Privacy Policy for the Teaching/Learning Platform “Moodle” at the FernUniversität in Hagen

As at 04.07.2024


1. Name and Address of the Controller

The controller within the meaning of the EU General Data Protection Regulation (GDPR) and the relevant national data protection laws of the member states as well as other data protection provisions (“body which decides on the purposes and means of the processing of personal data”) is the

FernUniversität in Hagen
Universitätsstraße 47
58097 Hagen,

a public-law corporation
represented by
the President, Prof. Dr. Stefan Stürmer.
Phone: 02331 987-2400
Email: rektor@fernuni-hagen.de

2. Contact Details of the Data Protection Commissioner

FernUniversität in Hagen
Data Protection Commissioner
Universitätsstraße 47
58097 Hagen
Phone: 02331 987-2511
Email: datenschutzbeauftragter@fernuni-hagen.de

3. General Information on Data Processing

Data processing operations include the collection, recording, organizing, arranging, storing, adapting, modifying, reading out, querying, transmitting and deletion of personal or person-related data.

Personal or person-related data (hereinafter referred to as personal data) is any information relating to an identified or identifiable natural person and is an expression of that person’s identity.

As a public corporation, the FernUniversität in Hagen processes personal data on the basis of the EU General Data Protection Regulation (GDPR) and the applicable national data protection laws and regulations of the Federal Republic of Germany and the State of North Rhine-Westphalia, which apply in addition to or subordinate to the regulations of the European Union. Following its entry into force, this applies in particular to the Data Protection Act of the State of North Rhine-Westphalia in its version adapted to the GDPR.

In most cases, the purpose, scope and duration of our data processing operations are based on the legal mandate of the university pursuant to Section 3 of the Higher Education Act of North Rhine-Westphalia (Hochschulgesetz NRW) and the related legal standards.
(Legal basis: Art. 6(1)(e) of the GDPR in conjunction with § 3 (Duties) and other provisions for universities in the Higher Education Act of North Rhine-Westphalia (HG NRW).)

This remit includes, in particular, the cultivation and development of the sciences through research, teaching, study, the promotion of young academics, and the transfer of knowledge, taking into account aspects of social and democratic responsibility. The FernUniversität in Hagen’s specialist field is the promotion and development of distance learning.

Furthermore, in the process of fulfilling its mission, the University is subject to various legal obligations (e.g., financial law) that require the processing of personal data.

In the performance of its duties, FernUniversität is also obliged to take all necessary technical and organizational measures to ensure the security of your personal data. These measures may also entail the processing of personal data.

For further information on data processing procedures, please refer to the university’s central rules and regulations (e.g., the admission and enrollment regulations) as well as the usage instructions for the individual applications.
In addition, data processing may take place in situations where you have given your explicit consent. This consent can be revoked at any time.

(Legal basis: Article 6(1)(a) of the GDPR)

If your personal data is processed, you are a data subject within the meaning of the GDPR. You will find your rights as a data subject vis-à-vis the FernUniversität in section 9, the final section of this statement.

In accordance with Art. 6 (1) (e) GDPR, as well as Art. 89 GDPR in conjunction with Section 17 DSG NRW, the data may also be processed for scientific or historical research purposes and for statistical purposes without consent, to the extent that the processing is necessary for these purposes and the interests of the data subject that are worthy of protection are not overridden. The FernUniversität in Hagen ensures appropriate and specific measures to protect the interests of the data subject in accordance with Section 17 (2) DSG NRW. The data will be anonymized in accordance with Section 17, para. 3 DSG NRW as soon as this is possible depending on the research or statistical purpose. The data will be deleted as soon as the research or statistical purpose permits. Any use or knowledge of the data contained in the teaching/learning environment by third parties is only possible in pseudonymized form in the context of collaborative projects being conducted together with the FernUniversität. In all other respects, the requirements of Section 17 DSG NRW apply.

Note:

As a university, the organization of the FernUniversität is decentralized into departments and faculties. In addition to the university administration, it has academic facilities and operating units. This decentralized organization is also reflected in the structure of the IT system landscape and the websites. Nevertheless, to provide you with the most uniform overview possible of the data processing procedures, this data protection declaration forms an overriding, binding framework. In situations in which websites or IT applications need legitimate development or supplementary data processing, you will be informed on the page itself.

