what it staff need to know about educational records privacy regulations

24
What IT Staff Need to Know About Educational Records Privacy Regulations Or . . .

Upload: alida

Post on 08-Jan-2016

19 views

Category:

Documents


1 download

DESCRIPTION

What IT Staff Need to Know About Educational Records Privacy Regulations. Or. FERPA for CIOs. Jeff von Munkwitz-Smith University Registrar University of Connecticut. What are the regulations?. A federal law, the Family Educational Rights and Privacy Act of 1974, as amended. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: What IT Staff Need  to Know About Educational Records Privacy Regulations

What IT Staff Need to Know About Educational

Records Privacy Regulations

Or . . .

Page 2: What IT Staff Need  to Know About Educational Records Privacy Regulations

FERPA for CIOs

Jeff von Munkwitz-Smith

University Registrar

University of Connecticut

Page 3: What IT Staff Need  to Know About Educational Records Privacy Regulations

What are the regulations?

• A federal law, the Family Educational Rights and Privacy Act of 1974, as amended.

• It is also known as “FERPA” and as the “Buckley Amendment”.

• The law applies to both K-12 and Postsecondary education.

Page 4: What IT Staff Need  to Know About Educational Records Privacy Regulations

What are a student’s rights?• The right to know about the purposes,

content, and location of information kept as part of their educational records.

• The right to gain access to and challenge the content of their educational records.

• The right to expect that information kept as part of their educational records will be kept confidential, disclosed only with their permission or under provisions of the law.

Page 5: What IT Staff Need  to Know About Educational Records Privacy Regulations

A few important definitions . . .

Page 6: What IT Staff Need  to Know About Educational Records Privacy Regulations

“Education Record”

• “Records, files, documents, and other materials that contain information directly related to a student and maintained by the institution or someone acting for the institution according to policy.”

Page 7: What IT Staff Need  to Know About Educational Records Privacy Regulations

Some examples

• Data on the student information system(s), including course management systems.

• Paper files maintained by the institution• E-mail messages relating to the student• Employment records for student

employees• Disciplinary records

Page 8: What IT Staff Need  to Know About Educational Records Privacy Regulations

What’s not?• Employment records of people not employed

as a result of their status as a student.• “Sole-possession” records• Records of police services• Application records of people not admitted• Alumni records• Medical records• Parents’ financial information (e.g., tax

returns)

Page 9: What IT Staff Need  to Know About Educational Records Privacy Regulations

“Directory Information”

“Information contained in an education record of a student which would not generally be considered harmful or an invasion of privacy if disclosed.”

Page 10: What IT Staff Need  to Know About Educational Records Privacy Regulations

“School Official”“A person employed by the University in an

administrative, supervisory, academic or research, or support staff position (including law enforcement unit personnel and health staff); a person or company with whom the University has contracted (such as an attorney, auditor, collection agent, or official of the National Student Clearinghouse, or the University Foundation); a person serving on the Board of Trustees; or a student serving on an official committee, such as a disciplinary or grievance committee, or assisting another school official in performing his or her tasks.”

Page 11: What IT Staff Need  to Know About Educational Records Privacy Regulations

Some key issues for IT . . .

• Expansion of access to data systems, including reporting data bases

• Software packages

• New types of systems and technologies

• On-line education

• Outsourcing

Page 12: What IT Staff Need  to Know About Educational Records Privacy Regulations

Expanded access

• Key questions:• Is the system secure?• Do the users fall under the definition of

“school official” and do they need access to do their job?

• Do they know their responsibilities regarding education records privacy?

Page 13: What IT Staff Need  to Know About Educational Records Privacy Regulations

Software packages

• Key questions:• How does the software handle FERPA

issues?• Is the software FERPA compliant?

Don’t assume they know what they’re doing!

Page 14: What IT Staff Need  to Know About Educational Records Privacy Regulations

New types of systems

• Key questions:• Does the system contain student

information?• If so, are security and access controls

appropriate? Is the software FERPA compliant?

Page 15: What IT Staff Need  to Know About Educational Records Privacy Regulations

On-line education

• Key point:

FERPA does cover students enrolled in on-line courses

Page 16: What IT Staff Need  to Know About Educational Records Privacy Regulations

Outsourcing

• Key questions:• Does the agreement specify appropriate

usage and security of the data?• Does your institution’s annual notification

to students of their rights include these vendors in the definition of “School officials”?

Page 17: What IT Staff Need  to Know About Educational Records Privacy Regulations

Some common questions . . .

Page 18: What IT Staff Need  to Know About Educational Records Privacy Regulations

If a student doesn’t have a “Privacy Bar”, we can release any

information. Right?

Wrong!

• If a student has a “privacy bar”, “no release code”, etc., you can’t release any information to the public.

• If a student doesn’t have one, you may ONLY release Directory Information.

Page 19: What IT Staff Need  to Know About Educational Records Privacy Regulations

What about releasing information to parents?

• Remember: the rights belong to the student, regardless of age or who’s paying the bills!

• Institutions MAY release non-directory information to parents of dependent students. (Know your institution’s policy.)

Page 20: What IT Staff Need  to Know About Educational Records Privacy Regulations

Do we have to release information such as email

address outside the institution?

• FERPA does not require release of directory information outside the institution, it allows it.

• If your institution is public, it pays to know your state’s freedom of information regulations.

Page 21: What IT Staff Need  to Know About Educational Records Privacy Regulations

Your questions . . .

Page 22: What IT Staff Need  to Know About Educational Records Privacy Regulations

Where can I go for help?

• Ask your Registrar

• Your institution’s attorney

• AACRAO FERPA Guide

• The Family Policy Compliance Office web site:

http://www.ed.gov/offices/OM/fpco

• Send e-mail to [email protected]

Page 23: What IT Staff Need  to Know About Educational Records Privacy Regulations

My best advice:

When in Doubt . . .

Ask!

Page 24: What IT Staff Need  to Know About Educational Records Privacy Regulations

Contact information

Jeff von [email protected]

www.registrar.uconn.edu/ferpa.html