Scope and Application
This Privacy Policy explains how personal information is handled through official Kaharagian websites, portals, applications and other digital services operated by or on behalf of the State of the Kaharagians and its institutions.
It applies generally across official Kaharagian digital services.
Some services perform specialised functions, such as identity management, public records, applications, education, verification, official publications or administrative casework. Those services may publish an additional privacy notice setting out the information they collect and how it is used.
Where a service-specific privacy notice is provided, it should be read with this general Policy. The service-specific notice takes precedence where it gives more detailed or different information about that service.
This Policy should also be read with the applicable Terms of Service and Cookies Policy.
This Policy gives general information. It does not reduce any right or duty under the Data Protection Code (DPC). If this Policy conflicts with the DPC or a higher source of Kaharagian law, the law prevails.
Data Controller
The controller is the State of the Kaharagians or the Kaharagian organ that determines the purposes and means of the relevant processing, as provided by DPC Art. 2.
The Royal Chancellery is the central point of contact for privacy enquiries and requests. It may refer a matter to the controller, its designated compliance contact or the supervisory authority.
At or before collection, the relevant service must provide the information required by DPC Art. 8, including the controller and contact details, purposes and lawful basis, any legitimate interest relied upon, recipients, retention period or criteria, applicable rights, complaint route, and whether providing the data is required by law or contract. The notice must be concise, clear, accessible, free of charge and persistently available through the service interface.
Where data is obtained from another source, the controller must provide the additional source and category information required by DPC Art. 9, normally within 30 days and no later than the first communication or disclosure, unless a statutory exception applies.
Our Approach to Personal Information
The State collects and uses personal data only on a lawful basis and only to the extent necessary for a specified, explicit and legitimate purpose.
Personal data must be:
- collected for a clear and lawful purpose;
- adequate, relevant and limited to what is necessary;
- accurate and, where necessary, kept up to date;
- protected against unauthorised access or misuse;
- retained in identifiable form only for as long as necessary; and
- processed transparently and consistently with the purpose for which it was collected.
These principles reflect DPC Arts. 4–6.
Official Kaharagian websites are not used to sell personal information or create commercial advertising profiles.
Nature of Official Kaharagian Digital Services
Official Kaharagian websites and services may be used to:
- publish official information, laws, notices and public records;
- provide access to government programmes and services;
- receive enquiries, applications and requests;
- manage accounts and identity verification;
- maintain administrative and institutional records;
- provide educational, cultural and public information;
- process registrations, appointments or submissions;
- issue, verify or manage official documents and credentials; and
- protect the security and integrity of State systems.
The information processed by a particular service will depend upon its purpose and functions.
Some public information websites may collect little more than ordinary technical information created when a page is requested. Other services may require personal information to provide an account, process an application or complete an administrative function.
Personal Information We May Process
Depending upon the service being used, the State may process the categories of information described below.
Website and Device Information
When an official website or service is accessed, technical information may be created or recorded automatically.
This may include:
- internet protocol address;
- browser and device type;
- operating system;
- preferred language;
- pages or resources requested;
- date and time of access;
- referring page or website, where provided by the browser;
- approximate location derived from network information;
- error messages and diagnostic information; and
- security, authentication and access logs.
This information is generally used to operate, secure and maintain the relevant service.
Contact and Correspondence Information
Where a person contacts a Kaharagian institution, the State may process:
- name;
- email address;
- postal address or telephone number, where provided;
- the subject and content of the enquiry;
- documents or information attached to the correspondence;
- the date and time of the communication; and
- records of any response or follow-up action.
Correspondence may be forwarded within the State where another institution or officer is better placed to deal with the matter.
Account Information
Services that require an account may process:
- name and contact details;
- username or account identifier;
- password information in protected or encrypted form;
- authentication records;
- account status;
- security and recovery information;
- assigned roles or permissions;
- login history; and
- preferences connected with the account.
Some services may use a central Kaharagian identity system to allow access across more than one official service.
Identity and Verification Information
Where identity must be confirmed, a service may process:
- full legal or recognised name;
- date of birth;
- nationality or status information;
- identification numbers;
- official documents;
- photographs;
- signatures;
- identity-verification results;
- supporting evidence; and
- records of authentication or verification checks.
Only information necessary for the relevant process may be requested.
Applications, Registrations and Administrative Records
Services used for applications, registrations, requests or official processes may collect:
- information entered into forms;
- eligibility information;
- declarations and attestations;
- supporting documents;
- appointment details;
- application history;
- case status;
- decisions and reasons;
- correspondence relating to the matter; and
- records required for audit or official administration.
The exact information required will depend upon the service and the nature of the application or request.
Transaction and Service Information
Where a service involves a payment, order or other transaction, the State may process:
- transaction reference numbers;
- the service or item requested;
- payment status;
- billing or delivery details;
- order history; and
- records required for accounting, audit or dispute resolution.
Payment-card information may be handled directly by an authorised payment provider rather than retained by the State.
Information Submitted Voluntarily
A person may choose to provide additional information when contacting the State or using a service.
Users should avoid submitting information that is not relevant to the purpose of the form, application or enquiry.
Providing unnecessary personal information may make it more difficult for the State to limit access, retention and disclosure appropriately.
Sensitive Personal Information
Some official services may need to process information that is particularly private or sensitive.
“Sensitive personal data” has the meaning given by DPC Art. 2 and includes data revealing or concerning:
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade-union membership;
- genetic data;
- biometric data used to identify a person uniquely;
- health; or
- a person’s sex life or sexual orientation.
Sensitive personal data must not be processed unless one of the conditions in DPC Art. 4(5) applies. Other confidential information, including financial, disciplinary, criminal, pastoral or child-related information, is protected according to its nature and the risks presented by the processing.
Users should not submit sensitive information through a general contact form unless it is necessary for the matter being raised. Where possible, a secure or service-specific method should be used.
Information About Other People
A User should not provide personal information about another person unless they are authorised to do so or there is another lawful reason for providing it.
Where an application or enquiry requires information about another person, the User may be asked to confirm that the information is accurate and has been provided lawfully.
Cookies and Similar Technologies
Official Kaharagian websites may use cookies, local storage, authentication tokens and similar technologies.
These may be used to:
- maintain a secure session;
- allow a User to sign in;
- remember display or accessibility preferences;
- protect against fraud or malicious activity;
- record a cookie choice; or
- understand and improve the operation of a service.
The cookies and similar technologies used by official services are addressed in the Cookies Policy and in any service-specific cookie notice.
Purposes for Which Information May Be Used
Personal information may be processed for the following purposes.
Providing Official Services
Information may be used to provide the website, account, service, information or administrative function requested by the User.
Responding to Enquiries
Contact information and correspondence may be used to consider, answer and maintain a record of an enquiry, request or complaint.
Processing Applications and Requests
Information may be used to assess eligibility, verify identity, review supporting evidence, make decisions and administer the relevant process.
Maintaining Official Records
The State may retain information where it forms part of an official, legal, administrative, historical or institutional record.
Security and Abuse Prevention
Technical and account information may be used to:
- protect websites and systems;
- detect unauthorised access;
- investigate suspicious activity;
- prevent fraud or misuse;
- enforce applicable terms;
- maintain audit records; and
- respond to security incidents.
Service Administration and Improvement
Information may be used to diagnose errors, maintain infrastructure, understand service performance and make reasonable improvements.
Compliance with Law and Official Duties
Information may be processed where necessary to comply with Kaharagian law, an official order, a legal obligation or the lawful functions of a Kaharagian institution.
Protection of Rights and Interests
Information may be used where reasonably necessary to protect the rights, safety, property or lawful interests of the State, its institutions, its officers, Users or other persons.
Basis for Processing
Personal data is processed only where at least one lawful basis in DPC Art. 4 applies:
- valid consent for one or more specified purposes;
- necessity for a contract with the data subject or requested pre-contractual steps;
- necessity to comply with a legal obligation under Kaharagian law or applicable mandatory host-jurisdiction law;
- necessity to protect the vital interests of the data subject or another natural person; or
- a legitimate interest pursued by the State, a Kaharagian organ or a Kaharagian legal person that is not overridden by the data subject’s fundamental rights and freedoms.
A controller relying on legitimate interests must conduct and document the balancing assessment required by DPC Art. 4(4).
The appropriate basis may differ between services and types of information.
Consent
Consent may be requested where a particular form of processing is optional and cannot reasonably be based upon another lawful ground.
Consent must be freely given, specific, informed and unambiguous, and expressed through a clear affirmative act. Silence, inactivity and pre-ticked boxes are not consent. The controller must record enough information to demonstrate valid consent.
Where processing is based upon consent, the person may withdraw it at any time through a method as easy to use as the method by which it was given.
Withdrawal does not make earlier processing unlawful. It may, however, affect the State’s ability to provide an optional feature or continue a process that depends upon the information concerned.
Not all processing is based upon consent. The State may still be required to retain or use information where another lawful basis applies.
