CONTENTS:
1. Introduction
Data protection ensures that individualsâ privacy rights are safeguarded when their personal data is collected, processed, stored, or otherwise handled. Kalasalingam academy of research and education (âthe universityâ) collects and uses personal data relating to its students, faculty, staff, researchers, alumni, and other individuals who interact with the university, collectively referred to as âdata subjectsâ.
In order to respect and protect the privacy rights of these individuals, the university is committed to complying with applicable data protection laws and regulations, including the digital personal data protection act, 2023 (india), the information technology act, 2000, and relevant rules and guidelines issued by statutory and regulatory authorities such as the university grants commission (ugc) and other competent bodies (collectively referred to in this policy as âdata protection lawsâ).
These laws not only provide individuals with rights in relation to their personal data but also impose obligations and responsibilities on the university and all persons who process personal data on its behalf. The university recognizes its duty to ensure that personal data is handled in a lawful, fair, and transparent manner, and that appropriate technical and organizational measures are implemented to safeguard such data against unauthorized access, disclosure, alteration, or destruction.
This policy establishes the framework within which the university ensures compliance with data protection laws and promotes a culture of privacy, accountability, and responsible data management across all its academic, administrative, and research activities.
2. Purpose
This policy is a statement of the universityâs commitment to protect the rights and privacy of individuals in accordance with applicable data protection laws in india, including the digital personal data protection act, 2023 and the information technology act, 2000 (as amended) (collectively referred to in this policy as the âdata protection lawsâ).
It sets out responsibilities for all members of the university, including managers, employees, students, contractors, and any other individuals who may access or use personal data in the course of their work for, or studies with, the university.
3. Personal data and âsensitive personal dataâ
Personal data refers to any information that can be used to identify a living individual, either directly or indirectly. Even when separate pieces of information do not identify a person on their own, they may be considered personal data if, when combined, they can lead to the identification of an individual. Identifiers such as a personâs name, identification number, contact details, location data, or online identifiers, as well as characteristics related to physical, mental, economic, cultural, or social identity, may be used to recognize an individual.
In general, any information relating to a living person who can be identified from the available data, or from data that could reasonably be accessed, will be treated as personal data. This also includes pseudonymised data, where identifying details are replaced with codes or symbols. Although such data does not directly reveal the identity of the individual, identification may still be possible by linking it with additional information. Illustrative examples of personal data are provided in appendix f.
Certain types of personal data require a higher level of protection due to their sensitive nature. Under applicable indian laws, including the digital personal data protection act, 2023 and relevant provisions of the information technology act, 2000, such data is classified as âsensitive personal dataâ.
These include categories such as:
Processing of such sensitive personal data is permitted only under specific conditions, such as obtaining explicit consent from the individual or where processing is authorized by law, as detailed in appendix b.
In addition, personal data relating to criminal offences or legal proceedings, although not classified as sensitive personal data, may be subject to additional safeguards and restrictions in accordance with applicable laws and institutional requirements (see appendix c).
Further clarification of the terminology used in this policy is provided in the definitions section.
4. Scope
4.1 what information is included in this policy?
This policy covers all personal data that is collected, generated, or received as part of the universityâs academic, administrative, research, or operational activities, regardless of the date of creation. Personal data may exist in various forms, including paper records, physical storage media, and electronic systems, and may be stored, processed, or transmitted through any of these formats.
4.2 to whom does this policy apply?
This policy applies to:
All such individuals are hereinafter collectively referred to as âmembersâ.
4.3 where does the policy apply?
This policy applies to all environments where university-related personal data is accessed or processed, including on-campus locations, off-site facilities, and remote working arrangements, as well as through digital and cloud-based platforms.
5. Data protection principles
The institution shall be accountable for, and capable of demonstrating, adherence to the following data protection principles in accordance with applicable indian data protection laws.
Personal data shall be:
These principles apply to all entities and individuals processing personal data within the institution. Non-compliance with these principles may result in violations under the applicable data protection regulations. A detailed explanation of each principle is provided in the subsequent sections.
