SSN Registration
Why Register?
The purpose of registering a data collection containing SSN is to inform University risk
managers of storage practices for restricted data types in all areas of the University. This information
will be used to direct educational and risk reduction efforts to those situations that present the
most significant reputation and financial risks to the University.
How do I register?
- Download a copy of the SSN
registration form (.xls format) from the SSN-PII Policy Web
site.
- Duplicate the form as needed to report each data collection containing SSN
that you possess or that you are responsible for controlling access to.
- Submit a registration form for each collection containing SSN. Email it to SSNRegistry@rochester.edu.
- A Privacy Officer or
an information security staff member may contact you to discuss the registry form in more detail.
- If
you have any question that is not answered by the FAQs,
please submit your question to SSNRegistry@rochester.edu.
Additional Information:
- The deadline for submission of registrations for existing data collections containing SSN is June 30, 2009. The deadline for faculty members who are away from the University at that time is as soon as possible after their return, but not later than October 31, 2009. New data collections containing SSN that are created after June 30, 2009, must be registered immediately.
- Submit a separate registration form for each collection that serves a different
business purpose. For example, if you are planning to retain old Personnel Action Forms with SSN
and also study subject W-9 forms with SSN, submit
a registration form for the PAFs and a separate registration form for the W-9s, even if they all
are locked in the same file cabinet.
- Submit a separate registration form for
each medium (paper, electronic, microfiche, etc.) that the same collection serving the same
business purpose may be recorded on. For example, if you maintain the primary copy of your collection
in electronic media but you also print out and retain paper copies containing SSN, submit
a registration form for the electronic collection and also for the paper collection.
- If you are submitting a
form to register a collection containing SSN, please indicate on the form whether that
collection also contains any of the other restricted data types listed on the form.
- Review the FAQ page
for this SSN-PII policy
for additional examples of data collections and for information on evaluating, modifying,
and reporting data collection practices.
- Examples of data collections containing SSN may include departmental and central computer information
systems (such as MISER or CIS or HRMS), files on
an individual's computer or on a department file server, or folders
of paper forms in a individual's desk or in department office file cabinets.