1. Policy Statement
Brussels College is committed to protecting the privacy and personal data of all students, staff, applicants, and stakeholders in accordance with the General Data Protection Regulation (GDPR) and Belgian data protection laws. We recognize that personal data is entrusted to us and we have a legal and ethical responsibility to handle this information with the highest standards of security, transparency, and accountability.
✓ Our Commitment: Brussels College processes personal data lawfully, fairly, and transparently. We collect only the minimum data necessary, maintain accurate records, and implement robust security measures to protect your information from unauthorized access, loss, or misuse.
2. Scope and Application
This policy applies to all personal data processed by Brussels College, including:
- Student data (prospective, current, and alumni)
- Staff and faculty personal information
- Applicant and recruitment data
- Partner and supplier contact information
- Website visitor data and cookies
- Research participant information
- All data processed through digital systems, paper records, and third-party platforms
3. Data Protection Principles
3.1 Lawfulness, Fairness, and Transparency
All personal data is processed lawfully based on at least one legal basis under GDPR Article 6:
- Consent: Explicit consent obtained for specific processing activities
- Contract: Processing necessary for enrollment and educational services
- Legal Obligation: Compliance with educational regulations and legal requirements
- Legitimate Interests: Processing for institutional purposes that do not override individual rights
3.2 Purpose Limitation
Personal data is collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
3.3 Data Minimization
We collect only personal data that is adequate, relevant, and limited to what is necessary for the intended purpose.
3.4 Accuracy
Brussels College takes reasonable steps to ensure personal data is accurate and kept up to date. Individuals are encouraged to notify us of any changes to their information.
3.5 Storage Limitation
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, in accordance with our retention schedules and legal requirements.
3.6 Integrity and Confidentiality
Appropriate technical and organizational measures are implemented to ensure data security against unauthorized or unlawful processing, accidental loss, destruction, or damage.
4. Types of Personal Data Collected
| Data Category |
Information Collected |
Purpose |
| Identification Data |
Name, date of birth, nationality, passport/ID number, photograph |
Student enrollment, identity verification, immigration compliance |
| Contact Information |
Email address, phone number, postal address, emergency contacts |
Communication, emergency situations, service delivery |
| Academic Records |
Previous qualifications, transcripts, attendance, grades, assessments |
Admissions processing, academic progress tracking, certification |
| Financial Data |
Payment information, bank details, tuition fees, scholarships |
Payment processing, financial aid administration |
| Special Category Data |
Health information, disability status, religious requirements |
Support services, reasonable adjustments, welfare provision |
| Technical Data |
IP address, login credentials, system usage, cookies |
Platform access, security, system improvements |
🔒 Special Category Data: We process sensitive personal data (health, ethnicity, religious beliefs) only with explicit consent or where legally permitted, and with additional safeguards to protect this information.
5. Legal Basis for Processing
5.1 Student Data Processing
- Contract Performance: Processing necessary to provide educational services
- Legal Obligation: Compliance with education regulations, visa requirements, quality assurance
- Legitimate Interests: Academic administration, safety, and institutional development
- Consent: Marketing communications, alumni engagement, research participation
5.2 Staff Data Processing
- Contract Performance: Employment administration and payroll
- Legal Obligation: Tax, pension, employment law compliance
- Legitimate Interests: Staff development, performance management, internal communications
6. Individual Rights Under GDPR
Brussels College respects and facilitates the following rights for all data subjects:
6.1 Right of Access
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data. We will respond to access requests within one month.
6.2 Right to Rectification
You may request correction of inaccurate or incomplete personal data. We will update our records promptly upon verification.
6.3 Right to Erasure (Right to be Forgotten)
You may request deletion of your personal data in certain circumstances, such as when data is no longer necessary for its original purpose. This right is subject to legal and regulatory retention requirements.
6.4 Right to Restrict Processing
You may request that we limit how we use your data in specific situations, such as when you contest the accuracy of data or object to processing.
6.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another organization.
6.6 Right to Object
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds.
6.7 Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
⚠️ Exercising Your Rights: To exercise any of these rights, contact our Data Protection Officer at i.chiloglu@brucol.be. We will respond within one month and provide clear explanations if we cannot fulfill your request.
