Please ensure Javascript is enabled for purposes of website accessibility

Data Protection Policy


KARE AR PORTAL


Data Protection

1. Introduction

Data protection ensures that individuals’ privacy rights are safeguarded when their personal data is collected, processed, stored, or otherwise handled. Kalasalingam academy of research and education (“the university”) collects and uses personal data relating to its students, faculty, staff, researchers, alumni, and other individuals who interact with the university, collectively referred to as “data subjects”.

In order to respect and protect the privacy rights of these individuals, the university is committed to complying with applicable data protection laws and regulations, including the digital personal data protection act, 2023 (india), the information technology act, 2000, and relevant rules and guidelines issued by statutory and regulatory authorities such as the university grants commission (ugc) and other competent bodies (collectively referred to in this policy as “data protection laws”).

These laws not only provide individuals with rights in relation to their personal data but also impose obligations and responsibilities on the university and all persons who process personal data on its behalf. The university recognizes its duty to ensure that personal data is handled in a lawful, fair, and transparent manner, and that appropriate technical and organizational measures are implemented to safeguard such data against unauthorized access, disclosure, alteration, or destruction.

This policy establishes the framework within which the university ensures compliance with data protection laws and promotes a culture of privacy, accountability, and responsible data management across all its academic, administrative, and research activities.

2. Purpose

This policy is a statement of the university’s commitment to protect the rights and privacy of individuals in accordance with applicable data protection laws in india, including the digital personal data protection act, 2023 and the information technology act, 2000 (as amended) (collectively referred to in this policy as the “data protection laws”).

It sets out responsibilities for all members of the university, including managers, employees, students, contractors, and any other individuals who may access or use personal data in the course of their work for, or studies with, the university.

3. Personal data and ‘sensitive personal data’

Personal data refers to any information that can be used to identify a living individual, either directly or indirectly. Even when separate pieces of information do not identify a person on their own, they may be considered personal data if, when combined, they can lead to the identification of an individual. Identifiers such as a person’s name, identification number, contact details, location data, or online identifiers, as well as characteristics related to physical, mental, economic, cultural, or social identity, may be used to recognize an individual.

In general, any information relating to a living person who can be identified from the available data, or from data that could reasonably be accessed, will be treated as personal data. This also includes pseudonymised data, where identifying details are replaced with codes or symbols. Although such data does not directly reveal the identity of the individual, identification may still be possible by linking it with additional information. Illustrative examples of personal data are provided in appendix f.

Certain types of personal data require a higher level of protection due to their sensitive nature. Under applicable indian laws, including the digital personal data protection act, 2023 and relevant provisions of the information technology act, 2000, such data is classified as ‘sensitive personal data’.

These include categories such as:

  • Financial information
  • Health-related information
  • Biometric identifiers
  • Genetic information
  • Data relating to minors
  • Any other category as may be specified under applicable laws

Processing of such sensitive personal data is permitted only under specific conditions, such as obtaining explicit consent from the individual or where processing is authorized by law, as detailed in appendix b.

In addition, personal data relating to criminal offences or legal proceedings, although not classified as sensitive personal data, may be subject to additional safeguards and restrictions in accordance with applicable laws and institutional requirements (see appendix c).

Further clarification of the terminology used in this policy is provided in the definitions section.

4. Scope

4.1 what information is included in this policy?

This policy covers all personal data that is collected, generated, or received as part of the university’s academic, administrative, research, or operational activities, regardless of the date of creation. Personal data may exist in various forms, including paper records, physical storage media, and electronic systems, and may be stored, processed, or transmitted through any of these formats.

4.2 to whom does this policy apply?

This policy applies to:

  • All individuals employed by or formally associated with the university who handle personal data as part of their roles or responsibilities;
  • All students who process or access personal data, other than publicly available information, during their academic, project, or research activities
  • Individuals engaged through third-party service providers, contractors, or subcontractors who process personal data while performing services for the university;
  • Interns, trainees, visiting scholars, research collaborators, and volunteers associated with the university;
  • Members of the university’s governing bodies or committees while carrying out their official functions.

All such individuals are hereinafter collectively referred to as “members”.

4.3 where does the policy apply?

This policy applies to all environments where university-related personal data is accessed or processed, including on-campus locations, off-site facilities, and remote working arrangements, as well as through digital and cloud-based platforms.

5. Data protection principles

The institution shall be accountable for, and capable of demonstrating, adherence to the following data protection principles in accordance with applicable indian data protection laws.

Personal data shall be:

  • Handled in a lawful, fair, and transparent manner with respect to the individual;
  • Collected and processed solely for clearly defined, specific, and legitimate purposes;
  • Relevant, adequate, and restricted to what is necessary for the intended purpose;
  • Maintained with accuracy and updated whenever required;
  • Stored only for the duration necessary to fulfill the purpose;
  • Protected through appropriate security measures to ensure confidentiality and integrity

These principles apply to all entities and individuals processing personal data within the institution. Non-compliance with these principles may result in violations under the applicable data protection regulations. A detailed explanation of each principle is provided in the subsequent sections.

5.1 processing of personal data in a lawful, fair and transparent manner

Whenever kare collects personal data, it is required to provide relevant information to the individual to whom the data relates. This obligation applies whether the data is obtained directly from the individual or indirectly through another source. Such information shall be communicated through a privacy notice (or equivalent notice in digital platforms such as websites or applications). Additionally, kare must ensure that every processing activity is supported by a valid legal ground as prescribed under applicable indian data protection laws, including the digital personal data protection act, 2023.

5.1.1 privacy notices

When should a privacy notice be provided?

  • If personal data is collected directly from the individual, the privacy notice must be provided at the time of data collection.
  • If personal data is collected from another source, the privacy notice must be provided:
    • Within a reasonable period, not exceeding one month from the date of collection;
    • At the time of first communication with the individual, if the data is used for communication purposes;
    • At the time of first disclosure, if the data is intended to be shared with another party

What information must be included in a privacy notice?