4. Data Processing Operations in Moodle

Moodle (Modular Object-Oriented Dynamic Learning Environment) is an open-source software package used to support teaching. It enables web-based access to module- or course-specific learning environments. An installation/deployment of a version of Moodle on a server is hereafter called a Moodle instance.
This privacy notice applies to the Moodle instance which can be accessed at https://moodle.fernuni-hagen.de/.
The system environment contains databases containing the course and user data that are set up specifically for the Moodle instance and also specially programmed web servers on which the files uploaded by users are stored in addition to the Moodle program code. Only the system administrators at the Center for Digitalization and IT (ZDI) have access to this IT base. Users of Moodle instances who do not have administration rights only have access to web-based data via the functions in Moodle.

Every time you access the Moodle learning platform, the following data and information are automatically collected from the access device you use:

  • Information about the browser type and version
  • Operating system of the device being used
  • The user’s Internet service provider
  • IP address of the device being used
  • The name, URL, and amount of data transferred for the file being accessed
  • HTTP status code (requested file transferred, not found, etc.)
  • Date and time of access
  • Websites from which the system you are using accesses the website
  • Websites accessed via the website from your system
4.1 User Profiles in Moodle

Access to the Moodle instance https://moodle.fernuni-hagen.de/ and the archives (moodle-ksw.fernuni-hagen.de, moodle-psy.fernuni-hagen.de, and moodle-wrm.fernuni-hagen.de) is restricted exclusively to members and affiliates of the FernUniversität who are validly registered in the central user directory (LDAP).
Invalid user profiles are automatically deleted at regular intervals (at least once per semester). You can also request to have your profile immediately deleted.

4.2 Personal Data in Moodle User Profiles

Every time a user logs in with their FernUni account, the following information is automatically transferred or updated from the LDAP account to the corresponding Moodle user profile: last name, first name and email address. It is not possible to change this data in Moodle. All other information provided for the user profile, such as contact information, is voluntary and will also be stored if provided.
The collection of this data is required for the operation of Moodle. Consequently, it is not possible for users to refuse this.
No passwords are stored in Moodle user profiles. For FernUni accounts, this information is stored in the connected LDAP authentication system.

5. Teaching/Learning in Moodle

Running a course in Moodle involves a variety of actions and activities on the part of users with authorized access. The following section describes the data that is collected and stored in the database.
The collection of this data is required for the operation of Moodle. Consequently, it is not possible for users to refuse this.

5.1 Personal Data Use During Teaching/Learning with Moodle

All posts, task solutions, or actions made or performed while using the platform in forums or during other activities are stored in the Moodle database in such a way that it is possible to trace who made these posts, entered these task solutions or performed these actions. The term ‘actions’ refers to all activities that lead to a result, such as writing a forum post, casting a vote in a poll or answering questions in an online test. In addition, Moodle defines certain events to make user behavior traceable. These events map both reading behavior and the above-named actions by users. Event logs from the previous 180 days are stored in the database and can be viewed by administrators via the Moodle interface. These are stored together with the following user data:

  • The IP address of the computer from which the users triggered the events
  • The name of the user
  • The time when the action was performed

Purpose of data recording:

  • To support communication and cooperation between Moodle users
  • To review the learning progress
  • Feedback
  • Error analysis

A thorough explanation of the visible data, broken down according to its role in Moodle, can be found in the user guide.

5.2 Web Server Log Files

Each Moodle instance is deployed via a web server. In addition to the event logs mentioned above, which Moodle stores in its database, the Moodle web servers each maintain their own log files recording web-based access to the Moodle instance and any application errors reported during this access.
The access log file records every HTTP access (specifically, every connection your web browser makes to Moodle). The following personal data is stored for each access:

  • The IP address from where the access was made
  • The time of access
  • The type of access (e.g., GET or POST)
  • The URL of the access
  • The HTTP response code that was sent back
  • The referrer link from which the Moodle instance was linked to, if applicable
  • The user agent that was used for the access
  • The size of the returned response

The error log file records the following personal data in addition to error-related information:

  • The time of access
  • The associated IP address

This information is used primarily for the following purposes:

  • Error analysis and problem solving,
  • Ensuring the security of our information technology systems,
  • User support (second-level support via Moodle administration),
  • Clarification of various issues (e.g., confirmation of a missed deadline caused by technical problems on the system side),
  • Supporting development in the planning of the technical system,
  • As a source of statistics.

