Privacy Policy
Privacy Policy
This Privacy Policy explains how personal data are processed in connection with the Nordic Statistics database and related services, which are operated by Nordregio. It also sets out your rights under applicable data protection legislation, including the EU General Data Protection Regulation (GDPR).
We are committed to protecting your privacy and ensuring that personal data are processed in a secure, fair, and transparent manner. This policy applies when you use the Nordic Statistics database, visit our website, subscribe to mailings, participate in events, or otherwise interact with us.
If you have any questions about this policy or about how we process personal data, please contact us: nordicstatistics@nordregio.org
Who are we?
Nordregio is an international research centre for regional development and planning, established by the Nordic Council of Ministers. Nordregio operates the Nordic Statistics Database. As part of this work, we collect certain personal data when you interact with the database or related services, or if you contact us.
What is personal data?
Personal data refers to any information that can be used to identify an individual, either directly or indirectly. This may include, for example, a name, email address, image, or IP address.
How do we collect personal data?
We may collect personal data in the following ways:
when you use the Nordic Statistics database or visit the website
when you download data or other content
when you subscribe to our newsletters or other communications
when you provide us with the data yourself
when you register or take part in events, online meetings or webinars
when you contact us directly by email or other means
when you enter into a contract with Nordregio.
Why do we collect and use personal data?
We collect and process personal data for specific and defined purposes, including:
Provision of services and data access: to operate and maintain the Nordic Statistics Database and provide related services.
Communication and information: to respond to enquiries, provide updates, distribute newsletters and share information about the Nordic Statistics database and Nordregio’s activities.
Events and meetings: to manage registrations, participation, and follow-up related to events, seminars, meetings, webinars or similar activities.
Administrative and legal obligations: to comply applicable laws, such as accounting and record-keeping requirements.
Only individuals who have requested communications from us will receive emails or notifications. You may opt out at any time.
Where personal data collection and processing are based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.
Categories of personal data
We process personal data in two main categories:
Data necessary to provide a service
This includes identification and contact details such as name, organisation, email address, postal address, or telephone number. Without this data, we may not be able to provide certain services. For instance, if you wish to subscribe to Nordregio newsletters, you will need to consent to the processing of your data for this purpose, e.g. in the form of your e-mail address. We may also need to process data for other reasons, e.g. to fulfil the terms of a contract; or we may need to record and save certain personal data for legal reasons, e.g. to ensure that we comply with tax legislation and the Swedish Bookkeeping Act.
Data used to improve our services
This includes technical and usage-related data, such as IP addresses and website interaction data, including cookies. Such data help ensure that the website functions correctly and support service improvement. It also helps us improve our services, to tailor our communications to your needs and to offer you precisely the services that you require. More information is available in the Cookie Policy.
How long do we store personal data?
We delete all personal data when it is no longer needed. We retain personal data only for as long as necessary for the purpose for which it was collected.
We perform a discretionary assessment of when we no longer require your data. Once your data is no longer required for the purpose for which we collected it, we will delete it.
We are required by law (e.g. the Swedish Bookkeeping Act) to retain some personal data for a minimum of five years, e.g. data used to issue invoices, calculate and pay tax and VAT, submit tax returns, and data used for contracts.
As per the general principles of public law, other personal data collected as part of Nordic activities is filed along with the specific case in question. This will only be relevant and necessary data and it cannot be deleted once the case has been completed.
Sharing of personal data
We do not share personal data with third parties unless:
it is necessary for us to comply with legal obligations,
you have given your consent, or
because we use data processors within the EU, EEA or a secure third country.
Personal data may be shared with trusted service providers who support Nordregio’s operations, such as IT, communication, or administrative service providers. Such providers act as data processors and process personal data only on Nordregio’s instructions and under data processing agreements. Nordregio does not sell personal data to third parties.
To the extent permitted by law, we are entitled to share personal data for the purposes of protecting or enforcing our rights, e.g., where relevant to prevent fraud or other criminal offences.
Where data processors are used, they are subject to data processing agreements. Personal data are processed within the EU/EEA or in countries that ensure an adequate level of data protection in accordance with GDPR.
Your rights
You have rights regarding our processing of your data, including:
Right of access to your data and to be issued with a copy
You have the right to know whether we process your data; this includes the categories of personal data and information about the origins of the data, as well as the purposes of the processing and, if possible, the period for which your data will be saved. We issue a copy of the personal data processed on request. Please be aware that your right of access may be limited due to the need to protect other people’s data.
Right to correction or deletion of your data
You are entitled to have any incorrect data that we hold about you corrected. You may at any time demand the deletion of the data that we hold about you. If there is no longer any reason for us to hold the data, we will delete it as soon as possible following a request from you.
Right to demand information about transferring of data to countries and organisations outside the EU and EEA
You have a right to know if we share your data with a country outside the EU and EEA. For your information, we do not share personal data with countries outside the EU and EEA, with the exception of a number of data processors in the USA who are bound by the EU-USA Privacy Shield.
Right to avoid profiling and automated decision-making
We do not use personal data for automated decision-making or profiling.
We do everything in our power to ensure that your data is processed in a secure manner and that your rights are protected as far as possible. We also conduct regular reviews of our procedures and of how we process personal data.
If you would like more information or would like to exercise any of the above rights, please get in touch using the contact details below.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
How do we protect your data?
We are committed to protecting your data, not only because it is required by law, but also because our own internal ethics rules demand that we take good care of all personal data.
Nordregio applies appropriate technical and organisational security measures to safeguard personal data and ensure that there is no unauthorised access to the personal data that we hold and that it is not used, destroyed, modified, made public or misused in any other way.
Personal data are generally processed and stored within the EU/EEA. Nordregio does not intentionally transfer personal data to countries outside the EU/EEA. If such transfers occur in exceptional cases, they are carried out in accordance with GDPR requirements and with appropriate safeguards in place.
In line with our internal rules guidelines and procedures for data security, personal information is available only to the employee(s) who require(s) it. Ongoing staff training in the correct procedures for processing personal data and checks that they are complying with the rules are also part of our data security rules.
Our IT systems are protected by up-to-date security measures.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will inform you without undue delay, in accordance with legal requirements.
Contact details
For questions about this Privacy Policy or the processing of personal data related to the Nordic Statistics Database, please contact:
Nordic Statistics Database (Nordregio)
Holmamiralens Väg 10, Skeppsholmen, Stockholm, Tel.: + 46 8 463 54 00
Email: nordicstatistics@nordregio.org
We reserve the right to update or amend this policy to reflect changes in legal requirements or in our use of cookies. The most recent version is always published on the website.