5.1 processing of personal data in a lawful, fair and transparent manner
Whenever kare collects personal data, it is required to provide relevant information to the individual to whom the data relates. This obligation applies whether the data is obtained directly from the individual or indirectly through another source. Such information shall be communicated through a privacy notice (or equivalent notice in digital platforms such as websites or applications). Additionally, kare must ensure that every processing activity is supported by a valid legal ground as prescribed under applicable indian data protection laws, including the digital personal data protection act, 2023.
5.1.1 privacy notices
When should a privacy notice be provided?
What information must be included in a privacy notice?
The privacy notice must clearly inform individuals about:
Individuals must also be informed about their rights in relation to personal data (refer Section 5.6 â Data Subject Rights).
Additional information to be provided to individuals.
KARE shall also ensure that individuals are made aware of
Further operational details may be defined in KAREâs internal Privacy Notice procedures.
Legal Basis for Processing
To lawfully process personal data, KARE must identify and document a valid legal basis before initiating processing activities. The applicable legal grounds, aligned with Indian data protection principles, include:
KARE shall record the selected legal basis in its Privacy Notices and maintain proper documentation in institutional records of data processing.
Conditions relating to Consent
Where consent is relied upon, KARE must ensure that:
Legitimate Use / Institutional Interest
Where processing is based on legitimate institutional interests, KARE may conduct an internal assessment to ensure that such processing does not adversely impact the rights and freedoms of individuals.
Further details regarding legal bases and consent mechanisms may be provided in internal appendices or guidelines.
Special Categories of Personal Data and Criminal Data
For processing sensitive or special categories of personal data, KARE must ensure that:
Similarly, personal data relating to criminal records or offences must be handled with stricter controls and only under authorized conditions, ensuring full compliance with applicable legal provisions.
All such processing activities must be properly documented to demonstrate compliance and accountability.
5.1.2 Processing of Personal Data for Specific, Clear and Lawful Purposes (âPurpose Limitationâ)
Members shall ensure that:
5.1.3 Ensuring Personal Data is Relevant, Adequate and Limited (âData Minimisationâ)
Members shall:
Further:
5.1.4 Maintaining Accuracy of Personal Data (âAccuracyâ)
Members shall ensure that:
5.1.5 Retention of Personal Data for Limited Duration (âStorage Limitationâ)
Members shall:
Additionally:
5.1.6 Ensuring Security of Personal Data (âIntegrity and Confidentialityâ)
Members shall implement suitable technical and organisational safeguards to protect personal data against risks such as:
While applicable Indian data protection laws, including the Digital Personal Data Protection Act, 2023, may not prescribe exact security controls, they require institutions to consider:
KARE shall follow internal information security frameworks and institutional policies to ensure continuous protection of personal data, including adherence to its IT Security Policy and Acceptable Usage Policy
In cases where personal data is transferred outside India, appropriate safeguards, contractual arrangements, and security controls must be established to ensure that the privacy rights of individuals are adequately protected (refer Section 5.11).
Members must seek guidance from the designated Data Protection Officer or relevant authority within KARE before initiating any such cross-border data transfer.
5.1.7 Accountability
Under applicable data protection laws, KARE, as a data fiduciary, is responsible for ensuring and demonstrating compliance with all data protection principles. This requires the institution to:
5.2 RECORDS OF PROCESSING ACTIVITIES (ROPA)
To ensure proper documentation and transparency in data handling practices, KARE shall maintain a centralized Record of Processing Activities (ROPA). This record will include details such as:
KARE shall also maintain a ROPA in situations where it processes personal data on behalf of another entity, acting in the capacity of a data processor.
All Schools, Departments, and functional units within KARE are responsible for documenting relevant information required for the preparation and maintenance of the ROPA. This activity shall be coordinated by the designated Data Protection Officer or authorized compliance authority.
Designated representatives or coordinators within each unit shall facilitate the collection and submission of required information, in consultation with the respective Heads of Departments/Units. The Heads shall ensure timely submission of accurate information and must promptly notify the compliance authority of any changes in personal data processing activities within their respective areas.
5.3 PRIVACY BY DESIGN AND BY DEFAULT
The principles of Privacy by Design and Privacy by Default are integral to data protection practices and are embedded within modern data protection frameworks, including the Digital Personal Data Protection Act, 2023.
Privacy by Design requires that data protection considerations are incorporated into every stage of any activity involving personal data. This includes institutional processes such as project planning, research initiatives, system development, software applications, and IT infrastructure. KARE shall ensure that privacy safeguards are built into systems and processes throughout their entire lifecycle.
