Personal Data: General Policy on the Protection of Personal Data

Preamble

Whether you are a student, staff member, external partner, supplier, or simply a visitor, the University of Grenoble Alpes is constantly committed to protecting your personal data.

Committed to ensuring a high level of compliance, the University of Grenoble Alpes places data protection at the heart of its priorities. It continuously ensures compliance with Regulation (EU) 2016/679 of April 27, 2016, known as the General Data Protection Regulation (GDPR), as well as with the “Data Protection Act” of January 6, 1978, in its current version.

The purpose of this personal data protection policy is to inform you, in a clear, accessible, and transparent manner, about the data processing activities carried out by the University as well as the rights you have in this regard.

Each instance of personal data processing is also accompanied by a specific privacy notice detailing its purposes, legal basis, recipients, retention period, and related rights. These notices are systematically provided to data subjects prior to the collection of their data.

View the Cookie Policy

Data Controllers

The University of Grenoble Alpes, represented by its President in his capacity as data controller, determines the purposes and means of the processing of personal data carried out under its responsibility.

Address:
University of Grenoble Alpes
621 Avenue Centrale
38400 Saint-Martin-d’Hères

Data Protection Officer

In accordance with Article 37 of the GDPR, the University of Grenoble Alpes has appointed a Data Protection Officer (DPO).

You can contact the DPO by email or by mail.
 
Email address:
dpo@grenet.fr

Mailing address:
DPO Office – DPO
Shared Information Systems Department (DSIM)

Campus 31, rue des mathématiques
38400 Saint-Martin-d'Hères

What is your status?

Are you a student or an applicant?

What data do we process, and why?
The University of Grenoble Alpes processes your personal data for the purposes of managing applications, enrollment, administrative and academic tracking, as well as supporting your academic journey at the institution.

Other processing activities may also be carried out for the purposes of management, statistics, surveys, event organization, or in connection with student health services.

This data processing is based on various legal grounds provided for by the General Data Protection Regulation (GDPR), including the performance of a task carried out in the public interest, compliance with legal obligations, the University’s legitimate interests, or, in certain cases, your consent.

For more details on the data processed, the specific purposes, and the rights that apply to you, please consult the policy on the processing of applicant and student data available at:

etudiant.univ-grenoble-alpes.fr

Are you a staff member or a job applicant?

What data do we process, and why?
The University of Grenoble Alpes processes your personal data for the purposes of recruitment management, human resources administration, and the monitoring of careers and professional life within the institution.

Other processing activities may be carried out for the purposes of management, statistics, internal surveys, event management, or to provide access to certain services offered to staff members.

This data processing is based on various legal grounds provided for by the General Data Protection Regulation (GDPR), including the performance of a task carried out in the public interest, compliance with legal obligations, the University’s legitimate interests, or, in certain cases, your consent.

For more details on the data processed, the specific purposes, and the rights that apply to you, please consult the policy on the processing of staff and applicant data on the staff intranet.

Are you a partner, supplier, or guest?

What data do we process, and why?
The University of Grenoble Alpes processes your personal data in connection with the management of contractual or partnership relationships, the awarding and execution of contracts or agreements, the promotion of its activities, and your participation in projects, events, meetings, or activities organized by the institution.

The purposes of this processing include, in particular, the administrative, financial, and logistical management of these relationships; institutional communications; the security of the premises; and compliance with legal obligations applicable to the University.

This processing is based on various legal grounds provided for by the General Data Protection Regulation (GDPR), such as the performance of a contract or pre-contractual measures, compliance with a legal obligation, the performance of a task carried out in the public interest, or the University’s legitimate interests.

Data is collected during your interactions with the University of Grenoble Alpes, whether in connection with contracts, events, or specific services.

The categories of data collected include:
  • Identity and contact information: information used to identify and contact you.
  • Professional Information: Information related to your professional activities and your company.
  • Connection data: information related to your use of digital services.
  • Financial data: information regarding transactions and payment methods.
  • For partners, suppliers, or guests, this data is used for purposes such as:
    • Managing contracts with suppliers or service providers.
    • Event management.
    • Management of external library user accounts. 
The University of Grenoble Alpes is committed to handling your personal data with the utmost care, providing you with transparent information about how your data is processed, and complying with the principles of the General Data Protection Regulation (GDPR).

In this regard, specific notices are provided to you at the time your data is collected, depending on the context and the purposes of the processing.

Who has access to your data?

Personal data collected by the University of Grenoble Alpes is accessible only to authorized departments and staff, within the limits of their respective responsibilities and in strict accordance with the purposes for which it was collected.

The University maintains a rigorous access control system and ensures that only individuals who need access to the data as part of their duties may access it.

