UNISTUNIST

ADMISSIONS

Giving
Open mobile menu
 

UNIST site map

Close All menus
STUDENT
 
ETC

ETC

We are growing into a world-leading science and technology university that contributes to the lives of humanity.

Privacy Policy

2021.07.28 ~ 2022.05.29.
All personal information handled by UNIST (hereinafter referred to as “UNIST”) is collected, retained, and processed in accordance with relevant laws and regulations or with the consent of the data subject.

This policy is effective from July 27, 2021.

Ulsan National Institute of Science and Technology(hereinafter referred to as "UNIST") processes personal information lawfully and manages it securely in compliance with the Personal Information Protection Act and related laws and regulations to protect the freedom and rights of data subjects. Accordingly, in accordance with Article 30 of the Personal Information Protection Act, UNIST establishes and discloses the following Personal Information Processing Policy to inform data subjects of the procedures and standards regarding the processing of personal information and to ensure the prompt and smooth handling of grievances related thereto.

In accordance with Article 30 of the Personal Information Protection Act , UNIST has established the following processing policy to protect the personal information of data subjects and to handle related grievances promptly and smoothly.

Purpose of processing personal information, period of processing and retention of personal information, items of personal information processed

  • (Purpose of Processing) Ulsan National Institute of Science and Technology collects personal information to the minimum extent for the purpose of performing its duties and handling civil complaints, and provides guidance so that data subjects can verify it by posting it on the relevant Website operated by each department.
    Table for Page/Service Name, Personal Information File Name, and Website
    Website/ Service Name Personal Information File Name Website
    Portal system Faculty & Staff, Students Information https://portal.unist.ac.kr
    Main Website(including Admissions and Graduate) Faculty & Staff, Students Information
    Research Support Headquarters Website Faculty & Staff and Researcher Information https://ucrf.unist.ac.kr
    Laboratory Safety Management Research personnel https://safety.unist.ac.kr
  • In addition, information on personal information files operated by each department is available on the 'Comprehensive Personal Information Support Portal'.
    Please use the following method: Personal Information Protection Comprehensive Support Portal (www.privacy.go.kr) → Personal Information Complaints → Request for Access to Personal Information, etc. → Search Personal Information File List → Enter ' Ulsan National Institute of Science and Technology' in the Institution Name field and search.

Provision of personal information to third parties

In principle, UNIST processes the personal information of data subjects within the scope specified for the purpose of collection and use, and, except in the following cases, does not process it beyond the original purpose or provide it to third parties without the prior consent of the data subject.

  1. In cases where separate consent has been obtained from the data subject
  2. Where there are special provisions in other laws
  3. Cases where prior consent cannot be obtained because the data subject or their legal representative is unable to express their intent or Address is unknown, and it is deemed clearly necessary for the urgent benefit of the life, body, or property interests of the data subject or a third party
  4. In cases where personal information is provided in a form that does not allow the identification of specific individuals, as necessary for purposes such as statistical compilation and academic Research.
  5. Cases where duties prescribed by other laws cannot be performed unless personal information is used for a purpose other than the original purpose or provided to a third party, and where the Protection Commission has deliberated and resolved.
  6. When necessary to provide to a foreign government or international organization for the implementation of a treaty or other international agreement
  7. When necessary for the investigation of a crime and the filing and maintenance of a prosecution
  8. When necessary for the performance of the court's judicial duties
  9. When necessary for the execution of punishment, custody, or protective measures

If UNIST provides personal information to a third party, we will obtain consent after informing the data subject of the following items.

  1. Name of the recipient (or name of a corporation or organization) and Contact
  2. Purpose of use of personal information by the recipient, items of personal information provided
  3. Retention and usage period of personal information by the recipient
  4. The fact that there is a right to refuse consent, and if there are disadvantages resulting from the refusal of consent, the Content of such disadvantages

Outsourcing of personal information processing

In principle, UNIST does not entrust the processing of personal information to third parties without the user's consent. However, in cases where personal information processing tasks are entrusted to a third party, the Content of the entrusted tasks and the trustee are posted on the relevant service's Website. Furthermore, when entrusting personal information processing tasks, the process is carried out in accordance with a standard entrustment contract (document) containing the following Content.