The log file is recorded over the course of one semester and deleted during the following semester. It can only be accessed by system administrators.

The legal basis for the temporary storage of data and log files is Article 6(1)(e) of the GDPR in conjunction with IT security requirements under Article 32 of the GDPR.

The collection and storage of data in log files is necessary for the operation of Moodle. Consequently, it is not possible for users to refuse this.

5.3 Use of Cookies

Cookies are small text files that are stored on the user’s computer system by their web browser whenever they visit a website. Cookies allow the browser to temporarily “remember” data while users move between pages in the Moodle instance (e.g., by following a link). This data is available to both JavaScript in the browser and the server-side system (Moodle instance).
The cookies used in the FernUni Moodle instances are session cookies. Session cookies are automatically deleted when the web browser is closed (at the latest), inasmuch as this has been set in the web browser.
The following cookies are used:

  • “MoodleSession”: This cookie ensures that users remain logged in when accessing other Moodle pages. It contains an encrypted session ID that references a session temporarily stored on the server. A session cookie stores temporary information about a user’s browser session on the server, such as whether the user is logged into the system and, if so, under which username. Sessions end automatically after 180 minutes, as long as no further URLs in this Moodle instance have been called up during this time. Each call-up resets the expiration time.
  •  “MDL_SSP_SessID” and “MDL_SSP_AuthToken”: These cookies are set when users log in to Moodle via SSO. The “MDL_SSP_SessID” cookie stores a session ID for the Moodle SSO session and “MDL_SSP_AuthToken” stores a string generated for that session that is used to maintain authentication by the SSO provider.

Users have full control over the use of cookies. By making adjustments to the browser settings, users can allow the transmission of cookies to be restricted or disabled.
Cookies that have already been saved can be deleted at any time. This action can also be automated. If technically required cookies are disabled for Moodle, it may adversely affect certain functions of the website. The legal basis for technically required cookies is Section 25 (2) TTDSG (Telecommunications Telemedia Data Protection Act).

6. Web Analytics, Social Media, and Moodle Plugins

6.1 Matomo

Moodle does not use external analytics services to track your browsing behavior, nor does it embed external advertising. We use Matomo, a locally installed open-source software tool to improve our Moodle website and provide our users with the best possible Moodle experience. The software uses digital fingerprints to associate online activities with individual browser sessions and deletes this data after 24 hours. Matomo does not use cookies. When individual pages of our website are accessed, the following data is stored:

  • Two bytes of the IP address of the user’s system
  • The web page that was accessed
  • The website from which the user accessed the current web page (referrer)
  • The sub-pages that are accessed from the current web page
  • Time spent on the website
  • Which browser is being used, with which plugins, on which operating system, and at which screen resolution

The software runs exclusively on the servers at the FernUniversität in Hagen. Users’ personal data is only stored there. This data is not disclosed to third parties.
Visitors to our website have the option to opt out of the analytics process. To unsubscribe, please uncheck the corresponding option in the blue box below. This will place an opt-out cookie on your device: this signals our system not to store your data. Please note: if you delete the opt-out cookie from your system, you will need to reactivate the opt-out to remain excluded from tracking.

You have the option of preventing the actions you take here from being analyzed and linked. This will protect your privacy, but will also prevent the owner from learning from your actions and improving usability for you and other users.

(Note: The Matomo checkbox notice is currently only in german. Deselect the following checkbox to opt out.)

Matomo Opt-Out Checkbox-Platzhalter


Social media plugins are not centrally integrated for all Moodle users.

6.2 YouTube

When you use embedded YouTube videos in the course materials on the FernUniversität’s Moodle platform, you should be aware that this may result in the transfer of personal data (IP addresses or browsing behavior) to YouTube, a Google company headquartered at 901 Cherry Ave., San Bruno, CA 94066, USA. This transfer takes place especially for users who are logged into their personal YouTube account whilst using the service. This enables YouTube to link users’ browsing behavior to their personal profile. To prevent this from happening, users should log out of their YouTube accounts. We recommend that you read and understand YouTube’s privacy policy before using embedded content, as its data processing practices may differ from those of the FernUniversität.

6.3 Zoom (X)

The Zoom video conferencing system is used at the FernUniversität in Hagen to deliver synchronous courses. Course administrators can create Zoom-based activities when managing courses. From the instructor’s perspective, this allows relevant settings for the respective Zoom meeting to be configured directly in Moodle. The user link will then be automatically provided to course participants in Moodle and added to the course calendar. To assign the Zoom meeting to the corresponding Zoom account (as the host), Moodle sends the email address stored in Moodle to the FernUniversität’s Zoom server when creating or editing Zoom activities.
For participants in Zoom meetings who use the “Join Meeting” button automatically provided in Moodle, the name stored in Moodle is sent to the FernUniversität’s Zoom server.

6.4 Medial

The Medial video management system is used at the FernUniversität in Hagen to manage and distribute videos. When editing courses, course coordinators can make videos available in such a way that they are managed by the distance-learning university’s locally hosted Medial instance. To this end, employees can link their Moodle account to their Medial account: this gives them permanent access to their Medial resources within Moodle.
Participants in Moodle courses gain access to the corresponding videos by enrolling in the course. The first time the system is accessed, Moodle sends the stored name and the associated email address to the FernUniversität’s media server and creates a local LTI account on that server. After this, whenever Medial is used in Moodle, the system automatically associates the user with this account based on the Moodle user ID.

6.5 LTI Interface to evasys

The evaluation software evasys is used at the distance learning university to evaluate the quality of teaching. Students are invited via email to participate in the evaluation of modules and courses and are given the opportunity to rate them anonymously. When you log in to Moodle, the system checks to see if there are any pending invitations to take part in evaluations.

To do this, the email address stored in the Moodle profile is sent to the FernUniversität’s evasys server via an LTI interface. The evasys server indicates whether there are any evaluations currently running for the associated email address. If there is at least one pending invitation to an evaluation, the number of pending evaluations and the personalized invitation link will also be displayed in Moodle. 

Participation in this evaluation is voluntary.

7. Redirection to the KI-Campus Moodle

If needed, instructors can set up a connection to the KI-Campus system. KI-Campus offers courses on artificial intelligence (AI), which are available on the FeU’s KI-Campus Moodle platform as part of the “KI Campus 2.0” project. Students at the FernUniversität can access the courses offered on the FeU KI-Campus Moodle via a standardized LTI (learning tools interoperability) interface from their respective Moodle learning environment within the FeU Moodle production system. When you access the KI-Campus course offering, you will be redirected from the FeU Moodle production system to the FeU’s KI-Campus Moodle instance via this standardized interface.

Information on the Use of Personal Data:

  • Anonymization during forwarding: No personal data (such as first and last names) is transferred from the FeU Moodle production system to the KI-Campus Moodle. A new user ID and a dummy email address are generated for use.
  • Data security: The FeU’s KI-Campus Moodle is hosted in a secure environment and managed exclusively by the system administrators at the FernUniversität in Hagen.
  • No transfer of personal profile data: None of your personal profile data will be transferred from the FeU Moodle production system to the KI-Campus Moodle. Your use of the service is anonymous.
  • Visibility of personal data: Project staff and other authorized individuals can access the courses. However, students who access the courses via the LTI interface remain anonymous and cannot be identified.
  • LTI interface settings: The LTI settings prevent students’ full names and email addresses from being shared with KI-Campus Moodle. No grades are sent back to the FeU Moodle.
  • Responsibility for content: KI-Campus is responsible for the learning content provided. Content is provided by both internal and external sources and is available free of charge.

For more information about KI-Campus, visit https://ki-campus.org/. The Stifterverband für die Deutsche Wissenschaft e.V. is responsible for this project.

