event and is not used for any other purpose.

Types of personal data collected from the Platform users

Mandatory data

To register in the Platform, individuals:

  • Must access through an EU Login account which includes: first name, last name and email. Such data will be processed to create an account of the Platform
  • Must provide the following mandatory personal data: preferred language, member type (role in organization), education level, and country of work.

Optional data

Users’ profiles: Optional personal data may be collected to enrich users’ profile including: images, users’ description, location, languages spoken, subjects and topics of interest, links to social media accounts such as Facebook, Instagram or LinkedIn.

Partner finding posts: Users are allowed to share content and photos which may contain personal information

Articles: Occasionally, personal data may be included in the articles published on the Platform. Any inclusion of personal data voluntarily provided by the Platform user will be the responsibility of the user.

Course catalogue: The Platform offers a course catalogue whose content is submitted by registered users. Entries include a free text field which can be edited by the author and may contain personal data.

Surveys: EUN, as part of its project activities, regularly publishes surveys: online course evaluation, user satisfaction surveys, self-assessment questionnaires, open calls to participate in focus groups or interviews researching various pedagogical issues. Users participating in these surveys are directed to EU Survey, which has its own privacy statement and to which respondents must adhere. Users’ responses to the surveys, scores of the self-assessment questions may contain personal data beyond what is collected for creating the EU Login account.

Focus groups: Users participating in focus groups and/or interviews may share additional personal data, the processing of which is subject to its own privacy statement.

Online courses: Registered users may participate in EU Academy online courses. When enrolled, users are redirected to the EU Academy e-learning platform where the EU Academy courses are held. The EU Academy platform is operated by the EC and has its own privacy policy to which participants must adhere. Activities carried out by participants in the courses, including assessment data and outcomes of the training sessions, are processed by EUN for the deployment of the project activities.

Newsletters: Users may voluntarily subscribe to the Platform newsletters by editing their profile page or during registration. The personal data collected include: email addresses and preferred language.

Third party events: Users may participate in online and onsite courses and events promoted through the Platform, organised by third parties which have their own privacy policies.

Types of personal data collected from eTwinners

In addition to the personal data collected from users to register in the Platform as described above, the following data are collected from eTwinners:

Mandatory data

Country/region of work, organization name, subjects of teaching, age range of pupils.

Optional data in case eTwinner is further involved in eTwinning activities 

Any personal data contained in public feeds, posts and content posted voluntarily.

eTwinners may participate in TwinSpaces, groups, and rooms. When personal data is shared, it is processed as follows:

TwinSpaces are collaborative spaces where teachers work with partners. Pupils (who may be minors) also participate upon invitation from their teachers after obtaining consent from their parents. Teachers ensure that informed consent procedures, as required by the Regulation 2018/1725 and their national Data Protection Regulation, are in place and confirm to EUN, through a clear, active affirmative action, that they have obtained informed consent from parents/legal guardians and written consent from pupils who are illiterate, prior to the collection of minors’ personal data. Minors and their parents/legal guardians are informed that their personal data will be shared with EUN. Those personal data are erased as soon as possible when no longer needed in line with the retention policy specified in EUN privacy statement.

eTwinning rooms and groups are virtual spaces where teachers can discuss and meet online. No additional data are collected from eTwinners through above-mentioned collaborative spaces, except when they voluntarily disclose personal information via comments, discussions, or shared content.

Third-party tools: TwinSpaces and groups allows third-party communication, collaboration and publishing tools to be embedded in their pages. Users may voluntarily choose to share comments, photos, videos and/or other personal data. These tools apply their own privacy policies which are clearly shared with end-users.

Online-onsite events: The types of personal data collected are: name, surname, signatures, country, profession, title, image and sound data, IP address, dietary requirements (if the event is onsite).

Web analytics: Personally Identifiable Information (PII) mostly (un)aggregated and anonymised specified here: https://school-education.ec.europa.eu/en/cookies-policy through first party cookies.

Editorial activities

  • From authors: Basic identity information, signatures, profession, titles, image, short bio, any personal data voluntarily shared by the author in the content
  • From call contributors: full name, email address, country of origin, CVs,

Other

Certificates of completion of online courses: names, surnames, signatures, email and school name.