  1. Matters concerning the prohibition of processing personal information for purposes other than the performance of entrusted tasks
  2. Matters concerning technical and administrative protective measures for personal information
  3. Other matters prescribed by Presidential Decree for the safe management of personal information

Rights and Obligations of Data Subjects and Methods of Exercising Them

Data subjects may exercise the following rights, and the legal representative of a child under the age of 14 may request access to, correction of, deletion of, or suspension of processing of the child's personal information.

  1. Request for access to personal information
    You may request access to your personal information files held by UNIST in accordance with Article 35 (Access to Personal Information) of the Personal Information Protection Act. However, requests for access to personal information may be restricted as follows pursuant to Article 35, Paragraph 5 of the Act.
    1. 1) Cases where access is prohibited or restricted by law
    2. 2) Cases where there is a risk of harm to the life or physical integrity of another person, or a risk of unfairly infringing upon the property and other interests of another person
    3. 3) Cases where a public institution causes significant impediment when performing any of the duties falling under the following subparagraphs
      • Business related to the imposition, collection, or refund of taxes
      • Tasks concerning the evaluation of Grade or the selection of applicants at schools of all levels pursuant to the Elementary and Secondary Education Act and the Higher Education Act, lifelong Academics facilities pursuant to the Lifelong Education Act, and higher Academics institutions established under other laws.
      • Work related to Exam concerning education, skills, and recruitment, and qualification screening
      • Work related to ongoing evaluations or judgments regarding the calculation of compensation, benefits, etc.
      • Work concerning Standing Auditor and investigations in progress under other laws
  2. Request for correction or deletion of personal information
    You may request the correction or deletion of personal information files held by UNIST in accordance with Article 36 (Correction and Deletion of Personal Information) of the Personal Information Protection Act. However, you may not request deletion if the personal information is explicitly designated as a subject of collection under other laws.
  3. Request to suspend personal information processing
    You may request the suspension of processing of personal information files held by UNIST in accordance with Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act. However, a request for the suspension of processing of personal information may be refused pursuant to Article 37, Paragraph 2 of the Act.
    1. 1) Where there are special provisions in the law or it is unavoidable to comply with statutory obligations
    2. 2) Cases where there is a risk of harm to the life or physical integrity of another person, or a risk of unfairly infringing upon the property and other interests of another person
    3. 3) Cases where a public institution cannot perform its duties prescribed by other laws if it does not process personal information
    4. 4) Cases where the performance of a contract is difficult, such as being unable to provide the services agreed upon with the data subject if personal information is not processed, and the data subject has not clearly expressed an intention to terminate the contract
      You may exercise your rights pursuant to the above matters by completing Form No. 8 of the Enforcement Rules of the Personal Information Protection Act and submitting it in writing, via email, or by fax, and the Institution will take action without delay. If a data subject requests correction or deletion regarding errors in their personal information, the Institution will not use or provide the relevant personal information until the correction or deletion is completed. The rights of a data subject to request access to or suspension of processing of personal information may be restricted pursuant to Article 35, Paragraph 5 and Article 37, Paragraph 2 of the Personal Information Protection Act. A request for correction or deletion of personal information cannot be made if such personal information is explicitly designated as a subject of collection under other laws. Upon receiving a request for access, correction/deletion, or suspension of processing in accordance with the rights of a data subject, we will verify whether the person making the request is the principal or a legitimate representative. [Form No. 8 of the Enforcement Rules of the Personal Information Protection Act] “Request Form for Access, Correction, Deletion, etc. of Personal Information”
      You may exercise your rights pursuant to the above matters through a representative, such as a legal representative of the data subject or an authorized agent. In this case, you must submit a “Power of Attorney” in accordance with [Form No. 11 of the Enforcement Rules of the Personal Information Protection Act].