Purpose Limitation
Personal information must not be used for an incompatible purpose. Before changing a purpose, the controller must document the compatibility assessment required by DPC Art. 5 and, where necessary, provide a new notice or obtain valid consent.
Further processing may proceed where:
- the new use is reasonably compatible with the original purpose;
- the individual has been properly informed;
- consent has been obtained where required; or
- the use is authorised or required by Kaharagian law.
For example, information submitted through a general enquiry channel must ordinarily be used only to consider and respond to that enquiry.
Security logs must ordinarily be used only for system protection, abuse prevention, investigation and operational diagnosis.
Accuracy of Information
The controller must take every reasonable step to keep personal data accurate and, where necessary, current, and to erase or rectify inaccurate data without undue delay.
Users should provide accurate information and should notify the relevant institution when important information changes.
The State may request documents or other evidence where information must be verified before a service can be provided or an official record can be changed.
Data Retention
Personal information is retained only for as long as there is a lawful, administrative, security, historical or operational reason to keep it.
Retention periods will vary according to the information and the service concerned.
Each controller must maintain a documented retention policy specifying the period for each category of personal data, review that policy regularly, and erase or anonymise data that is no longer necessary, subject to the lawful archival, research and statistical exceptions in DPC Arts. 5 and 6.
Factors considered may include:
- the purpose for which the information was collected;
- whether an application, enquiry or case remains open;
- legal and administrative recordkeeping requirements;
- security and audit needs;
- the possibility of review, complaint or dispute;
- the historical or evidential value of the record; and
- any applicable retention schedule.
Technical and Security Logs
Technical logs are generally retained for the period needed for security monitoring, investigation, maintenance and operational diagnosis.
Logs may be retained for longer where they relate to a suspected security incident, abuse, legal matter or ongoing investigation.
Enquiries and Correspondence
Correspondence may be retained while the matter is being handled and for a reasonable period afterwards for reference, follow-up, audit and institutional recordkeeping.
Accounts
Account information may be retained while the account remains active and for a reasonable period after closure where required for security, audit, recovery or legal purposes.
Official and Administrative Records
Some records may need to be retained for an extended period or permanently where they form part of an official register, legal record, historical archive or continuing administrative record.
Cookies and Local Storage
Information stored on the User’s device remains until it expires, is replaced or is cleared through the browser or device settings.
Further details are provided in the Cookies Policy.
Accountability and Processing Records
Each controller must be able to demonstrate compliance. It must maintain the written or electronic record of processing activities required by DPC Art. 17, including purposes, data and data-subject categories, recipients, international transfers and safeguards, erasure periods, and a general description of security measures, unless the narrow exception in DPC Art. 17(5) applies.
Controllers must allocate responsibility for compliance, maintain procedures for data-subject requests, train persons who process personal data, and review measures whenever processing or risk changes materially, as required by DPC Art. 15.
Data Security
The State must implement data protection by design and by default and maintain security appropriate to the risks presented by the processing. Under DPC Arts. 16 and 18, State processing must use:
- encryption in transit and at rest, using cryptographic standards recognised as current international good practice;
- multi-factor authentication and role-based access control;
- comprehensive, tamper-protected audit logs;
- measures supporting the confidentiality, integrity, availability and resilience of systems;
- the ability to restore access to personal data after an incident; and
- regular testing, assessment and review of security measures.
Access is limited to authorised personnel on a need-to-know basis. Pseudonymisation, anonymisation and separation of data are used where required or appropriate. Any alternative to the presumptive encryption standard must provide an equivalent or higher level of protection and be documented.
No electronic system is risk-free. This qualification does not reduce the mandatory security duties imposed by the DPC.
Data Breaches and Security Incidents
The State must contain, investigate and document every personal data breach. Unless a breach is unlikely to risk the rights and freedoms of natural persons, the controller must notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. A processor must notify the controller without undue delay.
Where a breach is likely to result in a high risk, the controller must also notify affected data subjects without undue delay in clear and plain language, unless an exception in DPC Art. 20 applies. Notifications must describe the nature and likely consequences of the breach, provide a contact point, explain the response and recommend protective steps where relevant.
These duties are set out in DPC Arts. 19 and 20.
Sharing Within the State
Personal information may be shared between Kaharagian institutions where reasonably necessary to:
- provide the requested service;
- answer an enquiry;
- verify information;
- maintain an official record;
- carry out a lawful administrative function;
- investigate suspected misconduct or security concerns;
- comply with a legal requirement; or
- refer a matter to the institution responsible for dealing with it.
Information must not be shared within the State merely for convenience. Every disclosure requires a documented lawful basis, a specified purpose and data minimisation.
Service Providers
The State may use service providers to host, secure, maintain or support official digital services.
These providers may include:
- hosting and cloud service providers;
- domain and network providers;
- identity and authentication services;
- communications platforms;
- payment processors;
- email and notification services;
- video-conferencing providers;
- technical support providers; and
- security and monitoring services.
Service providers may process limited personal information as part of providing their services. A controller may appoint only processors that provide sufficient guarantees of DPC compliance.
Processing must be governed by a written contract or other binding instrument satisfying DPC Art. 23. Among other things, it must limit the processor to documented instructions, impose confidentiality and security duties, regulate sub-processors, support data-subject rights and breach response, provide for deletion or return of data, and permit compliance audits.
Other Disclosures
Personal information may be disclosed where:
- the individual has authorised the disclosure;
- disclosure is required by Kaharagian law;
- disclosure is required by a lawful order or official process;
- it is necessary to investigate fraud, misuse or a security incident;
- it is necessary to protect a person from serious harm;
- it is necessary to establish, exercise or defend a legal claim; or
- the information is transferred as part of a lawful reorganisation of a Kaharagian service or institution.
Only the information necessary for the lawful purpose may be disclosed. International disclosures must also comply with DPC Art. 22.
Sale and Commercial Use of Personal Information
The State does not sell, rent or trade personal information.
Personal information collected through official Kaharagian services is not disclosed to third parties for their independent advertising or commercial marketing purposes.
Official services must not use personal information for behavioural advertising or unrelated commercial profiling.
International Hosting and Data Processing
State personal data is necessarily stored across foreign jurisdictions. The State’s obligations under the DPC apply regardless of the location of infrastructure.
An international transfer may be made only in accordance with DPC Art. 22:
- to a jurisdiction covered by an adequacy determination;
- under appropriate and enforceable safeguards, such as approved contractual clauses, an approved code of conduct or certification; or
- where a specific statutory derogation applies and its conditions are met.
The State must publish and maintain a current list of the foreign jurisdictions in which State data is held, the categories of personal data stored in each jurisdiction and the applicable safeguards. A data subject may ask for information about the safeguards governing a transfer.
Mandatory host-jurisdiction law applies to the extent required by DPC Arts. 3 and 29. Where it provides a higher level of protection, the higher standard prevails; it must never be used to reduce a right granted by the DPC.
Worldwide Access
Official Kaharagian websites may be accessed from many countries.
When a person uses an official service from outside Kaharagia, technical information may pass through networks or systems located in more than one jurisdiction.
Users should understand that the legal rules applying to their own device, network provider or local activity may differ from Kaharagian law.
Third-Party Websites
Official websites may contain links to external websites or services.
The State is not responsible for the privacy practices of a website or service it does not operate.
Users should review the privacy information provided by the relevant third party before submitting personal information to it.
The inclusion of a link does not mean that the State controls or endorses the third party’s handling of personal information.
Individual Rights
Persons whose personal information is processed by the State have rights under Kaharagian data protection law.
Subject to the conditions and exceptions in the DPC, these include the right to:
- ask whether personal information is being processed;
- obtain access to personal information;
- request correction of inaccurate or incomplete information;
- request erasure where there is no lawful reason for continued retention;
- request restriction of certain processing;
- object to certain uses of personal information;
- receive eligible data in a structured, commonly used and machine-readable format and transmit it to another controller;
- withdraw consent where processing is based upon consent;
- request information about how personal information is being used, including transfer safeguards and meaningful information about relevant automated decision-making;
- raise a complaint or request a review.
These rights may be subject to lawful limitations.
For example, information may need to be retained where it forms part of an official record, is required by law, is relevant to an investigation or is necessary for the protection of another person’s rights.
Where erasure is required, it must be complete and irreversible across copies, replications and backups, except where a specific copy must lawfully be retained. The controller must document the erasure and notify recipients unless doing so is impossible or would involve disproportionate effort. Comparable recipient-notification duties apply to rectification and restriction.
Making a Privacy Request
Requests concerning personal information should be directed to the Royal Chancellery.
A request should include enough information to identify:
- the person making the request;
- the website, service or institution concerned;
- the information or processing being questioned; and
- the action being requested.
The State may ask for proof of identity before disclosing, correcting or deleting personal information.
This is intended to prevent information from being released or altered at the request of an unauthorised person.
Requests under DPC Arts. 10–14 will be answered without undue delay and within 30 days. Where permitted by the DPC, that period may be extended once by a further 30 days because of complexity or volume; the requester will be told of the extension and reasons within the initial period. The first access copy is free. A reasonable administrative fee may be charged, or action refused, only where the controller proves that a request is manifestly unfounded or excessive.
