List of active policies
| Name | Type | User consent |
|---|---|---|
| ΕΝΗΜΕΡΩΣΗ ΑΠΟΡΡΗΤΟΥ – PRIVACY NOTICE | Privacy policy | All users |
Summary
The University of Western Macedonia, as data controller, processes personal data on the Moodle platform and affiliated e-learning services to fulfil its educational mission (Article 6(1)(e) GDPR): identification and access, course participation, educational material, communication, assignment submission, assessment, technical support and security.
Using the platform or acknowledging this notice does not constitute consent. Joining a videoconference does not imply recording; recording is permitted only by exception, for a specific purpose and with a specific notice provided before it begins.
You have the right of access, rectification, erasure, restriction of processing and objection, subject to the conditions of the GDPR. Requests should be sent to the Data Protection Officer at dpo@uowm.gr. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).
Please read the full text of this notice.
Full policy
Moodle Platform Privacy Notice
University of Western Macedonia
1. Identity and Contact Details
The Data Controller is the University of Western Macedonia, based in ZEP, Kozani.
Contact: +30 24610 56200, rector@uowm.gr
Data Protection Officer (DPO): For data protection matters and the exercise of your rights, contact the DPO at dpo@uowm.gr.
2. Scope and Purposes
This notice applies to students, instructors, and other authorized users of the Moodle platform and affiliated e-learning services used for the educational activities of the University.
Data is processed for identification and access management, course enrollment and participation, distribution of educational material, communication, assignment submissions, grading/evaluation, technical support, and service security. Synchronous instruction is conducted via approved videoconferencing tools. Live broadcasting does not automatically imply recording.
3. Legal Bases
Processing necessary for the University’s educational mission—including the required administration and secure operation of e-learning services—is based on Article 6(1)(e) and 6(3) GDPR, in conjunction with the applicable institutional framework governing higher education.
Using the platform or acknowledging this notice does not constitute consent. Where distinct, genuinely optional processing is based on consent, such consent is requested separately for a specific purpose and may be withdrawn without affecting the lawfulness of processing carried out prior to withdrawal. Refusal does not affect access to educational services that do not require such optional processing.
Standard use of Moodle does not warrant the general collection of special categories of personal data. If such processing is required (e.g., for educational adjustments or accommodations), a specific notice will be provided citing the applicable basis under Article 6, the specific condition under Article 9(2) GDPR, and the corresponding safeguards. Do not upload health data or other non-essential personal information to shared/public fields.
4. Data Categories and Sources
Depending on the feature used, processing concerns:
Account and contact details: Full name, user ID or student registration number, institutional role/status, and email address. Telephone numbers are collected only when required for a specific function with a declared purpose.
Educational data: Course enrollments, assignments, submitted answers, grades, feedback, and logs of activity participation or completion where applicable. Participation metrics are not treated merely as simple identification data.
Communication content: Messages, forum discussions, notes, and calendar entries you submit. Visibility depends on the designated space and activity settings.
Technical data: IP address, login and request timestamps, access logs, device and browser information, requested URLs, responses, and errors, strictly to the extent necessary for system operation and security.
Videoconferencing media: Image, voice, display name, chat logs, and shared screen content during live sessions. Storing these as recordings is permitted only under the conditions set out in Section 5.
Data originates from you, your interactions within the service, and instructors during academic assessment. Mandatory fields must be flagged alongside their stated purpose. Failure to provide required information may prevent the use of specific features; leaving optional fields blank does not affect your enrollment or studies.
5. Videoconferences and Recordings
Activating a camera or microphone and recording a session are distinct actions. Joining or remaining in a session does not constitute consent to be recorded. Prior to any permitted recording, a specific notice will inform participants of the purpose, legal basis, recorded data categories, recipients, retention period, and instructions for exercising their rights.
Recording lectures or examinations is neither a default nor an unrestricted feature. It requires documented necessity, proportionality, and a decision by the competent institutional body where required. Unauthorized local recordings and redistributions are strictly prohibited.
6. Recipients and Service Providers
Access is granted to authorized instructors, administrative staff, and technical personnel solely to the extent required by their respective roles. Participants in a shared course activity can view content designated for group access in accordance with the activity’s settings. Grades, contact details, and individual submissions must not be made publicly or generally visible without a specific necessity and a valid legal basis.
