Skip to Main Content
  • Sylvester Comprehensive Cancer Center |
  • Bascom Palmer Eye Institute

General Data Protection Regulation (GDPR)

University of Miami Health
  • Appointments
  • Pay a Bill
  • Refer a Patient
  • International Patients
  • Donate Now
  • Search
  • Patient Login
  • Find a Doctor
  • Treatments Page 1
    Featured Treatments For
    • Allergy and Immunology
    • Arthritis (Rheumatology)
    • Bariatrics (Weight Loss Surgery)
    • Cancer (Oncology)
    • Cardiac and Vascular
    • Concierge Medicine
    • Dentistry
    • Dermatology
    • Diabetes
    • Ear, Nose, and Throat (ENT)
    • Emergency Care
    • Endocrinology, Diabetes and Metabolism
    • Executive Physicals
    • Eye Care (Ophthalmology)
    • Fertility Center
    • Gastrointestinal
    • Genetics
    • Geriatrics
    • Hematologic (Blood) Cancers
    • Hepatology
    • High Blood Pressure (Hypertension)
    • Infectious Diseases
    • Internal Medicine
    • Interventional Radiology
    • Lymphedema
    • Nephrology
    • Neurology
    • Neurosurgery
    • Obstetrics and Gynecology
    • Orthopaedics
    • Pain Management and Palliative Care
    • Pediatrics
    • Physical and Occupational Therapy
    • Physical Medicine and Rehabilitation
    • Plastic Surgery
    • Primary Care
    • Psychiatry
    • Pulmonary Medicine
    • Radiology
    • Sleep Medicine
    • Sports Medicine Institute
    • Surgery
    • Transplant
    • UHealth Comprehensive Women’s Health Alliance
    • UHealth Premier
    • Urology
    View all Treatments
    Browse A-Z A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
    Featured Treatments For
    • Allergy and Immunology
    • Arthritis (Rheumatology)
    • Bariatrics (Weight Loss Surgery)
    • Cancer (Oncology)
    • Cardiac and Vascular
    • Concierge Medicine
    • Dentistry
    • Dermatology
    • Diabetes
    • Ear, Nose, and Throat (ENT)
    • Emergency Care
    • Endocrinology, Diabetes and Metabolism
    • Executive Physicals
    • Eye Care (Ophthalmology)
    • Fertility Center
    • Gastrointestinal
    • Genetics
    • Geriatrics
    • Hematologic (Blood) Cancers
    • Hepatology
    • High Blood Pressure (Hypertension)
    • Infectious Diseases
    • Internal Medicine
    • Interventional Radiology
    • Lymphedema
    • Nephrology
    • Neurology
    • Neurosurgery
    • Obstetrics and Gynecology
    • Orthopaedics
    • Pain Management and Palliative Care
    • Pediatrics
    • Physical and Occupational Therapy
    • Physical Medicine and Rehabilitation
    • Plastic Surgery
    • Primary Care
    • Psychiatry
    • Pulmonary Medicine
    • Radiology
    • Sleep Medicine
    • Sports Medicine Institute
    • Surgery
    • Transplant
    • UHealth Comprehensive Women’s Health Alliance
    • UHealth Premier
    • Urology
    View all Treatments
  • Locations
  • Patients & Families
    Quick links
    • Appointments
    • Pay a Bill
    • Make a Gift
    • Insurance Plans Accepted
    • MyUHealthChart
    • Advance Directives
    For Patients & Families
    • Your First Visit
    • Medical Records
    • Frequently Asked Questions
    • Patients & Families
    • Public Transportation
    • UHealth Clinic at Walgreens
    • Support Groups
    • Interpreter Services
    • International Patients
    • UMiami Health Talks
    About Uhealth
    • Why Choose UHealth
    • Benefits of an Academic Medical Center
    • Mission & Values
    • Leadership
    • Community Health Improvement
    • Nursing at UHealth
    • Health News
    • Miller School of Medicine
    • University of Miami
    • Careers
    • Volunteers
    • Contact Us
    Clinical Trials
    • Find a Clinical Trial
    • Understanding Clinical Trials
    • Clinical Trials FAQ's
    Traveling from overseas?
    We can help plan your visit. Learn More
    Quick links
    • Appointments
    • Pay a Bill
    • Make a Gift
    • Insurance Plans Accepted
    • MyUHealthChart
    • Advance Directives
    For Patients & Families
    • Your First Visit
    • Medical Records
    • Frequently Asked Questions
    • Patients & Families
    • Public Transportation
    • UHealth Clinic at Walgreens
    • Support Groups
    • Interpreter Services
    • International Patients
    • UMiami Health Talks
    About Uhealth
    • Why Choose UHealth
    • Benefits of an Academic Medical Center
    • Mission & Values
    • Leadership
    • Community Health Improvement
    • Nursing at UHealth
    • Health News
    • Miller School of Medicine
    • University of Miami
    • Careers
    • Volunteers
    • Contact Us
    Clinical Trials
    • Find a Clinical Trial
    • Understanding Clinical Trials
    • Clinical Trials FAQ's
Patient Login
  • University of Miami Health System
  • Website Disclaimers
  • Privacy Statement
  • General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR)

« Back to Privacy Statement
Website Disclaimers
  • Medical Disclaimer
  • Privacy Statement
    • Cookie Notice
    • Notice of Availability
    • Notice of Nondiscrimination
    • Non-Discrimination Policy
    • General Data Protection Regulation (GDPR)
    • Accreditation
    • Reserved Rights
    • SMS Terms and Conditions
    • Visual Identity and Branding
    • Web Content Policy
  • Social Media Terms of Use
  • Terms for Online Appointments
  • Terms of Use

The General Data Protection Regulation (GDPR) replaces the Data Protection Directive and was designed to harmonize data privacy laws across Europe, to protect and empower all EU citizens data privacy, and to reshape the way organizations across the region approach data privacy.  It became effective on May 25, 2018.

Who does GDPR apply to?

GDPR applies not only to organizations that process data in the EU, but also to any organization that offers goods or services to, or monitors the behavior of, people inside the EU. GDPR applies even if the processing takes place outside of the EU.

Which data elements fall under GDPR?

GDPR applies to information that directly or indirectly could identify an individual.  This includes names, addresses, phone numbers, dates of birth, as well as IP addresses, cookie identifiers, device information, advertising identifiers, financial information, geo-location information, social media information, consumer preferences, etc.

Who does GDPR protect?

EU data subjects are individuals physically residing in the EU, irrespective to nationality or permanent place of residence. This includes members of the University of Miami (UM) community who may be residing (permanently or temporarily) in the EU, and EU residents who attend or work for UM.

What constitutes personal data?

Any information related to a natural person or “data subject” that can be used to directly or indirectly identify the person.

What rights are afforded by GDPR?

GDPR gives EU data subjects significant new rights over how their personal data is collected, processed, and transferred by data controllers and processors. Under GDPR, EU data subjects have the right to, among other things:

  • Access any data that an organization has collected about the individual;
  • Know why an organization is processing the individual’s personal data and the categories of personal data that an organization processes;
  • Correct any errors in personal data collected or processed by an organization;
  • Know how long an organization will store the individual’s personal data; and
  • Under certain circumstances, require the organization to permanently delete the individual’s personal data (this right is sometimes referred to as the right to be forgotten or the right to erasure).
  • From an organizational perspective, GDPR requires significant data protection safeguards be implemented and imposes a number of obligations; notable requirements include that the organization:
  • Have a legal basis for collecting and processing the personal data of EU data subjects, document that legal basis, and only collect and use data when a legal basis exists;
  • Minimize the collection and processing of personal data whenever possible;
  • Protect any personal data that it collects and uses;
  • Conduct an assessment to determine any risks and privacy impacts related to collecting and processing the personal data of data subjects, implement a plan to mitigate those risks and impacts, and continuously monitor both the risks and the mitigation plan for change;
  • Conduct a data protection impact assessment for special categories of high-risk data collection and processing; and
  • Have a breach notification policy, and notify authorities within 72 hours of learning of the breach.

How will GDPR impact UM?

EU data subjects are individuals physically residing in the EU, irrespective to nationality or permanent place of residence. This includes members of the University of Miami community who may be residing (permanently or temporarily) in the EU, and EU residents who attend or work for UM.

Since UM handles data related to these individuals, the University will need to show a path to compliance by May 25, 2018. GDPR imposes penalties on organizations that fail to comply.

GDPR will affect all aspects of UM operations, including the methods used to collect, store, and process data, including active and passive collection on websites; how UM shares data with third parties; contractual agreements; research; recruiting; alumni relations; study abroad; and online learning. Additionally, business processes and systems will be examined.

UM must have a documented legal basis for collecting and processing the personal data of EU data subjects. There are two basic categories of legal basis: (1) consent from the data subject, and (2) one of the specified business reasons for processing data.

UM must specifically be able to point to consent or to one of the stated business purposes as the reason for processing data. GDPR consent requirements are very specific and limit the use of personal data for uses other than those specifically stated in the consent document.

How can you help?

If you work with UM data, which you believe is EU data that your unit may be storing, transferring, maintaining, or marketing, we ask that you please contact the Office of University Compliance Services.

Data Subject Access Request (DSAR)

GDPR and the UK Data Protection Act 2018 confer several rights on individuals about whom the University holds and processes personal data, which includes access and erasure. The University must administer requests from individuals relating to these rights.

Any DSARs should be sent via email to: ucs@Miami.edu.

Resources

  • Protection of Personal Data in the EU – Fact Sheet
  • General Data Protection Regulation
  • European Commission Data Protection
  • GDPR (Searchable Feature)

Additional Information

  • GDPR Guide
  • UM-GDPR-PowerPoint

Office of University Compliance Services

Office of University Compliance Services

Nelson E. Perez, JD, CCEP
Executive Director
1320 South Dixie Highway
Gables One Tower, Suite 700
Coral Gables, FL 33146
Phone: 305-284-2924
Fax: 305-284-4804
Email: nelsonperez@miami.edu


logo
alt="Twitter Logo">
USNWR Best Hospitals 2025-2026 USNWR Best Regional Hospitals 2025-2026
Quick links
  • Appointments
  • Find a Doctor
  • Pay a Bill
  • Insurance Plans Accepted
  • MyUHealthChart
  • Make a Gift
Patient & Families
  • Frequently Asked Questions
  • Medical Records
  • Interpreter Services
  • Clinical Trials
  • International Patients
  • UHealth Clinic at Walgreens
  • Support Groups
  • Price Transparency
  • Florida Health Finder
Healthcare Professionals
  • Refer a Patient
  • Physician & Executive Recruitment
  • Advanced Practice Providers
  • Immunology & Histocompatibility Laboratory
  • Nursing
  • Sleep Center
  • Sports Medicine Institute
  • Pathology Reference Services
About Uhealth
  • Why Choose UHealth
  • Benefits of an Academic Medical Center
  • Mission & Values
  • Leadership
  • Community Health Improvement
  • For Media
  • Miller School of Medicine
  • University of Miami
  • Careers
  • Volunteers
  • Supply Chain
  • Contact Us

University of Miami Centennial Logo

Medical Disclaimer | Terms of Use | Privacy Statement | HIPAA Notice of Privacy Practices | Non-Discrimination Policy | No Surprises Billing Rights
© 2025 University of Miami Health System. All rights reserved.