Era University is a premier healthcare and educational institution in Northern India, comprising a multi-specialty teaching hospital and academic institutions. The University is committed to protecting the privacy of patients, students, employees, researchers, visitors, and other stakeholders. This Policy outlines how personal data is collected, used, stored, shared, protected, and retained in compliance with applicable laws and institutional standards.
This Policy shall apply to all departments, colleges, teaching hospital, laboratories, research centres, hostels, administrative offices, websites, mobile applications, cloud services, employees, faculty members, students, consultants, outsourced personnel, contractors and third-party service providers engaged by Era University.
For the purposes of this Privacy & Data Protection Policy, the following terms shall have the meanings assigned below:
1. Personal Data means any data about an individual who is identifiable by or in relation to such data, whether directly or indirectly, in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA).
2. Sensitive Personal Information Refers to categories of information that require enhanced protection under applicable law and institutional policy, including but not limited to health records, biometric information, genetic data, financial information, government-issued identification details, and any other information classified as sensitive under applicable legal or regulatory requirements. This category is maintained by the University as an internal risk-tiering classification, informed presently by the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules") and general good practice. The Digital Personal Data Protection Act, 2023 does not itself create a separate statutory class of "sensitive" personal data and regulates Personal Data uniformly, save for its special provisions relating to children's data and any cross-border transfer restrictions the Central Government may in future notify.
3. Data Principal means the individual to whom the Personal Data relates. In the case of a child or a person with a disability having a lawful guardian, the term includes such parent, lawful guardian or authorised representative, as applicable under law.
4. Data Fiduciary means Era University, which alone or jointly with others determines the purpose and means of processing Personal Data.
5. Data Processor means any person or organisation that processes Personal Data on behalf of Era University under a valid contractual arrangement and in accordance with applicable laws and this Policy.
6. Processing means any operation or set of operations performed on Personal Data, whether wholly or partly automated, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, sharing, transmission, alignment, combination, restriction, erasure or destruction.
7. Consent means a free, specific, informed, unconditional and unambiguous indication of the Data Principal's agreement to the processing of Personal Data for a specified purpose, provided through a clear affirmative action, wherever consent is the lawful basis for processing.
8. Anonymisation means the process of irreversibly transforming Personal Data so that an individual can no longer be identified, directly or indirectly.
9. Pseudonymisation means the processing of Personal Data in such a manner that it can no longer be attributed to a specific individual without the use of additional information, provided such additional information is kept separately and protected through appropriate technical and organisational measures.
10. Personal Data Breach means any unauthorised or accidental processing, disclosure, acquisition, alteration, loss, destruction or compromise of Personal Data affecting its confidentiality, integrity or availability.
11. Child means an individual who has not completed the age of eighteen (18) years, as fixed under Section 2(f) of the Digital Personal Data Protection Act, 2023 (DPDPA). Any narrower verifiable-consent exemption the Central Government may in future prescribe by rule for specified, verifiably safe processing purposes shall apply only to the parental or guardian consent requirement under applicable law and shall not alter this definition.
12. Third Party means any natural or legal person, public authority, agency or organisation other than the Data Principal, Era University or a person authorised to process Personal Data on behalf of Era University.
13. Applicable Laws means all applicable laws, rules, regulations, notifications, guidelines, standards and governmental directions relating to privacy, data protection, healthcare, education, research, cybersecurity and information technology in force from time to time.
14. Institutional Ethics Committee (IEC) means the committee constituted by Era University to review, approve and monitor research involving human participants in accordance with the Indian Council of Medical Research (ICMR) National Ethical Guidelines for Biomedical and Health Research Involving Human Participants, Good Clinical Practice (GCP) Guidelines and other applicable legal and regulatory requirements.
Era University processes Personal Data in accordance with applicable laws and regulatory requirements, including but not limited to:
The DPDPA received Presidential assent in August 2023 but commences in stages, by notification of the Central Government, rather than all at once. As of the date of this Policy, only the Data Protection Board of India's establishment and procedural provisions, and related definitional and rule-making provisions, are in force. The substantive obligations most relevant to this Policy — notice and consent requirements, Data Principal rights, breach intimation to the Board, Significant Data Fiduciary duties, and the cross-border transfer regime under Section 16 — are expected to commence in further stages. Because Section 43A of the IT Act has not yet been omitted, the SPDI Rules remain fully in force in the interim. This Policy will be revised as further DPDPA provisions are notified; the applicable commencement notification should be checked for the current position before this Policy is relied upon for a specific compliance determination.
The University may collect the following categories of Personal Data:
Era University processes personal data only for lawful, specified and legitimate purposes connected with healthcare delivery, education, research, administration and institutional operations. The University collects only such personal data as is necessary to fulfil these purposes and retains it only for as long as required by applicable law, regulatory obligations, medical record retention requirements, academic requirements or legitimate institutional needs. Appropriate technical, administrative and physical safeguards are implemented to protect personal data against unauthorised access, disclosure, alteration, loss or misuse. Personal data is processed in accordance with the principles of consent, purpose limitation, data minimisation, accuracy, storage limitation and accountability as prescribed under the Digital Personal Data Protection Act, 2023 and other applicable laws.
Era University and its associated teaching hospital collect and process personal data relating to patients for purposes including but not limited to:
Wherever feasible and appropriate, research and AI activities shall utilise anonymised or pseudonymised datasets to minimise privacy risks while maintaining scientific integrity.
Era University collects and processes personal data relating to students for purposes including:
Where personal data of minors is processed, Era University shall comply with the applicable provisions governing children's personal data under Section 9 of the DPDPA and applicable rules.
Era University processes personal data relating to employees, faculty members, residents, consultants and contractual staff for purposes including:
Certain processing activities may be undertaken where necessary for employment-related purposes as permitted under applicable law.
Era University collects and processes personal data relating to vendors, contractors, consultants, suppliers, research collaborators and business partners for purposes including:
Where third-party service providers process personal data on behalf of Era University, they are contractually required to implement appropriate security and confidentiality measures consistent with applicable legal and regulatory requirements.
Personal data may be stored in secure physical records, institutional servers, authorised cloud infrastructure, Electronic Medical Record systems, Enterprise Resource Planning (ERP) systems, Learning Management Systems, Hospital Information Systems, research databases and other approved information systems. Era University implements appropriate administrative, technical and organisational safeguards including access controls, encryption where appropriate, audit logging, backup mechanisms, disaster recovery procedures and periodic security assessments to protect personal data.
Personal data shall be retained only for the period necessary to fulfil the purposes for which it was collected or as required under applicable healthcare, educational, employment, taxation, legal or regulatory record retention requirements. Upon expiry of the applicable retention period, personal data shall be securely deleted, anonymised or archived in accordance with the University's Records Retention and Secure Disposal Policy and applicable law.
Any actual or suspected Personal Data Breach shall be reported immediately to the University's designated incident response function and the office of the Data Protection Officer, who shall assess the scope, cause and affected Data Principals.
Where the incident constitutes a cyber security incident within the meaning of the directions issued by CERT-In under Section 70B of the IT Act, it shall be reported to CERT-In within six (6) hours of detection or of being notified, in the form and manner prescribed under those directions.
An internal breach log shall be maintained, recording the nature, cause, impact and remedial action taken for every Personal Data Breach, regardless of whether external reporting is triggered.
Once the corresponding provisions of the DPDPA (including Rule 7 of the Digital Personal Data Protection Rules, 2025) come into force, the University shall additionally intimate the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed thereunder.
Remedial and corrective measures arising from a Personal Data Breach shall be documented and reviewed by the Institutional Data Protection Committee, and this Policy and associated security controls shall be updated as necessary in light of the review.
Personal Data, including sensitive personal data such as health and biometric records, may be stored or processed using cloud infrastructure and service providers located within or outside India. Any transfer of sensitive personal data outside India shall be undertaken only (a) with the consent of the Data Principal, or (b) where necessary for the performance of a lawful contract between the University and the Data Principal, or between the University and a third party for the Data Principal's benefit, and in either case only to a recipient that maintains a level of security at least equivalent to that required under the SPDI Rules and this Policy.
Once Section 16 of the DPDPA and the related rules come into force, cross-border transfers shall additionally be assessed against any list of restricted countries or territories notified by the Central Government. The University shall maintain a record of its cross-border processing arrangements and the underlying data processing agreements with its cloud and technology service providers, and shall make this record available for internal audit and, where legally required, to regulators.
Personal Data used for research shall, wherever feasible, be anonymised or de-identified. All research involving identifiable Personal Data shall be undertaken only after obtaining approval from the Institutional Ethics Committee (IEC) and shall be conducted in accordance with the Indian Council of Medical Research (ICMR) National Ethical Guidelines, Good Clinical Practice (GCP) Guidelines, applicable laws and institutional research governance requirements.
Subject to applicable law, Data Principals may:
The University shall endeavour to acknowledge and substantively respond to requests and grievances under this section within thirty (30) days of receipt. Where a Data Principal is not satisfied with the University's response, they may, once the corresponding provisions of the DPDPA come into force, escalate the grievance to the Data Protection Board of India, in addition to any other remedy available in law.
Given the nature and volume of Personal Data it processes, Era University will assess, on an ongoing basis, whether it is liable to be notified as a Significant Data Fiduciary under Section 10 of the DPDPA once that provision and the related notification framework come into force. If so notified, the University shall comply with the attendant obligations, including appointment of a Data Protection Officer based in India, periodic Data Protection Impact Assessments, and independent data audits, and shall update this Policy accordingly.
Where required by law, verifiable consent of a parent, lawful guardian or authorised representative shall be obtained before processing personal data of children or persons with disabilities, in accordance with Section 9 of the DPDPA and applicable rules.
The University's website may use cookies to improve functionality and security. If there are any links provided to third-party websites for convenience, Era University is not responsible for their privacy practices. Users should review the privacy policies of such websites before sharing personal information.
Personal data shall be retained only for the period required under applicable laws, regulatory requirements, medical record retention obligations, academic requirements, contractual obligations and institutional policies, after which it shall be securely anonymised, de-identified, archived or disposed of, in accordance with the University's Records Retention and Secure Disposal Policy.
In addition to this Policy, the University shall provide itemised notice at or before the point of collection — including on patient registration and admission forms, student admission and LMS enrolment forms, and employee onboarding documentation — describing the Personal Data collected, the purpose of collection, and the manner in which consent may be given, where consent is the basis of processing. Such point-of-collection notices shall reference this Policy for further detail.
This Policy may be reviewed and updated periodically to reflect changes in applicable laws, technology, institutional practices, accreditation requirements and regulatory obligations.
For any request related to exercise of data principals' rights under different laws mentioned above, which include right to access, updating, deletion, data correction, withdrawal of consent, or any other grievance related to data retention, please send mail to the following address:
Email: dpo@erauniversity.in
This Policy has been approved by the Executive Council of Era University, Lucknow and shall be reviewed annually or whenever required by law.