Institutional high-quality accreditation link stiky-sticky

▲ Back to Top

Privacy Notice

The University of Cundinamarca, in accordance with the provisions of Law 1581 of 2012 and its Regulatory Decree 1074 of 2015, communicates that, in the development of its academic, commercial, or labor activities, it requests, collects, stores, uses, and circulates information and personal data of the Data Subjects who permanently or temporarily access or seek to access the services provided by the Institution, and which will be processed according to the purposes described in the document ESG-SSI-G007 GUIDE TO PURPOSES FOR THE PROCESSING OF PERSONAL DATA OF THE DATA SUBJECTS OF THE UNIVERSITY OF CUNDINAMARCA, which is part of the manual ESG-SSI-M001 MANUAL OF INFORMATION SECURITY AND PRIVACY GUIDELINES

 

The processed information is stored in our databases, and data subjects may exercise their rights of access, update, rectification, and suppression regarding this information, in accordance with the Personal Data Protection Guidelines for Data Subjects of the University of Cundinamarca, available here: https://ucundinamarca.dp150.xyz/proteccion-de-datos-personales

 

The processing of minors' data responds to and respects their best interests, as well as ensures respect for their fundamental rights.

 

Likewise, the University of Cundinamarca informs that the processing of sensitive data is carried out under strict standards of confidentiality and security, implementing administrative, technical, and legal measures, which are mandatory for administrative staff, faculty members, students, and third parties, considering at all times that the Data Subject has the free right not to authorize the processing of their sensitive data.

 

To exercise your rights before the data controller, that is, the University of Cundinamarca, you can go to its facilities at the Citizen Service Office or contact them via email [email protected]

Processing of Personal Data

On August 8, 2023, the University of Cundinamarca adopted through Resolution No. 091 of 2023, “THE GUIDELINES FOR THE PROTECTION OF PERSONAL DATA OF THE DATA SUBJECTS OF THE UNIVERSITY OF CUNDINAMARCA”, in compliance with the provisions of Statutory Law 1581 of 2012 and its regulatory decrees, which shall be communicated to all data subjects.

 

For any questions or additional information related to the processing of personal data, I can contact the email address: [email protected].

 

Important information

Below are the aspects that must be taken into account within the framework of the guidelines for the protection of personal data of the data subjects at the University of Cundinamarca.

NAME OF THE INSTITUTION: University of Cundinamarca has its origin in Ordinance No. 045 of December 19, 1969, by which the UNIVERSITY INSTITUTE OF CUNDINAMARCA, ITUC, is created. In 1992, through Resolution No. 19530 of December 30, issued by the Ministry of National Education, it was recognized as a UNIVERSITY, as stated in minutes No. 026 of December 17, 1992.

Below is the geographical coverage of the headquarters, regional sections, extensions, and the Bogotá office of the University of Cundinamarca:

HEADQUARTERS:

Fusagasugá:

Diagonal 18 No. 20-29, including the La Esperanza Agro-environmental Unit, Guavio Bajo rural district, and the Sports Academic Center (CAD), located at Carrera 17 A No. 19-65

CHAPTERS:

Girardot 19th Street No. 24 – 209.

Ubaté 6th Street No. 9-80, including the El Tíbar Agro-environmental Unit, San Pablo rural district, Novilleros sector, and any others that may apply.

EXTENSIONS:

Facatativá 14th Street and 15th Avenue, including the El Vergel Agroenvironmental Unit, and any others that may apply.

Chia Chía – Cajicá Highway, “El Cuarenta” Sector”

Soacha Diagonal 9 No. 4B – 85

Zipaquirá 7th Street No. 1-31

BOGOTA OFFICE:

20th Street No. 39-32, Teusaquillo.

  • Political Constitution, article
  • Law 1266 of 2008
  • Law 1581 of 2012
  • Partial Regulatory Decree 1377 of 2013
  • Judgments C-1011 of 2008 and C-748 of 2011 of the Constitutional Court

The principles, procedures, and provisions contained in this guideline shall apply to personal data registered in any database owned by a natural person that is in the custody of the University of Cundinamarca, either in the capacity of Controller or as the Processor of the Processing.

Likewise, it is mandatory for everyone who is part of and/or relates to the University of Cundinamarca and who processes personal data within Colombian territory, or when the Controller and/or Processor located outside Colombian territory is subject to Colombian laws by virtue of international treaties, contractual relationships, among others.