Privacy by Default ensures that, by default, only the minimum necessary personal data is collected, processed, and retained. Systems and services should be configured with the highest level of privacy settings automatically, without requiring intervention from individuals. Any personal data provided must be limited to what is strictly necessary for delivering the intended service. Collection or retention of excessive data would be considered a violation of this principle.
Members shall apply these principles while handling personal data by:
5.4 DATA PROTECTION IMPACT ASSESSMENT (DPIA)
When KARE processes personal data, there may be potential risks to the rights and freedoms of individuals. A Data Protection Impact Assessment (DPIA) is a structured process used to identify, evaluate, and minimize such risks at an early stage.
The purpose of a DPIA is to enable KARE to anticipate possible data protection concerns before they arise and to implement appropriate mitigation measures in advance.
Under applicable data protection laws, a DPIA is mandatory in situations where data processing is likely to result in a high risk to individuals, especially in cases involving:
Even in situations where it is not explicitly required, conducting a DPIA is considered a best practice and supports compliance with data protection obligations.
KARE may provide internal tools or frameworks to assist staff and researchers in determining whether a DPIA is necessary for a specific activity.
Detailed procedures and guidance on conducting DPIAs shall be made available through institutional policies or internal documentation.
It is important to note that the DPIA process is separate from ethical review procedures and may be required in addition to institutional ethics approvals.
5.5 PERSONAL DATA SECURITY BREACHES
In the event of any compromise involving personal data, it is essential that the situation is addressed promptly and effectively to reduce potential harm and prevent recurrence. If any member of KARE becomes aware of an actual, suspected, or potential personal data breach, they must immediately inform their respective Head of Department/Unit.
The Head of Department/Unit shall promptly escalate the matter to the designated Data Protection Officer or authorized compliance authority by submitting a Personal Data Breach Report Form through the prescribed communication channel.
All Members are required to act without delay and report any such incidents as soon as they are identified.
KARE shall take all necessary measures to mitigate the impact of personal data breaches by following its established Personal Data Breach Management Procedures. Where a breach is likely to pose a risk to the rights and freedoms of individuals, the designated authority shall coordinate with the appropriate regulatory body, such as the Data Protection Board of India, and report the incident within the timelines prescribed under applicable law.
Where necessary, affected individuals shall be informed, and appropriate remedial actions shall be recommended to minimize risks to their privacy and personal data.
5.6 DATA SUBJECT RIGHTS
Under applicable data protection laws in India, individuals (data principals) are entitled to certain rights regarding their personal data.
5.6.1 Right to be Informed
Individuals have the right to receive clear and transparent information about how their personal data is collected, used, and processed. This forms a fundamental aspect of transparency and is addressed through Privacy Notices (refer relevant section above).
5.6.2 Right of Access
Individuals have the right to request access to their personal data held by KARE, along with relevant details about how such data is processed.
KARE shall respond to such requests within a reasonable timeframe as prescribed under applicable law.
Any request received by a Member must be promptly forwarded to the designated Data Protection Officer or compliance authority, who will coordinate the response in consultation with relevant departments, while considering any permissible exemptions under the law.
Disclosure of personal data to third parties (such as parents, employers, or external organizations) shall not be made without the individualâs consent or another valid legal basis, unless required by law.
5.6.3 Right to Rectification
Individuals have the right to request correction of inaccurate or incomplete personal data.
Such requests may be made verbally or in writing, and KARE shall respond within the prescribed time limits. Requests for rectification must be forwarded immediately to the designated authority for appropriate action.
In certain cases, requests may be declined in accordance with applicable legal provisions.
5.6.4 Right to Erasure
Individuals may request deletion of their personal data, subject to applicable conditions. This is commonly referred to as the âright to erasure.â
Requests can be submitted verbally or in writing, and KARE shall process them within the stipulated timeframe. However, this right is not absolute and may be limited based on legal or operational requirements.
All such requests must be reported promptly to the designated authority for review and action.
5.6.5 Right to Restrict Processing
Individuals have the right to request limitation or suspension of the processing of their personal data under certain conditions.