7. Data Security Measures
7.1 Technical Security
- Encryption of data in transit and at rest using industry-standard protocols
- Secure authentication and access controls (multi-factor authentication)
- Regular security updates and patch management
- Firewall protection and intrusion detection systems
- Secure backup procedures with encrypted storage
- Antivirus and anti-malware software on all systems
7.2 Organizational Security
- Role-based access controls limiting data access to authorized personnel only
- Staff training on data protection and information security
- Confidentiality agreements for all staff with access to personal data
- Clear desk and clear screen policies
- Secure disposal of paper records (shredding) and electronic media (wiping)
- Regular security audits and risk assessments
7.3 Third-Party Security
All third-party service providers that process personal data on our behalf are:
- Carefully selected based on their security capabilities
- Bound by data processing agreements meeting GDPR standards
- Regularly assessed for compliance with security requirements
- Prohibited from using data for any purpose other than providing services to Brussels College
8. Data Retention and Disposal
8.1 Retention Periods
| Data Type |
Retention Period |
Legal Basis |
| Student Academic Records |
Permanently (in secure archive) |
Educational regulations, certification requirements |
| Unsuccessful Applications |
2 years after application cycle |
Recruitment records, potential appeals |
| Financial Records |
7 years after completion |
Tax and accounting regulations |
| Staff Employment Records |
7 years after employment ends |
Employment law, pension requirements |
| Marketing Consent |
3 years (renewable with consent) |
Marketing preferences, engagement tracking |
| CCTV Footage |
30 days (unless incident reported) |
Security and safety purposes |
8.2 Secure Disposal
Upon expiry of retention periods, personal data is securely destroyed:
- Paper Records: Cross-cut shredding or secure incineration
- Electronic Records: Secure deletion using data-wiping software
- Storage Media: Physical destruction of hard drives, USB devices, and other media
9. Data Breach Procedures
9.1 Detection and Reporting
All staff are required to report suspected data breaches immediately to the Data Protection Officer. A data breach includes:
- Unauthorized access to personal data
- Accidental or unlawful destruction, loss, or alteration of data
- Unauthorized disclosure of personal data
- Loss or theft of devices containing personal data
9.2 Breach Response Process
- Containment (Within 1 hour): Immediate action to contain the breach and prevent further data loss
- Assessment (Within 24 hours): Evaluate the severity, scope, and potential impact of the breach
- Notification to Authority (Within 72 hours): Report to the Belgian Data Protection Authority if the breach poses a risk to individuals' rights and freedoms
- Notification to Individuals: Inform affected individuals without undue delay if the breach poses a high risk
- Documentation: Record all details of the breach, actions taken, and impacts
- Review and Prevention: Analyze root causes and implement measures to prevent recurrence
⚠️ Report Data Breaches: If you suspect a data breach, contact the Data Protection Officer immediately at i.chiloglu@brucol.be or call +32 471 09 6641.
10. International Data Transfers
Brussels College may transfer personal data outside the European Economic Area (EEA) in the following circumstances:
- Use of cloud-based services with servers located outside the EEA
- Partnerships with international institutions
- Student exchanges and study abroad programs
Safeguards for International Transfers:
- Transfers only to countries with adequate data protection as recognized by the European Commission
- Standard Contractual Clauses (SCCs) approved by the EU for transfers to countries without adequacy decisions
- Binding Corporate Rules for transfers within multinational organizations
- Explicit consent obtained where required for specific transfers
11. Data Protection Officer (DPO)
Data Protection Officer:
Dr. İbrahim Çıloğlu, Vice Rector
Email: i.chiloglu@brucol.be
Phone: +32 471 09 6641
DPO Responsibilities:
- Monitor compliance with GDPR and this Data Protection Policy
- Advise on data protection impact assessments (DPIAs)
- Serve as point of contact for data subjects and the supervisory authority
- Conduct staff training on data protection
- Maintain records of processing activities
- Investigate data breaches and coordinate response actions
12. Complaints and Supervisory Authority
If you have concerns about how we handle your personal data, please contact our Data Protection Officer first. We are committed to resolving issues promptly and fairly.
Belgian Data Protection Authority:
Address: Rue de la Presse 35, 1000 Brussels, Belgium
Phone: +32 2 274 48 00
Email: contact@apd-gba.be
Website: www.dataprotectionauthority.be
You have the right to lodge a complaint with the supervisory authority if you believe your data protection rights have been violated.
📋 Data Subject Requests: To exercise your rights or request information about how we process your data, contact i.chiloglu@brucol.be. We will respond within one month and provide all necessary information free of charge.
13. Policy Review and Updates
This Data Protection Policy is reviewed annually and updated as necessary to reflect:
- Changes in data protection legislation
- New processing activities or technologies
- Outcomes of data protection impact assessments
- Lessons learned from data breaches or complaints
- Best practices from the education sector
Next Scheduled Review: April 2027
14. Contact Information
Data Protection Officer:
Dr. İbrahim Çıloğlu, Vice Rector
Email: i.chiloglu@brucol.be
Phone: +32 471 09 6641
General Enquiries:
Email: office@brucol.be
Phone: +32 471 09 6641