Data decisions are based on policy and pillars
The privacy team works with data stewards, governance and data authorities to inform and advise in their data use decisions. We create awareness of privacy considerations for units and university stakeholders and connect individuals to appropriate compliance and legal advisers to aide their ability to meet good privacy practices and regulatory compliance.
| Privacy policies | Privacy by design |
| Terms to know | Privacy regulations |
| Privacy principles | Fair information practices principles |
University privacy policies
- Information Security Policy: Universitywide policy on the use of data, applications, networks and computer systems.
- Campus/University Policies: More information about University of Illinois policies.
- System PCI DSS Policies: Lists of policies that apply to all system and University of Illinois’ merchants in addition to what is included in the PCI DSS
- Social Security Number Policy: Information on the University’s commitment to protecting the privacy of members of the university community.
Terms to know
Commonly used privacy acronyms and their meanings:
| PI – Personal Information | TIA– Transfer Impact Assessment |
| PII – Personally Identifiable Information | DSAR – Data Subject Access Request |
| NPI – Nonpublic Personal Information | PbD – Privacy by Design |
| SPI – Sensitive Personal Information | PIA– Privacy Impact Assessment |
| DPIA – Data Protection Impact Assessment | PIQ – Privacy Impact Questionnaire |
Privacy regulations
- FERPA: Student records are protected under the Family Education Rights and Privacy Act. The Office of the Registrar manages student record privacy. FERPA-Office of the Registrar
- FOIA: External Relations and Communications at the System Offices processes all Freedom of Information requests to the University of Illinois System or any of the three universities. The Illinois Freedom of Information Act provides public access to government documents and records. FOIA-University of Illinois
- GDPR: Data privacy laws issued by the European Commission, also known as the General Data Protection Regulation, govern data collected from individuals located in the European Union. GDPR – University of Illinois
- HIPAA: The Health Information Portability and Accountability Act protects health information. The University President is responsible for the University’s HIPAA compliance program. The Universitywide Privacy and Security Compliance Council, also known as the HIPAA Subcommittee of the University Information Privacy and Security Committee, is a key part of the President’s oversight effort. HIPAA-University of Illinois System
- IPA: The Identity Protection Act (5 ILCS 179) is an Illinois state law that governs the collection and use of social security numbers by state and local government agencies. It prohibits certain uses of SSNs, creates collection and protection requirements, and requires state agencies, such as the University of Illinois, to enact policy for public view and for employees working with SSNs. IPA – University of Illinois System
- PIPA: Whenever a breach of the security of the data collector’s system data occurs, the Personal Information Protection Act specifically requires public universities, such as the University of Illinois, and other data collectors to notify affected individuals PIPA-UIUC
- PIPL: The University of Illinois Supplemental Privacy Notice – Personal Information Protection Law (“Supplemental Notice – PIPL”) supplements the University of Illinois System Privacy Statement for certain individuals in the People’s Republic of China. PIPL-University of Illinois