During such restriction, KARE may retain the data but shall not actively process it unless permitted by law.
Requests may be submitted verbally or in writing and must be addressed within the specified timeframe. All such requests must be communicated to the designated authority without delay.
5.6.6 Right to Data Portability
Individuals have the right to obtain and reuse their personal data across different platforms or services in a structured and secure manner.
This right applies only when:
All portability-related requests must be forwarded to the designated authority for appropriate handling.
5.6.7 Right to Object
Individuals have the right to object to certain types of data processing, including:
a) Processing based on legitimate use or public functions (including profiling):
b) Direct marketing (including profiling):
c) Processing for research, historical, or statistical purposes:
5.6.8 Rights related to Automated Decision-Making and Profiling
KARE shall ensure that individuals are provided with mechanisms, including online options where applicable, to object to automated decision-making processes.
Individuals have the right not to be subjected to decisions made solely through automated processing, including profiling, where such decisions have significant legal or similar effects on them, unless:
5.7 External Data Processors and Joint Data Controllership
At times, KARE may engage third-party service providers (data processors) to support its operations. Where such services involve processing or hosting of personal data (including student, staff, or research data) on behalf of the institution, appropriate due diligence and safeguards must be established before any data is shared. Relevant procedures such as institutional vendor management or IT procurement guidelines must be followed prior to engagement.
As a data fiduciary under applicable Indian law, KARE is responsible for determining the purpose and means of processing personal data under its control, including but not limited to academic, administrative, and alumni-related data. The institution must ensure not only its own compliance with applicable data protection laws but also verify that any external processors adhere to equivalent standards of data protection and security.
There may be situations where KARE jointly determines the purpose and means of processing personal data along with another institution or organization. In such cases of joint data controllership, a formal agreement shall be established clearly defining the respective roles, responsibilities, and obligations of each party, including provisions related to compliance, data subject rights, and accountability.
5.8 Transfers of Personal Data Outside of India
Applicable Indian data protection laws, including the Digital Personal Data Protection Act, 2023, may impose conditions on the transfer of personal data outside India. Such restrictions are intended to ensure that the level of protection afforded to individualsâ personal data is not compromised when data is transferred internationally.
KARE shall ensure that any transfer of personal data beyond national boundaries is carried out in accordance with legal requirements and government-notified conditions. Transfers may be permitted to jurisdictions approved by the Government of India or subject to compliance with prescribed safeguards.
Personal data may be transferred internationally where the receiving entity provides adequate assurances regarding data protection, security measures, and enforceability of data subject rights. Such safeguards must ensure that individuals have access to effective remedies in case of misuse or breach.
Appropriate safeguards for international data transfers may include:
Where KARE intends to transfer personal data outside India, it must consult the designated Data Protection Officer or relevant compliance authority within the institution to ensure legal compliance. Where necessary, a risk assessment of the destination countryâs data protection framework may also be undertaken before proceeding with such transfers.
5.9 Marketing / Mailing Lists / Electronic Privacy Regulations
In India, electronic communications and digital marketing practices are governed by applicable provisions of the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and related rules and guidelines. These laws provide individuals with specific rights concerning the use of their personal data in electronic communications and prescribe obligations for organizations engaging in such activities.
These regulations address, among other things:
Although these requirements are particularly relevant to telecommunications and internet service providers, they are equally applicable to institutions such as KARE when using electronic communication channels to engage with students, staff, alumni, or the public.
Unsolicited or unauthorized direct marketing communications are a common source of complaints. Failure to comply with applicable legal requirements may result in regulatory action, as each non-compliant communication may be treated as a separate violation.
Before using personal data for marketing or outreach purposes, KARE must ensure that appropriate consent mechanisms, opt-in provisions, and opt-out facilities are clearly established through privacy notices or other means.
Where Members use personal data to disseminate information regarding institutional programs, events, or activities, every communication must include a clear and simple method for recipients to unsubscribe or withdraw from future communications.
All Members must adhere to institutional guidelines and best practices on direct marketing communications when sending messages on behalf of KARE.
5.10 Personal Data relating to Criminal Convictions/Offences (including Background Verification)
Processing personal data relating to criminal history, convictions, or offences requires a valid legal basis under applicable Indian laws, including the Digital Personal Data Protection Act, 2023, along with appropriate authorization under relevant statutory or regulatory provisions. Such processing must be justified, necessary, and documented prior to initiation.