Where a request is unusually complex or concerns a large amount of information, the Royal Chancellery may contact the requester for clarification.
Children and Minors
Some official services may be intended for, or available to, children and young people.
Under the Civil Code, a person under 18 is a minor. Where processing relies on consent from a minor, consent must be given or authorised by the holder of parental authority or legal guardianship, and the controller must make reasonable efforts to verify that authority. Services involving minors must:
- collect only what is reasonably necessary;
- explain the use of the information clearly;
- apply appropriate security and access controls;
- obtain and verify parental or guardian authorisation where consent is the lawful basis; and
- avoid unnecessary profiling or commercial use.
A child or minor should not use a general contact form to submit sensitive personal information without the knowledge of a parent, guardian or other responsible adult, unless seeking assistance in circumstances where doing so would be inappropriate or unsafe.
Service-specific age requirements may apply.
Automated Decision-Making
Some services may use automated checks to support security, verification, eligibility or administrative processing.
Before systematic and extensive automated evaluation or profiling likely to create a high risk, the controller must complete the data protection impact assessment required by DPC Art. 21. A data subject has a right to meaningful information about the logic, significance and expected consequences of relevant automated decision-making.
Where an automated process significantly affects an individual, human review must be available where required by Kaharagian law or administrative policy.
Automated tools must not be treated as a substitute for lawful judgement where an official decision requires consideration of individual circumstances.
Complaints and Concerns
A person who believes that their personal data has been handled unlawfully may complain to the supervisory authority under DPC Art. 27. The Sovereign is the supervisory authority unless the function has been delegated by decree. A complaint may be sent through the Royal Chancellery for referral.
The concern should identify:
- the service or institution involved;
- the information concerned;
- what is believed to have gone wrong;
- any earlier correspondence about the matter; and
- the outcome being sought.
The supervisory authority must acknowledge a complaint within 14 days and report on its progress and outcome within 90 days. A single further period of up to 90 days is available for a complex matter if the complainant is notified, with reasons, before the initial period expires.
The complainant may petition the Sovereign for review, seek compensation under DPC Art. 28, and pursue any additional remedy available under the law of the jurisdiction in which they reside or the damage occurred.
Governing Law, Jurisdiction and Enforcement
This Policy is governed by Kaharagian law, subject to the Fundamental Laws, applicable promulgated treaties and Kaharagian conflict-of-laws rules. Kaharagian law governs the State’s internal authority and the official character of its services. Mandatory host-jurisdiction law applies where the Fundamental Laws or the DPC so provides, including the higher-protection rule in DPC Art. 29.
Acting through a competent authority and as permitted by applicable law, the State may choose to commence, defend, support or participate in proceedings; seek interim or final relief; enforce rights or judgments; cooperate with foreign authorities; or refer conduct to a competent authority in any jurisdiction. A choice to act in a foreign forum is limited to that matter and carries the jurisdictional consequences imposed by applicable law; it is not a general submission for unrelated matters.
This section is to be read with FN Arts. 6, 36, 38, 42, 45 and 47 and DPC Arts. 3, 26 and 29. Officials acting abroad do not claim immunity or privilege that the host jurisdiction does not recognise.
Contact
Questions, requests and concerns relating to privacy or personal information should be directed to:
Royal Chancellery
chancellery@kaharagia.org
Correspondence should identify the official website, service or institution concerned and provide sufficient information for the matter to be considered.
The Royal Chancellery may refer the correspondence to the authorised institution, office or officer responsible for the relevant service or record.
Changes to This Policy
This Privacy Policy may be amended to reflect changes in Kaharagian law, administrative practice, technology or the operation of official services.
The review date above will be updated after a substantive change.
Where a change materially affects the way a service processes personal information, additional notice may be provided through the relevant website or service.
Supplements for Particular Services
This policy applies to every official service of the State. Some services do something it does not describe, and publish a supplement saying so. A supplement is read together with this policy; it does not replace it.
- The National ePortaleportal.kaharagia.org
- K-Connectconnect.kaharagia.org
- The Verification Portalverify.kaharagia.org
- The Honours Portalhonours.kaharagia.org
- The Kaharagian Shopshop.kaharagia.org
- The Royal Kaharagian Gazettegazette.kaharagia.org
- KahaLexkahalex.kaharagia.org
- The Global Factbookcountries.kaharagia.org
- The Design Systemdesign.kaharagia.org
- Kaharagia.orgkaharagia.org