For the purposes of these guidelines and in accordance with current regulations on the protection of personal data, the following definitions shall be taken into account:

AuthorizationPrior, express, and informed consent of the Data Subject to carry out the Processing of personal data.

Privacy NoticeVerbal or written communication generated by the controller, addressed to the Data Subject for the processing of their personal data, by means of which they are informed about the existence of the information processing policies that will apply to them, the manner of accessing the same, and the purposes of the processing intended for the personal data.

Database. It is any organized set of personal data that is subject to Processing.

InquiryData subjects or their successors in title may consult the personal information of the data subject contained in any database, whether from the public or private sector. The Data Controller or Data Processor must provide them with all the information contained in the individual record or associated with the identification of the Data Subject.

Custodian: Role or process designated by the University to manage and ensure compliance with the security controls defined by the institution (backups, privilege assignment, modification, and deletion).

Personal dataAny information linked to or that can be associated with one or more specific or determinable natural persons.

Public dataIt is data that is not semi-private, private, or sensitive. Public data includes, among others, data relating to the marital status of persons, their profession or trade, and their status as a merchant or public servant. By their nature, public data may be contained, among others, in public registries, public documents, official gazettes and bulletins, and duly executed judicial rulings that are not subject to confidentiality.

Semi-private DataThese are data that are not of an intimate, reserved, or public nature, and whose knowledge or disclosure may be of interest not only to the owner but to a certain sector or to society in general. Financial and credit data from commercial or service activity are some examples, as well as academic information and contact data of the person.

Private DataIt is the data that, due to its intimate or reserved nature, is only relevant to the data subject. People's tastes or preferences, for example, correspond to private data.

Sensitive dataSensitive data is understood to be those that affect the privacy of the Data Subject or whose improper use may generate discrimination, such as those that reveal racial or ethnic origin, political orientation, religious or philosophical convictions, membership in trade unions, social organizations, human rights organizations or that promote the interests of any political party or that guarantee the rights and guarantees of opposition political parties, as well as data related to health, sexual life, and biometric data.

Data ProcessorNatural or legal person, public or private, who, either independently or jointly with others, carries out the Processing of personal data on behalf of the data controller.

Habeas DataFundamental right of every person to know, update, rectify, and/or cancel the information and Personal Data that has been collected about them and/or is processed in public or private Databases, in accordance with the provisions of the Law and other applicable regulations.

Data ControllerNatural or legal person, public or private, who, independently or jointly with others, makes decisions regarding the database and/or the processing of the data.

Data subjectNatural person whose personal data is subject to Processing.

Transferdata transfer takes place when the controller and/or processor of personal data, located in Colombia, sends the information or personal data to a recipient, who in turn is the controller and is located inside or outside the country.

Transmissionprocessing of personal data that involves the transmission of the same within or outside the territory of the Republic of Colombia when its purpose is the performance of processing by the processor on behalf of the controller.

TreatmentAny operation or set of operations performed on personal data, such as collection, storage, use, circulation, or deletion.

In compliance with the constitutional right of all persons to know, update, and rectify information regarding them stored in databases or archives, the implementation of the following principles is provided:

Principle of Restricted Access and CirculationThe processing of personal data is subject to the limits derived from their nature, the provisions of the law, and the Constitution. Consequently, such processing may only be carried out by persons authorized by the data subject and/or by persons provided for by law. Personal data, except for public information, may not be available on the internet or other means of dissemination or mass communication.

Principle of ConfidentialityThe person who at the University of Cundinamarca administers, manages, updates, or has access to information of any kind found in Databases is obligated to guarantee the confidentiality of the information, and therefore undertakes to keep and maintain it in a strictly confidential manner and not to disclose to third parties all information that they may come to know in the execution and exercise of their functions; except when dealing with activities expressly authorized by Law. This obligation persists and shall be maintained even after the termination of their relationship with any of the tasks comprising the Processing.

Principle of Purpose LimitationThe personal data processing activity carried out by the University of Cundinamarca or to which it has access shall be subject to a legitimate purpose in accordance with the Political Constitution of Colombia, which must be informed to the respective data subject.