The privacy notice must clearly inform individuals about:

  • The identity of the institution collecting the data (e.g., kalasalingam academy of research and education or specific departments);
  • The purpose(s) for which the personal data is being collected and used;
  • The legal basis or authorization under which the data is processed;
  • The categories and nature of personal data being processed;
  • The duration for which the data will be retained;
  • Details of recipients or categories of recipients with whom the data may be shared;
  • Contact details of the designated data protection officer or responsible authority;
  • Information regarding any transfer of personal data outside india along with applicable safeguards;
  • In cases of indirect data collection, the source and categories of such data.

Individuals must also be informed about their rights in relation to personal data (refer Section 5.6 – Data Subject Rights).

Additional information to be provided to individuals.

KARE shall also ensure that individuals are made aware of

  • Their right to file a complaint with the Data Protection Board of India;
  • The consequences, if any, of not providing the requested personal data;
  • The existence of automated processing or profiling, where applicable;
  • Applicable rights such as withdrawal of consent, correction, erasure, access, data portability, restriction, and objection, depending on the context of processing.

Further operational details may be defined in KARE’s internal Privacy Notice procedures.

Legal Basis for Processing

To lawfully process personal data, KARE must identify and document a valid legal basis before initiating processing activities. The applicable legal grounds, aligned with Indian data protection principles, include:

  • Consent: The individual has voluntarily provided clear and informed consent for a specific purpose;
  • Contractual necessity: Processing is required to fulfill a contract with the individual or to take pre-contractual steps;
  • Legal obligation: Processing is necessary to comply with applicable laws or regulatory requirements;
  • Protection of vital interests: Processing is required to protect the life or safety of an individual;
  • Public function: Processing is necessary for performing tasks in the public interest or institutional responsibilities;
  • Legitimate use: Processing is reasonably necessary for lawful institutional purposes, provided it does not override the individual’s rights.

KARE shall record the selected legal basis in its Privacy Notices and maintain proper documentation in institutional records of data processing.

Conditions relating to Consent

Where consent is relied upon, KARE must ensure that:

  • Consent is free, specific, informed, and unambiguous.
  • Consent is obtained through a clear affirmative action.
  • Records of consent are properly maintained.
  • Individuals are allowed to withdraw consent at any time without adverse consequences.

Legitimate Use / Institutional Interest

Where processing is based on legitimate institutional interests, KARE may conduct an internal assessment to ensure that such processing does not adversely impact the rights and freedoms of individuals.

Further details regarding legal bases and consent mechanisms may be provided in internal appendices or guidelines.

Special Categories of Personal Data and Criminal Data

For processing sensitive or special categories of personal data, KARE must ensure that:

  • The processing satisfies both a valid legal basis and additional safeguards as required under Indian law;
  • Enhanced protection measures are applied due to the sensitive nature of such data.

Similarly, personal data relating to criminal records or offences must be handled with stricter controls and only under authorized conditions, ensuring full compliance with applicable legal provisions.

All such processing activities must be properly documented to demonstrate compliance and accountability.

5.1.2 Processing of Personal Data for Specific, Clear and Lawful Purposes (“Purpose Limitation”)

Members shall ensure that:

  • Personal data is retained only for purposes that are clearly defined, lawful, and explicitly communicated through an appropriate privacy notice;
  • Processing activities are carried out strictly in line with the stated purposes and not beyond them;
  • Personal data is used in a manner that is fair and consistent with the reasonable expectations of the individual;
  • Data is not repurposed for any unrelated activity without proper authorization or without informing the individual, unless permitted under applicable law;
  • All collection and processing activities are supported by at least one valid legal basis as prescribed under applicable data protection regulations (refer Appendix A).

5.1.3 Ensuring Personal Data is Relevant, Adequate and Limited (“Data Minimisation”)

Members shall:

  • Collect only such personal data that is strictly necessary and relevant for achieving the intended purpose as specified in the privacy notice;
  • Avoid excessive or unnecessary data collection beyond what is required;

Further:

  • Personal data shall be shared or disclosed only when it is essential and aligned with the original purpose of collection;
  • Additional care must be taken while handling sensitive or special categories of personal data, and such data shall only be disclosed where explicit consent or another valid legal basis exists (refer Appendix A).

5.1.4 Maintaining Accuracy of Personal Data (“Accuracy”)

Members shall ensure that:

  • Personal data processed by KARE is accurate, reliable, and updated whenever required;
  • Appropriate mechanisms and internal procedures are implemented to maintain data accuracy, including regular verification, review, and audits;
  • Reasonable steps are taken to correct or update inaccurate or incomplete data without delay.

5.1.5 Retention of Personal Data for Limited Duration (“Storage Limitation”)

Members shall:

  • Clearly define the retention period for personal data along with the justification for retaining such information;
  • Ensure that personal data is not retained longer than necessary for the purpose(s) for which it was collected;
  • Ensure that personal data is not retained longer than necessary for the purpose(s) for which it was collected;

Additionally:

  • Members must adhere to KARE’s Records Management Policy and follow approved Records Retention Schedules to ensure that data is retained only for appropriate durations;
  • Personal data may be retained for longer periods only where it is required for archival purposes in public interest, academic research, historical documentation, or statistical analysis, provided that suitable technical and organisational safeguards are implemented to protect the rights and freedoms of individuals.

5.1.6 Ensuring Security of Personal Data (“Integrity and Confidentiality”)

Members shall implement suitable technical and organisational safeguards to protect personal data against risks such as:

  • Weak or improper access controls that may permit misuse of data;
  • Unauthorized modification, deletion, or destruction of data;
  • Disclosure of personal data to individuals who are not authorized to receive it;
  • Attempts to compromise systems, including cyber-attacks, malware, hacking, or similar threats;
  • Accidental loss or theft of data;
  • Processing activities that are unlawful or not in compliance with applicable regulations.

While applicable Indian data protection laws, including the Digital Personal Data Protection Act, 2023, may not prescribe exact security controls, they require institutions to consider:

  • The current state of technological advancements
  • The nature and sensitivity of the personal data;
  • The potential impact or harm that may arise from unauthorized access or misuse.

