ROWAN UNIVERSITY POLICY
Title: Records Release Policy and Security of Donor Information
Subject: University Advancement
Policy No: UA: 2014:02
Issuing Authority: President
Responsible Officer: Associate Vice President for University Advancement/Executive Director, Rowan University Foundation
Last Revision: 9/2014
Last Reviewed: 4/14/2015
A. Mission Statement:
- Rowan University Advancement employees are ethically obligated to respect and safeguard the privacy rights and the confidential information obtained from Rowan University alumni, prospects and donors. It is important that Advancement employees act with integrity and are honest in their dealings with the University and with those that they come in contact with. Advancement employees shall avoid conflicts of interests and may not accept favors or any other benefits for personal gain and shall follow the letter and spirit of the laws and regulations affecting advancement and observe these standards by also encouraging your colleagues to do so as well.
- Staff Members of Rowan University's Division of Advancement are entrusted with sensitive and personal information regarding University alumni, prospects and donors. It is therefore incumbent upon each employee to protect the privacy rights of those who have dealings with the University. An employee's stewardship of personal information can be guided by the following code of ethics and principles set forth below:
- Rowan University's Department of Advancement Services (DAS) maintains a database (Millennium) of biographical and gift/pledge information about University alumni and friends in accordance with the general needs and expectations of the University community. The information contained in this database is intended exclusively for purposes related to Rowan University's programs.
- Staff members of University Advancement will have access to Millennium [alumni and/or development information as well as data analysis] from their workstations. Each employee user should diligently deal with sensitive information regarding alumni, prospects and donors in the areas of data retrieval, retention, dissemination and disposal. This policy document is designed to protect the privacy of Rowan University alumni and other constituents and to maintain standards of confidentiality associated with electronic records in Millennium. Exceptions to this policy can only be made by the Vice President of University Advancement or his/her designee.
- An employee's need to access Millennium does not equate to casual viewing. It is the employee's obligation, and his/her supervisor's responsibility, to ensure that access to Millennium is only to complete assigned functions.
- The Director of Advancement Services in recognition of the right to privacy of donors to Rowan University, ethical considerations, and the need for good donor relations has categorized Millennium data as restricted. Data and information available in Millennium and in related reports and files is the property of Rowan University and its use is governed be federal, state and local law, as well as University regulations. It may only be used to support University-sponsored or University-approved development or alumni relations functions.
- The Department of Advancement Services expects that individuals with access to Millennium data understand their responsibilities with respect to use, interpretation and distribution of that data and the consequences for misuse of data. The ability to access and produce reports and mailings does not constitute automatic authority to do so. Unauthorized release or use of Millennium information for any purpose is strictly prohibited and may result in suspension, and/or termination of employment for the employees involved. Additional legal action may be taken, when warranted.
- It is the desire of the Department of Advancement Services to support the ongoing activities of Rowan University by providing assistance for programs, communications, and events, which bring together alumni, donors, and friends of the University. In order to provide the best possible service to those with legitimate needs for such information, and at the same time maintain the confidentiality of the information entrusted to us by our alumni, the following policies have been developed.
- Exceptions to this policy can only be made by the Associate Vice President of University Advancement or his/her designee.
- In cases of dispute about whether an organization has a legitimate affiliation with the University, the final decision will rest with the Associate Vice President of University Advancement or his/her designee.
- In cases of dispute about what constitutes an approved activity, the final decision will rest with the Associate Vice President of University Advancement or his/her designee.
E. Compliance with the above policy.
F. Attachment 6, Distribution of Information
G. Attachment 7, Hyperlinks
STATEMENT OF UNDERSTANDING FOR MILLENNIUM USERS
I, the undersigned, have read and understand the policies for access to and privacy of Rowan University Alumni and Donor records. I agree to use the information provided only for the approved University program(s). Furthermore, I understand that the use of the information for political or commercial purposes is strictly prohibited.
Supervisor Signature Supervisor Approval Date
Complete in duplicate:
Copy (1) Millennium User
Copy (2) Office of Advancement Services
- University-affiliated organizations and alumni constituent groups, in support of approved activities include, but are not limited to the organizations listed below. In cases of dispute about whether an organization has a legitimate affiliation with the University, the final decision will rest with the Vice President of University Advancement or his/her designee.
- Rowan University Alumni Engagement
- Alumni constituent groups chartered under the Rowan University Alumni Association
- Rowan University Development
- Administrative units of Rowan University
- Academic units of Rowan University
- Athletic units of Rowan University
- Central Administration
- Career Development Center(s)
- Law enforcement agencies and student loan agencies.