8. Areas of responsibility of the content providers

Moodle is a publication platform for course content prepared and offered by the responsible content providers (e.g., faculty departments and institutes) or assigned task groups. The design of the course content is quite flexible and may include content that extends beyond the privacy framework of the Moodle instance described here. Moodle learning environments may contain content that can be installed or run on the user’s browser or as standalone programs on the user’s computer.
Users have various options for creating content: for example, in polls, feedback surveys, hyperlinks, calendars, group management, assignments, quizzes, interactive content, forums, glossaries, or wikis, as well as across learning spaces in the messaging feature. Uploaded files are also considered content data.
This data category also includes grades assigned to rated learning activities. Assessments/evaluations can be performed either automatically by the system, as with electronic self-tests, or manually by users in the Manager and Advisor roles, as with assignments. If grades are assigned automatically, managers set the underlying default settings and have the option to review and correct them manually.

In this case, the providers of the content are responsible for data protection.

9. Rights of the Data Subject

When exercising your rights as an affected person, your request should first be addressed to the providers of the respective content, e.g., a teaching department or another organizational unit, since the relevant knowledge about data processing is available there. However, general inquiries about data protection and the protection of data subjects’ rights can also be addressed directly to the data protection officer.

9.1 Right of access – Article 15 GDPR

Users may request confirmation from the FernUniversität as to whether their personal data is being processed.
If this is the case, information regarding the following may be requested:

  1. The purposes for which the personal data are being processed;
  2. The categories of personal data which are being processed;
  3. The recipients or categories of recipients to whom the relevant personal data have been or will be disclosed;
  4. Where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  5. The existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
  6. The right to lodge a complaint with a supervisory authority;
  7. Where the personal data are not collected from the data subject, any available information as to their source;
  8. The existence of automated decision-making, including profiling, referred to in Article 22 (1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

Users have the right to request information about whether personal data concerning them is transferred to a third country or to an international organization. In this context, you may request information about the appropriate safeguards pursuant to Article 46 GDPR in connection with the transfer of such data.

9.2 Right to Rectification – Article 16 GDPR

Users have a right to rectification and/or completion vis-à-vis the FernUniversität if the personal data processed concerning them is inaccurate or incomplete. The FernUniversität will make the correction immediately as soon as the appropriate verification has been made.

9.3 Right to Erasure – Article 17 GDPR

Under the following conditions, users may request the deletion of their personal data:

  1. The personal data are no longer necessary for the purposes for which they were collected or otherwise processed.
  2. The data subject withdraws consent on which the processing is based pursuant to Article 6 (1) (a) or Article 9 (2) (a) GDPR and there is no other legal basis for the processing.
  3. The data subject objects to the processing pursuant to Article 21 (1) of the GDPR and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21 (2) of the GDPR.
  4. The personal data have been unlawfully processed.
  5. The deletion of the personal data is necessary for compliance with a legal obligation under Union or Member State law to which the controller is subject.
  6. The personal data was collected in relation to information society services offered pursuant to Article 8 (1) GDPR.

Exceptions:
The right to erasure does not exist if the processing is necessary

  1. For exercising the right of freedom of expression and information;
  2. For compliance with a legal obligation which requires processing under Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Article 17(3)(b) and (e) of the GDPR);
  3. For reasons of public interest in the area of public health pursuant to Article 9 (2) (h ) and (i) or Article 9 (3) GDPR;
  4. For archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes pursuant to Article 89 (1) of the GDPR, inasmuch as the right referred to in section 1) is likely to render impossible or seriously prejudice the achievement of the purposes of such processing; or
  5. For asserting, exercising, or defending legal claims (exception under Article 17(3)).
9.4 Right to Restriction of Processing – Article 18 GDPR

Under the following conditions, a user may request the restriction of the processing of their personal data:

  1. If the accuracy of the personal data is contested by the user, for a period enabling the controller to verify the accuracy of the personal data;
  2. If the processing is unlawful and the user opposes the erasure of the personal data and requests the restriction of their use instead;
  3. If the controller no longer needs the personal data for the purposes of the processing, but they are required by the user for the establishment, exercise or defense of legal claims; or
  4. If the user has objected to processing pursuant to Article 21 (1) GDPR pending the verification of whether the legitimate grounds of the controller override those of the data subject.