KARE shall follow internal information security frameworks and institutional policies to ensure continuous protection of personal data, including adherence to its IT Security Policy and Acceptable Usage Policy

In cases where personal data is transferred outside India, appropriate safeguards, contractual arrangements, and security controls must be established to ensure that the privacy rights of individuals are adequately protected (refer Section 5.11).

Members must seek guidance from the designated Data Protection Officer or relevant authority within KARE before initiating any such cross-border data transfer.

5.1.7 Accountability

Under applicable data protection laws, KARE, as a data fiduciary, is responsible for ensuring and demonstrating compliance with all data protection principles. This requires the institution to:

  • Maintain comprehensive records of all data processing activities, commonly referred to as a Record of Processing Activities (ROPA) (see Section 5.2).
  • Establish and implement appropriate technical and organisational measures to ensure compliance and demonstrate accountability.
  • Adopt and enforce the principles of privacy by design and by default (see Section 5.3), including:

    • Limiting data collection to what is necessary (data minimisation).
    • Applying techniques such as pseudonymisation where appropriate.
    • Ensuring transparency in all data processing activities.
    • Continuously strengthening and updating security measures.
  • Conduct Data Protection Impact Assessments (DPIAs) wherever required, especially for high-risk processing activities.
  • Maintain proper records of all personal data breaches and incidents, and take necessary corrective actions (refer Section 5.5).

5.2 RECORDS OF PROCESSING ACTIVITIES (ROPA)

To ensure proper documentation and transparency in data handling practices, KARE shall maintain a centralized Record of Processing Activities (ROPA). This record will include details such as:

  • Categories of personal data processed by the institution in its role as a data fiduciary;
  • The purposes for which such data is processed;
  • The legal basis supporting each processing activity;
  • Details of entities or individuals with whom the data may be shared;
  • The storage location of the data;
  • The duration for which the data is retained.

KARE shall also maintain a ROPA in situations where it processes personal data on behalf of another entity, acting in the capacity of a data processor.

All Schools, Departments, and functional units within KARE are responsible for documenting relevant information required for the preparation and maintenance of the ROPA. This activity shall be coordinated by the designated Data Protection Officer or authorized compliance authority.

Designated representatives or coordinators within each unit shall facilitate the collection and submission of required information, in consultation with the respective Heads of Departments/Units. The Heads shall ensure timely submission of accurate information and must promptly notify the compliance authority of any changes in personal data processing activities within their respective areas.

5.3 PRIVACY BY DESIGN AND BY DEFAULT

The principles of Privacy by Design and Privacy by Default are integral to data protection practices and are embedded within modern data protection frameworks, including the Digital Personal Data Protection Act, 2023.

Privacy by Design requires that data protection considerations are incorporated into every stage of any activity involving personal data. This includes institutional processes such as project planning, research initiatives, system development, software applications, and IT infrastructure. KARE shall ensure that privacy safeguards are built into systems and processes throughout their entire lifecycle.

Privacy by Default ensures that, by default, only the minimum necessary personal data is collected, processed, and retained. Systems and services should be configured with the highest level of privacy settings automatically, without requiring intervention from individuals. Any personal data provided must be limited to what is strictly necessary for delivering the intended service. Collection or retention of excessive data would be considered a violation of this principle.

Members shall apply these principles while handling personal data by:

  • Conducting a Data Protection Impact Assessment (DPIA) (refer Section 5.4) in cases where processing is likely to pose a high risk to individuals’ rights, particularly when introducing new technologies;
  • Undertaking a DPIA when large-scale processing, profiling, or handling of sensitive personal data or criminal-related data is involved;
  • Ensuring that only the minimum required personal data is collected, used, and retained for the intended purpose;
  • Applying anonymisation or de-identification techniques wherever feasible and appropriate.

5.4 DATA PROTECTION IMPACT ASSESSMENT (DPIA)

When KARE processes personal data, there may be potential risks to the rights and freedoms of individuals. A Data Protection Impact Assessment (DPIA) is a structured process used to identify, evaluate, and minimize such risks at an early stage.

The purpose of a DPIA is to enable KARE to anticipate possible data protection concerns before they arise and to implement appropriate mitigation measures in advance.

Under applicable data protection laws, a DPIA is mandatory in situations where data processing is likely to result in a high risk to individuals, especially in cases involving:

  • Introduction of new technologies;
  • Large-scale data processing activities;
  • Research projects involving sensitive personal data.

Even in situations where it is not explicitly required, conducting a DPIA is considered a best practice and supports compliance with data protection obligations.

KARE may provide internal tools or frameworks to assist staff and researchers in determining whether a DPIA is necessary for a specific activity.

Detailed procedures and guidance on conducting DPIAs shall be made available through institutional policies or internal documentation.

It is important to note that the DPIA process is separate from ethical review procedures and may be required in addition to institutional ethics approvals.

5.5 PERSONAL DATA SECURITY BREACHES

In the event of any compromise involving personal data, it is essential that the situation is addressed promptly and effectively to reduce potential harm and prevent recurrence. If any member of KARE becomes aware of an actual, suspected, or potential personal data breach, they must immediately inform their respective Head of Department/Unit.

The Head of Department/Unit shall promptly escalate the matter to the designated Data Protection Officer or authorized compliance authority by submitting a Personal Data Breach Report Form through the prescribed communication channel.

All Members are required to act without delay and report any such incidents as soon as they are identified.

KARE shall take all necessary measures to mitigate the impact of personal data breaches by following its established Personal Data Breach Management Procedures. Where a breach is likely to pose a risk to the rights and freedoms of individuals, the designated authority shall coordinate with the appropriate regulatory body, such as the Data Protection Board of India, and report the incident within the timelines prescribed under applicable law.

Where necessary, affected individuals shall be informed, and appropriate remedial actions shall be recommended to minimize risks to their privacy and personal data.

5.6 DATA SUBJECT RIGHTS

Under applicable data protection laws in India, individuals (data principals) are entitled to certain rights regarding their personal data.

5.6.1 Right to be Informed

Individuals have the right to receive clear and transparent information about how their personal data is collected, used, and processed. This forms a fundamental aspect of transparency and is addressed through Privacy Notices (refer relevant section above).