Videos and podcasts: basic identity information, nationality, profession, title, signatures, image and sound data.

Coordination of NSOs: basic identity information, profession, title, name, surname, gender, work emails, country of origin, organisation, and role within the organisation.

User support/ticketing system: name, email, any personal data the data subject chooses to share in the subject/message text fields and as an attachment.

Social media management-analytics on communication activities: names, usernames, image data, any personal data contained in comments/messages, email addresses and the associated timestamp.

4. Who has access to your personal data and to whom is it disclosed?

Data publicly accessible

A portion of personal data submitted by registered users is publicly displayed on the Platform, making such information freely accessible on the internet. Registered users can control the visibility of their personal data through the 'profile visibility' and 'who can contact you' features in their profiles. The data which may be public upon a user’s consent are described below.

Platform users’ data:

  • Profile (first name, last name, picture, if any, country, role, free text description including social media accounts) can be made public if the user enables the profile visibility to 'everyone on the internet'.
  • Posts shared by registered users are public and must comply with the Terms and Conditions of
  • Courses’ descriptions are public in the course

Data accessible by other registered users

Other personal data may be shared with other registered users as follows:

  • Profile page, including the following information: first name, last name, country of work, picture, if any, affiliated organisation(s), role, any personal data user chooses to share in the free text field (bio), spoken languages, interested topics/subjects, affiliated projects and whether the user is eTwinning validated, social media is accessible to other registered users in case the visibility is set to 'users registered on the Platform'.
  • Users’ activity on online courses is accessible by all participants in that

Data accessible by specific recipients

  • The transmission of data to third parties (e.g. EC Open Data Portal, research centres and universities) can be permitted under specific authorisation of EACEA and in these cases, data will be shared in an aggregated format.
  • The names, email addresses and course selection of the Platform users who decide to attend online courses conducted through EU Academy platform are shared with the EU Academy platform designated staff following the EU Academy privacy policy.
  • For all data collected via EU Survey, for which a specific disclaimer is applied, the personal data are shared with the EU Survey platform designated staff
  • For all data collected via Newsroom and used for newsletters, for which a specific disclaimer is applied, the personal data are shared with the EC’s Newsroom service designated staff.

Data accessible by EACEA, processors and sub-processors

Access to the full data is provided to the EACEA staff responsible for carrying out this processing operation and to the data processors and the sub-processor listed above under point 6 according to the 'need to know' principle.

Data recipient categories concerning personal data of eTwinners

In addition to the provisions above, which are valid for all registered users, including eTwinners, eTwinners’ personal data may be visible to specific categories as follows:

Data accessible by other eTwinners

  • eTwinners may access the full set of other eTwinners’ personal data, except users' email address and school principals’ contact details, in the eTwinning restricted area of the
  • Any personal data shared voluntarily by eTwinners are accessible within the ‘My eTwinning’ area, eTwinning groups, rooms, and TwinSpaces only by the respective members of these
  • Pupils’ personal data, if present in restricted areas dedicated to project collaboration among partners (TwinSpaces), is visible to other members of the project.

Data accessible by NSO

NSOs have direct access to eTwinners’ full set of data to validate/manage eTwinners’ registration and perform related activities. NSOs have only access to the data of users from their respective countries.

Pupils’ personal data, if present in restricted areas dedicated to project collaboration among partners (TwinSpaces), is visible by NSO in case such projects are subject to an evaluation for National Quality Labels.

Data recipient categories concerning personal data of both the Platform users and eTwinners 

Personal data processed in the context of the Platform including the eTwinning area may be disclosed to public authorities in accordance with Union and Member State law such as the European Court of Justice, the relevant national judge as well as the lawyers and the agents of the parties in case of legal proceedings, the Investigation and Disciplinary Office of the European Commission (IDOC), the competent Appointing Authority in case of a request or a complaint lodged under Articles 90 of the Staff Regulations, the European Anti-Fraud Office (OLAF), the Internal Audit Service of the Commission (IAS), the Court of Auditors, the European Ombudsman, the European Data Protection Supervisor (EDPS) and the European Public Prosecutor’s Office (EPPO).