Destruction of personal information

In principle, UNIST destroys personal information without delay once the retention period has expired or the purpose of processing has been achieved. However, this does not apply if preservation is required under other laws. The procedures, deadlines, and methods for destruction are as follows.

  1. Destruction procedures and deadlines
    Information entered by users is destroyed in accordance with internal policies and relevant laws after the retention period has expired or the purpose of processing has been achieved.
  2. Method of destruction
    In the case of electronic files: Permanent deletion using an irreversible method
    For records, printed materials, written documents, or other recording media other than electronic files: shredding or incineration

Measures to ensure the security of personal information

In principle, UNIST destroys personal information without delay once the purpose of processing has been achieved. The procedures, timelines, and methods for destruction are as follows.

  1. Establishment and implementation of internal management plans
    We establish and implement an internal management plan in accordance with the 'Standards for Measures to Ensure the Safety of Personal Information'.
  2. Minimization of designation of personal information handlers and Academics
    We minimize the designation of personal information handlers and conduct regular Academics.
  3. Restriction on access to personal information
    We control access to personal information by granting, changing, or revoking access rights to database systems that process personal information, and we control unauthorized access from the outside by utilizing intrusion blocking systems and intrusion prevention systems.
  4. Storage of access records and prevention of tampering
    We store and manage records of access to the personal information processing system (web logs, summary information, etc.) for at least 6 months.
  5. Encryption of personal information
    Users' personal information is stored and managed in an encrypted manner. In addition, separate security features are used, such as encrypting important data during storage and transmission.
  6. Technical measures to prevent hacking, etc.
    To prevent the leakage and damage of personal information caused by hacking or computer viruses, we install security programs, perform periodic updates and checks, install systems in areas where external access is controlled, and monitor and block access technically and physically.
  7. Access control for unauthorized persons
    We maintain a separate physical storage location for personal information systems that store personal information and have established and operate access control procedures for it.

Administrative measures: Establishment of management plans, regular employee Academics , etc.

Technical measures: Security measures such as access control to personal information

Physical measures: Access control for computer rooms, data storage rooms, etc.

Methods for Remedying Infringement of Rights

Data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, etc., to seek relief for personal information infringement. For other reports or consultations regarding personal information infringement, please contact the organizations listed below.

  1. Personal Information Dispute Mediation Committee ( www.kopico.go.kr ) : 02-2100-2499
  2. Supreme Prosecutors' Office Cybercrime Investigation Division: 02-3480-3571 ( http://www.spo.go.kr/ )
  3. National Police Agency Cyber ​​Bureau: 182 (without area code) (http://cyberbureau.police.go.kr/ )

A person whose rights or interests have been infringed by a disposition or inaction by the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), and Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.

For more information on administrative appeals, please refer to the Ministry of Government Legislation Website(http://www.moleg.go.kr).

Personal Information Inquiries and Complaints: For inquiries regarding the protection and processing of personal information, you can receive consultation by using the 118 Customer Center operated by the Korea Internet & Security Agency.

☞ Personal Information Infringement Report Center: 118 (without area code) (Extension 2)

Reporting and Response to Leaks by Relevant Agencies

  • If personal information of 1,000 or more people is leaked, Ulsan National Institute of Science and Technology reports this directly to the Minister of the Interior and Safety within 5 days.
  • In the event that personal information regarding 1,000 or more data subjects is leaked, the leaked items are posted for at least 7 days at the same time as the data subjects are notified.

Chief Privacy Officer

  1. Chief Privacy Officer: Director of Administration Choi Young-do
  2. Privacy Officers: General Affairs Team , Shin Young-ho 052-217-1162 ( yhshin@unist.ac.kr ), IT Team Member, Kim In-ho 052-217-1543 ( ihkim@unist.ac.kr )

Installation and operation of image information processing devices

UNIST installs and operates image information processing devices as follows.