Where background verification or similar checks are conducted (for example, during recruitment or collaborations), the information obtained must be handled with strict confidentiality and stored securely. Access to such sensitive information must be limited only to authorized personnel on a need-to-know basis.
KARE shall implement internal procedures governing the secure handling, retention, and disclosure of such data, in line with applicable laws and institutional policies.
Further guidance on handling such data and related compliance requirements may be obtained from the institutionâs Data Protection Officer or designated compliance authority.
5.11 Profiling and/or Automated Decision Making
Profiling refers to any form of automated processing of personal data used to evaluate, analyze, or predict aspects relating to an individualâs characteristics, such as academic performance, professional behavior, financial status, health conditions, personal preferences, interests, reliability, location, or activities.
A distinction exists between profiling and automated decision-making. In practice, profiling may occur in the following ways:
While such technologies can enhance efficiency and decision-making processes, their use is subject to legal and ethical considerations. Applicable laws place restrictions on automated decision-making, particularly where such decisions have significant or legal effects on individuals.
KARE shall ensure that:
Where applicable, individuals must be provided with the ability to seek human intervention, express their views, or contest decisions made through automated means.
Members are encouraged to consult the Data Protection Officer or designated authority within KARE for advice and guidance before implementing profiling or automated decision-making processes.
5.12 CCTV
The use of Closed-Circuit Television (CCTV) systems at KARE, except for purely personal or domestic purposes, shall be carried out in accordance with applicable Indian data protection and privacy laws, including the Digital Personal Data Protection Act, 2023, and relevant provisions of the Information Technology Act, 2000. Guidance issued by competent authorities shall also be taken into consideration.
In general, the deployment of CCTV systems must be justified, proportionate, and limited to clearly defined purposes such as safety, security, and asset protection. Since CCTV surveillance involves the collection of individualsâ visual data, it directly affects privacy rights; therefore, a valid and legitimate reason must exist before installation. The purpose of surveillance must be clearly communicated through visible signage placed in appropriate locations.
Prior to installing or significantly modifying any CCTV system within the institution, Members must consult with the designated authority responsible for legal and data protection compliance (such as the Data Protection Officer or equivalent authority at KARE). Additionally, a Data Protection Impact Assessment (DPIA) or equivalent risk assessment shall be conducted to evaluate potential privacy risks and ensure appropriate safeguards are implemented.
5.13 Childrenâs Personal Data
Under applicable Indian data protection law, including the Digital Personal Data Protection Act, 2023, children are recognized as a category requiring enhanced protection, given their vulnerability and limited capacity to fully understand the implications of data processing.
KARE shall ensure that personal data relating to children is handled with heightened care and responsibility. Processing of such data must be carried out in a lawful, fair, and transparent manner, with appropriate safeguards in place to protect the interests and rights of children.
Specific guidelines, including requirements relating to parental or guardian consent and limitations on processing activities involving childrenâs data, shall be followed in accordance with institutional policies and applicable legal provisions. Detailed procedures governing the handling of childrenâs personal data are provided in the relevant appendix of this policy.
6. Roles and Responsibilities
Kalasalingam Academy of Research and Education (KARE) holds primary responsibility for ensuring compliance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023. However, responsibility for protecting personal data is shared across the institution. All employees who handle personal data as part of their duties, individuals engaged through placements or deputation, and students who process personal data during academic, research, or employment activities within KARE are equally responsible for adhering to data protection requirements.
KARE shall provide necessary guidance, support, training, and awareness programs to departments, faculty, staff, and students to facilitate compliance with applicable laws and this policy. The designated Data Protection Officer (or equivalent authority) will assist the institution and its Members in fulfilling their obligations under data protection legislation.