5.6.2 Right of Access

Individuals have the right to request access to their personal data held by KARE, along with relevant details about how such data is processed.

KARE shall respond to such requests within a reasonable timeframe as prescribed under applicable law.

Any request received by a Member must be promptly forwarded to the designated Data Protection Officer or compliance authority, who will coordinate the response in consultation with relevant departments, while considering any permissible exemptions under the law.

Disclosure of personal data to third parties (such as parents, employers, or external organizations) shall not be made without the individual’s consent or another valid legal basis, unless required by law.

5.6.3 Right to Rectification

Individuals have the right to request correction of inaccurate or incomplete personal data.

Such requests may be made verbally or in writing, and KARE shall respond within the prescribed time limits. Requests for rectification must be forwarded immediately to the designated authority for appropriate action.

In certain cases, requests may be declined in accordance with applicable legal provisions.

5.6.4 Right to Erasure

Individuals may request deletion of their personal data, subject to applicable conditions. This is commonly referred to as the “right to erasure.”

Requests can be submitted verbally or in writing, and KARE shall process them within the stipulated timeframe. However, this right is not absolute and may be limited based on legal or operational requirements.

All such requests must be reported promptly to the designated authority for review and action.

5.6.5 Right to Restrict Processing

Individuals have the right to request limitation or suspension of the processing of their personal data under certain conditions.

During such restriction, KARE may retain the data but shall not actively process it unless permitted by law.

Requests may be submitted verbally or in writing and must be addressed within the specified timeframe. All such requests must be communicated to the designated authority without delay.

5.6.6 Right to Data Portability

Individuals have the right to obtain and reuse their personal data across different platforms or services in a structured and secure manner.

This right applies only when:

  • The data has been provided by the individual;
  • Processing is based on consent or contractual necessity;
  • Processing is carried out through automated means.

All portability-related requests must be forwarded to the designated authority for appropriate handling.

5.6.7 Right to Object

Individuals have the right to object to certain types of data processing, including:

a) Processing based on legitimate use or public functions (including profiling):

  • Objections must be based on specific personal circumstances;
  • KARE must discontinue processing unless it can demonstrate overriding legitimate grounds or the necessity for legal claims;
  • Individuals must be informed of this right at the time of initial communication and through Privacy Notices, in a clear and prominent manner.

b) Direct marketing (including profiling):

  • Processing for direct marketing must cease immediately upon objection;
  • No exceptions apply in such cases;
  • Individuals must be provided with an easy and free mechanism to opt out of communications;
  • Each communication must include an option to unsubscribe or manage preferences.

c) Processing for research, historical, or statistical purposes:

  • Individuals may object based on their specific situation;
  • However, objections may not apply where processing is necessary for public interest research purposes, subject to applicable safeguards.;

5.6.8 Rights related to Automated Decision-Making and Profiling

KARE shall ensure that individuals are provided with mechanisms, including online options where applicable, to object to automated decision-making processes.

Individuals have the right not to be subjected to decisions made solely through automated processing, including profiling, where such decisions have significant legal or similar effects on them, unless:

  • Explicit consent has been obtained; ;
  • The processing is necessary for contractual purposes; or
  • It is authorized under applicable law.

5.7 External Data Processors and Joint Data Controllership

At times, KARE may engage third-party service providers (data processors) to support its operations. Where such services involve processing or hosting of personal data (including student, staff, or research data) on behalf of the institution, appropriate due diligence and safeguards must be established before any data is shared. Relevant procedures such as institutional vendor management or IT procurement guidelines must be followed prior to engagement.

As a data fiduciary under applicable Indian law, KARE is responsible for determining the purpose and means of processing personal data under its control, including but not limited to academic, administrative, and alumni-related data. The institution must ensure not only its own compliance with applicable data protection laws but also verify that any external processors adhere to equivalent standards of data protection and security.

There may be situations where KARE jointly determines the purpose and means of processing personal data along with another institution or organization. In such cases of joint data controllership, a formal agreement shall be established clearly defining the respective roles, responsibilities, and obligations of each party, including provisions related to compliance, data subject rights, and accountability.

5.8 Transfers of Personal Data Outside of India

Applicable Indian data protection laws, including the Digital Personal Data Protection Act, 2023, may impose conditions on the transfer of personal data outside India. Such restrictions are intended to ensure that the level of protection afforded to individuals’ personal data is not compromised when data is transferred internationally.

KARE shall ensure that any transfer of personal data beyond national boundaries is carried out in accordance with legal requirements and government-notified conditions. Transfers may be permitted to jurisdictions approved by the Government of India or subject to compliance with prescribed safeguards.

Personal data may be transferred internationally where the receiving entity provides adequate assurances regarding data protection, security measures, and enforceability of data subject rights. Such safeguards must ensure that individuals have access to effective remedies in case of misuse or breach.

Appropriate safeguards for international data transfers may include:

  • Legally enforceable agreements between institutions or authorities;
  • Internal corporate policies governing cross-border data transfers within affiliated entities;
  • Standard contractual clauses or agreements incorporating data protection obligations;
  • Adherence to approved codes of practice or certification mechanisms, where applicable;
  • Contractual commitments ensuring data protection compliance by the recipient organization;
  • Or other mechanisms as may be prescribed by the Government of India.

Where KARE intends to transfer personal data outside India, it must consult the designated Data Protection Officer or relevant compliance authority within the institution to ensure legal compliance. Where necessary, a risk assessment of the destination country’s data protection framework may also be undertaken before proceeding with such transfers.

5.9 Marketing / Mailing Lists / Electronic Privacy Regulations

In India, electronic communications and digital marketing practices are governed by applicable provisions of the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and related rules and guidelines. These laws provide individuals with specific rights concerning the use of their personal data in electronic communications and prescribe obligations for organizations engaging in such activities.

These regulations address, among other things:

  • Promotional communications through phone calls, emails, SMS, and other electronic means;
  • Use of cookies and similar tracking technologies on websites and applications;
  • Ensuring the security and integrity of communication systems; and
  • Protection of user privacy in relation to communication data, including usage details and identifiers.

