INSTITUTIONAL POLICIES ON ETHICS, DATA PROTECTION AND RESPONSIBLE RESEARCH:

  1. Ethics, Integrity and Responsible Research Policy of the Community Organization “Ukrainian Modern Digital Science”
  2. Data Protection and Privacy Policy of the Community Organization “Ukrainian Modern Digital Science”
  3. Policy on Research Involving Vulnerable Participants of the Community Organization “Ukrainian Modern Digital Science”

DATA PROTECTION AND PRIVACY POLICY

COMMUNITY ORGANIZATION “UKRAINIAN MODERN DIGITAL SCIENCE”

Version: 1.0
Effective date: 25 August 2026
Data Protection & Privacy contact: privacy@umdigital.science

1. General Provisions

This Policy establishes the principles and rules governing the processing of personal data by the Community Organization “Ukrainian Modern Digital Science” (hereinafter referred to as UMDS or the Organization).

The Policy applies to personal data processing in connection with:

  • operation of the official UMDS website;
  • scientific, research, analytical, educational and awareness-raising activities;
  • international and national projects and grant programmes;
  • conferences, training sessions, seminars, round tables and other events;
  • surveys, questionnaires, interviews and focus groups;
  • interaction with members of the Organization, experts, researchers, partners, authors and other stakeholders;
  • information and communication activities of UMDS.

The Policy applies taking into account UMDS activities in Ukraine, interaction with individuals and organizations in the EU/EEA, and participation in international projects.

2. Information about the Organization

COMMUNITY ORGANIZATION “UKRAINIAN MODERN DIGITAL SCIENCE”

Legal entity identification code: 44851106
Location: Kyiv, Ukraine
Website: umdigital.science
General enquiries: hello@umdigital.science
Data Protection & Privacy: privacy@umdigital.science

Where UMDS independently determines the purposes and means of personal data processing, the Organization acts as a data controller.

Within individual international or research projects, UMDS may act as a controller, joint controller or processor depending on the actual allocation of roles among project partners.

3. Legal Framework

UMDS processes personal data in accordance with:

  • Ukrainian legislation on personal data protection;
  • Regulation (EU) 2016/679 — the General Data Protection Regulation (GDPR) where applicable;
  • the terms of international, grant-funded and research projects;
  • other applicable legal requirements.

The Organization also takes into account current guidance issued by the European Data Protection Board and other competent authorities.

4. Personal Data Protection Principles

UMDS follows the principles of:

  • lawfulness, fairness and transparency;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • storage limitation;
  • integrity and confidentiality;
  • accountability for compliance with personal data protection requirements.

UMDS seeks to apply the principles of data protection by design and data protection by default.

5. Whose Personal Data We May Process

UMDS may process personal data relating to:

  • members of the Organization and its governing bodies;
  • administrative staff;
  • experts, researchers and project team members;
  • participants in research, surveys, interviews and focus groups;
  • participants in events;
  • authors of publications;
  • representatives of partner organizations, universities, public authorities and international institutions;
  • persons contacting UMDS through the website or by email;
  • other individuals interacting with the Organization.

UMDS does not conduct research involving children.

6. Personal Data We May Process

Depending on the purpose of the relevant activity, UMDS may process:

  • first and last name;
  • email address and telephone number;
  • organization name, position and professional or academic affiliation;
  • professional and biographical information;
  • materials from questionnaires, surveys, interviews and focus groups;
  • responses to research questions;
  • information concerning financial behaviour;
  • information used in research into fraud, financial crime, cybercrime, AML/CFT, digital assets and related areas;
  • photographs and audio or video recordings.

In certain research projects, special categories of personal data within the meaning of Article 9 GDPR may be processed. Such processing takes place only where it is necessary, has an appropriate legal basis and is subject to suitable safeguards.

7. Purposes and Legal Bases for Processing

UMDS may process personal data for:

  • carrying out its statutory activities;
  • implementing scientific, research and analytical projects;
  • organizing events;
  • communicating with participants, experts and partners;
  • responding to enquiries;
  • preparing and disseminating scientific, analytical and informational materials;
  • complying with contractual, grant and legal requirements;
  • ensuring security and protecting the legitimate interests of the Organization.

Depending on the particular purpose, the legal basis may include:

  • consent;
  • performance of a contract or steps taken before entering into a contract;
  • compliance with a legal obligation;
  • the legitimate interests of UMDS or a third party;
  • another legal basis provided by applicable law.

UMDS determines the appropriate legal basis separately for each relevant activity.

8. Consent

Where processing is based on consent, such consent must be freely given, specific, informed and unambiguous.

A data subject may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Where special categories of personal data are processed and consent is relied upon as the relevant condition, UMDS obtains explicit consent in accordance with the GDPR.

9. Personal Data in Research

Before collecting personal data within a research project, UMDS determines:

  • the purpose of the research;
  • the amount and categories of data required;
  • the legal basis for processing;
  • the roles of partners in relation to the processing;
  • the applicable retention period or criteria;
  • rules governing access to data;
  • necessary confidentiality and security safeguards.

Where possible, research data are anonymised or pseudonymised.

Where proposed processing may result in a high risk to the rights and freedoms of natural persons, UMDS assesses whether a Data Protection Impact Assessment (DPIA) is required.

Specific requirements for research involving vulnerable participants are governed by a separate UMDS policy.