For online - onsite events: Data Recipients are EUN, EACEA, NSOs, third-party platforms/ service providers mentioned (such as MS Teams, YouTube and Eventtia). Both online and hybrid events are livestreamed through various channels, including YouTube, MS Teams, the Platform and EC audiovisual service. Dietary information of the participants collected through registration forms (concerning onsite events) is shared with the catering vendor in an anonymised way. As for the Annual conference,

personal data of attendees are shared with the contracted travel agency to arrange the travel and accommodation.

For web analytics: Data Recipients are EC (DIGIT), EUN and Tremend.

For editorial activities: The articles are made publicly available through EUN's social media channels and on the Platform. In case quotes are collected, these are displayed on the Platform or social media along with the name and surname of the contributor. Personal data collected through call for contributions form is accessible to respective NSOs.

For enrolment of the users to EU Academy courses: The names, emails, and course selection of the Platform users attending training courses will be shared with and processed by the European Commission’s EU Academy for the purposes of providing such trainings, following the EU Academy privacy policies. Data on the progress of learners and the outcome of the training course is accessed by the Platform moderators for gathering and sharing training credentials.

For surveys: Data Recipients are EUN, third party platform (i.e. EU Survey) used to run surveys.

For certificates of completion of online courses: Data Recipients are EACEA, EUN, HOFI, respective NSOs which evaluate the project and award National Quality Labels, European Quality Labels, eTwinning School labels and eTwinning European prizes as part of the grant agreement they have with the Agency, teachers who collect the signed consent forms from parents and minors.

For videos and podcasts: Data Recipients are EUN, EACEA, third-party platforms (such as MS Teams). Local audiovisual partners are occasionally hired to create on-site recordings on behalf of EUN.

For coordination of NSOs: Data Recipients are EACEA, EUN, the member NSOs, third-party platforms (such as MS Teams).

For user support/ticketing system: Data Recipients are EUN, IT contractor to follow up on the requests. EAC and EACEA upon request for monitoring purposes. NSO of the user involved for support purposes.

For newsletters (the Platform and eTwinning): Data Recipients are EC (Newsroom services), Tremend and EUN.

For social media management-analytics on communication activities: Data Recipients are EC, EACEA, EUN, third-party tools such as Meta.

Platform registered users

EUN does not directly transfer the personal data of the Platform registered users to countries outside the European Union (‘EU’) nor the European Economic Area (‘EEA’).

eTwinners

eTwinners’ personal data may be transferred to third countries outside the EU or the EEA: Albania, Armenia, Azerbaijan, Bosnia and Herzegovina, Georgia, Jordan, Lebanon, Kosovo, Moldova, Montenegro, North Macedonia, Palestine, Serbia, Tunisia and Türkiye.

The primary purpose of the transfer is to enable NSOs to validate eTwinners’ personal data, specifically their affiliation with a school within the NSO's country. This enables NSOs to fulfil their contractual obligations under the grant agreement with EACEA, including awarding National Quality Labels, European Quality Labels, eTwinning School labels, and eTwinning European prizes. NSOs only receive personal data of eTwinners from their own country.

The types of personal data transferred to NSOs include the following:

  • Mandatory eTwinner data: username, email address, name, surname, role at school (if a teacher, the subjects taught), communication language(s), age range of pupils, user’s
  • School Principal’s data: name, surname, professional email
  • Optional data voluntary shared by the eTwinner (e.g. image data, personal data eTwinner chooses to share on forums and other online communication tools through comments, photos and videos).

The transfers to these countries are necessary for reasons of public interest and are based on Article 50(1)(d) of Regulation (EU) 2018/1725 as recognised in the following Union law:

  • Article 14 of the Charter of Fundamental Rights of the European Union
  • Article 26 of the Universal Declaration of Human Rights
  • Article 11 of the Treaty of the European Union
  • Article 15 of the Treaty on the Functioning of the European Union

In addition, data may be disclosed to public authorities in accordance with Union and Member State law such as the European Court of Justice, the relevant national judge as well as the lawyers and the agents of the parties in case of legal proceedings, the Investigation and Disciplinary Office of the European Commission (IDOC), the competent Appointing Authority in case of a request or a complaint lodged under Articles 90 of the Staff Regulations, the European Anti-Fraud Office (OLAF), the Internal Audit Service of the Commission (IAS), the Court of Auditors, the European Ombudsman, the European Data Protection Supervisor (EDPS) and the European Public Prosecutor’s Office (EPPO).