The following roles and responsibilities are defined under this Policy:
All users of KARE information systems:
Institutional Leadership / Administration:
Registrar / Senior Administrative Authority:
The Registrar or designated senior administrative authority shall act as the key official responsible for overseeing institutional compliance with data protection requirements, including:
Heads of Departments / Schools:
Heads of Departments or Schools are responsible for:
Data Protection Officer (DPO) / Designated Authority:
The Data Protection Officer or designated compliance authority is responsible for overseeing operational aspects of data protection across KARE. Key responsibilities include:
Designated Data Protection Coordinators (Department Level):
Each Department/School that processes personal data should nominate a staff member to act as a Data Protection Coordinator. Their responsibilities include:
Staff, Students, and Other Members of KARE:
All Members of KARE are expected to:
7. Breach of This Policy
Any violation or non-compliance with this Policy may result in appropriate disciplinary action in accordance with the institutional rules and regulations of KARE, including applicable staff service rules and student conduct regulations, as revised from time to time.
8. Supporting Policies, Procedures & Guidelines
This Policy establishes a structured framework to support KAREâs compliance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023. However, it does not serve as a comprehensive or exhaustive interpretation of all legal provisions relating to data protection.
For any specific queries, clarifications, or concerns related to personal data processing, Members are advised to contact the Data Protection Officer or the designated authority within KARE.
This Policy should be read together with the following institutional policies, procedures, and guidelines:
In addition, compliance with the following Indian laws and regulations must be ensured alongside this Policy:
9. Definitions
The Digital Personal Data Protection Act, 2023 and related Indian laws regulate the processing of personal data. The terms used within this Policy carry specific legal meanings. Key definitions relevant to this Policy are provided below, with explanatory notes where appropriate:
Personal Data
Personal data refers to any information relating to:
(a) an identified individual; or
(b) an individual who can be identified, directly or indirectly, particularly by reference to:
This definition is broad and may vary depending on the context in which the data is used.
Special Categories of Personal Data (Sensitive Personal Data)
Certain types of personal data require enhanced protection under applicable laws. These include:
Processing of such data requires stricter safeguards and conditions under applicable law.
Although information relating to criminal convictions or offences is not always classified under this category, it is subject to additional safeguards and protections.
Data Concerning Health
This refers to personal data related to an individualâs physical or mental health condition, including details about medical history, diagnosis, treatment, or healthcare services, which indicate the health status of the individual.
Data Subject (Data Principal)
A data subject (referred to as a Data Principal under Indian law) is the individual to whom the personal data relates.
Data Controller (Data Fiduciary)
A data controller (or Data Fiduciary) is an individual or organization that determines the purpose and means of processing personal data, either independently or jointly with others. KARE acts as a Data Fiduciary with respect to personal data of its students, staff, and other stakeholders.
Data Owner
The data owner is typically the senior-most official within a department, school, or administrative unit where the data originates. This role may be formally delegated. The data owner is responsible for ensuring the accuracy, quality, and integrity of the data within their domain.
Data Processor (Data Fiduciary)
A data processor is any individual or entity that processes personal data on behalf of a data controller/data fiduciary. This does not include employees processing data as part of their official duties within the institution. Examples include third-party service providers such as payroll agencies, auditors, or survey agencies.
Direct Marketing
Direct marketing refers to:
âthe communication, through any medium, of advertising or promotional material directed at specific individuals.â
This includes promotional messages related to services, programs, events, or campaigns, including those by non-profit or educational institutions.
Such communication is considered direct marketing when it is targeted at identifiable individuals. Most electronic communications such as emails, phone calls, SMS, and messages fall within this category.
Market research activities are generally excluded; however, if such activities include promotional intent or data collection for future marketing, they will be treated as direct marketing.
Unsolicited communication refers to messages that individuals have not explicitly requested. Even where prior consent (opt-in) exists, such communications are still considered unsolicited, though they may be lawful if compliant with applicable regulations.
Members
Within this Policy, âMembersâ includes:
Processing
Processing refers to any operation performed on personal data, whether by automated means or otherwise, including:
This definition is intentionally broad and covers virtually all activities involving personal data.
Pseudonymisation
Pseudonymisation refers to processing personal data in such a way that it can no longer be directly associated with a specific individual without additional information. This additional information must be stored separately and protected through appropriate technical and organizational safeguards.
Even when data is pseudonymised, it is still considered personal data and remains subject to applicable data protection laws.
10. Policy Review and Approval
This Policy has been formally reviewed and approved by the competent authority of Kalasalingam Academy of Research and Education (KARE), such as the Institutional Leadership/Administrative Council or an equivalent governing body.