10. Website and Contact Form

Users may contact UMDS through the contact form available on the Organization’s website.

The following information may be collected through the form:

  • contact name;
  • telephone number;
  • email address;
  • text of the enquiry.

These data are used to receive, review and respond to the enquiry.

UMDS recommends that users do not include special categories of personal data or other confidential information in the text of an enquiry unless this is necessary.

11. Cookies and Tracking Technologies

As of the date of approval of this Policy, UMDS does not use Google Analytics, Meta/Facebook Pixel, LinkedIn Insight Tag or other marketing or behavioural tracking tools known to the Organization on its website.

UMDS does not use optional analytics or marketing cookies requiring the user’s prior consent.

The website may use strictly necessary technologies required for its operation and security.

If optional cookies or similar technologies are introduced, UMDS will update this information and, where required, provide a mechanism for obtaining and withdrawing consent.

12. Social Media and External Resources

The UMDS website contains links to the Organization’s official pages on Facebook and LinkedIn.

Once a user follows a link to an external platform, personal data processing is also governed by the policies of that platform.

UMDS does not control independent personal data processing carried out by external platform providers.

13. Photographs, Audio and Video Materials

UMDS may photograph and make video recordings at conferences, training sessions, round tables and other events and may also receive such materials from partners.

These materials may be used for:

  • documenting activities;
  • project reporting;
  • scientific and educational activities;
  • public communication and coverage of events.

The legal basis is determined according to the nature of the event and the way in which the materials are used.

Interviews, focus groups and other research sessions are recorded only after participants have been appropriately informed and where an appropriate legal basis exists.

14. Publication of Professional Information

UMDS may publish on its website and official information resources:

  • first and last name;
  • position;
  • professional or institutional affiliation;
  • authorship;
  • professional biographical information;

The amount of personal data made public must correspond to the purpose of publication and the principle of data minimisation.

15. Disclosure and Transfer of Personal Data

In the course of legitimate activities, personal data may be transferred or made available to:

  • authorized UMDS representatives;
  • members of research and project teams;
  • consortium partners;
  • universities and research institutions;
  • organizers of joint events;
  • the European Commission, executive agencies and other EU bodies where required by a project or grant agreement;
  • providers of technology, hosting or communication services;
  • competent public authorities where disclosure is required by law.

Personal data are disclosed only to the extent necessary for the relevant legitimate purpose.

16. International Transfers of Data

Due to the international nature of UMDS activities, personal data may be transferred to other countries.

Where the GDPR applies to such transfers, transfers of personal data from the EU/EEA to a third country are carried out in accordance with Chapter V GDPR.

Depending on the circumstances, UMDS may rely on:

  • European Commission adequacy decision;
  • Standard Contractual Clauses;
  • other mechanisms and safeguards provided for under the GDPR.
17. Data Retention

UMDS retains personal data for no longer than necessary for the purposes for which they are processed unless a longer period is required by law or by applicable grant or contractual requirements.

When determining retention periods, UMDS takes into account:

  • the purpose of processing;
  • the nature of the data;
  • legal requirements;
  • grant and contractual obligations;
  • research integrity requirements;
  • risks to the rights and freedoms of natural persons.

At the end of the necessary retention period, personal data are deleted, securely destroyed or anonymised unless there is a lawful basis for further retention.

18. Personal Data Security

UMDS applies organizational and technical measures to protect personal data against:

  • unauthorized access;
  • loss;
  • unlawful use;
  • alteration;
  • disclosure;

Access to personal data is granted only to persons who require it in order to perform their functions.

In the event of a personal data breach, UMDS takes appropriate measures to contain the breach, mitigate its consequences and comply with applicable notification requirements concerning competent authorities and affected data subjects.

19. Rights of Data Subjects

Where the GDPR applies to the relevant processing, an individual may, depending on the circumstances, have the right to:

  • receive information about the processing of their personal data;
  • access their personal data;
  • request rectification;
  • request erasure;
  • request restriction of processing;
  • object to processing;
  • exercise the right to data portability where provided for by the GDPR;
  • withdraw consent;
  • lodge a complaint with a competent supervisory authority.

These rights may be subject to limitations provided by applicable law.

20. How to Exercise Your Rights

To obtain information or exercise rights relating to personal data, please contact:

privacy@umdigital.science

UMDS may request information necessary to verify the identity of the person making the request.

Requests are handled within the time limits established by applicable law.

21. Responsibility for Personal Data Protection

Overall responsibility for organizing implementation of this Policy rests with the Chair of UMDS.

As of the date of approval of this Policy, a separate Data Protection Officer (DPO) has not been appointed.

All enquiries concerning personal data protection should be sent to:

privacy@umdigital.science

UMDS periodically assesses whether appointment of a DPO is required in light of the nature and scale of its activities and applicable legal requirements.

22. Updates to this Policy

UMDS may review this Policy in response to changes in legislation, the Organization’s activities, technology or methods of personal data processing.

The current version of this Policy is published on the official UMDS website.

23. Contact Information

COMMUNITY ORGANIZATION “UKRAINIAN MODERN DIGITAL SCIENCE”

Identification code: 44851106
Kyiv, Ukraine

Data Protection & Privacy: privacy@umdigital.science
General enquiries: hello@umdigital.science
Website: https://umdigital.science

Approved by: the decision of the General Meeting of the CO “Ukrainian Modern Digital Science”
(Minutes No. 2 dated August 25, 2026)