EC, EACEA, EUN and NSOs personal data

Furthermore, EUN, EC, EACEA and NSOs communicate and share documents the Commission's dedicated MS Teams channel. In this respect, limited personal data (name, surname, email address, affiliation) of representatives of NSOs, EUN and the EC might be transferred to the United States (‘US’) through the MS 365 environment. Any such transfers are subject to appropriate safeguards, namely the adequacy decision with the US since its entry into force in 2023.

For online - onsite events: The international data transfer can occur with MS Teams and YouTube. Eventtia is used for online and onsite event registration. Some onsite events are organised in a non-EU location where NSOs are based.

For editorial activities: The international data transfer may occur because the articles, containing personal data of the authors, as well as the quotes collected from contributors, are made publicly available on the internet.

For surveys: The international data transfer may occur because MS Forms is used to conduct some of the surveys.

For certificates of completion of online courses: The international data transfer may occur because some NSOs evaluating the project may be based in a non-EU country.

For videos and podcasts: The international data transfer may occur because MS Teams and Restream are used to record videos/podcasts.

For coordination of NSOs: The international data transfer may occur because MS Teams on EC's account is used to coordinate the NSOs. Also, NSOs communicate with each other and run activities together and not all NSOs are located in EU.

For user support/ticketing system: The international data transfer may occur if the requestor is based in a non-EU country.

For newsletters (Platform and eTwinning): The international data transfer may occur because users who have subscribed for any of the newsletters, may be based outside the EU.

For social media management-analytics on communication activities: In principle there are no third-party platforms used. Exceptions are the servers of linked channels, such as Meta and X, via which the actual communication with the interested parties (social media users) takes place. These processing/potential data transfers are governed by the PP of the social media channel concerned (which acts as separate controller).

5. How long do we keep your personal data?

Anonymisation process

For all registered users, including eTwinners, personal data associated with their profile is kept for three years after the user’s last login. After this period, the users’ personal data is automatically anonymised as follows:

Two weeks before the three-year period expires, a notification is sent to the user informing her/him that her/his profile is about to be set as anonymous unless they log in within the following two weeks. If the user does not log in within this period, all personal data associated with the profile is automatically anonymised.

Users with an anonymised account who wish to continue using the Platform must register again. The anonymised data, in aggregate form, are stored solely for research and monitoring purposes at the disposal of EACEA, the European Commission, national or regional school authorities, authorities in charge of implementing the Platform and other third parties (see Point 6) under the authorisation of the data controller.

Personal data shared in EC corporate tools

Retention periods for personal data processed by the EC to manage EU Login accounts, conduct surveys and self-assessment tools via EU Survey and manage online courses via EU Academy, are subject to their respective privacy policies.

Personal data shared in third party tools

The retention period for personal data that the Platform user may have shared through third party tools (e.g. during an online course when using an external online tool, such as Facebook, Padlets, etc.) or through registration for online or onsite courses and events organised by third parties, is subject to the privacy policy of the third party concerned.

Newsletters

Personal data collected for newsletters’ subscription are kept until the user un-subscribes. Subscriptions linked with anonymised accounts are deleted automatically.

Online - onsite events: Personal data collected are kept for maximum 5 years after the end of the current service contract or when the data subject withdraws their consent, Dietary requirements are destroyed immediately after the event and in any case no longer than 1 month after the event. Image/sound data is retained for maximum 3 years following the event date.

Web analytics: Data retention for each type of cookie is specified here.

Editorial activities: Personal data collected are kept for maximum 5 years after the end of the current service contract or when the data subject withdraws their consent, whichever is earlier.

EU Academy courses: Details about participation in courses are retained until the user is registered in the Platform. Users are registered in the Platform until they are anonymised. Other data which may be shared by courses' participants is deleted immediately after the course is finished.

Surveys: Personal data collected are kept for maximum 5 years after the end of the contract or when the data subject withdraws their consent, whichever is earlier.

Certificates of completion of online courses: Data are kept until the end of activity, namely the creation of the certificates. Afterwards all data are permanently deleted from EUN servers.