Although these requirements are particularly relevant to telecommunications and internet service providers, they are equally applicable to institutions such as KARE when using electronic communication channels to engage with students, staff, alumni, or the public.

Unsolicited or unauthorized direct marketing communications are a common source of complaints. Failure to comply with applicable legal requirements may result in regulatory action, as each non-compliant communication may be treated as a separate violation.

Before using personal data for marketing or outreach purposes, KARE must ensure that appropriate consent mechanisms, opt-in provisions, and opt-out facilities are clearly established through privacy notices or other means.

Where Members use personal data to disseminate information regarding institutional programs, events, or activities, every communication must include a clear and simple method for recipients to unsubscribe or withdraw from future communications.

All Members must adhere to institutional guidelines and best practices on direct marketing communications when sending messages on behalf of KARE.

5.10 Personal Data relating to Criminal Convictions/Offences (including Background Verification)

Processing personal data relating to criminal history, convictions, or offences requires a valid legal basis under applicable Indian laws, including the Digital Personal Data Protection Act, 2023, along with appropriate authorization under relevant statutory or regulatory provisions. Such processing must be justified, necessary, and documented prior to initiation.

Where background verification or similar checks are conducted (for example, during recruitment or collaborations), the information obtained must be handled with strict confidentiality and stored securely. Access to such sensitive information must be limited only to authorized personnel on a need-to-know basis.

KARE shall implement internal procedures governing the secure handling, retention, and disclosure of such data, in line with applicable laws and institutional policies.

Further guidance on handling such data and related compliance requirements may be obtained from the institution’s Data Protection Officer or designated compliance authority.

5.11 Profiling and/or Automated Decision Making

Profiling refers to any form of automated processing of personal data used to evaluate, analyze, or predict aspects relating to an individual’s characteristics, such as academic performance, professional behavior, financial status, health conditions, personal preferences, interests, reliability, location, or activities.

A distinction exists between profiling and automated decision-making. In practice, profiling may occur in the following ways:

  • General profiling, where personal data is analyzed to identify patterns or characteristics;
  • Decision-making supported by profiling, where a human makes the final decision based on automated analysis; and
  • Fully automated decision-making, where decisions are made solely by technological systems without human involvement, and which may significantly impact the individual.

While such technologies can enhance efficiency and decision-making processes, their use is subject to legal and ethical considerations. Applicable laws place restrictions on automated decision-making, particularly where such decisions have significant or legal effects on individuals.

KARE shall ensure that:

  • Profiling and automated processing are carried out in a lawful, fair, and transparent manner;
  • Individuals are informed about the existence and purpose of such processing;
  • Appropriate safeguards are implemented to protect individual rights and interests; and
  • Automated decisions with significant impact are not made without necessary authorization, consent, or legal basis.

Where applicable, individuals must be provided with the ability to seek human intervention, express their views, or contest decisions made through automated means.

Members are encouraged to consult the Data Protection Officer or designated authority within KARE for advice and guidance before implementing profiling or automated decision-making processes.

5.12 CCTV

The use of Closed-Circuit Television (CCTV) systems at KARE, except for purely personal or domestic purposes, shall be carried out in accordance with applicable Indian data protection and privacy laws, including the Digital Personal Data Protection Act, 2023, and relevant provisions of the Information Technology Act, 2000. Guidance issued by competent authorities shall also be taken into consideration.

In general, the deployment of CCTV systems must be justified, proportionate, and limited to clearly defined purposes such as safety, security, and asset protection. Since CCTV surveillance involves the collection of individuals’ visual data, it directly affects privacy rights; therefore, a valid and legitimate reason must exist before installation. The purpose of surveillance must be clearly communicated through visible signage placed in appropriate locations.

Prior to installing or significantly modifying any CCTV system within the institution, Members must consult with the designated authority responsible for legal and data protection compliance (such as the Data Protection Officer or equivalent authority at KARE). Additionally, a Data Protection Impact Assessment (DPIA) or equivalent risk assessment shall be conducted to evaluate potential privacy risks and ensure appropriate safeguards are implemented.

5.13 Children’s Personal Data

Under applicable Indian data protection law, including the Digital Personal Data Protection Act, 2023, children are recognized as a category requiring enhanced protection, given their vulnerability and limited capacity to fully understand the implications of data processing.

KARE shall ensure that personal data relating to children is handled with heightened care and responsibility. Processing of such data must be carried out in a lawful, fair, and transparent manner, with appropriate safeguards in place to protect the interests and rights of children.

Specific guidelines, including requirements relating to parental or guardian consent and limitations on processing activities involving children’s data, shall be followed in accordance with institutional policies and applicable legal provisions. Detailed procedures governing the handling of children’s personal data are provided in the relevant appendix of this policy.

6. Roles and Responsibilities

Kalasalingam Academy of Research and Education (KARE) holds primary responsibility for ensuring compliance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023. However, responsibility for protecting personal data is shared across the institution. All employees who handle personal data as part of their duties, individuals engaged through placements or deputation, and students who process personal data during academic, research, or employment activities within KARE are equally responsible for adhering to data protection requirements.

KARE shall provide necessary guidance, support, training, and awareness programs to departments, faculty, staff, and students to facilitate compliance with applicable laws and this policy. The designated Data Protection Officer (or equivalent authority) will assist the institution and its Members in fulfilling their obligations under data protection legislation.

The following roles and responsibilities are defined under this Policy:

All users of KARE information systems:

  • Must participate in training and awareness initiatives organized by KARE to ensure understanding and compliance with this Policy;
  • Are expected to take all reasonable precautions to prevent any compromise of data security arising from their actions;
  • Must promptly report any actual or suspected personal data breaches to their respective Head of Department/School, who shall escalate the matter to the Data Protection Officer or designated authority without delay;
  • Must ensure that any personal information they have provided to KARE (such as contact details, identification information, or financial details) is accurate and updated whenever changes occur.