External service providers acting on behalf of the University are bound by data processing agreements under Article 28 GDPR and documented instructions. The role of each provider is assessed per processing activity. Using Moodle open-source software does not in itself imply that the Moodle company receives personal data.
For synchronous educational sessions, Zoom is utilized. It is assessed separately from the core Moodle infrastructure regarding data recipients, support sub-processors, storage locations, and potential third-country access. Any specific pre-recording notice supplements this privacy policy.
7. Security and Use Restrictions
The University implements appropriate technical and organizational measures commensurate with risk, including access controls, permission management, secure transmission protocols, software updates, and incident response procedures. Specific encryption standards depend on the service and its configuration; an overarching guarantee of end-to-end encryption across all services is not provided. Users must rely only on approved channels for storing and sharing educational content.
Access to educational data is strictly limited to the stated purpose. Any new purpose - such as the public publication of a recorded session - requires prior verification of lawfulness and a corresponding updated notice. Generating fully anonymized aggregate statistics is distinguished from processing identifiable or pseudonymized usage logs.
8. Cookies
Strictly necessary cookies are used to provide the requested service, such as maintaining an active session. Other cookies or tracking technologies are deployed only upon prior consent, which can be withdrawn just as easily. Declining optional cookies must not obstruct essential educational functionality.
9. Retention Periods
A single uniform retention period does not apply to all data. Retention is determined by the specific processing purpose, statutory academic obligations, and established timeframes for grading appeals and disputes. Upon expiry of the applicable period, data is securely erased or genuinely anonymized. Any retention extended due to pending disputes is limited strictly to necessary records and for the duration of the proceedings.
10. Transfers Outside the EEA
The University’s use of Moodle software does not, on its own, entail cross-border transfers outside the European Economic Area (EEA), nor does it grant Moodle Pty Ltd access to data. For Moodle, data residency is evaluated based on actual hosting infrastructure, backup storage, third-party plugins, and technical support access.
For synchronous sessions conducted via Zoom, the contractual vendor, sub-processors, processing and storage locations, and remote administrative access from third countries are evaluated separately. Selecting an EU/EEA-based data center does not automatically exclude remote access.
Where personal data within any of these services is transferred to or accessed from a third country, transfers take place exclusively under a valid mechanism pursuant to Chapter V GDPR. Users will be informed in advance of the specific service, destination country/countries, recipient categories, the presence or absence of an adequacy decision, appropriate safeguards deployed, and means to obtain a copy of those safeguards.
11. Automated Decision-Making
No automated individual decision-making or profiling is carried out.
12. Data Subject Rights and Complaints
You have the right to request access to and rectification of your personal data, as well as erasure or restriction of processing subject to the conditions of the GDPR. Where processing is based on Article 6(1)(e), you have the right to object on grounds relating to your particular situation. Data portability applies when automated processing is based on consent or a contract, but does not apply across the board to tasks carried out in the public interest. Where processing relies on consent, you may withdraw it at any time.
Subject to the conditions of Article 22 GDPR, you also have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you, subject to the exceptions and safeguards provided by law.
To exercise your rights, email dpo@uowm.gr. The absence of a self-service export or delete button within the platform does not nullify your rights. In cases of reasonable doubt regarding identity, additional verification details may be requested. Requests are handled without undue delay and within one month of receipt; this period may be extended by up to two additional months where warranted by the complexity and volume of requests, with notification provided within the initial month.
The right to erasure is not absolute and is evaluated against statutory compliance obligations and the University's educational mandate. Any refusal to satisfy a request will be duly justified.
You have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) (www.dpa.gr), irrespective of whether you have previously contacted the University, as well as the right to seek a judicial remedy.
13. Updates and Modifications
This notice is made accessible prior to data collection. When data is obtained from third-party sources, Article 14 GDPR disclosures are provided within the statutory deadlines unless an exemption applies. Material revisions will be communicated through appropriate channels, and new processing purposes will be notified prior to implementation. Acknowledging this notice does not constitute a waiver of any statutory rights.
Version: September 2026