Indiana University

Data Protection Information and Laws

Data Protection at Indiana University requires that every member of our community take appropriate measures to safeguard the privacy, security, and integrity of important data through its entire lifecycle, from creation to destruction.

This web site compiles information about appropriate data protection practices and tools in one place. It is the result of a collaboration between University Counsel, the Information Policy and Security Office, and Internal Audit.


Overview

  • Why are University Counsel, the University Information Policy and Security Office, and Internal Audit highlighting data protection issues now?
  • What do the three new Indiana laws cover?
  • Which personnel and units do these laws affect?
  • Do these laws affect faculty as well as staff?
  • What kinds of data are covered under these new laws?
  • Are there other types of data that also are considered sensitive or covered by other laws?
  • What is IU's policy regarding the use of SSNs?
  • Do these laws apply only to electronic data?
  • What are the penalties for violating these new data laws?
  • Who enforces these new data security laws?
  • Can someone whose data has been exposed sue the University or individual employees for violations of the law?
  • Didn't the university already undertake a project to eliminate the unnecessary collection of SSNs a few years ago?
  • How is this effort different than that previous project?
  • Who can I contact for more information?

top


What do I need to do?

top


The SSN Disclosure Law

  • What obligations does the SSN law impose?
  • If my office releases SSNs to an outside entity together with other data, is it OK under the new law to use one written release or consent to cover both SSNs and the other data, or do we need to get a separate written consent just for the SSN disclosure?
  • If a disclosure of SSNs occurs, must IU notify the state Attorney General's Office? If so, who at IU provides this notice?
  • What procedures must I follow in order to properly disclose an SSN or other sensitive data to an external organization or vendor?
  • Where can I find this law?

top


Data Disposal

top


The Breach Notification Law

  • What obligations does the breach notification law impose?
  • What types of "personal information" must we give notice about, if disclosed/exposed?
  • This law talks about breaches of security in electronic systems. So does that mean that IU doesn't have to give notice if there is a disclosure of paper records with unencrypted personal information in them?
  • What if a laptop or other portable device that contains personal information is stolen or lost? Does that trigger notice obligations under this law?
  • When must notice be given?
  • How is notice given?
  • What do we do if we have a disclosure of any of these types of data?
  • What if we're not sure if the computer that the data was on was compromised or not?
  • Who sends the notification to the affected person(s) when data has been exposed or disclosed?
  • Must IU also notify the state Attorney General's Office if any of the "personal information" covered by the breach notification law is disclosed?
  • Where can I find this law?

top


The Consumer Report Security Freeze Law

  • What are obligations imposed under the Consumer Report Security Freeze law?
  • How can this law help me?
  • What does this law let me do?
  • Who can obtain credit information while the security freeze is in place?
  • Where can I find this law?

top