Transfer of personal data to Canvas when using federated login

Description of Canvas
Canvas is a service/Learning Management System (LMS) directed towards staff and students from Enskilda Högskolan Stockholm / University College Stockholm (EHS) and is primarily used for course homepages.

Processing of personal data

Transfer of personal data
Personal data are being transferred from the identity provider eduID to Canvas to ensure that you as a user have access to your information in Canvas and to provide you with a user-friendly interface.

When logging in to this service, the following personal data is requested from eduID:

PERSONAL DATA PURPOSE TECHNICAL REPRESENTATION
Personal identity number Unique identifier to give you access to your information. norEduPersonNIN

Lawful basis
EHS holds personal details only when there is a legal basis to do so. The law determines the following: what counts as information of public interest, legal obligation, agreement, consent, and balance of interests when processing your personal data.

Rights of access, right of rectification and right of erasure of personal data
For access, rectification and erasure of your personal data, contact eduID and/or the Personal data controller at EHS for Canvas.

Purging of personal data
Account information and personal data is stored until user requests otherwise.

eduID - After account removal, user information is immediately purged.
Canvas - After account removal, user information is stored for no longer than 90 days.

Personal data controller
eduID
Please visit https://eduid.se/en/faq.html for more information.

Canvas
EHS has appointed a data protection officer. You can contact the data protection officer by e-mail dataskyddsombud@ehs.se, call 08 – 564 357 00 or send a letter to:

Enskilda Högskolan Stockholm
Dataskyddsombud
Åkeshovsvägen 29
168 39 Bromma

GÉANT Data Protection Code of Conduct
This service complies with the international framework GÉANT Data Protection Code of Conduct (http://www.geant.net/uri/dataprotection-code-of-conduct/v1) for the transfer of personal data from identity providers to the service. This framework is intended for services in Sweden, the EU and the EEA that are used in research and higher education.