Privacy policy

idem_home.pngUniversità degli Studi di Ferrara - Privacy policy for IDEM GARR AAI Identity Provider - This information is being provided to the interested parties (hereafter referred to as Users and User), in accordance with articles 13 and 14 of the EU General Data Protection Regulation (GDPR) 679/2016.

Latest version June 2020.


  • Data Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data;
  • Data Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
  • Identity Provider: IT system that provides the federated authentication service for Users of a specific Organization;
  • Resources: third-party services or of the Owner to which the User of the federated authentication service intends to access;
  • Federation of Identities: A group of entities providing federated authentication services and Entities providing access to resources who decide to interoperate according to a set of common rules;
  • User: natural person who uses the service;
  • Interested: natural person whose personal data are being processed by the Owner and any third parties (coincides with the User)
Service Name Identity Provider (IdP) for “Università degli Studi di Ferrara”
Service Description

The federated authentication service allows users of “Università degli Studi di Ferrara” to access federated resources using their institutional credentials.

The Resources can be provided through the Italian Federation of Identities of Universities and Research Bodies (IDEM), or directly.

The Federated Authentication Service is responsible for authenticating the user and issuing an authentication token and, if required, a minimum set of personal data to access the Resource.

Data Controller

Name: Università degli Studi di Ferrara


Certified email:

Address: Via Ariosto n. 35 - 44121 Ferrara (FE) - ITALY

“Università degli Studi di Ferrara” is the owner of the processing of personal data managed through the Service.

Data Processor (GDPR Section 4)

Lepida S.c.p.A.

Address: Via della Liberazione 15 – 40128 Bologna (BO) - ITALY

Phone.: +390516338844


Certified email:

Supervisory authority


Garante per la Protezione dei Dati Personali

Categories of personal data concerned
  1. one or more unique identifiers;
  2. recognition credential;
  3. name and surname;
  4. email address;
  5. role in the organization;
  6. belonging to working groups;
  7. specific rights over resources;
  8. name of the organization concerned;
  9. IdP service log record: user identification, date and time of use, resource requested, attributes transmitted;
  10. Log record of the services necessary for the operation of the IdP service

The personal data collected is stored in Italy in accordance with the GDPR. Their treatment is aimed at providing the authentication service. The legal bases for data processing are the provision of the authentication service (fulfillment of contractual obligations) and the legitimate interest of the owner.

Purpose of the processing of personal data

Provide the federated authentication service in order to access the resources requested by the interested party.

Check and monitor the proper functioning of the service and ensure its security (legitimate interest).

Fulfill any legal obligations or requests from the judicial authority.

Third parties to whom the data are disclosed

In order to correctly provide the service, the Data Controller communicates to the suppliers of the Resources to which the User intends to access proof of authentication and only the personal data (attributes) required, in full compliance with the principle of minimization.

Personal data are transmitted only when the interested party requests access to the third party's resource.

For purposes related to the legitimate interest of the Owner or the fulfillment of legal obligations, some log data may be processed by third parties (e.g. CERT, CSIRT, Judicial Authority).

Exercise of the rights of the interested parties Contact the data controller at the addresses indicated above to request access to personal data and the correction or cancellation of the same or the limitation of the processing concerning him or to oppose their treatment, or to exercise the right to portability of the data (articles from 15 to 22 of the GDPR).
Revocation of the consent of the interested party The only data that is collected with the consent of the interested party are the preferences regarding the transmission of the attributes to third parties. The preferences are collected at the time of the first access to the Resource and can be eliminated, with the result of withdrawing the consent to their transmission, starting the login procedure again.
Data portability The interested party can request the portability of their data relating to the federated authentication service, including preferences regarding the transmission of the attributes to third parties, which will be provided in an open format and pursuant to Art. 20 of the GDPR. The portability service is free of charge upon termination of the service.
Duration of Data Retention

All personal data collected in order to provide the federated authentication service are kept for as long as it is necessary to provide the service itself.

After 6 months from deactivation, all personal data collected or generated by the use of the service are deleted.