Grade A — Highly protective (score 92/100)
HSE University provides a detailed, purpose-driven privacy policy that outlines specific data categories and retention triggers, though it reserves the right to modify terms without notice.
Transparent data processing policy with clear purpose-based retention.
These Regulations may be amended without prior notification to personal data owners or subjects.
The University reserves the right to change its privacy policy at any time without notifying users.
The transfer of personal data to state agencies and institutions... are permitted without the consent of the relevant PD owner/subject.
The University shares personal data with government and municipal agencies without requiring user consent.
Personal data is destroyed... upon the withdrawal by the PD owner/subject of their consent to the processing of their personal data.
Users have the right to withdraw consent, which triggers the destruction of their personal data.
The 'biometric personal data' category includes: a colour, digital photographic image of the document owner's face.
The University collects facial images, which are classified as biometric data.
The timeframes for processing and storing personal data are established based on the specific terms of the legal grounds... processing and storage of personal data may not be carried out for a period longer than that required.
The University commits to not retaining data longer than necessary for the specific purpose for which it was collected.
Last reviewed 2026-08-06 under rubric v3.5.