Videos and podcasts: Personal data collected are kept for maximum 5 years after the end of the current service contract or when the data subject withdraws their consent, whichever is earlier. Image/sound data is retained for maximum 3 years following the date of production.

Coordination of NSOs: Personal data collected are kept until the data subject withdraws their consent.

User support/ticketing system: Personal data collected are kept until the ticket has been successfully addressed, after which the data is deleted from EUN servers.

Social media management-analytics on communication activities: Personal data collected are kept maximum 5 years after the end of the current service contract.

6. How do we protect and safeguard your personal data?

Relevant organisational and technical measures are taken by EACEA to ensure the security of your personal data.

A Corporate Local Informatics Security Officer (C-LISO) is in place. Its role includes supervising the Agency compliance with the relevant regulations, and the application of security measures recommended by DIGIT.

Technical measures include appropriate actions to address online security, risk of data loss, alteration of data or unauthorised access, taking into consideration the risk presented by the processing and the nature of the personal data being processed.

Organisational measures include restricting access to the personal data solely to authorised persons with a legitimate need to know for the purposes of this processing operation. Access to your data is done via authentication system on an individual basis through user-ID and password. Your data resides on the servers of the European Commission, which abide by strict security measures implemented by the European Commission (DG DIGIT) to protect the security and integrity of the relevant electronic assets. EACEA is also bound by Commission Decision 2017/46 of 10/1/17 on the security of communications & information systems in the EC.

EACEA’s contractors are bound by a specific contractual clause for any processing operations of your data on behalf of EACEA and by the confidentiality obligations deriving from the transposition of the General Data Protection Regulation in the EU Member States (‘GDPR’ Regulation (EU) 2016/679).

7. What are your rights concerning your personal data and how can you exercise them?

Under the provisions of the data protection regulation, you have the right to request to the controller to access the personal data that EACEA holds about you and to have your personal data rectified in case your personal data are inaccurate or incomplete.

Where applicable, you have the right to request the erasure of your personal data and to restrict the processing of your personal data.

You are also entitled to object to the processing of your personal data on grounds relating to your particular situation at any time unless EACEA demonstrates compelling and overriding legitimate grounds or in case of legal claims.

You have to right to data portability.

When processing is based on your consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of the processing before such a withdrawal.

However, the data controller may restrict the rights of the data subjects based on article 25 of the Data Protection Regulation (in exceptional circumstances and with the safeguards laid down in the Regulation. Such restrictions are provided for in the internal rules adopted by EACEA and published in the Official Journal of the European Union.2

Such a restriction will be proportionate, limited in time, and respect the essence of the above-mentioned rights. It will be lifted as soon as the circumstances justifying the restriction are no longer applicable. In principle, you will be informed on the principal reasons for a restriction unless this information may cancel the effect of the restriction. A more specific data protection notice may apply in such case.

8. Contact information

If you have questions or wish to exercise your rights under the Data Protection Regulation or if you want or to submit a complaint regarding the processing of your personal data, you are invited to contact the Data Controller (see contact details above).

You can also contact the Data Protection Officer of EACEA at the following email address: eacea-data-protection@ec.europa.eu.

You may lodge a complaint with the European Data Protection Supervisor: www.edps.europa.eu.
 

9. On which legal basis are we processing your personal data?

We process your personal data, because:

  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Union institution or body (as laid down in Union Law);
  • processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
  • the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

These are the Union laws that are the basis for such processing:

  • Council Regulation 58/2003 of 19 December 2002, laying down the Statute for executive agencies to be entrusted with certain tasks in the management of EU programmes;
  • Commission Implementing Decision (EU) 2021/173 of 12 February 2021 establishing the European Education and Culture Executive Agency;
  • Commission Decision C(2021)951 of 12 February 2021 delegating powers to the European Education and Culture Executive Agency with a view to the performance of tasks linked to the implementation of Union programmes in the field of education, audiovisual and culture, citizenship and solidarity;
  • Regulation (EU) 2021/817 establishing the Erasmus+ programme.

The following special category of personal data is being processed: health data/dietary requirement for catering during onsite events. We process special categories of personal data indicated above, because:

  • the data subject has given explicit consent to the processing for one or more specified purposes.

 

[1] Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC Text with EEA relevance, OJ L 295, 21.11.2018, p. 39.