  1. Basis and Purpose of Installation of Video Information Processing Devices: Facility safety, fire prevention, crime prevention
  2. Number of units installed, installation Location , and shooting range
    916 units Building interior and exterior

    Posting notices regarding the installation of video information processing devices at each building entrance

  3. Manager and Operations Manager
    Manager and Operations Manager
    Category name spot Affiliation Contact
    Management Approver Kang Chang-sik Team Leader General Affairs Team 052-217-1161
    authorized users Shin Young-ho Team members General Affairs Team 052-217-1162
    entrusted operator Manager Kang Jong-man Center Director S&I Corp. 052-217-6973
    Operations Manager Gujapan responsibility S&I Corp. 052-217-6972
    Wi In-ho Department Head LG CNS Corp. 052-217-6990
    Kim Yong-kwang Chief of Security KT Telecop Co., Ltd. 052-217-0112

    Processing Method: We record and manage matters regarding requests for the use of personal video information for purposes other than its intended use, provision to third parties, destruction, and viewing, and upon the expiration of the retention period, permanently delete the data using a method that makes restoration impossible (shredding or incineration in the case of printed materials).

  4. Matters concerning the method and location for verifying personal video information
    1. 1) How to check: You can check by contacting the person in charge of video information management in advance and visiting.
    2. 2) Verification Location: Integrated Control Room, 1st Floor, University Headquarters
  5. Measures regarding requests by data subjects for access to video information, etc.
    You may request access to, confirmation of existence of, or deletion of your personal video information from the operator of the video information processing device at any time. However, this is limited to personal video information in which you are filmed and personal video information that is clearly necessary for the urgent benefit of the data subject's life, body, or property. Upon receiving a request for access to, confirmation of existence of, or deletion of personal video information, this institution will take the necessary measures without delay.
  6. Measures to ensure the safety of video information
    Video information processed by this institution is securely managed through measures such as encryption. Furthermore, as an administrative measure for the protection of personal video information, this institution grants differential access rights. To prevent falsification or alteration of personal video information, we record and manage the creation date and time of the information, as well as the purpose of viewing, the viewer, and the date and time of viewing upon access. In addition, we have installed locking devices for the safe physical storage of personal video information.

Status of Personal Information Outsourcing

In principle, UNIST does not entrust the processing of personal information to third parties without the user's consent. When UNIST entrusts the processing of personal information to a third party, the Content of the entrusted work and the trustee are posted on the relevant service's Website. Furthermore, regarding the entrustment of personal information, legal notification requirements are complied with by each processing department, and the status of institutional entrustment is recorded and maintained through the General Affairs Team based on the Ministry of the Interior and Safety's annual assessment of the level of personal information protection management in public institutions.

Changes to the Privacy Policy

  1. This Privacy Policy is effective as of July 27, 2021.
  2. You can check the previous date of the Privacy Policy change below.
    • 2020.08.31 ~ 2021.07.27. (Click)
    • June 10, 2020 ~ August 30, 2020 (Click)
    • 2020.03.24 ~ 2020.06.10. (Click)
    • 2019.12.06 ~ 2020.03.24. (Click)
    • 2019.03.04 ~ 2019.12.06. (Click)
    • 2018.09.07 ~ 2019.03.04.
    • 2018.08.03 ~ 2018.09.07.
    • 2018.07.07 ~ 2018.08.03.
    • 2018.07.06 ~ 2018.07.07.
    • 2018.07.06 ~ 2018.07.11.
    • 2018.06.21 ~ 2018.07.06.
    • 2017.01.19 ~ 2018.06.20.
    • 2016.03.08 ~ 2017.01.18.
    • 2015.09.31 ~ 2016.03.07.
    • 2015.04.01 ~ 2015.09.30.