Privacy Policy
Version 2026-09-05.
The Centre des Hautes Études de Défense et de Sécurité (CHEDS) attaches particular importance to the protection, confidentiality and responsible use of the personal data entrusted to it in the course of organising its activities and, more specifically, the International Colloquium.
The purpose of this policy is to inform participants of the principles governing the collection, use, retention, safeguarding and, where applicable, disclosure of their data.
The processing carried out complies with the applicable personal data protection regulations, in particular Senegalese Law No. 2008-12 of 25 January 2008 and, where they apply, the relevant provisions of the General Data Protection Regulation (GDPR).
The Centre des Hautes Études de Défense et de Sécurité (CHEDS) ensures that all data is processed in accordance with the principles of lawfulness, fairness, transparency, proportionality, confidentiality, security, and storage limitation.
1. Data Controller
Centre des Hautes Études de Défense et de Sécurité (CHEDS)
Address: Boulevard de la Défense x Rue du Port, derrière le siège de la BCEAO, BP 4705, Dakar, Sénégal
Email:
infos@cheds.gouv.sn
Telephone: +221 33 822 91 67
The data controller determines the purposes of the processing and the general conditions under which personal data is used.
Any request concerning data protection may be addressed to it using the contact details given above or, where a specific point of contact has been designated, the contact details set out in this policy.
2. Data Protection Contact
CHEDS Directorate General (data protection contact point) — infos@cheds.gouv.sn
This point of contact may be approached with any question concerning this policy, the processing of your information or the exercise of your rights.
3. Scope
This policy applies to the data processed in connection with the registration, accreditation, participation, reception, any logistical support and administrative follow-up of participants in the Colloquium.
It also covers the processing required for the operation, administration, security and continuity of the platform made available to participants.
4. Applicable Principles
The Centre des Hautes Études de Défense et de Sécurité (CHEDS) ensures that personal data is collected for specified, explicit, and legitimate purposes. Collection is limited to information that is adequate, relevant, and necessary in relation to those purposes.
Personal data is not reused in a manner incompatible with the purposes for which it was collected. Access is restricted to authorised persons, its use remains controlled, and its retention is proportionate to its purpose.
The data controller also ensures, to the extent necessary, the quality, accuracy and currency of the information processed.
5. Purposes of Processing
The purpose of the processing carried out is to enable the organisation, administration and securing of participation in the Colloquium. It may in particular concern:
- the management, examination and approval of registrations;
- the identification and accreditation of participants;
- the organisation of participation in the various sessions of the Colloquium;
- the management of reception and access;
- the coordination of logistical support where it is provided;
- the transmission of information and documents necessary for participation;
- the administrative management and follow-up of participant files;
- the preparation and follow-up of presentations, where required;
- the safety and security of the event;
- the security, availability and continuity of the platform;
- the prevention of abusive, irregular or fraudulent use;
- the institutional and organisational follow-up of the Colloquium.
Personal data is not used for purposes unrelated to those for which it was collected.
6. Categories of Personal Data
In connection with registration and the organisation of the Colloquium, the Centre des Hautes Études de Défense et de Sécurité (CHEDS) may process the information strictly necessary to identify the participant, to contact them, to establish their institutional affiliation, to accredit them, to organise their participation and, where their situation so requires, to provide logistical support and to meet safety and security requirements.
Certain technical data may also be processed solely to the extent necessary for the operation, security and administration of the platform.
The nature of the information requested varies according to the participant's profile and the conditions of participation. In all circumstances, collection remains limited to data that is adequate, relevant and necessary for the purposes pursued.
7. Mandatory and Optional Information
Certain information is essential to the examination of the file or to the proper organisation of participation. Where an item of data is mandatory, this requirement is brought to the participant’s attention at the time of collection.
The absence of strictly necessary information may make it impossible to complete the formality or provide the service to which it relates. Information that is not of this nature remains optional.
8. Legal Bases for Processing
The processing carried out on the platform is based, according to its purpose, on the requirements of organising participation, on the performance of the data controller’s institutional missions, on legitimate safety and security requirements, on the applicable regulatory obligations and, where required, on the consent of the data subject.
Where a particular processing operation requires specific consent, that consent is sought separately, under conditions allowing the participant to express a free, informed and unambiguous choice.
9. Formalities with the competent authority
The processing concerned is subject, where applicable, to the formalities laid down by Senegalese regulations on the protection of personal data.
Reference: declaration in preparation; the receipt number will be published here as soon as the CDP issues it
10. Recipients of Personal Data
The information collected is accessible only to those persons whose duties justify access. Authorisations are determined according to the responsibilities held and the needs strictly necessary to carry out the missions concerned.
Where the organisation of the Colloquium requires the involvement of a third party, only the data essential to the performance of the task entrusted to it may be disclosed. Any disclosure remains limited, proportionate and supervised.
11. Service Providers and External Parties
The Centre des Hautes Études de Défense et de Sécurité (CHEDS) may call upon technical, administrative or logistical service providers required for the operation of the platform or the organisation of the event.
These parties act within the scope of the tasks entrusted to them and are bound by the applicable obligations of confidentiality, security and data protection. They have no independent right to use the information disclosed to them.
- DigitalOcean (serveur géré via Laravel Forge) : hosting of the application and files (European Union).
- Resend : delivery of e-mails (confirmation, approval, badge) (United States (standard contractual clauses)).
- OpenStreetMap (service de géocodage Nominatim) : placement sur la carte de la ville et du pays de résidence, sans aucune donnée nominative (European Union).
- Transport and accommodation providers: only the data needed for your travel arrangements (name, flight, dates).
No personal data is sold, rented or passed on to third parties for commercial or advertising purposes.
12. Processing Outside Senegal
Certain operations required for the running of digital services, for their security or for the routing of communications may involve processing by means of infrastructure located outside the national territory.
Where such a situation arises, the processing concerned is governed in accordance with the applicable personal data protection requirements and accompanied by appropriate safeguards.
In this context, the Centre des Hautes Études de Défense et de Sécurité (CHEDS) ensures that the confidentiality, integrity and security of the information concerned are preserved.
13. No commercial use
Personal data collected in connection with the Colloquium is not sold, rented or otherwise disclosed for commercial purposes. It is not used for advertising solicitation or commercial profiling.
Communications addressed to participants remain exclusively related to their registration, their file, their participation or the organisation of the Colloquium.
14. Confidentiality
The Centre des Hautes Études de Défense et de Sécurité (CHEDS) ensures that personal data is processed under conditions providing an appropriate level of confidentiality.
Access to information remains restricted to authorised persons and takes place only to the extent strictly necessary for the performance of their duties. Particular care is taken with information whose nature warrants a heightened level of protection.
15. Security
The Centre des Hautes Études de Défense et de Sécurité (CHEDS) implements appropriate technical and organisational measures to protect information against unauthorised access, improper disclosure, alteration, loss, destruction, modification or any use incompatible with the purposes pursued.
These measures are tailored to the nature of the data, the processing carried out and the risks liable to affect the data subjects. They receive ongoing attention and may evolve in line with risks, usage and applicable requirements.
16. Traceability
Where the nature of the operations so warrants, monitoring and traceability mechanisms may be implemented to ensure the security of the information system, to prevent improper use and to identify any anomalies.
Such processing remains strictly limited to the administrative, technical and security requirements of the system.
17. Data Retention
Data is retained for a period proportionate to the purposes that justified its collection and is not kept in a form permitting the identification of individuals beyond what is necessary.
Identity documents, photographs and particularly sensitive information required for the formalities relating to the event are intended to be deleted or anonymised no later than 90 days after the end of the event, unless a legitimate need or contrary obligation applies.
Other data required for the administrative follow-up of registration and participation may be retained for a maximum of 24 months after the event, subject to the applicable obligations.
Technical information and traceability records necessary for security purposes may be retained for a maximum period of 12 months.
18. Deletion and Anonymisation
Where the purposes pursued no longer justify the retention of data permitting the identification of a person, that data is deleted, anonymised or made inaccessible by appropriate means.
Anonymisation may in particular be chosen where a statistical, administrative or institutional interest justifies retaining information that no longer permits the direct or indirect identification of the persons concerned.
19. Accuracy of Information
The data controller ensures, to the extent necessary, the accuracy and quality of the information processed.
Participants may be asked to verify, complete, correct or update certain information where necessary for the processing of their file or the proper organisation of their participation.
20. Participant Area
Where a personal space is made available, it allows the participant to consult the information relevant to the follow-up of their file, to complete the formalities requested of them and to access the documents intended for them.
This space is strictly individual. The participant is invited to keep confidential any means of access communicated to them, so as to prevent unauthorised consultation.
21. Electronic Communications
The contact details provided may be used to send the participant information directly related to their registration, participation, accreditation, file or the organisation of the event.
Such communications may concern validations, formalities, documents, practical information or relevant updates. They are not intended for commercial purposes.
22. Cookies and Technical Mechanisms
The platform may use technical mechanisms strictly necessary for its operation, the security of exchanges, the maintenance of sessions, the protection of forms and the continuity of the registration process.
These mechanisms are limited to the requirements of the service. They are not used for behavioural advertising, commercial profiling or tracking participants across external services.
23. Audience measurement
Statistical measurement of visits may be carried out in order to assess the use of the platform and to improve its quality, ergonomics, availability or performance.
Where consent is required, the participant remains free to accept or decline this measurement. Their choice has no bearing on their registration, the examination of their file or their participation in the Colloquium.
Audience measurement data is retained for a maximum of 13 months, then deleted or anonymised in accordance with the applicable rules.
No advertising device or mechanism intended to build a commercial profile of the participant is used in this context.
24. Consent
Where certain processing activities are based on participant consent, such consent is obtained separately, transparently and unambiguously.
The participant remains free to withdraw their consent under the conditions laid down by the applicable regulations. Withdrawal of consent does not affect the lawfulness of processing carried out beforehand and does not call into question processing based on another legal ground.
25. Rights of Data Subjects
In accordance with applicable law, every data subject has the rights granted to them in relation to the protection of personal data.
Subject to the conditions laid down by applicable law, these rights may include:
- the right of access to information concerning them;
- the right to rectification and updating;
- the right to object where the legal conditions are met;
- the right to erasure where applicable;
- the right to withdraw consent where processing is based on it;
- and, where the applicable regulations so provide, the further rights arising therefrom.
The exercise of these rights remains subject to the legal, administrative, institutional or security obligations that may justify the retention or continuation of certain processing.
26. Exercising your rights
Any request concerning personal data may be addressed to the following point of contact:
CHEDS Directorate General (data protection contact point)
infos@cheds.gouv.sn
In order to preserve the confidentiality of information, the data controller may, where necessary, request evidence enabling the identity of the applicant to be verified.
Requests are examined under the conditions and within the time limits laid down by the applicable regulations.
27. Complaint to the supervisory authority
Any person who considers that the processing of their data does not comply with the applicable rules may exercise the remedies provided for by the regulations and refer the matter to the authority competent for the protection of personal data.
Personal Data Protection Commission (CDP) of Senegal — https://www.cdp.sn
28. Responsibility and Policy Evolution
Data protection is a component of the institutional responsibility of the Centre des Hautes Études de Défense et de Sécurité (CHEDS). Accordingly, processing is governed and assessed in the light of the applicable requirements, the purposes pursued and the risks liable to affect the persons concerned.
This policy may be updated to take account of regulatory, organisational, functional, technical or security developments. The applicable version is the one made available on the platform at the time it is consulted.
Any substantial change affecting the essential conditions of processing may be the subject of appropriate notification.
29. CHEDS Commitment
The protection of the information entrusted to the Centre des Hautes Études de Défense et de Sécurité (CHEDS) is not reduced to a formal compliance requirement. It stems from a more general duty of responsibility, restraint and control in the use of data.
Accordingly, the Centre des Hautes Études de Défense et de Sécurité (CHEDS) undertakes to limit collection to the needs actually pursued, to restrict access to authorised persons only, to protect information against unauthorised use, to retain it only for the period justified by its purpose and to prevent any use foreign to the context in which it was collected.
By continuing with your registration, you acknowledge that you have read this Privacy Policy and have been informed of the principles governing the processing of your personal data.