When a student completes a thesis as an assignment for an external party (a company, public corporation, association, university of applied sciences or other educational institution) or, for example, an RDI project, the common rules are agreed upon through a written commissioning agreement.
There are specific templates for creating the agreement:
Regarding the data, the agreement specifies:
A personal data register is created if you collect personal data in a commissioned thesis. A personal data register refers to structured information about research participants or other personal data collected for the study. In a commissioned thesis, the commissioning party is the data controller. The data controller defines the purposes and means of processing personal data and is fundamentally responsible for the legality of the processing and the realization of the rights of the data subjects.
The data controller must maintain a description of the processing activities for which they are responsible, as stipulated in Article 30 of the General Data Protection Regulation. The description must include the following information regarding all processing of personal data:
Consult with the data protection officer of the commissioning party to understand how personal data registers are managed within the commissioning organization's practices.
For more information, refer to the Data Protection Ombudsman’s office.