Institutional Leadership / Administration:

  • The senior leadership of KARE is responsible for reviewing, endorsing, and ensuring implementation of this Policy;
  • Each member of the leadership team is accountable for ensuring compliance with applicable data protection laws and institutional policies within their respective functional areas;
  • Leadership members shall periodically provide formal assurance that their respective units adhere to data protection requirements as part of institutional governance and internal control mechanisms.

Registrar / Senior Administrative Authority:

The Registrar or designated senior administrative authority shall act as the key official responsible for overseeing institutional compliance with data protection requirements, including:

  • Ensuring periodic review, approval, and implementation of this Policy;
  • Establishing and maintaining appropriate policies, procedures, and controls to support data protection compliance;
  • Coordinating with institutional leadership on data protection matters;
  • Ensuring that incidents involving personal data breaches are appropriately managed and addressed.

Heads of Departments / Schools:

Heads of Departments or Schools are responsible for:

  • Ensuring adherence to data protection laws and this Policy within their respective units;
  • Designating an appropriate staff member to coordinate data protection-related activities within their department;
  • Supporting the maintenance of institutional records of data processing activities by compiling, validating, and submitting relevant information in coordination with designated personnel;
  • Ensuring timely reporting and handling of any data protection concerns or incidents within their area.

Data Protection Officer (DPO) / Designated Authority:

The Data Protection Officer or designated compliance authority is responsible for overseeing operational aspects of data protection across KARE. Key responsibilities include:

  • Handling and responding to data access requests from individuals;
  • Managing requests related to correction, deletion, restriction, or objection to data processing;
  • Periodically reviewing and updating data protection policies, procedures, and documentation;
  • Providing guidance on Data Protection Impact Assessments (DPIAs) and related risk evaluations;
  • Acting as the primary liaison with regulatory authorities where required, including in the event of a data breach;
  • Maintaining records of all personal data breaches and ensuring appropriate response measures;
  • Organizing training, awareness sessions, and capacity-building programs for staff and students;
  • Offering ongoing advice and support on data protection compliance;
  • Maintaining centralized records of data processing activities (ROPA or equivalent);
  • Documenting and monitoring institutional compliance with applicable data protection laws.

Designated Data Protection Coordinators (Department Level):

Each Department/School that processes personal data should nominate a staff member to act as a Data Protection Coordinator. Their responsibilities include:

  • Serving as a liaison between their department and the Data Protection Officer;
  • Compiling and maintaining records of personal data processing activities within their department;
  • Communicating relevant updates, guidelines, and security practices to staff and stakeholders;
  • Participating in data protection and information security training programs as required.

Staff, Students, and Other Members of KARE:

All Members of KARE are expected to:

  • Familiarize themselves with and comply with the provisions of this Policy;
  • Understand the meaning of personal data and sensitive personal data, and handle such information responsibly;
  • Be aware of the legal basis and conditions for processing personal data;
  • Ensure that their actions do not compromise data privacy or violate applicable laws;
  • Immediately report any data breach or suspected incident to the appropriate authority;
  • Seek clarification from the Data Protection Officer or designated authority whenever they are uncertain about data protection requirements.

7. Breach of This Policy

Any violation or non-compliance with this Policy may result in appropriate disciplinary action in accordance with the institutional rules and regulations of KARE, including applicable staff service rules and student conduct regulations, as revised from time to time.

8. Supporting Policies, Procedures & Guidelines

This Policy establishes a structured framework to support KARE’s compliance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023. However, it does not serve as a comprehensive or exhaustive interpretation of all legal provisions relating to data protection.

For any specific queries, clarifications, or concerns related to personal data processing, Members are advised to contact the Data Protection Officer or the designated authority within KARE.

This Policy should be read together with the following institutional policies, procedures, and guidelines:

  • Data Protection Impact Assessment (DPIA) Procedure
  • Privacy Notice / Data Protection Notice Procedure
  • Records Retention and Management Policy
  • Information Security Policy
  • Acceptable Usage Policy (AUP)
  • Guidelines for Use of Portable Storage Devices
  • Guidelines for Mobile and Smartphone Usage
  • Procedures for Secure Disposal of Devices Containing Sensitive Data
  • Personal Data Breach Response and Management Procedure
  • Web Usage and Social Media Policy
  • Research Ethics and Code of Conduct

In addition, compliance with the following Indian laws and regulations must be ensured alongside this Policy:

  • Digital Personal Data Protection Act, 2023
  • Information Technology Act, 2000 and applicable Rules

9. Definitions

The Digital Personal Data Protection Act, 2023 and related Indian laws regulate the processing of personal data. The terms used within this Policy carry specific legal meanings. Key definitions relevant to this Policy are provided below, with explanatory notes where appropriate:

Personal Data

Personal data refers to any information relating to:

(a) an identified individual; or

(b) an individual who can be identified, directly or indirectly, particularly by reference to:

  • Identifiers such as name, identification number, location data, or online identifiers; or
  • One or more characteristics related to the individual’s physical, physiological, genetic, mental, economic, cultural, or social identity.

This definition is broad and may vary depending on the context in which the data is used.

Special Categories of Personal Data (Sensitive Personal Data)

Certain types of personal data require enhanced protection under applicable laws. These include:

  • Racial or ethnic origin;
  • Political beliefs or affiliations;
  • Religious or philosophical beliefs;
  • Trade union membership;
  • Genetic or biometric information used for identification;
  • Health-related data;
  • Data relating to an individual’s sex life or sexual orientation.

Processing of such data requires stricter safeguards and conditions under applicable law.

Although information relating to criminal convictions or offences is not always classified under this category, it is subject to additional safeguards and protections.

Data Concerning Health

This refers to personal data related to an individual’s physical or mental health condition, including details about medical history, diagnosis, treatment, or healthcare services, which indicate the health status of the individual.

Data Subject (Data Principal)

A data subject (referred to as a Data Principal under Indian law) is the individual to whom the personal data relates.

Data Controller (Data Fiduciary)

A data controller (or Data Fiduciary) is an individual or organization that determines the purpose and means of processing personal data, either independently or jointly with others. KARE acts as a Data Fiduciary with respect to personal data of its students, staff, and other stakeholders.

