Information on the processing and protection of personal data in the library system

In accordance with Art. 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter GDPR – Masaryk University hereby informs data subjects, i.e. persons registered in the MU library system, on the conditions under which their personal data are being processed within the MU library system services.

Data Controller and Data Processor

Personal Data Controller

The personal data controller of the data subjects, i.e., the entity that determines the purpose and means of personal data processing, carries out the processing, and is responsible for it, is

Masaryk University, Žerotínovo nám. 617/9, 601 77 Brno
ID No. (IČO): 00216224, VAT ID No. (DIČ): CZ00216224,
Data box ID: 9tmj9e4.

Information on personal data processing at MU is available on the official notice board on the page Personal Data Protection.

Data Protection Officer

The Data Protection Officer of MU is Iva Zlatušková,

  • e-mail: poverenec@muni.cz,
  • phone: +420 549 491 030 (office), +420 603 289 580 (mobile).

You may contact the Data Protection Officer should you have any questions or requests regarding personal data processing and protection or regarding the exercise of your rights.

Personal Data Processor

As part of the transition to the Alma cloud library system, the manner of processing readers' personal data has changed. The service partner for MU and at the same time the personal data processor under the Bilateral Agreement on Provision and Operational Support of the Next Generation Platform between the National Library of Technology (NTK) and MU, based on a data processing agreement, is

National Library of Technology, a state-funded organization established by the Ministry of Education, Youth and Sports (NTK)
registered office: 160 80 Prague 6, Dejvice, Technická 6/2710
ID No.: 61387142 VAT ID No.: CZ 61387142

Contact for the Data Protection Officer of NTK: gdpr@techlib.cz

Processing of Personal Data

Purpose of Personal Data Processing

MU libraries process personal data for the purpose of

  • providing library, information, and other services to users,
  • informing users about these services, and
  • protecting property and the library collection.

Categories of Persons Whose Personal Data Are Processed

Masaryk University processes personal data of MU employees and students, as well as other users who have registered for MU library and information services.

Categories of Processed Personal Data

MU processes users' personal data in the library system to the following extent:

  • contact details (postal addresses, e-mail addresses, or phone numbers, if applicable),
  • user identifiers (UČO / personal identification number, barcode number, and university smart card chip number),
  • user's relationship to MU (student, employee, external user, etc.),
  • history and current status of user obligations towards MU libraries (requests, loans, reservations, fees),
  • internal individual flags and notes affecting the scope of offered services (unpaid fees, unverified data, study status information, request for special treatment, etc.).

Legal Basis for Data Processing

MU libraries process personal data of users for the purpose of providing library, information, and other related services. The legal basis for this processing is the performance of a contract for the provision of library, information, and other related services to which the user is a party, or in order to take steps at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) of the General Data Protection Regulation. This legal basis applies to contact details, user identifiers, the user's relationship to MU, and the history and current status of user obligations towards MU libraries.

If necessary for the protection of the library collection, management of receivables, resolution of library rules violations, or protection of MU's rights and legal claims, MU libraries may also process personal data based on the legitimate interest of the controller pursuant to Article 6(1)(f) of the General Data Protection Regulation. This legal basis applies to internal individual flags and notes affecting the scope of offered services.

Transfer of Personal Data

The personal data controller does not transfer users' personal data, except in cases necessary to ensure the operation, support, and security of the MU cloud library system hosted within the European Union.

In connection with the operation of the library system, personal data are made accessible to NTK as a contractual processor of MU. In addition to this processor, companies from the Ex Libris / Clarivate group may also be involved in ensuring the operation, support, and security of the library system as sub-processors of the library system provider.

These processors are contractually bound to protect personal data and to comply with appropriate technical and organizational measures in accordance with the General Regulation. They may process personal data only to the extent necessary, for the purpose of ensuring the operation, support, and security of the library system, and in accordance with the instructions of MU or its contractual processor NTK.

Personal Data Retention Period

MU retains personal data for a maximum of 24 months from the termination of the contract and settlement of all obligations of the data subject towards MU. Thereafter, personal data are erased (name, user contact details, etc.) or anonymized (loan history of library units for statistical purposes, etc.).

Personal Data Security

Personal data are stored in a manner that prevents access by unauthorized persons. Access to personal data is restricted solely to employees of the controller and processor who handle them as part of their job duties.

Personal data are stored in electronic form in an automated library system. Access to these data is protected by a system of user accounts, passwords, and authorization levels established to the extent necessary for individual employees to perform their work duties.

Rights

Rights of the Data Subject

The user can access their personal data after logging into their personal account in the MU library system.

According to the General Regulation, the data subject has the right to:

  • request access to their personal data, provided that the conditions under Article 15 of the General Regulation are met;
  • request rectification or erasure of personal data, provided that the conditions under Articles 16 and 17 of the General Regulation are met;
  • request restriction of processing, provided that the conditions under Article 18 of the General Regulation are met;
  • object to the processing of personal data concerning them, provided that the conditions under Article 21 of the General Regulation are met.

Exercise of Data Subject Rights

The data subject is entitled to exercise their rights arising from the General Regulation against the controller,

either

  • by a written request with an officially certified signature or based on an officially certified power of attorney, sent to: Masaryk University, Data Protection Officer, Žerotínovo nám. 9, 601 77 Brno, or
  • by sending a request to Masaryk University's Data Box: 9tmj9e4, or
  • by sending a request via e-mail from an institutional MU e-mail address to: poverenec@muni.cz, or
  • by sending a request via e-mail equipped with at least a recognized electronic signature to: poverenec@muni.cz.

Information for data subjects on exercising their rights is available on the official notice board on the page Exercising Data Subject Rights.

Right to File a Complaint with a Supervisory Authority

The data subject has the right to submit a request, complaint, or initiative regarding personal data processing to the supervisory authority, which is

The Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7,
Data box ID: qkbaa2n,
telephone number: +420 234 665 111,
website: www.uoou.cz,
e-mail address: posta@uoou.cz.

Brno, 11 August 2026

You are running an old browser version. We recommend updating your browser to its latest version.

More info