Preamble
Whether you are a student, staff member, external partner, supplier, or casual visitor, Université Grenoble Alpes pays constant attention to the protection of your personal data.
Dedicated to ensuring a high level of compliance, Université Grenoble Alpes places data protection at the heart of its priorities. It continuously ensures compliance with Regulation (EU) 2016/679 of April 27, 2016, known as the General Data Protection Regulation (GDPR), as well as the French Data Protection Act ("Loi Informatique et Libertés") of January 6, 1978, as amended.
This personal data protection policy aims to inform you in a clear, accessible, and transparent manner about the processing activities carried out by the university and the rights you have in this regard.
Each personal data processing activity is also subject to a specific information notice detailing its purposes, legal basis, recipients, retention period, and associated rights. These notices are systematically brought to the attention of the individuals concerned prior to the collection of their data.
View the cookie policy
Data Controllers
Université Grenoble Alpes, represented by its President as the data controller, determines the purposes and means of the personal data processing carried out under its responsibility.
Address:
Université Grenoble Alpes
621 avenue centrale
38400 Saint-Martin-d’Hères
Data Protection Officer
In accordance with Article 37 of the GDPR, Université Grenoble Alpes has appointed a Data Protection Officer (DPO).
You can contact the DPO by email or by post.
Email address:
dpo@grenet.fr
Mailing address:
DPO Office – DPO
Shared Information Systems Department (DSIM)
Campus
31, rue des mathématiques
38400 Saint-Martin-d'Hères
What is your status?
Are you a student or an applicant?
What data do we process, and why?
Université Grenoble Alpes processes your personal data for the management of applications, registration, administrative and academic tracking, and support for your journey within the institution.
Other processing activities may also be carried out for management, statistical, survey, and event-organization purposes, or within the framework of student health services.
These processing activities rely on various legal bases provided by the General Data Protection Regulation (GDPR), notably the performance of a task carried out in the public interest, compliance with legal obligations, the legitimate interest of the university, or, in certain cases, your consent.
For more details regarding the data processed, specific purposes, and your applicable rights, you can consult the dedicated data protection policy for candidates and students available on the website:
etudiant.univ-grenoble-alpes.fr
Are you a staff member or a job applicant?
What data do we process, and why?
Université Grenoble Alpes processes your personal data for recruitment management, human resources administration, career tracking, and professional life within the institution.
Other processing activities may be carried out for management, statistics, internal surveys, event management, or access to certain services offered to staff.
These processing activities rely on various legal bases provided by the General Data Protection Regulation (GDPR), notably the performance of a task carried out in the public interest, compliance with legal obligations, the legitimate interest of the university, or, in certain cases, your consent.
For more details regarding the data processed, specific purposes, and your applicable rights, you can consult the data protection policy dedicated to staff and applicants on the staff intranet.
Are you a partner, supplier, or guest?
What data do we process, and why?
Université Grenoble Alpes processes your personal data as part of the management of contractual or partnership relations, the award and execution of contracts or agreements, the promotion of its activities, and your participation in projects, events, meetings, or activities organized by the institution.
The purposes of these processing activities include the administrative, financial, and logistical management of these relationships, institutional communication, premises security, and compliance with legal obligations applicable to the university.
They rely on various legal bases provided by the General Data Protection Regulation (GDPR), such as the performance of a contract or pre-contractual measures, compliance with a legal obligation, the performance of a task in the public interest, or the legitimate interest of the university.
Data is collected during your interactions with Université Grenoble Alpes, whether through contracts, events, or specific services.
Categories of data collected include:
- Identity and contact information: information used to identify and contact you.
- Professional Information: Information related to your professional activities and your company.
- Connection data: information related to your use of digital services.
- Financial data: information regarding transactions and payment methods.
- For partners, suppliers, or guests, this data is used for purposes such as:
- Managing contracts with suppliers or service providers.
- Event management.
- Management of external library user accounts.
Université Grenoble Alpes strives to process your personal data with the utmost care, informing you transparently about the processing concerning you and respecting the principles of the General Data Protection Regulation (GDPR).
In this regard, specific information notices are provided to you at the time your data is collected, depending on the context and the purposes of the processing.
Who has access to your data?
Personal data collected by Université Grenoble Alpes is accessible only to authorized departments and personnel, within the limits of their respective duties and in strict compliance with the purposes for which they were collected.
The university applies rigorous access management and ensures that only individuals who need to access the data for their duties can do so.