- Agencies that assist the Department of Advancement Services in locating Rowan University's lost alumni, e.g. AlumniFinder, AlumniSync, HEPData, etc.
- All requests from anyone seeking information on another person will be forwarded to that person so that he/she can decide whether or not to contact the requestor. No No information will be released for those records coded "Do Not Release" indicating the alumnus or alumna has requested no University contact.
- All requests for information from members of the media must be referred to the Division of University Relations.
- Information available for release is confined to "public information" i which is limited to:
- Full name
- Address and telephone number
- Degree(s) and date of degree(s) awarded by Rowan University
- School(s) from which degree(s) was/were granted with major field of study
- Employer address and telephone number
- E-mail address
- Fax number(s)
- Federal law severely restricts the amount of information that may be released on current students ii . No information on students will, therefore, be released based on data maintained by Millennium. All requests for information on current students should be forwarded to the appropriate Registrar's office.
- Information provided to volunteer alumni constituent groups will be limited to those alumni who are affiliated with the requesting group.
- In addition to "public information," requests from the Rowan University Alumni Association; Development; administrative, academic, or athletic units of Rowan University; and Central Administration will be provided the following information:
- Employment History
- Student activities
- Alumni activities
- Family members
- Degrees obtained from other Schools
- Miscellaneous comments, awards, text, etc.
- Gift/Pledge data
PROTECTING AND PRESERVING ROWAN ALUMNI AND DONOR PRIVACY PRIVACY
- Securing Paper RecordsRecords
- Store paper records in a room, cabinet, or other container that is locked when unattended
- Ensure that storage areas are protected against destruction or potential damage from physical hazards, like fire or floods, by keeping doors closed and items off the floor
- Promptly shred and dispose of outdated constituent information recorded on paper
- Securing Computers and Electronic Records
- Shut down applications if you leave for lunch or any extended period of time
- Use password-activated screensavers
- If you use a computer other than the one you have been assigned, leave a note to notify the assigned user that includes the date and your name as an authorized employee of the College
- Use strong passwords (at least eight characters long) including numbers and letters and non-numeric characters
- Change passwords every ninety days
- Do not post passwords near your computer (for example: passwords written on post-it notes)
- Do not download unauthorized files
- Check with software vendors regularly to obtain and install patches that resolve software vulnerabilities (for example: Microsoft updates, internet explorer upgrades, etc.)
- Use anti-virus software that updates automatically
- Store electronic customer information on a secure server that is accessible only with a password - or has other security protections (for example: in Banner or on network drives, which are backed up by I.T. nightly)
- Maintain secure backup media and keep archived data secure, for example, by storing off-line or in a physically-secure area
- If you transmit sensitive data by electronic mail:
- DO NOT include the constituent's social security number or credit card information
- But DO include a confidentiality notice:
"This communication, including any attachment(s), contains information that may be confidential or privileged, and is intended solely for the individual(s) to whom it is addressed. If you are not the intended recipient, please notify the sender at once and then delete this message. You are hereby notified that any disclosure, copying, or distribution of this message is strictly prohibited."
- Secure laptops to avoid theft and possible access to constituent data when traveling and in the office – lock doors when leaving for the day
- Do not save constituent data on your home computer
- Backup your hard drive on a regular basis
INTERNAL USES OF INFORMATION
Acceptable Internal Uses of Information from the Millennium Database
- Rowan University's Department of Advancement Services will make available information from Millennium for the support of approved, University-related activities. Approved activities include the following:
- Alumni engagement
- Public relations
- Government relations
- School/department communications to alumni/constituents
- University-sanctioned research
- Continuing education programs
- Student recruitment
- In cases of dispute about what constitutes an approved activity, the final decision will rest with the Vice President of University Advancement.
- Information maintained by Millennium is not available for release for non-related commercial or political purposes.
- If the information provided will result in the preparation of lists or directories that are to be published in book, magazine, newsletter or other forms for general distribution among alumni groups, prior to publication each individual who might be included must be provided the opportunity to indicate in writing whether he/she wishes to be excluded.
DISTRIBUTION OF INFORMATION
Formats Available for Distribution of Information
Information may be obtained in the form of lists, labels, electronic files and downloads by authorized university representatives in support of approved activities as noted in Section III.A of this document. It is the responsibility of the unit requesting information to maintain the absolute confidentiality of that information as specified in this policy statement.