General Data Protection Regulation (GDPR)

Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR) applies as of 25 May 2018. It repeals Directive 95/46/EC.

The regulation is an essential step to strengthen individuals’ fundamental rights in the digital age and facilitate business by clarifying rules for companies and public bodies in the digital single market.

The text of the GDPR is available in all EU languages on the European Commission website and in pdf format in English by clicking here.

The cross-references between the articles and the recitals in the preamble can be found at:

Law 125(I)2018

Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data of 2018 (Law 125(I)/2018)

On 31 July 2018 the national law providing for the protection of natural persons with regard to the processing of personal data and for the free movement of such data (Law 125(I)/2018), was published in the official gazette of the Cyprus Republic.

The law was adopted for the effective implementation of certain provisions of the Regulation (EE) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR), which applies as of 25 May 2018.

Upon entry into force of the provisions of the law 125(I)/2018, the Processing of Personal Data (Protection of Individuals) Law of 2001 (Law 138(I)/2001) was repealed.

Acts issued by the Commissioner under the provisions of the Processing of Personal Data (Protection of Individuals) Law, which is repealed, will continue to be valid until their expiration or replacement.

Data Protection Policy

In carrying out its statutory duties, City Unity College Nicosia needs to hold personal data for a variety of reasons. It strives to ensure that such data is held securely, and that it is used only in appropriate ways. To that end, the College Council has produced the following Data Protection Policy.

All those acting on behalf of the College are required to observe and enforce these policies.

The College takes its responsibilities with regards to the management of the requirements of the General Data Protection Regulation (GDPR) very seriously.

The College obtains, uses, stores and otherwise processes personal data relating to potential staff and students (applicants), current staff and students, former staff and students, current and former workers, contractors, website users and contacts, collectively referred to in this policy as data users. When processing personal data, the College is obliged to fulfil individuals’ reasonable expectations of privacy by complying with GDPR and other relevant data protection legislation (data protection law).

The DPO ensures that we:

Data Users' Rights

Data user has rights in relation to the way we handle their personal data.

These include the following rights:

Requests (including for data user access – see below) must be sent to the College’s DPO for processing and approval


The College must implement appropriate technical and organizational measures in an effective manner to ensure compliance with data protection principles. The College is responsible for, and must be able to demonstrate compliance with, the data protection principles.
We must therefore apply adequate resources and controls to ensure and to document GDPR compliance including:


1. College responsibilities

The College is responsible for establishing policies and procedures in order to comply with data protection law.

2. Data Protection Officer responsibilities

The DPO is responsible for:

3. Staff responsibilities

Staff members who process personal data about students, staff, applicants, alumni or any other individual must comply with the requirements of this policy. Staff members must ensure that:

Where members of staff are responsible for supervising students doing work which involves the processing of personal information (for example in research projects), they must ensure that those students are aware of the Data Protection principles.
Staff who are unsure about who are the authorized third parties to whom they can legitimately disclose personal data should seek advice from the Data Protection Officer

4. Third-Party Data Processors

Where external companies are used to process personal data on behalf of the College, responsibility for the security and appropriate use of that data remains with the College.

5. Where a third-party data processor is used

For further guidance about the use of third-party data processors please contact the Data Protection Officer.

6. Contractors, Short-Term and Voluntary Staff

The College is responsible for the use made of personal data by anyone working on its behalf.

Managers who employ contractors, short term or voluntary staff must ensure that they are appropriately qualified for the data they will be processing. In addition, managers should ensure that:

7. Student responsibilities

Students are responsible for:

Limitations on the Transfer of Personal Data

The GDPR restricts data transfers to countries outside the EU in order to ensure that the level of data protection afforded to individuals by the GDPR is not undermined. You transfer personal data originating in one country across borders when you transmit or send that data to a different country or view/access it in a different country.

You may only transfer personal data outside the EU if one of the following conditions applies:

The data user has provided written consent to the proposed transfer after being informed of any potential risks; or the transfer is necessary for one of the other reasons set out in the GDPR including:

Sharing Personal Data

In the absence of a written consent, a legal obligation or other legal basis of processing, personal data should not generally be disclosed to third parties unrelated to the College (e.g. students’ parents, members of the public, private property owners).

Changes to this Policy

We reserve the right to change this policy at any time without notice to you so please check regularly to obtain the latest copy.

Data Protection Training Sessions

Data protection training for all staff is available through eClass, short burst seminars and one to one sit ins.

Under the College’s Data Protection Policy, all staff have responsibility for data protection compliance in their day-to-day work. To keep up to date with these responsibilities, staff must complete the College’s mandatory data protection training session.

Academics conducting research and the research support staff members must also complete the additional data protection training session.

Privacy by Design

‘Privacy by design’ is another term for ‘data protection by design’, and refers to the action of determining the minimum personal data required to carry out the necessary processing. By processing only, the minimum personal data required, we’re maintaining an individual’s privacy (protecting data). Read the Privacy Policy

Data Subject Rights'

The GDPR builds on the data subject rights in the Data Protection Act. These are:

The right of data portability is only available where the personal data is processed with the consent of the data subject, not where the personal data has been collected using any of the other legal basis for processing.

Data Protection Officer

The controller for personal data is City Unity College Nicosia 19 Stasinou Street, 2404, Engomi, Nicosia.

For information and quires about your personal information, or if you require advice on how to exercise your rights regarding GDPR, contact the Data Protection Officer (DPO) of the College.

The main tasks of the Data Protection Officer are:

The role of the DPO is defined in the GDPR. The DPO must be allowed to perform tasks in an independent manner, set the data protection strategy for the College and report to the College Council.

Office Location: Main Building (19 Stasinou Street, 2404, Engomi, Nicosia)
Tel: +357 22332333
Contact Email: