TCR-IT-005: Data Privacy and Protection Policy
Summary
Section titled “Summary”Principles and procedures for managing personal data of students, faculty, staff, and other stakeholders, in electronic or paper form, across TCR’s educational and administrative activities.
Why it exists
Section titled “Why it exists”TCR is required to comply with FERPA, COPPA, PPRA, the Colorado Student Data Transparency and Security Act, HIPAA, and other applicable privacy laws. This policy translates those legal obligations into a consistent set of principles and rights so personal data is handled the same way across every system and department.
Policy
Section titled “Policy”Definitions
Section titled “Definitions”- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data, automated or not.
Principles of data protection
Section titled “Principles of data protection”- Lawfulness, fairness, and transparency
- Purpose limitation: collected for specified, explicit, legitimate purposes only.
- Data minimization: adequate, relevant, and limited to what’s necessary.
- Accuracy: kept accurate and up to date where necessary.
- Storage limitation: kept identifiable no longer than necessary.
- Integrity and confidentiality: processed with appropriate security against unauthorized/unlawful processing and accidental loss, destruction, or damage.
Rights of data subjects
Section titled “Rights of data subjects”Individuals have the right to be informed, the right of access, the right to rectification, the right to erasure (under certain conditions), the right to restrict processing, the right to data portability, the right to object to processing (legitimate interests, direct marketing, research/statistics), and rights related to automated decision-making and profiling. Personal data may also be subject to the Acceptable Use Policy.
Data protection measures
Section titled “Data protection measures”- Encryption of personal data.
- Ensuring confidentiality, integrity, availability, and resilience of processing systems.
- Regular testing and evaluation of security measures.
Enforcement
Section titled “Enforcement”TCR has designated a Data Protection Officer (DPO) responsible for overseeing implementation and compliance, reachable at help@tcr.edu. Suspected breaches of this policy or of personal data security should be reported immediately to the DPO; TCR is committed to investigating, responding to, and mitigating breaches promptly.
Review
Section titled “Review”Reviewed regularly and updated as needed to reflect changes in legislation, regulatory guidance, and best practices. Significant changes are communicated to affected parties.
Digitized from TCR-IT-005 - Data Privacy And Protection [Rev 1.0].docx; the original is kept under source/policies/ in this repo.