Personal Data: General Policy on the Protection of Personal Data

Preamble

Whether you are a student, staff member, external partner, supplier, or casual visitor, Université Grenoble Alpes pays constant attention to the protection of your personal data.

Committed to ensuring a high level of compliance, Université Grenoble Alpes places data protection at the heart of its priorities. It constantly ensures the application of Regulation (EU) 2016/679 of April 27, 2016, known as the General Data Protection Regulation (GDPR), as well as the French Data Protection Act ("Loi Informatique et Libertés") of January 6, 1978, as amended.

The purpose of this personal data protection policy is to inform you, in a clear, accessible, and transparent manner, about the processing activities carried out by the university as well as the rights you have in this regard.

Each personal data processing activity is also subject to a specific information notice detailing its purposes, legal basis, recipients, retention period, and associated rights. These notices are systematically brought to the attention of the individuals concerned prior to the collection of their data.

View the cookie policy

Data Controllers

Université Grenoble Alpes, represented by its President acting as data controller, determines the purposes and means of the personal data processing operations carried out under its responsibility.

Address:
Université Grenoble Alpes
621 avenue centrale
38400 Saint-Martin-d’Hères

Data Protection Officer

In accordance with Article 37 of the GDPR, Université Grenoble Alpes has appointed a Data Protection Officer (DPO).

You can contact the DPO by email or post.
 
Email address:
dpo@grenet.fr

Mailing address:
DPO Office – DPO
Shared Information Systems Department (DSIM)

Academic Division 31, rue des mathématiques
38400 Saint-Martin-d'Hères

What is your status?

Are you a student or an applicant?

What data do we process, and why?
Université Grenoble Alpes processes your personal data as part of the management of applications, enrollment, administrative and academic monitoring, and support for your journey within the institution.
 
Other processing activities may also be carried out for management, statistical, survey, and event organization purposes, or as part of student health services.

These processing activities are based on various legal grounds provided for by the General Data Protection Regulation (GDPR), notably the performance of a task carried out in the public interest, compliance with legal obligations, the legitimate interest of the university, or, in certain cases, your consent.

For more details on the data processed, specific purposes, and your applicable rights, you can consult the data protection policy dedicated to candidates and students available on the website:

etudiant.univ-grenoble-alpes.fr

Are you a staff member or a job applicant?

What data do we process, and why?
Université Grenoble Alpes processes your personal data as part of recruitment management, human resources administrative management, career monitoring, and professional life within the institution. 

Other processing activities may be carried out for management, statistical, internal survey, and event management purposes, or to provide access to certain services offered to staff members.

These processing activities rely on various legal grounds provided for by the General Data Protection Regulation (GDPR), notably the performance of a task carried out in the public interest, compliance with legal obligations, the legitimate interest of the university, or, in certain cases, your consent.

For more details on the data processed, specific purposes, and your applicable rights, you can consult the data protection policy dedicated to staff and applicants on the staff intranet.

Are you a partner, supplier, or guest?

What data do we process, and why?
Université Grenoble Alpes processes your personal data as part of the management of contractual or partnership relations, the awarding and execution of contracts or agreements, the promotion of its activities, and your participation in projects, events, meetings, or activities organized by the institution.

The purposes of these processing activities include the administrative, financial, and logistical management of these relations, institutional communication, premises security, and compliance with legal obligations applicable to the university.

They are based on various legal grounds provided for by the General Data Protection Regulation (GDPR), such as the performance of a contract or pre-contractual measures, compliance with a legal obligation, the performance of a task carried out in the public interest, or the legitimate interest of the university.

Data is collected during your interactions with Université Grenoble Alpes, whether through contracts, events, or specific services. 

The categories of data collected include:
  • Identity and contact information: information used to identify and contact you.
  • Professional information: details about your professional activities and your company.
  • Connection data: information related to your use of digital services.
  • Financial data: information regarding transactions and payment methods.
  • For partners, suppliers, or guests, this data is used for purposes such as:
    • Managing contracts with suppliers or service providers.
    • Event planning and management.
    • Management of external library user accounts. 
Université Grenoble Alpes strives to process your personal data with the utmost care, informing you transparently about the processing operations concerning you and complying with the principles of the General Data Protection Regulation (GDPR).

In this regard, specific information notices are provided to you when your data is collected, depending on the context and the purposes of the processing.

Who has access to your data?

The personal data collected by Université Grenoble Alpes is accessible only to authorized departments and personnel, within the limits of their respective duties and in strict compliance with the purposes for which it was collected.

The university applies strict access management and ensures that only individuals who need to access the data as part of their duties are able to do so.

