Policy on Personally Identifiable Information Security

Filed under: Administrative Computing, Policies — Information Resources @ October 30th, 2005

Personally identifiable information (PII) is described as any electronic data that can be used to disclose the identity of an individual. This includes but is not limited to social security number, address, phone number, college ID number, email address, or name.

In an effort to maintain data security in all realms of data collection SUNY Cortland requires that all online data collection programs conform to the following information security regulations:

  • Personally identifiable information will not be stored on any server accessible by the public. This includes but is not limited to web servers and email servers.
  • All personally identifiable information will be stored on securely controlled central database servers that conform to all access control and authentication regulations set forth by designated data/cyber security officers in Administrative Computing Services.
  • All online data collection, data retrieval, and application requests involving personally identifiable information will be reviewed by designated data/cyber security officers in Administrative Computing Services. Prior to production or implementation, the designated data/cyber security officer(s) will ensure that all security principles, programming standards, data storage, and that all data elements are being collected securely and appropriately.
  • Programs and methods that do not conform to information collection and security policies will be removed and taken out of production. The administrator/requestor of the program will be notified. Once security violations are corrected the program will be placed back into a production environment.

Online data collection programs are defined as any Web form, application, or survey tool that is made available to the public and stores some or all of the personally identifiable information elements. Surveys, while they may or may not collect personally identifiable information, must be reviewed by a designated data/cyber security officer to ensure that the data being collected is securely stored in a manner consistent with all designed security standards established for personally identifiable information (PII).

Disclosure of Personally Identifiable Information to Parties Outside the University

SUNY Cortland does not sell, rent, give away, or loan any personally identifiable information about students, faculty or staff to any third party other than agencies directly connected to the university. Agencies who have access to personally identifiable information are required to protect this information in a manner that is consistent with this privacy policy and those set forth by the State of New York and the Federal government. Violators of these privacy acts will be prosecuted by every extent of the law.

Accessing or Correcting Personal Information

The BannerWeb Systems provide a mechanism for you to manage your personal information. It is very important that all of your personal contact information is current and up to date.

Consent

By using the college technology infrastructure, you consent to the collection and use of your personally identifiable information by SUNY Cortland. The policies that govern the usage of SUNY Cortland’s technological infrastructure and your personally identifiable information can be located at the following URL: http://www.cortland.edu/ir/policies.asp

Administrative Computing
SUNY Cortland
Winchell Hall
607.753.2501

Tags:

BannerWeb Privacy Policy

Filed under: Administrative Computing, BannerWeb, Policies — Information Resources @ October 30th, 2005

Banner is SUNY Cortland’s enterprise student information system, which is used for all transactions related to course registration, housing and finance.

SUNY Cortland does not collect any personal information about you when you visit the BannerWeb site unless you choose to provide this information. However, certain information about site visitors is automatically collected, such as usage statistics, domain from which you are accessing (for example: aol.com if connecting from America Online), your current IP address, and the date and time you accessed the Banner site. This non-personally identifiable information is used as a means to improve the design and content of the site to personalize your Cortland Internet experience.

SUNY Cortland’s BannerWeb site requires you to provide correct and up-to-date personally identifiable information such as personal email accounts, permanent mailing addresses, and cell phone numbers to further personalize your educational experience at Cortland. It is our intent to only use this personal information you have provided as a means to communicate with you individually and solely for administrative and emergency purposes. All information collected through BannerWeb will be stored in a secure, authenticated environment. For no reason will your personal information be provided or exposed to third party, Non-Affiliated agencies, or SUNY Cortland sponsored programs for commercial advertising, surveys or general purposes which are not in the scope of administrative functions. This includes but is not limited to, general bulk contacts, solicitation for information, and request of services or special offers.

Special requests for personal information will be individually reviewed by appropriate parties, including the Associate Provost for Information Resources and the Director of Administrative Computing Services. All solicitations conducted by SUNY Cortland will give the recipients the option to remove themselves from future mailings.

The privacy of all information collected and stored in the SUNY Cortland BannerWeb database and the disclosure of that information is subject to the provisions of New York State’s Internet Security and Privacy Act, the Freedom of Information Law, and the Personal Privacy Protection Law.

Disclosure of Personally Identifiable Information to Parties Outside the University

SUNY Cortland does not sell, rent, give away, or loan any personally identifiable information about students, faculty or staff to any third party other than agencies directly connected to the university. Agencies who have access to personally identifiable information are required to protect this information in a manner that is consistent with this privacy policy and those set forth by the State of New York and the Federal government. Violators of these privacy acts will be prosecuted by every extent of the law.

Accessing or Correcting Personal Information

The BannerWeb Systems provide a mechanism for you to manage your personal information. It is very important that all of your personal contact information is current and up to date.

Consent

By using the college technology infrastructure, you consent to the collection and use of your personally identifiable information by SUNY Cortland. The policies that govern the usage of SUNY Cortland’s technological infrastructure and your personally identifiable information can be located at the following URL: http://www.cortland.edu/ir/policies.asp

For more information see SUNY Cortland’s Policy on Personally Identifiable Information Security.

Administrative Computing
SUNY Cortland
Winchell Hall
607.753.2501

Tags: