Compliance policies
On this page, you will find information about compliance requirements and policies for DTU's digital learning tools.
Compliance Policies for Teaching Support Systems
When you use one of Teaching Support’s digital learning systems, various types of data are stored, such as profile information, responses, feedback, or video recordings. These data may, for example, contain personal data or sensitive information and should therefore not be retained longer than necessary.
Teaching Support has compliance policies for the systems for which we are system owners. These policies describe how long data are retained and when they are deleted in each system. They support DTU’s efforts to ensure data minimization and data protection.
The rules vary from system to system. Below, you can select the system you use and see which deletion policies apply, as well as whether there is anything you need to be aware of yourself.
If you have any questions about the compliance policies for Teaching Supports systems, please contact us via DTU’s Service Portal: Support and Guidance - Digital Learning Tools.
You can read more about GDPR, the processing of personal data, and data protection on DTU Inside.
Deletion Policy
Courses and Course Materials
Courses in DTU Learn are stored permanently, and data are generally not deleted from the integrated learning tools. DTU prioritizes ensuring that students have access to course materials from completed courses throughout their studies. After six years, courses are deactivated, meaning that they, along with all associated course materials, will no longer be visible to enrolled students.
If instructors wish to limit students’ access to their course materials, they should consider the following options for hiding the materials:
- Turn of visibility
- Set an end date
- Add release conditions
User Data
Users (students and instructors) and their data are retained in DTU Learn. Instructors are deactivated within one month of leaving DTU, and the students are deactivated after 180 days. When a user is deactivated in DTU Learn, some of their data are hidden. This means that the user no longer appears in class lists or groups, but their name remains visible in messages, discussions, and various activity logs.
User creation
All user creation in DTU Learn is managed through DTUbasen. This is because DTU Learn authenticates users through DTUbasen and uses DTU's single sign-on (SSO) solution, which provides a higher level of IT security. To create a user in DTUbasen, please contact your local DTUBasen administrator. You can find an overview of DTUBasen administrators in the main menu of DTUBasen. Once the user has been created, they will be able to log in to DTU Learn within three hours.
Process for Approval of LTI Integrations with Third-Party Software
Integrations between DTU Learn and third-party software must be approved before they can be put into use. This page describes the approval process, documentation requirements, and responsibilities related to operation, security, and data management: dtu-learn-proces-for-approval-of-lti-integrations-with-third-party-software
Deletion Policy
FeedbackFruits Peer Review is integrated with DTU Learn. When a user loses access through DTU Learn, the user’s data are not automatically deleted from FeedbackFruits Peer Review.
Inactive users are reviewed once a year for potential deletion. Deletion of users and their associated activity data is carried out through a separate request to FeedbackFruits.
Deletion Policy
Videos that are more than 18 months old are continuously flagged for deletion. If one of your videos is flagged, Panopto will send you an email informing you of the planned deletion and giving you the option to extend the retention period.
You may extend the retention period if there is still a lawful and legitimate reason to retain the video, for example, if it will be used in teaching during the current or upcoming semesters. The email contains a link labeled “Extend retention period”, which you can select to keep the video. The link opens a page confirming the extension.
Transfer of Video Ownership
When transferring ownership of videos, the current owner must provide written consent for the videos to be transferred. The transfer agreement must clearly specify:
- Which specific videos are being transferred.
- From whom and to whom the videos are being transferred.
- That the videos do not contain material owned by third parties.
If you have any questions regarding copyright or transfer of videos, please contact ophavsret@dtu.dk.
Deletion Policy
Response data in Vevox are deleted 18 months after the last activity. Following deletion, the data can be restored for a further six months. After that, they are permanently deleted.
If you use the PowerPoint integration, your slides will not be deleted. The deletion applies only to response data from your Vevox polls.
Deletion Policy
In ThingLink, users are deleted after five years of inactivity. Conteent they have created is not deleted.
We are currently updating the deletion policy. The goal is for users to be automatically deleted when they leave DTU. At the same time, we are working on introducing a retention limit of 18 months for inactive content. This page will be updated when the policy comes into effect.