Data Owner

The data owner is typically the senior-most official within a department, school, or administrative unit where the data originates. This role may be formally delegated. The data owner is responsible for ensuring the accuracy, quality, and integrity of the data within their domain.

Data Processor (Data Fiduciary)

A data processor is any individual or entity that processes personal data on behalf of a data controller/data fiduciary. This does not include employees processing data as part of their official duties within the institution. Examples include third-party service providers such as payroll agencies, auditors, or survey agencies.

Direct Marketing

Direct marketing refers to:

“the communication, through any medium, of advertising or promotional material directed at specific individuals.”

This includes promotional messages related to services, programs, events, or campaigns, including those by non-profit or educational institutions.

Such communication is considered direct marketing when it is targeted at identifiable individuals. Most electronic communications such as emails, phone calls, SMS, and messages fall within this category.

Market research activities are generally excluded; however, if such activities include promotional intent or data collection for future marketing, they will be treated as direct marketing.

Unsolicited communication refers to messages that individuals have not explicitly requested. Even where prior consent (opt-in) exists, such communications are still considered unsolicited, though they may be lawful if compliant with applicable regulations.

Members

Within this Policy, “Members” includes:

  • Employees or individuals engaged by KARE who process personal data as part of their work;
  • Students who handle personal data during academic, research, or institutional activities;
  • Individuals employed by contractors or service providers who process personal data on behalf of KARE.

Processing

Processing refers to any operation performed on personal data, whether by automated means or otherwise, including:

  • Collection, recording, organization, structuring, or storage;
  • Modification, adaptation, or alteration;
  • Retrieval, consultation, or use;
  • Disclosure through transmission, dissemination, or making data available;
  • Alignment or combination;
  • Restriction, deletion, or destruction.

This definition is intentionally broad and covers virtually all activities involving personal data.

Pseudonymisation

Pseudonymisation refers to processing personal data in such a way that it can no longer be directly associated with a specific individual without additional information. This additional information must be stored separately and protected through appropriate technical and organizational safeguards.

Even when data is pseudonymised, it is still considered personal data and remains subject to applicable data protection laws.

10. Policy Review and Approval

This Policy has been formally reviewed and approved by the competent authority of Kalasalingam Academy of Research and Education (KARE), such as the Institutional Leadership/Administrative Council or an equivalent governing body.

Any revisions, updates, or additions to this Policy or related documents shall be proposed by the Data Protection Officer or designated compliance authority and submitted to the appropriate institutional authority for review and approval, or to any body to which such responsibility has been formally delegated.

This Policy shall be reviewed periodically, at least once every two years, by the Data Protection Officer along with the designated administrative authority. Updates shall be made as necessary to reflect changes in applicable laws, including the Digital Personal Data Protection Act, 2023, technological advancements, or institutional requirements.

11. Further Information

For any questions, clarifications, or additional information regarding this Policy or matters related to personal data protection, Members may contact the Data Protection Officer or the designated authority at KARE.

Relevant contact details shall be made available through official institutional communication channels.

12. Miscellaneous

Kalasalingam Academy of Research and Education (KARE) retains the right to modify, update, or withdraw this Policy at any time, without prior notice, in a manner deemed appropriate by the University. Such decisions may be taken at the discretion of the University administration or the Hon’ble Vice-Chancellor/Competent Authority.

13. Policies

Alumni and Supporters Data Protection Notice

Data Protection Policy

Student Data Protection Notice

Staff Data Protection Notice

Appendix A: Lawful Bases for Processing

Under applicable Indian data protection law, particularly the Digital Personal Data Protection Act, 2023, it is essential that every instance of personal data processing is supported by a valid legal ground. The following are the recognised lawful bases:

Consent from the Individual

The data principal must provide clear, informed, and specific consent before their personal data is processed. Consent must be given voluntarily and should be capable of being withdrawn at any time without negative consequences.

Performance of a Contract

Processing is permitted where it is necessary to fulfill obligations under a contract between KARE and the individual, or to take steps at the request of the individual prior to entering into such a contract. Example: Processing applicant data during recruitment or admission procedures.

Compliance with Legal Obligations

KARE may process personal data where required to meet statutory or regulatory obligations under Indian law.
Example: Maintenance of employee records, financial records, academic records, or compliance with government regulations.

Protection of Vital Interests

Processing is allowed where it is necessary to safeguard the life, health, or safety of the individual or another person.
Example: Sharing emergency medical information during a health crisis.

Public Interest / Official Function

Processing may be carried out when KARE performs functions that serve public interest, particularly in its role as an educational and research institution recognized under law.

Legitimate Uses (as per Indian framework)

Processing may also be undertaken for reasonable and lawful purposes aligned with institutional functions, provided such use does not override the rights and interests of the data principal.

In cases involving personal data related to criminal records or offences, such processing must strictly comply with applicable Indian laws and institutional policies, ensuring additional safeguards.

If there are any uncertainties regarding the appropriate legal basis for processing, guidance should be sought from the University’s designated Data Protection Officer (DPO) or relevant authority.

Appendix B: Conditions for Processing Special Categories of Personal Data

Under applicable Indian data protection law, particularly the Digital Personal Data Protection Act, 2023, certain types of personal data that are sensitive in nature require enhanced safeguards during processing.

Kalasalingam Academy of Research and Education (KARE) shall ensure that, in addition to having a valid lawful basis for processing personal data, specific conditions are satisfied before processing such sensitive categories of data.

Processing of such data may be carried out under the following conditions:

  • The data principal has provided explicit and informed consent for one or more clearly defined purposes, unless restricted by applicable law.
  • Processing is necessary to fulfill obligations or exercise rights related to employment, social security, or similar legal frameworks as permitted under Indian law.
  • Processing is required to protect the vital interests of the data principal or another individual where consent cannot reasonably be obtained.
  • Processing is undertaken by a not-for-profit body or institution (such as an educational or research institution) in the course of its legitimate activities, provided appropriate safeguards are implemented and the data is not disclosed externally without consent.
  • The personal data has been clearly made public by the data principal.
  • Processing is necessary for the establishment, exercise, or defense of legal claims, or for judicial proceedings.
  • Processing is required for reasons of substantial public interest, in accordance with applicable Indian laws, while ensuring proportionality and protection of individual rights.
  • Processing is necessary for medical purposes, including preventive or occupational health, diagnosis, treatment, or management of healthcare services, subject to confidentiality obligations.
  • Processing is required in the interest of public health, such as addressing health emergencies or ensuring safety and quality standards in healthcare systems.
  • Processing is carried out for research, statistical, archival, or historical purposes, provided appropriate safeguards are implemented to protect individual rights.