Regarding the collection of personal data, the University of Cundinamarca will limit itself to those data that are pertinent and adequate for the purpose for which they were collected or required; the Vice-Rectorates, Secretariats, Directorates, Faculties, Units, Areas, Centers, etc., must inform the data subject of the reason why the information is requested and the specific use that will be given to it.

Principle of LegalityData processing is a regulated activity, which must be subject to the current and applicable legal provisions governing the matter.

Principle of FreedomThe processing of personal data may only be carried out with the prior, express, and informed consent of the data subject. Personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal, statutory, or judicial mandate that reveals consent.

Security PrincipleThe information subject to processing by the University of Cundinamarca must be handled with the technical, human, and administrative measures necessary to provide security to the records, preventing their adulteration, loss, consultation, use, or unauthorized or fraudulent access.

Principle of TransparencyIn the processing of personal data, the University of Cundinamarca shall guarantee the data subject the right to obtain at any time and without restrictions, information regarding the existence of any type of information or personal data of their interest or ownership.

Principle of Truthfulness or QualityInformation subject to the processing of personal data must be truthful, complete, accurate, updated, verifiable, and understandable. The processing of partial, incomplete, fractionated, or misleading data is prohibited.

In the ESG-SSI-M001 manual – SECURITY GUIDELINES MANUAL AND

INFORMATION PRIVACY, the guidelines established by the institution regarding the PROCESSING OF PERSONAL DATA, SENSITIVE DATA, DATA LIFE CYCLE, and MANAGEMENT OF PROCESSORS can be consulted

TREATMENT, among others.

In accordance with the provisions of the current applicable regulations on data protection, the owner of the personal data shall have the following rights:

  1. Access, know, update, and rectify your personal data with the University of Cundinamarca in its capacity as the data controller. This right may be exercised, among others, with respect to data that is partial, inaccurate, incomplete, fractionated, misleading, or data whose processing is expressly prohibited or has not been authorized.
  2. Request proof of the authorization granted to the University of Cundinamarca for data processing, through any valid means, except in cases where authorization is not required.
  3. To be informed by the University of Cundinamarca, upon request, regarding the use it has made of your personal data
  4. File complaints with the Superintendence of Industry and Commerce, or the entity acting in its stead, for violations of the provisions of Law 1581 of 2012 and others.
  5. Revoke the authorization and/or request the deletion of the data when the processing does not respect constitutional principles, rights, and guarantees, and
  6. To access your personal data that has been subject to processing free of charge, at least once every calendar month, and whenever there are substantial modifications to this policy that motivate new ones.

The University of Cundinamarca requires the free, prior, express, and informed consent of the personal data owner for the processing of such data, except in cases expressly authorized by law, namely:

  1. Information requested by a public or administrative entity in the exercise of its legal functions or by order
  2. Publicly available data.
  3. Medical emergency cases or
  4. Information processing authorized by law for historical, statistical, or scientific purposes.
  5. Data related to the Civil Registry of the

Statement of authorization

The authorization to the University of Cundinamarca for the processing of personal data will be granted by:

  • The account holder, who must sufficiently prove their identity through the various means made available by the University of
  • The legal successors of the holder, who must prove such
  • The representative and/or attorney-in-fact of the data subject, upon prior proof of representation or
  • Another in favor of whom or for whom the holder has stipulated.

Treatment shall ensure respect for the prevailing rights of minors. The processing of personal data of minors is prohibited, except for data of a public nature.

It is the duty of the State and educational entities of all kinds to provide information and train Legal Representatives and Guardians regarding the potential risks minors face regarding the improper processing of their personal data, and to provide knowledge about the responsible and safe use by minors of their personal data, their right to privacy, and the protection of their personal information and that of others.