Where the processing of personal data concerning them has been restricted, such data shall, with the exception of storage, only be processed with the data subject’s consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or a Member State.
If processing has been restricted in accordance with the above conditions, the user will be informed by the controller before the restriction of processing is lifted.
Limitation of the right in the case of data processing for scientific, historical or statistical research purposes – Article 89 GDPR:

The above right may be limited if it is likely to make impossible or seriously impair the achievement of the research or statistical purposes and the limitation is necessary for the fulfillment of the research or statistical purposes.

9.5 Right of Notification – Article 19 GDPR

If users have asserted the right to rectification, erasure or restriction of processing against the controller, the controller is obliged to notify all recipients to whom the personal data have been disclosed of this rectification or erasure of the data or restriction of processing, unless this proves impossible or involves a disproportionate effort.

Users have the right to be informed about these recipients by the controller.

9.6 Right to Revoke the Declaration of Consent under Data Protection Law – Article 7 (3) GDPR

Users have the right to revoke their declaration of consent at any time. The withdrawal of consent shall not affect the lawfulness of the processing carried out on the basis of the consent up until the revocation. Revocation should be informally addressed to the data controller to whom you have consented to the data processing.

For content providers, Moodle Administration acts as a contact point by default and can be reached via the help desk. For further data protection consents or other consents for the use of certain protected areas or courses, please contact the respective content providers, e.g., the relevant teaching department.

9.7 Right to Object – Article 21 GDPR

Users have the right to object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them which is carried out on the basis of Article 6 (1) (e) GDPR; this also applies to profiling based on these provisions.
Note: the FernUniversität carries out no profiling, marketing or direct advertising on the Moodle Platform.
The controller shall no longer process the user’s personal data unless they can demonstrate compelling legitimate grounds for the processing which override the user’s interests, rights and freedoms, or for the establishment, exercise, or defense of legal claims.
If the personal data is processed for the purposes of direct marketing, users have the right to object at any time to the processing of their personal data for the purposes of such marketing; this also applies to profiling, to the extent that it is related to such direct marketing.
If users object to processing for direct marketing purposes, their personal data will no longer be processed for these purposes.
Users may exercise their right to object in connection with the use of information society services – notwithstanding Directive 2002/58/EC, the Privacy and Electronic Communications Directive (also known as the ePrivacy Directive or, colloquially, the Cookies Directive) – by means of automated procedures using technical specifications.
Limitation of the right in the case of data processing for scientific, historical or statistical research purposes:
Users also have the right to object, on grounds relating to their particular situation, to the processing of their personal data which is carried out for scientific or historical research purposes or for statistical purposes pursuant to Article 89 (1) GDPR.

This right to object may be limited if it is likely to make impossible or seriously impair the achievement of the research or statistical purposes and the limitation is necessary for the fulfillment of the research or statistical purposes.

9.8 Data Disclosure

Subject to statutory provisions, personal data will not be disclosed to third parties or used for purposes other than those specified here.

Courses at the FernUniversität in Hagen are evaluated as part of the student course evaluation procedure using the evasys system. To simplify data access, every user can call up the published surveys and survey results on the “Surveys” block on the dashboard. To ensure that individual data is displayed, users’ email addresses are transmitted to the evasys system.

9.9 Data Transfers to Third Countries

None of the personal data specified above will be transferred from the FernUniversität’s Moodle platform to third countries.

9.10 Technical and Organizational Measures to Safeguard Integrity and Confidentiality

In accordance with Article 32 of the GDPR, various technical and organizational measures have been implemented to ensure the integrity and confidentiality of personal data. Access to personal data within the application is controlled through user authentication (user name and password). Access to the server is restricted to specific workstations by means of both user authentication and firewall rules. Communication between the application and the servers is encrypted via a secure connection (HTTPS) that prevents unauthorized data processing.

9.11 Right to Lodge a Complaint with a Supervisory Authority – Article 77 GDPR

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, workplace or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78 GDPR.

The supervisory authority of the FernUniversität in Hagen is the Data Protection Officer of the State of North Rhine-Westphalia.

Contact:
State Commissioner for Data Protection and Freedom of Information, North Rhine-Westphalia
P.O. Box 20 04 44
40102 Düsseldorf
Phone: +49 (0)211 / 38424 – 0
https://www.ldi.nrw.de/
poststelle@ldi.nrw.de