Guidelines for Use
March 31, 1998
The Augsburg University of Applied Sciences hereby issues the following guideline pursuant to Article 5(3)(3) of the Bavarian Higher Education Act (BayHSchG) of December 1, 1993 (GVBl, p. 953), as currently in force.
Preamble
Augsburg University of Applied Sciences and its facilities (“Operator” or “System Operator”) operate an information processing infrastructure (IP infrastructure) consisting of data processing systems (computers), communication systems (networks), and other auxiliary facilities for information processing. The IT infrastructure is integrated into the German research network and, consequently, into the global Internet.
These usage guidelines govern the conditions under which the services offered may be used.
The User Guidelines
- are based on the university’s legally defined responsibilities as well as its mandate to safeguard academic freedom,
- establish basic rules for the proper operation of the IT infrastructure,
- draw attention to the rights of third parties that must be respected (e.g., software licenses, network operator requirements, data protection considerations),
- require users to behave appropriately and to use the available resources efficiently,
- and explain any measures the operator may take in the event of violations of the usage regulations
These guidelines apply to the information infrastructure provided by Augsburg University of Applied Sciences and its facilities, consisting of data processing equipment (computers), communication systems (networks), and other information-processing support facilities, to the extent that this infrastructure is connected to external networks (e.g., the German Research Network).
- The facilities referred to in § 1 are available to members of the Augsburg University of Applied Sciences for the purpose of fulfilling their duties in the areas of research, teaching, administration, education and continuing education, public relations, and the university’s external image, as well as for other duties described in Article 2 of the Bavarian Higher Education Act.
- Other individuals and institutions may be permitted to use these facilities. This generally requires a separate, written agreement.
- “Users” as defined by these guidelines include all individuals who have formal authorization to use the network, as well as individuals who gain access to the German Academic Network—for example, in administrative settings, at closed events, in projects, or at individual workstations—without formal authorization (whether based on a personal ID or group identifier).
Authorization to use the facilities must be requested from the responsible system operator. Exceptions are services set up for anonymous access (e.g., information services).
The application must include the following information:
- Applicant: Name, address, and, if applicable, student ID number, as well as affiliation with an organizational unit at the university of applied sciences;
- Purpose of use, e.g., research, education, administration;
- Systems for which authorization is being requested;
- A statement that the user acknowledges these guidelines and consents to the collection and processing of personal data in accordance with § 5. Consent may also be provided electronically, as the requirements of Art. 2 § 3(7) of the Information and Communication Services Act (IuKDG) are met;
- A notice that consent may be revoked at any time with future effect.
The system operator may only request additional information to the extent that it is necessary to decide on the application.
- The responsible system operator decides on the application. The system operator may make the granting of user authorization contingent upon proof of certain knowledge regarding the use of the system.
- Authorization is granted within the limits of available capacity. It may be subject to a limit on computing time as well as other conditions and requirements.
- Authorization for use is generally granted for a period of 2 years, with the possibility of renewal. For professors, research staff, and non-research staff, authorization is automatically extended for an additional year without the need for an application, provided it is not revoked.
- The user ID is non-transferable. If the user discovers any misuse of their user ID, they must immediately notify the office that issued the user ID so that the ID can be blocked. Furthermore, the user is responsible for all actions taken by third parties if the user has enabled access by third parties through at least gross negligence.
- Once the authorized user has reported the unauthorized use by another party, they are no longer responsible for any further unauthorized use carried out with the user ID after that point in time.
- Authorization may be denied, revoked, or subsequently restricted, in particular if
- no proper application has been submitted or the information provided is incorrect or no longer accurate, including, in particular, if the consent under paragraph 1 is revoked;
- the conditions for proper use of the facilities are not met or are no longer met;
- the authorized user has been barred from use;
- the proposed use is not compatible with the purposes set forth in § 2;
- the facility is unsuitable for the intended use or is reserved for specific purposes;
- the capacity of the facility for which use is requested is insufficient for the intended work due to existing utilization;
- the facility to be used is connected to a network that must meet specific data protection requirements, and there is no apparent objective reason for this request for access;
- it is to be expected that the requested use will unreasonably disrupt other authorized uses.
- The authorization to use the facility applies only to work related to the requested use.
- The authorization to use the facility is limited to work related to the requested use.
- Authorized users have the right to use the facilities, data processing equipment, and public software systems in accordance with their authorization under these guidelines, as well as to make use of the services offered by the academic departments or the Computer Center. Use for other purposes, in particular for commercial purposes, may be permitted only upon request and for a fee.
- Users are required to
- comply with licensing provisions;
- comply with these guidelines, in particular to refrain from any action that disrupts the proper operation of the university’s facilities;
- provide proof of their authorization to use the systems upon request;
- immediately report any malfunctions, damage, or errors in computer systems and data storage media to the responsible staff;
- to follow the instructions of the staff in the computer rooms;
- to notify the department or the computer center prior to processing personal data and—without prejudice to the user’s own obligation to protect data—to observe and utilize the data protection and data security measures maintained by the department or the computer center;
- to back up their data and programs in such a way that no damage results from loss during processing in the department or the data center;
- to use the data networks only in accordance with the Terms of Use and to comply with the guidelines for the use of the data networks;
- ensure that no other person gains knowledge of their user ID;
- to work exclusively with the user IDs they are authorized to use, and to take precautions to prevent unauthorized third parties from accessing the information processing systems of Augsburg University of Applied Sciences;
- to protect access to the facilities with a password that must be kept confidential.
- The user is not authorized to copy and/or distribute software, documentation, and data—particularly those subject to licensing—unless expressly permitted, nor to use them for purposes other than those permitted, especially not for commercial purposes. Authorization to install software is governed separately depending on the respective local and technical system conditions.
- The user is prohibited from making any changes to the hardware installation or modifying the configuration of the operating systems, system files, or the network without the consent of the responsible system administrator.
- The user is prohibited from maintaining more than one remote access connection to the Augsburg University of Applied Sciences’ access points at the same time.
- The user is prohibited from accessing and/or using messages intended for other users.
- Violations may give rise to claims for damages.
- Please be advised of the following criminal offenses:
- Interception of data (Section 202a of the German Criminal Code (StGB))
- Unauthorized alteration, deletion, suppression, or rendering of data unusable (§ 303a StGB)
- Computer sabotage (Section 303b of the German Criminal Code (StGB)) and computer fraud (Section 263a of the German Criminal Code (StGB))
- The dissemination of propaganda materials from unconstitutional organizations (Section 86 of the German Criminal Code) or racist ideology (Section 130 of the German Criminal Code)
- the dissemination of certain forms of pornography online (Section 184(3) StGB)
- Accessing or possessing documents containing child pornography (Section 184(5) of the German Criminal Code (StGB))
- Offenses against personal dignity, such as insult or defamation (Sections 185 et seq. of the German Criminal Code (StGB)).
- Each system operator shall maintain documentation regarding the user authorizations granted. The records must generally be retained for two years after the authorization expires.
- The system operator has the right to prevent or detect misuse in an appropriate manner, particularly through random checks. To this end, the system operator is specifically authorized to:
- document and analyze user activities to the extent that this serves the purposes of billing, resource planning, monitoring operations, or investigating errors and violations of these guidelines and statutory provisions.
- If, as a result of measures taken under subparagraph (a), there is compelling evidence of misuse, access may be temporarily suspended or revoked following a prior hearing with the user. Once the facts of the matter have been sufficiently clarified, the suspension may be lifted or access reinstated.