  1. Guarantee the data subject, at all times, the full and effective exercise of the right of habeas corpus
  2. Request and keep a copy of the respective authorization granted by the data subject for the processing of data
  3. Properly inform the data subject about the purpose of the collection and the rights they hold by virtue of the authorization
  4. Preserve the information under the necessary security conditions to prevent its alteration, loss, consultation, use, or unauthorized access or
  5. Ensure that the information is truthful, complete, accurate, up-to-date, verifiable and
  6. Timely update the information, thereby addressing all developments regarding the data. Additionally, all necessary measures must be implemented to keep the information updated.
  7. Correct the information when it is incorrect and communicate it
  8. Process the inquiries and complaints filed in the terms indicated by the
  9. Identify when certain information is under discussion by
  10. Inform the data subject upon request about the use given to their
  11. Comply with the requirements and instructions issued by the Superintendence of Industry and Commerce on the specific matter.
  12. Ensure the proper use of minors' personal data in cases where the processing of their data is authorized
  13. Refrain from circulating information that is being contested by the data subject and whose blocking has been ordered by the Superintendency of Industry and Commerce
  14. Grant access to information only to persons who are authorized to have access to
  15. Use the data subject's personal data only for those purposes for which it is duly authorized, and in all cases respecting current regulations on the protection of personal data.

The purposes for which the University of Cundinamarca carries out or will carry out the processing of personal data of data subjects may be consulted in document ESG-SSI-G007 GUIDE TO PURPOSES FOR THE PROCESSING OF PERSONAL DATA OF DATA SUBJECTS OF THE UNIVERSITY OF CUNDINAMARCA, articulated with

number 5.1 Objectives of the ESG-SSI-M001 MANUAL OF INFORMATION SECURITY AND PRIVACY GUIDELINES located in the strategic macroprocess, integrated systems, information security of the Digital Operation Model of the University of Cundinamarca.

In compliance with the provisions of Law 1581 of 2012 and Decree 1377 of 2013, we inform you below of the aspects to be taken into account for the exercise of your rights regarding the processing of your personal data contained in the databases of the University of Cundinamarca.

  1. When the data subject needs to know, update, rectify, suppress their data, and/or revoke the authorization, they must consult the personal data management procedure within the institution's Digital Operating Model.
  2. The Data Subject interested in exercising one of these rights must prove this condition by providing a copy of their identification document or any other document requested by the Universidad de Cundinamarca to verify the identity of the subject. As mentioned, the subject must consult the procedure for the management of personal data within the institution's Digital Operation Model.
  3. In the event that the Data Subject is represented by a third party, they must attach the respective power of attorney stating the appointment and acceptance by the third party, which must have notarized recognition of signature and content before a notary public. The attorney-in-fact must also prove their identity in the indicated terms. If this document is not presented by the third party to prove that they are acting on behalf of the Data Subject, in order to protect the Data Subject's data, the claim will be considered as not submitted, as mentioned, they must consult the procedure for the management of personal data within the institution's Digital Operating Model.
  4. The response will be delivered exclusively to the Data Owner or their legal representative and solely to the same physical and/or electronic notification address included in the request; as mentioned, they must consult the procedure for the management of personal data within the institution's Digital Operating Model.
  5. Once the request has been received in the terms described above, and ownership has been verified, the University of Cundinamarca will respond in accordance with the response times and terms set by the Citizen Service Office.

The Personal Data Protection Officer shall be appointed by the management of the University of Cundinamarca. The tactical-operational team of the ISMS shall support the implementation of the Data Protection Law for Data Subjects of the University of Cundinamarca, for which the management of the University of Cundinamarca shall ensure the continuous training of the personnel in the ISMS area.

The function of the Data Protection Officer at the University of Cundinamarca will be to ensure compliance with the guidelines and procedures adopted by it, in order to comply with the regulatory standards established at the national level for the protection of personal data, as well as the implementation of good practices within the Institution.

Below are some of the functions to be performed by the data processing officer:

  1. Implement the guideline for the protection and processing of personal data and any other guidelines derived from the
  2. Report the existence of databases and modifications to the Superintendency of Industry and Commerce.
  3. Process the inquiry and complaint requests made by data subjects or their legal representatives, within the legal deadlines and through the channels established for
  4. Design, correct, modify, or update the established protocols and procedures for the collection, storage, use, and circulation of personal data within the institution.
  5. Address the requirements that the Superintendency of Industry and Commerce submits to the University.
  6. Generate and follow up on the reports required by the Superintendence of Industry and
  7. Review and propose data transmission and personal data transfer contracts with third parties, if applicable
  8. Serve as a communication channel within the University to resolve questions, incidents, and issues regarding data processing topics.

This Policy shall enter into force on August 8, 2023, and supersedes any prior policies to the contrary.

Personal Data Protection

Personal Data Protection

Personal Data Protection

Personal Data Protection