Where applicable, certain data may be transmitted to institutional, academic, or contractual partners, or to service providers acting on behalf of the university, as part of clearly defined and contractually bound missions.
These recipients are also subject to confidentiality and security obligations.
Finally, data transfers are carried out in compliance with the principle of data minimization, limiting shared data to what is strictly necessary for the intended purpose.
How long is your data retained?
Université Grenoble Alpes only retains your personal data for the strictly necessary period to achieve the purposes for which it was collected, in compliance with the legal, regulatory, or contractual obligations applicable to it.
Retention periods vary depending on the nature of the data and the processing involved. They are defined in accordance with current regulations and, where applicable, the recommendations of competent authorities or the rules applicable to public archives.
At the end of these periods, the data is either deleted or securely archived when longer retention is required for evidentiary or archival purposes.
Accordingly, Université Grenoble Alpes complies in particular with the provisions of the instruction "DAF DPACI/RES/2005/003 of February 22, 2005, on the sorting and retention of archives received and produced by services and institutions contributing to national education".
Security and Incident Management
How is your data secured?
Université Grenoble Alpes has defined technical, legal, and organizational measures to appropriately protect your data based on its nature and the scope of processing.
In accordance with Article 32 of the GDPR, Université Grenoble Alpes implements appropriate technical and organizational measures to ensure the security of the personal data processed.
These measures aim to guarantee the confidentiality, integrity, availability, and resilience of information systems, as well as to prevent and detect security incidents.
Université Grenoble Alpes is committed to continuously reviewing and improving these measures to protect users' personal data against security risks.
These measures comply with the information system security policy of Université Grenoble Alpes.
Data Breach Management
In the event of a personal data breach—whether internal or external, intentional or accidental—Université Grenoble Alpes strives to gather as much information as possible in order to respond quickly and prevent any recurrence.
A data breach is characterized by a loss of data integrity, availability, or confidentiality.
When the breach poses a risk to the rights and freedoms of the individuals concerned,Université Grenoble Alpes notifies the CNIL within 72 hours.
In the event of a high risk, the data subjects are informed without delay so that they can take the necessary measures.
If you become aware of a breach, please report it immediately to the Data Protection Officer (DPO) at the following address:
dpo@grenet.fr
Transfer of Your Personal Data Outside the European Union
In general, personal data processed by Université Grenoble Alpes is hosted and stored within the European Union.
However, certain processing operations may involve data transfers to countries located outside the European Economic Area, particularly within the context of international partnerships, student mobility, or the use of certain digital tools.
In such cases, Université Grenoble Alpes ensures that these transfers are governed by appropriate safeguards in compliance with the requirements of the General Data Protection Regulation (GDPR), such as:
- A decision by the European Commission on adequacy.
- The signing of standard contractual clauses approved by the European Commission.
- Or any other warranty provided for by applicable regulations.
You can obtain additional information about these transfers by contacting the Data Protection Officer.
What are your rights, and how can you exercise them?
Université Grenoble Alpes processes your personal data as part of its missions and in accordance with the GDPR; you have the following rights:
- Right to be informed: You have the right to know all the details regarding the processing of your personal data, including the data involved, the purposes and legal bases for processing, retention periods, recipients, and all other information related to the processing.
- Right of access: Any person may review all information concerning them, as well as its source, and obtain a copy of it.
- Right to rectification: the right to request that data be corrected, supplemented, updated, or deleted.
- Right to restrict processing: You may request that the organization temporarily suspend the use of certain data about you. This right may be exercised, in particular, while your request to exercise another right is being processed.
And, depending on the processing activities and their legal basis:
- Right to erasure: You may request that your data be erased under certain conditions, including if the data is no longer necessary for the purposes of the processing or if the processing is unlawful.
- Right to data portability: allows you to retrieve some of your data in a machine-readable format, which may enable you to transfer it to another organization.
- Right to Object: You have the right to object to an organization’s use of your data for a specific purpose, citing a particular circumstance.
- Right to withdraw your consent.
- Right to request direct intervention by an agent: in the case of an automated decision or profiling.
- The right to establish guidelines regarding your personal data after your death.
You may contact the Data Protection Officer to exercise your rights or, more generally, for any questions regarding the protection of your data.
You also have the right to file a complaint with the CNIL:
www.cnil.fr/fr/plaintes
Developments in Personal Data Protection Policy
This privacy policy is subject to change, particularly in light of changes in laws and regulations.