Note:

Relevant provisions under Indian law may provide additional grounds for processing sensitive personal data, including for purposes such as insurance, pensions, or regulatory compliance. KARE shall ensure adherence to all such applicable provisions.

Appendix C: Conditions for Processing Personal Data Related to Criminal Convictions or Offences

Personal data relating to criminal history, allegations, proceedings, or convictions is subject to additional protections under applicable data protection frameworks. While such data may not always fall under “special categories,” it requires careful handling due to its sensitive nature.

For KARE to process such data:

  • There must be a valid lawful basis under applicable Indian law, including provisions of the Digital Personal Data Protection Act, 2023.
  • The processing must be supported by legal authority, statutory requirement, or official institutional responsibility.
  • The purpose and justification for processing must be clearly identified and documented prior to processing.
  • Appropriate security and confidentiality safeguards must be implemented to prevent misuse or unauthorized disclosure.

In line with good governance practices:

  • Records relating to criminal data shall only be maintained where there is a legitimate institutional requirement and in accordance with applicable legal provisions;
  • Any comprehensive database or register of such information shall be maintained only under authorized supervision and control, ensuring compliance with relevant laws and institutional policies.

KARE shall ensure that all such processing activities are carried out with strict adherence to legal requirements, transparency, and respect for the rights of individuals.

Appendix D: Conditions for Consent

The Digital Personal Data Protection Act, 2023 lays down requirements for obtaining and managing consent for processing personal data:

  • Where processing is based on consent, Kalasalingam Academy of Research and Education (KARE) must be able to demonstrate that the data principal has provided valid consent for the processing of their personal data.
  • If consent is requested as part of a written document that includes other matters, the consent request must be clearly distinguishable, presented in a simple, understandable, and easily accessible format using clear language. Any unclear or misleading portion shall not be considered valid.
  • The data principal shall have the right to withdraw consent at any time. Withdrawal shall not affect the legality of processing carried out prior to such withdrawal. Individuals must be informed of this right before giving consent. The process of withdrawing consent must be as simple as giving consent.
  • While determining whether consent has been freely given, careful consideration must be given to whether services or contractual benefits are made conditional on consent for processing personal data that is not essential for the purpose of that contract.

Appendix E: Guidelines on Processing Personal Data Relating to Children

Children require enhanced protection when their personal data is collected and processed, as they may not fully understand the associated risks.

  • KARE shall ensure that systems and processes are designed with child protection as a priority, incorporating safeguards from the initial stage of data collection.
  • Adherence to data protection principles, especially fairness, transparency, and accountability, must be central when handling children’s personal data.
  • A valid legal basis must exist for processing children’s data. While consent may be used, other lawful grounds may sometimes be more appropriate depending on the context.
  • In accordance with the Digital Personal Data Protection Act, 2023, consent for processing children’s data must generally be obtained from a parent or lawful guardian, particularly in the context of online services directed at children.
  • Special care must be taken when using children’s data for marketing, behavioural analysis, or profiling activities, ensuring that such processing does not harm their interests.
  • KARE shall avoid making significant decisions based solely on automated processing involving children where such decisions may have legal or similarly impactful consequences.
  • Privacy notices intended for children must be written in clear, simple language so that they can understand how their data will be used and what rights they have.
  • Children enjoy the same data protection rights as adults, including:
    • Right to access their personal data
    • Right to correction
    • Right to object to processing
    • Right to erasure
  • The right to erasure is especially important where consent was given during childhood.
  • Additional guidance issued by relevant Indian authorities should be referred to for best practices in handling children’s personal data.

Appendix F: Examples of Personal Data

The following are examples of information that may be considered personal data. This list is indicative and not exhaustive:

General Personal Data:

  • Names of individuals
  • Contact information (residential address, phone numbers, email IDs)
  • Date of birth and age
  • Place of birth, nationality, citizenship
  • Gender
  • Marital status
  • Government-issued identification details (e.g., Aadhaar, PAN, Passport)
  • Student or employee identification numbers
  • Family details (next of kin, dependents)
  • Photographs and images
  • Curriculum vitae (CVs) and resumes
  • Financial information (bank details, payment records)
  • Donation or contribution details
  • Salary or income information
  • Biometric identifiers (fingerprints, facial recognition data)
  • CCTV footage
  • Audio/video recordings identifying individuals
  • Employment records and history
  • Medical records, health reports, or sick leave details
  • Leave records (other than medical leave)
  • Educational qualifications and academic records
  • Performance evaluations
  • References for staff or students
  • Disciplinary or grievance records
  • Examination and assignment results
  • Memberships in professional bodies
  • Signatures (including digital signatures)
  • Passwords, PINs, and authentication credentials
  • Professional development records
  • Vehicle registration details
  • Research-related data linked to identifiable individuals
  • Online identifiers (IP addresses, login credentials)
  • Location data
  • Data relating to minors
  • Consent forms collected for research participation

Special Categories of Personal Data:

  • Racial or ethnic background
  • Biometric identifiers used for unique identification
  • Political views
  • Health-related information
  • Religious or philosophical beliefs
  • Information about an individual’s sex life or sexual orientation
  • Trade union membership
  • Genetic information

Criminal Data (Subject to Additional Safeguards):

  • Information relating to criminal offences or alleged offences
  • Details of legal proceedings, investigations, or court outcomes

Note:

  • Although data protection laws primarily apply to living individuals, KARE shall also handle information relating to deceased persons with due sensitivity and confidentiality.
  • While criminal offence-related data may not always fall under “special categories,” it is subject to enhanced protection requirements under applicable law and institutional policy.