Where applicable, certain data may be transmitted to institutional, academic, or contractual partners, or to service providers acting on behalf of the University, within the framework of clearly defined and contractually governed tasks.
 
These recipients are also subject to confidentiality and security obligations.

Finally, data transfers are carried out in accordance with the principle of data minimization, limiting the data shared to what is strictly necessary for the intended purpose.

How long is your data retained?

Grenoble Alpes University retains your personal data only for as long as is strictly necessary to fulfill the purposes for which it was collected, in compliance with the legal, regulatory, or contractual obligations applicable to the University.

Retention periods vary depending on the nature of the data and the processing operations involved. They are defined in accordance with current regulations and, where applicable, with the recommendations of the competent authorities or the rules applicable to public archives.
At the end of these retention periods, the data is either deleted or securely archived when longer retention is required for evidentiary or archival purposes.

In this regard, the University of Grenoble Alpes complies, in particular, with the provisions of Directive "DAF DPACI/RES/2005/003 of February 22, 2005, on the sorting and retention of records received and produced by departments and institutions contributing to national education."

Security and Incident Management

How is your data secured?

The University of Grenoble Alpes has established technical, legal, and organizational measures to protect your data appropriately, depending on its nature and the scope of its processing.

In accordance with Article 32 of the GDPR, the University of Grenoble Alpes implements appropriate technical and organizational measures to ensure the security of the personal data it processes.

These measures aim to ensure the confidentiality, integrity, availability, and resilience of information systems, as well as to prevent and detect security incidents.

The University of Grenoble Alpes is committed to continuously reviewing and improving these measures to protect users’ personal data against security risks.

These measures comply with the University of Grenoble Alpes’ information system security policy.

Data Breach Management

In the event of a personal data breach—whether internal or external, intentional or accidental—the University of Grenoble Alpes strives to gather as much information as possible in order to respond quickly and prevent any recurrence.

A data breach is characterized by a loss of data integrity, availability, or confidentiality.

When the breach poses a risk to the rights and freedoms of the individuals concerned, the University of Grenoble Alpes notifies the CNIL within 72 hours. 

In the event of a high risk, the data subjects are informed without delay so that they can take the necessary measures.

If you become aware of a breach, please report it immediately to the Data Protection Officer (DPO) at the following address:

dpo@grenet.fr 

Transfer of Your Personal Data Outside the European Union

In general, the personal data processed by the University of Grenoble Alpes is hosted and stored within the European Union.

However, certain processing activities may involve data transfers to countries outside the European Economic Area, particularly in the context of international partnerships, student exchange programs, or the use of certain digital tools.

In such cases, the University of Grenoble Alpes ensures that these transfers are subject to appropriate safeguards, in accordance with the requirements of the General Data Protection Regulation (GDPR), such as:
  • A decision by the European Commission on adequacy.
  • The signing of standard contractual clauses approved by the European Commission.
  • Or any other warranty provided for by applicable regulations.
You can obtain additional information about these transfers by contacting the Data Protection Officer.

What are your rights, and how can you exercise them?

The University of Grenoble Alpes processes your personal data as part of its operations, and in accordance with the GDPR, you have the following rights:
  1. Right to be informed: You have the right to know all the details regarding the processing of your personal data, including the data involved, the purposes and legal bases for processing, retention periods, recipients, and all other information related to the processing.
  2. Right of access: Any person may review all information concerning them, as well as its source, and obtain a copy of it.
  3. Right to rectification: the right to request that data be corrected, supplemented, updated, or deleted.
  4. Right to restrict processing: You may request that the organization temporarily suspend the use of certain data about you. This right may be exercised, in particular, while your request to exercise another right is being processed.
And, depending on the processing activities and their legal basis:  
  1. Right to erasure: You may request that your data be erased under certain conditions, including if the data is no longer necessary for the purposes of the processing or if the processing is unlawful.
  2. Right to data portability: allows you to retrieve some of your data in a machine-readable format, which may enable you to transfer it to another organization.
  3. Right to Object: You have the right to object to an organization’s use of your data for a specific purpose, citing a particular circumstance.
  4. Right to withdraw your consent.
  5. Right to request direct intervention by an agent: in the case of an automated decision or profiling.
  6. The right to establish guidelines regarding your personal data after your death.
You may contact the Data Protection Officer to exercise your rights or, more generally, for any questions regarding the protection of your data.

You also have the right to file a complaint with the CNIL:

www.cnil.fr/fr/plaintes

Developments in Personal Data Protection Policy

This privacy policy is subject to change, particularly in light of changes in laws and regulations.
Published on November 14, 2019
Updated on September 7, 2026