Any revisions, updates, or additions to this Policy or related documents shall be proposed by the Data Protection Officer or designated compliance authority and submitted to the appropriate institutional authority for review and approval, or to any body to which such responsibility has been formally delegated.
This Policy shall be reviewed periodically, at least once every two years, by the Data Protection Officer along with the designated administrative authority. Updates shall be made as necessary to reflect changes in applicable laws, including the Digital Personal Data Protection Act, 2023, technological advancements, or institutional requirements.
11. Further Information
For any questions, clarifications, or additional information regarding this Policy or matters related to personal data protection, Members may contact the Data Protection Officer or the designated authority at KARE.
Relevant contact details shall be made available through official institutional communication channels.
12. Miscellaneous
Kalasalingam Academy of Research and Education (KARE) retains the right to modify, update, or withdraw this Policy at any time, without prior notice, in a manner deemed appropriate by the University. Such decisions may be taken at the discretion of the University administration or the Honâble Vice-Chancellor/Competent Authority.
Appendix A: Lawful Bases for Processing
Under applicable Indian data protection law, particularly the Digital Personal Data Protection Act, 2023, it is essential that every instance of personal data processing is supported by a valid legal ground. The following are the recognised lawful bases:
Consent from the Individual
The data principal must provide clear, informed, and specific consent before their personal data is processed. Consent must be given voluntarily and should be capable of being withdrawn at any time without negative consequences.
Performance of a Contract
Processing is permitted where it is necessary to fulfill obligations under a contract between KARE and the individual, or to take steps at the request of the individual prior to entering into such a contract. Example: Processing applicant data during recruitment or admission procedures.
Compliance with Legal Obligations
KARE may process personal data where required to meet statutory or regulatory obligations under Indian law.
Example: Maintenance of employee records, financial records, academic records, or compliance with government regulations.
Protection of Vital Interests
Processing is allowed where it is necessary to safeguard the life, health, or safety of the individual or another person.
Example: Sharing emergency medical information during a health crisis.
Public Interest / Official Function
Processing may be carried out when KARE performs functions that serve public interest, particularly in its role as an educational and research institution recognized under law.
Legitimate Uses (as per Indian framework)
Processing may also be undertaken for reasonable and lawful purposes aligned with institutional functions, provided such use does not override the rights and interests of the data principal.
In cases involving personal data related to criminal records or offences, such processing must strictly comply with applicable Indian laws and institutional policies, ensuring additional safeguards.
If there are any uncertainties regarding the appropriate legal basis for processing, guidance should be sought from the Universityâs designated Data Protection Officer (DPO) or relevant authority.
Appendix B: Conditions for Processing Special Categories of Personal Data
Under applicable Indian data protection law, particularly the Digital Personal Data Protection Act, 2023, certain types of personal data that are sensitive in nature require enhanced safeguards during processing.
Kalasalingam Academy of Research and Education (KARE) shall ensure that, in addition to having a valid lawful basis for processing personal data, specific conditions are satisfied before processing such sensitive categories of data.
Processing of such data may be carried out under the following conditions:
Note:
Relevant provisions under Indian law may provide additional grounds for processing sensitive personal data, including for purposes such as insurance, pensions, or regulatory compliance. KARE shall ensure adherence to all such applicable provisions.
Appendix C: Conditions for Processing Personal Data Related to Criminal Convictions or Offences
Personal data relating to criminal history, allegations, proceedings, or convictions is subject to additional protections under applicable data protection frameworks. While such data may not always fall under âspecial categories,â it requires careful handling due to its sensitive nature.
For KARE to process such data:
In line with good governance practices:
KARE shall ensure that all such processing activities are carried out with strict adherence to legal requirements, transparency, and respect for the rights of individuals.
Appendix D: Conditions for Consent
The Digital Personal Data Protection Act, 2023 lays down requirements for obtaining and managing consent for processing personal data:
Appendix E: Guidelines on Processing Personal Data Relating to Children
Children require enhanced protection when their personal data is collected and processed, as they may not fully understand the associated risks.
Appendix F: Examples of Personal Data
The following are examples of information that may be considered personal data. This list is indicative and not exhaustive:
General Personal Data:
Special Categories of Personal Data:
Criminal Data (Subject to Additional Safeguards):
Note: