100 likes | 184 Views
Releasing and Publishing Information: 1 st Ask Yourself 2 Questions. Am I authorized to disclose this information? What level of protection does this information require?. Federal Laws Ex: FERPA, GLBA, HIPAA State Laws Ex: TPIA University Policy and Procedure Statements (UPPS).
E N D
Releasing and Publishing Information: 1st Ask Yourself 2 Questions Am I authorized to disclose this information? What level of protection does this information require?
Federal Laws Ex: FERPA, GLBA, HIPAA State Laws Ex: TPIA University Policy and Procedure Statements (UPPS) UPPS 01.04.00 - Overview
Am I authorized to disclose this information? Use UPPS 01.04.00, Attachment II Information Custodian Chart Are you the custodian/owner of the data? Question 1
State of Texas-DIR says: a System Owner is a person responsible for (A) For a business function; and (B) For determining controls and access to information resources supporting that business function. The owner of an information resource…is responsible for classifying business functional information. Typically this is a department or unit head System Owner
What level of protection does this information require? Question 2
You work in the Graduate College and receive a request from a large technology company for a list of CS and CIS candidates for spring 2008 graduation with current GPA’s above 3.50. Am I authorized to disclose this information? What level of protection does this information require? How might my answer be different if: I worked in a different office? they asked for graduates from fall 2007 & the GPA threshold was 3.40, 3.60, or 3.80? Scenarios – Ask the 2 Questions
You teach a Sociology class and want to put all of your students’ essays on your personal faculty webpage for review and comment by other students in the class. Am I authorized to disclose this information? What level of protection does this information require? What unstated considerations might affect my answers to the questions above? Scenarios – Ask the 2 Questions
More Examples • Professor's blog • E-mail addresses • Date of birth, ethnicity • Unique or proprietary chemical formulas or computer code • Login/password credentials • Donor or other third party partner information