Governance and Digitalization

Personal Data Protection and Privacy Policy

Institut Pendidikan Indonesia Garut is committed to protecting personal data through lawful, transparent, accountable, and secure data processing practices.

Policy Summary

This policy supports institutional compliance with Indonesia's Personal Data Protection Law and recognized international privacy principles for higher education governance.

Effective Date24 June 2026
Version1.0
Policy OwnerTDSI
Review PeriodAnnually or when required

1. Introduction

Institut Pendidikan Indonesia Garut is committed to protecting personal data and ensuring that all data processing activities are conducted lawfully, fairly, securely, transparently, and responsibly.

This Personal Data Protection and Privacy Policy explains how Institut Pendidikan Indonesia Garut collects, uses, stores, protects, shares, retains, and disposes of personal data in the implementation of higher education, academic services, research, community service, institutional administration, digital services, public communication, and sustainability reporting.

This policy is established in alignment with Law of the Republic of Indonesia Number 27 of 2022 concerning Personal Data Protection and with internationally recognized data protection principles, including accountability, transparency, lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and information security.

2. Scope of Policy

This policy applies to all personal data processed by Institut Pendidikan Indonesia Garut through institutional activities, academic systems, administrative systems, websites, online forms, learning platforms, communication channels, information systems, and third-party services used to support institutional operations.

This policy applies to:

  • students and prospective students;
  • lecturers, education staff, researchers, and institutional personnel;
  • alumni;
  • parents or guardians, where applicable;
  • research participants and community service beneficiaries;
  • partners, vendors, guests, and institutional stakeholders;
  • website visitors and users of digital services managed by Institut Pendidikan Indonesia Garut.

3. Categories of Personal Data Processed

Institut Pendidikan Indonesia Garut may process personal data according to institutional needs and applicable legal requirements. The categories of personal data may include:

  • identity data, such as name, student identification number, employee identification number, national identification number, place and date of birth, gender, and citizenship;
  • contact data, such as address, phone number, email address, and emergency contact;
  • academic data, such as study program, course registration, attendance, grades, academic progress, thesis or final project records, graduation records, and academic history;
  • administrative data, such as registration records, financial administration records, scholarship information, and correspondence;
  • employment data, such as position, work unit, employment status, attendance, performance administration, and professional records;
  • digital identity data, such as username, institutional email, access logs, IP address, device information, and system activity records;
  • documentation data, such as photos, videos, certificates, event records, and institutional publication materials;
  • other data required for education, research, community service, regulatory reporting, accreditation, institutional governance, and sustainability reporting.

Institut Pendidikan Indonesia Garut limits the collection of personal data to data that is relevant, adequate, and necessary for legitimate institutional purposes.

4. Purposes of Personal Data Processing

Personal data may be processed for the following purposes:

  • student admission, registration, and academic administration;
  • academic learning services, academic advising, assessment, and graduation administration;
  • student affairs, scholarships, alumni affairs, and career development services;
  • human resource administration and institutional employment management;
  • research, publication, community service, and academic development;
  • institutional communication, documentation, reporting, and public information;
  • quality assurance, accreditation, institutional ranking, and sustainability reporting;
  • operation, maintenance, integration, monitoring, and security of information systems;
  • compliance with laws, regulations, government reporting, and institutional obligations;
  • protection of institutional rights, safety, cybersecurity, and service continuity.

7. Rights of Data Subjects

Institut Pendidikan Indonesia Garut respects the rights of data subjects in accordance with applicable data protection regulations. Data subjects may request:

  • access to their personal data;
  • correction or completion of inaccurate personal data;
  • explanation of the purpose and legal basis of processing;
  • restriction or postponement of processing where applicable;
  • withdrawal of consent where processing is based on consent;
  • deletion or destruction of personal data where legally permitted;
  • information regarding disclosure or transfer of personal data;
  • submission of complaints related to personal data processing.

Requests related to personal data rights may be submitted through the official contact channel designated by Institut Pendidikan Indonesia Garut.

8. Data Accuracy and Updating

Institut Pendidikan Indonesia Garut takes reasonable steps to ensure that personal data processed by the institution is accurate, complete, relevant, and up to date according to the purpose of processing.

Students, staff, lecturers, and other data subjects are encouraged to update their personal information through official academic, administrative, or institutional channels when changes occur.

9. Personal Data Security Measures

Institut Pendidikan Indonesia Garut applies technical and organizational measures to protect personal data from unauthorized access, misuse, alteration, disclosure, loss, destruction, or unlawful processing.

Security measures may include:

  • user authentication and role-based access control;
  • access limitation based on institutional duties and responsibilities;
  • secure system administration and account management;
  • backup and recovery mechanisms;
  • monitoring of system access and activity logs;
  • data confidentiality obligations for authorized personnel;
  • information system maintenance and security updates;
  • secure storage and controlled access to institutional records;
  • awareness activities related to data protection and information security.

10. Third-Party Systems and Service Providers

Institut Pendidikan Indonesia Garut may use third-party systems and service providers to support academic, administrative, learning, digital communication, and information system operations.

For core academic information system services, including SIAKAD and integrated academic administration, Institut Pendidikan Indonesia Garut uses services provided by SEVIMA. SEVIMA has obtained ISO/IEC 27001:2022 certification for Information Security Management System, which supports the assurance that the academic information system provider applies recognized information security management practices.

Third-party service providers are expected to process personal data only for authorized institutional purposes and in accordance with contractual, legal, confidentiality, and security requirements. Institut Pendidikan Indonesia Garut maintains institutional responsibility for ensuring that third-party processing supports the protection of personal data.

11. Disclosure and Sharing of Personal Data

Institut Pendidikan Indonesia Garut may disclose or share personal data only when necessary and lawful, including to:

  • government authorities and higher education regulatory bodies;
  • accreditation, quality assurance, or institutional ranking bodies;
  • academic and administrative service providers;
  • banking, scholarship, insurance, or student service partners where relevant;
  • research or community service partners with appropriate safeguards;
  • parties authorized by law, regulation, court order, or official institutional obligation.

Personal data is not sold, traded, or disclosed for unrelated commercial purposes.

12. Data Retention

Institut Pendidikan Indonesia Garut retains personal data only for as long as necessary to fulfill academic, administrative, legal, regulatory, archival, accountability, accreditation, and institutional reporting purposes.

Retention periods may vary depending on the type of data, applicable law, institutional record retention schedules, and operational requirements. When personal data is no longer required, the institution may delete, anonymize, archive, or securely destroy the data in accordance with applicable procedures.

13. Personal Data Breach and Incident Response

In the event of a personal data security incident or suspected data breach, Institut Pendidikan Indonesia Garut will take appropriate steps to assess, contain, investigate, respond to, and recover from the incident.

The response may include:

  • identification of affected systems and data;
  • containment of unauthorized access or exposure;
  • internal reporting to the responsible institutional unit;
  • corrective and preventive actions;
  • notification to affected data subjects and/or relevant authorities where required by applicable law;
  • documentation of the incident and improvement of security controls.

14. Website, Cookies, and Digital Services

The official website and digital services of Institut Pendidikan Indonesia Garut may collect limited technical data, such as IP address, browser type, device information, access time, pages visited, and interaction logs. This information is used to maintain website security, improve services, analyze access performance, and support institutional communication.

Cookies or similar technologies may be used to improve website functionality and user experience. Users may manage cookie preferences through browser settings.

15. Awareness and Institutional Responsibility

Institut Pendidikan Indonesia Garut promotes awareness of personal data protection and information security among relevant personnel, system users, and institutional units.

Each authorized user of institutional data is responsible for maintaining confidentiality, using data only for legitimate institutional purposes, preventing unauthorized disclosure, and reporting suspected misuse or security incidents through official channels.

16. Review and Continuous Improvement

This policy is reviewed periodically to ensure alignment with applicable laws, institutional needs, technological developments, information security requirements, and good governance practices.

Institut Pendidikan Indonesia Garut is committed to continuous improvement in personal data protection, cybersecurity, academic system governance, and responsible digitalization.

17. Contact for Personal Data Protection

Questions, requests, or complaints related to this Personal Data Protection and Privacy Policy may be submitted to:

Responsible Unit
Unit Transformasi Digital dan Sistem Informasi
Institution
Institut Pendidikan Indonesia Garut
Address
Jl. Terusan Pahlawan No.32, RW.01, Sukagalih, Kec. Tarogong Kidul, Kabupaten Garut, Jawa Barat 44151

18. Additional Evidence for UI GreenMetric 7.14

The implementation of this policy may be supported by the following evidence:

  • publicly accessible Personal Data Protection and Privacy Policy page on the official website of Institut Pendidikan Indonesia Garut;
  • screenshot of the official policy page;
  • appointment or designation of the responsible institutional unit for data protection and information system governance;
  • consent forms, academic registration forms, or online forms containing privacy notices;
  • procedures for access rights, data correction, consent withdrawal, and complaint handling;
  • information security measures applied to institutional systems;
  • evidence of third-party academic system security assurance, including SEVIMA ISO/IEC 27001:2022 certification for Information Security Management System;
  • documentation of awareness, review, or internal coordination related to personal data protection.