Where applicable, certain data may be forwarded to institutional, academic, or contractual partners, or to service providers acting on behalf of the university, as part of clearly defined and contractually bound missions.
 
These recipients are also bound by confidentiality and security obligations.

Finally, data transmissions are carried out in compliance with the principle of minimization, limiting shared data to what is strictly necessary for the pursued purpose.

How long is your data retained?

Université Grenoble Alpes retains your personal data only for as long as strictly necessary to fulfill the purposes for which it was collected, in compliance with the legal, regulatory, or contractual obligations applicable to it.

Retention periods vary depending on the nature of the data and the processing activities concerned. They are defined in accordance with current regulations and, where applicable, the recommendations of competent authorities or the rules applicable to public archives.
At the end of these periods, data is either deleted or securely archived when longer retention is required for evidentiary or archival purposes.

In this respect, Université Grenoble Alpes complies in particular with the provisions of instruction "DAF DPACI/RES/2005/003 of February 22, 2005 on sorting and retention for archives received and produced by services and institutions contributing to national education".

Security and Incident Management

How is your data secured?

Université Grenoble Alpes has defined technical, legal, and organizational measures to protect your data appropriately according to its nature and the scope of the processing.

In accordance with Article 32 of the GDPR, Université Grenoble Alpes implements appropriate technical and organizational measures to ensure the security of the personal data processed.

These measures aim to guarantee the confidentiality, integrity, availability, and resilience of information systems, as well as to prevent and detect security incidents.

Université Grenoble Alpes is committed to continually reviewing and improving these measures to protect users' personal data against security risks.

These measures comply with the information system security policy of Université Grenoble Alpes.

Data Breach Management

In the event of a personal data breach, whether internal or external, intentional or accidental, Université Grenoble Alpes strives to gather as much information as possible in order to react quickly and prevent recurrence.

A data breach is characterized by a loss of integrity, availability, or confidentiality of data.

When the breach poses a risk to the rights and freedoms of the individuals concerned, Université Grenoble Alpes notifies the CNIL within 72 hours. 

In the event of a high risk, the individuals concerned are informed without delay so that they can take the necessary measures.

If you notice a breach, please report it immediately to the Data Protection Officer (DPO) at the following address:

dpo@grenet.fr 

Transfer of Your Personal Data Outside the European Union

In general, the personal data processed by Université Grenoble Alpes is hosted and stored within the European Union.

However, certain processing operations may involve data transfers to countries located outside the European Economic Area, particularly as part of international partnerships, student mobility, or the use of certain digital tools.

In such cases, Université Grenoble Alpes ensures that these transfers are governed by appropriate safeguards compliant with the requirements of the General Data Protection Regulation (GDPR), such as:
  • A decision by the European Commission on adequacy.
  • The signing of standard contractual clauses approved by the European Commission.
  • Or any other warranty provided for by applicable regulations.
You can obtain additional information about these transfers by contacting the Data Protection Officer.

What are your rights, and how can you exercise them?

Université Grenoble Alpes processes your personal data as part of its missions and in accordance with the GDPR, you have the following rights:
  1. Right to be informed: You have the right to know all the details regarding the processing of your personal data, including the data involved, the purposes and legal bases for processing, the retention periods, the recipients, and all other information pertaining to the processing.
  2. Right of access: Any person may review all information concerning them, as well as its source, and obtain a copy of it.
  3. Right to rectification: the right to request that data be corrected, supplemented, updated, or deleted.
  4. Right to restrict processing: You may ask the organization to temporarily suspend the use of certain data about you. This right may be exercised, in particular, while your request to exercise another right is being processed.
And, depending on the processing activities and their legal basis:  
  1. Right to erasure: You may request that your data be erased under certain conditions, including if it is no longer necessary for the purposes of the processing or if the processing is unlawful.
  2. Right to data portability: allows you to retrieve some of your data in a machine-readable format, which may enable you to transfer it to another organization.
  3. Right to Object: You have the right to object to an organization’s use of your data for a specific purpose, citing a particular circumstance.
  4. Right to withdraw your consent.
  5. Right to request direct intervention by an agent: in the case of an automated decision or profiling.
  6. The right to establish guidelines regarding your personal data after your death.
You may contact the Data Protection Officer to exercise your rights or, more generally, for any questions regarding the protection of your data.

You also have the right to file a complaint with the CNIL:

www.cnil.fr/fr/plaintes

Developments in Personal Data Protection Policy

This privacy policy is subject to change, particularly in light of legislative and regulatory developments.
Published on 14, November 2019
Updated on17, September 2026