Data Office Privacy Policy

 

1. Scope of Personal Data

Data that may be collected by the university includes:

  • Name, national ID, address, and contact details.
  • Email address and phone number.
  • Banking details, billing information, and credit card data.
  • Academic and employment data.
  • Still and moving images (photos and videos).
  • Demographic information, such as age, gender, country, and educational level.
  • Website usage data, such as pages visited and services used.
  • IP address, browser type, access times, and referring websites.
  • Survey responses and optional preferences.

2. Purposes of Data Collection and Processing

Data is processed for the following purposes:

  • Admissions, registration, and academic programs.
  • Recruitment, employee records management, and payroll.
  • Providing electronic and administrative services.
  • Organizing events, interviews, and requests.
  • Managing academic and employment accounts.
  • Analytics and service quality improvement.
  • Fulfilling statutory and regulatory obligations.
  • Executing contracts with students and employees.
  • Compiling statistics and understanding portal usage.
  • Analyzing data using artificial intelligence to improve academic and administrative services.

3. Stated Legal Grounds

The policy relies on:

  • The Saudi Personal Data Protection Law (PDPL).
  • Regulations governing student and employee data.
  • Contractual performance.
  • Legal and regulatory obligations.
  • Regulatory authority requirements.
  • Necessity for delivering educational and administrative services.

The Data Office must link each processing activity to a specific legal basis and avoid using the phrase "consent to all operations" as a blanket legal basis for all processing activities.

4. Processing Operations

Operations covered in the policy include:

  • Collection and recording.
  • Retention and storage.
  • Transfer, sharing, and disclosure.
  • Linking with other data.
  • Analysis, pattern extraction, and inference.
  • Updating and rectification.
  • Destruction/Disposal.
  • Manual or automated processing.

5. Mandatory and Optional Data

Mandatory data includes information required to:

  • Register students and manage their academic affairs.
  • Recruit staff and manage payroll and records.
  • Deliver a service that cannot be performed without specific details.
  • Comply with regulatory requirements.

Optional data includes surveys, preferences, and additional details used to enhance services. The policy notes that paper-based alternatives may be used in certain cases, but not universally.

Failure to provide mandatory data may result in the inability to process admission, registration, employment, payroll issuance, or eligibility for allowances, promotions, and electronic services.

6. Data Sharing and Disclosure

The university may share data with:

  • Relevant internal departments.
  • Service providers and contractors.
  • Hosting and data analytics entities.
  • Employment, education, and research entities.
  • Governmental or regulatory authorities upon request or legal obligation.
  • Third parties rendering services on behalf of the university.

Data sharing must be:

  • Within the limits of the specified purpose.
  • Restricted strictly to necessary data.
  • Governed by contracts, protection commitments, and confidentiality obligations.
  • Compliant with Saudi laws and regulations.
  • Accessible only to authorized personnel.

7. Rights of Data Subjects

The policy grants the following rights:

  • The right to be informed of the legal basis and purpose of data collection.
  • The right to access data.
  • The right to obtain a clear copy of the data.
  • The right to request rectification, completion, or updating of data.
  • The right to object to processing that lacks a statutory basis.
  • The right to request destruction of data once the purpose ceases, unless a legal obligation mandates retention.
  • The right to know the outcome of requests and the reasons for refusal, if rejected.

The policy specifies that requests must be processed within no more than 30 business days from receipt.

Data Management Office (DMO) Channels:

  • Email: DMO@KKU.EDU.SA
  • Phone: 0172403663
  • Electronic request form referenced on the webpage.

8. Responsibilities of the Data Subject

Under the policy, data subjects are responsible for the correctness and accuracy of the information they provide. University personnel may update their profile information through university portals or official channels.

This does not negate the university's responsibility to enforce data quality controls, verify data, and correct errors upon discovery.

9. Retention and Destruction

The policy stipulates:

  • Retaining data as long as necessary for its intended purpose or to fulfill legal requirements.
  • Destroying digital data via permanent deletion and techniques that prevent recovery.
  • Purging data from backup systems following the timeframe defined in the retention policy.
  • Disposing of paper documents using methods that prevent content retrieval.
  • Notifying the data subject of data destruction when required by law.

The Data Management Office is required to maintain an approved retention and disposal schedule defining retention periods according to data category, purpose, and legal basis, rather than relying on vague terms like "after a specified period."

10. Updating the Privacy Notice

The university reserves the right to amend the policy, and amendments take effect upon publication. Therefore, the Data Office must handle:

  • Periodic reviews of the notice.
  • Documenting versions and revision dates.
  • Assessing the impact of material changes.
  • Notifying data subjects when the purpose, legal basis, or nature of data sharing changes, rather than relying solely on continued website usage.