- If the suspicion under subparagraph (b) is not unequivocally dispelled, in the event of repeated violations of these guidelines—to the extent that such violations may lead to serious disruptions of operations—or in the event of renewed, well-founded suspicion of criminal acts (German Criminal Code [StGB] and others), in compliance with the dual-control principle and the record-keeping requirement, user data may be accessed, or the user’s network usage may be logged in detail and in real time, without prior notice to the user, if this is unavoidable to maintain proper operations or, in the event of suspected misuse, to prevent such misuse.
- in cases of strong suspicion of criminal acts—if necessary—to take measures to preserve evidence.
- The user must be notified immediately after a measure under subsections 2(c) and (d) has been implemented, provided that this does not frustrate the purpose of the measure or unduly impede its implementation.
- For measures under paragraph 2(c) taken against members pursuant to Art. 17, paragraph 1, no. 2, 4, 5, 8, 9, and 10 of the Bavarian Higher Education Act (BayHSchG), the approval of the President is required; for members under Art. 17, para. 1, no. 6 of the Bavarian Higher Education Act (BayHSchG), the approval of the Chancellor is required, in each case together with the responsible dean or head of a central institution.
- For members pursuant to Art. 17, para. 1, no. 7 of the Bavarian Higher Education Act (BayHSchG) (students), the approval of the Chancellor and the responsible system operator is required.
- If a measure under paragraph 2(c) is to be implemented with respect to members under Article 17(1)(6) of the Bavarian Higher Education Act (BayHSchG), the staff council must be consulted.
- The system operator is obligated to maintain confidentiality.
- Individuals who violate these guidelines or commit criminal acts may be temporarily or permanently barred from use, unless restrictions on use are proportionate to the violation and can prevent further misuse. Such exclusion does not affect the user’s obligations arising from the user agreement. The university’s claim to the agreed-upon fee remains in effect. The user is not entitled to claims for damages based on the exclusion.
- The university reserves the right to withdraw from a user agreement, in whole or in part, if the user’s admission is revoked or restricted. In such cases, the university is not obligated to pay compensation.
- Administrative measures under the Bavarian Higher Education Act (BayHSchG) as well as disciplinary measures remain unaffected by this.
- The university reserves the right to take criminal and/or civil legal action.
Teaching operations take top priority. Requests from internal users (members of the university) are processed before those from external users.
- The services provided by the University of Applied Sciences are provided to internal users as defined in § 2(1)—insofar as they are basic services—without charge. For external users as defined in § 2(1), the university may charge fees equal to the operating costs; for other users (§ 2(2)), fees equal to the full costs may be charged.
- Full costs comprise the total costs of operating the system. They include personnel costs, material costs, depreciation, and overhead costs.
- The University of Applied Sciences does not guarantee that the system will operate error-free and without interruption. The University of Applied Sciences cannot guarantee the integrity and confidentiality of the data stored with it.
- The University of Applied Sciences assumes no responsibility for the accuracy of programs, even if they were written by a University of Applied Sciences employee, and is not liable for damages or incorrect results arising from technical malfunctions or defective equipment, unless the damage is due to intentional or grossly negligent conduct on the part of an employee or an agent of the University of Applied Sciences.
- Persons who unlawfully use the University’s computer facilities without instruction or permission are liable for all damages they cause.
- The user is liable for all damages caused in connection with the use of the computer labs. This applies in particular to damages caused by failure to comply with the user’s obligations, by providing false information regarding the type of use and consumption, and by the unauthorized use of another person’s identification, protected data, or protected programs. Compensation for damages must be paid in cash. The user is obligated to indemnify the university against any claims for damages by third parties.
The provisions of data protection laws apply accordingly.
- Fees for the use of information processing systems may be established in separate regulations.
- For certain systems, supplementary or different rules of use may be established as needed.
These guidelines shall take effect on the day following their publication by posting.
The President of Augsburg University of Applied Sciences
Prof. Dipl. Ing. H. Benedikt
April 1, 1998
These guidelines were adopted by the university on April 1, 1998; their adoption was announced on April 1, 1998, by posting a notice on campus. The date of announcement is therefore April 1, 1998.