Document status
This document is a draft policy foundation prepared to make unresolved privacy questions visible. It has no approved effective date and remains subject to formal legal, governance, security and operational review.
It must be replaced or materially updated before Tamil Ulagam introduces forms, accounts, membership, Tamil ID, chapter applications, event registration, payments or any other feature that processes personal information.
Who is responsible
The final legal entity, data controller or other responsible organisation has not yet been confirmed. Its legal name, registered address, role in each processing activity and approved privacy contact must be established before this document becomes a governing notice.
Tamil Ulagam is the public project name used by this website. It should not be interpreted as confirmation of a final incorporated entity or controller identity.
Current public website
The current website consists of public informational pages describing Tamil Ulagam’s mission, planned platform and draft operating foundations. Its organisation-enrollment experience is a local demonstration only and does not provide a live transactional service.
The demonstration stores mock records in the visitor’s browser. It does not create a production account or transmit an organisation application to Tamil Ulagam.
The hosting and operational configuration must be reviewed before launch to confirm what technical information may be processed. This draft does not make an unverified claim that technical logs or similar operational records are absent.
The current public release provides:
- No production membership account creation
- No live organisation application submission
- No working contact form
- No chapter application
- No event registration
- No article submission
- No payment processing
- No Tamil ID issuance
Information that may be processed in future
Future approved services may require carefully defined information categories. The following possibilities are planning inputs only and are not a statement that the information is collected today.
Potential future categories, each subject to necessity, approval and implementation:
- Account information
- Membership information
- Profile information
- Identity-verification information
- Organisation and chapter information
- Event registrations
- Enquiry information
- Accessibility preferences
- Consent records
- Payment information through approved providers
- Device, security and audit information
- Editorial contribution information
- Support and complaint records
Potential future purposes
Every purpose must be defined, documented and approved before the related processing begins. Collection should remain limited to information that is necessary for the approved purpose.
Possible future purposes, subject to final approval and operational implementation:
- Operating accounts
- Processing membership
- Issuing Tamil ID
- Managing chapters and organisations
- Supporting event participation
- Handling enquiries
- Maintaining platform security
- Preventing fraud and misuse
- Supporting accessibility
- Meeting applicable legal obligations
- Publishing approved public communications
- Providing support
- Improving approved services
Legal bases
No final legal basis is assigned by this draft. The lawful grounds available will depend on the responsible organisation, jurisdiction, service design, information category and relationship with the individual.
Categories requiring legal determination for each relevant activity may include:
- Consent
- Contractual necessity
- Legal obligation
- Legitimate interests where applicable
- Other jurisdiction-specific grounds
Children and young people
Age eligibility has not been approved. No child-specific operational service is currently available through this public website.
Any future service involving children or young people will require formal legal review, safeguarding design, age-appropriate information, consent or authorisation rules and proportionate access controls before children’s data is processed.
International transfers
Hosting regions, access locations and international transfer mechanisms have not been finalised. This draft does not claim that cross-border transfers currently occur or that they do not occur.
The final system design must map relevant information flows and establish any notices, safeguards, contractual measures or assessments required by applicable law.
Retention
No final retention period is approved. Retention schedules must be defined by information category, documented purpose, applicable legal requirement, security need and account or service lifecycle.
The final approach should include deletion or anonymisation rules, preservation requirements, backup handling, review ownership and exceptions that are narrow and documented.
Security
Tamil Ulagam intends to use proportionate organisational and technical safeguards. These principles are design expectations, not a guarantee that information can be made completely secure.
Intended security principles include:
- Least-privilege access
- Role-based access controls
- Encryption where appropriate
- Secure authentication
- Auditing and accountable changes
- Tested backup and recovery arrangements
- Incident response
- Provider review
- Data minimisation
Individual rights
Individual rights depend on the applicable law and processing context. The final notice must explain which rights apply, how they may be exercised, how identity is verified proportionately and when lawful limitations may apply.
Potential rights, where applicable, may include:
- Access
- Correction
- Deletion
- Withdrawal of consent
- Objection
- Restriction
- Portability
- Complaint to an appropriate authority
Automated decisions and recommendations
No operational automated decision-making system is represented by the current public website.
Any future matching, recommendation, ranking or eligibility system will require an approved purpose, meaningful transparency, quality and bias testing, human-review safeguards where appropriate and formal legal review before use.
Contact and complaints
An approved privacy contact, rights-request route and complaint process are pending. No Data Protection Officer, grievance officer or regulator contact is represented as appointed by this draft.
The current Contact page explains future enquiry routes but does not provide or process submissions.
Changes to the policy
A future approved policy should use clear version control and distinguish material changes from routine clarifications. Changes must be assessed against applicable notice and consent requirements.
Future publication controls should include:
- Approved effective date
- Revision date
- Material-change explanation
- Appropriate user notification
- Archived versions where necessary
Decisions required before launch
The checklist below records unresolved work. Completion must be evidenced through legal, governance, security and operational review before this draft is replaced by a governing privacy notice.