Skip to content

TCR-IT-005: Data Privacy and Protection Policy

Principles and procedures for managing personal data of students, faculty, staff, and other stakeholders, in electronic or paper form, across TCR’s educational and administrative activities.

TCR is required to comply with FERPA, COPPA, PPRA, the Colorado Student Data Transparency and Security Act, HIPAA, and other applicable privacy laws. This policy translates those legal obligations into a consistent set of principles and rights so personal data is handled the same way across every system and department.

  • Personal data: any information relating to an identified or identifiable natural person.
  • Processing: any operation performed on personal data, automated or not.
  • Lawfulness, fairness, and transparency
  • Purpose limitation: collected for specified, explicit, legitimate purposes only.
  • Data minimization: adequate, relevant, and limited to what’s necessary.
  • Accuracy: kept accurate and up to date where necessary.
  • Storage limitation: kept identifiable no longer than necessary.
  • Integrity and confidentiality: processed with appropriate security against unauthorized/unlawful processing and accidental loss, destruction, or damage.

Individuals have the right to be informed, the right of access, the right to rectification, the right to erasure (under certain conditions), the right to restrict processing, the right to data portability, the right to object to processing (legitimate interests, direct marketing, research/statistics), and rights related to automated decision-making and profiling. Personal data may also be subject to the Acceptable Use Policy.

  • Encryption of personal data.
  • Ensuring confidentiality, integrity, availability, and resilience of processing systems.
  • Regular testing and evaluation of security measures.

TCR has designated a Data Protection Officer (DPO) responsible for overseeing implementation and compliance, reachable at help@tcr.edu. Suspected breaches of this policy or of personal data security should be reported immediately to the DPO; TCR is committed to investigating, responding to, and mitigating breaches promptly.

Reviewed regularly and updated as needed to reflect changes in legislation, regulatory guidance, and best practices. Significant changes are communicated to affected parties.

Digitized from TCR-IT-005 - Data Privacy And Protection [Rev 1.0].docx; the original is kept under source/policies/ in this repo.

Owner: IT Systems Coordinator · Revision 1 · Last reviewed Aug 18, 2026 · Next review due Aug 18, 2027