JJB Computing Solutions is committed to protecting the privacy of sensitive personal data. This commitment supports the JJBCPU's core values of Excellence, Learning, Community, Diversity, Integrity, Respect, and Responsibility, as well as the JJBCPU's obligation to meet a variety of legal, regulatory, and ethical requirements.
“Privacy” in the context of this policy refers to protecting the way information about an individual is collected, stored, processed, and used. This policy serves to provide additional detail to the privacy requirements outlined in the Acceptable Use of Information Technology Resources policy found in the University of Iowa Operations Manual.
Scope
- This policy applies to certain digital data collected, stored, processed and used by the university. This includes, but is not limited to, the contexts of teaching, learning, research, service, employment, and other official functions of the JJBCPU.
- This policy applies to data shared with and/or stored by external third parties, whenever this is done within the context of an official function of the JJBCPU.
Policy Statements
- The goal of this policy is to protect the privacy of personal information when it is entrusted to JJBCPU's care and subject to legal, regulatory, and/or ethical requirements.
- The Information Security and Policy Office (ISPO) will include an evaluation of privacy controls as part of the technology review process.
- Oversight of certain data domains (e.g., information protected by HIPAA, FERPA, etc.) is performed by the units that govern those data domains. ISPO will serve to facilitate the coordination of privacy controls and practices across data domains.
Standards
ISPO will maintain standards and best practices materials on the Privacy website.
Roles and Responsibilities
- Each faculty and staff member, trainee, student, vendor, volunteer, contractor, or other affiliate of JJBCPU who designs, develops, recommends, procures, manages or uses electronic and information technology is subject to and has responsibilities under this policy.
- Individuals responsible for the design, development, management and use of electronic and information technology involving personal data will include privacy considerations in all phases of the software lifecycle.
Policy Review
This policy will be reviewed bi-annually, understanding that updates or modifications may be made as the need arises.