A Custodian of Social Security Number or Personal Identifying Information must:
Try to REDUCE the number of copies of SSN or PII that you are keeping. Review the Policy on Retention of University Records. It is especially important to reduce the number of places that ELECTRONIC copies are stored. Contact a Privacy Officer or Information Security Officer for assistance in this effort.
PROTECT Social Security numbers and Personal Identifying Information:
Electronic copies containing this information must be stored only in designated data centers of the University or in another secure location as authorized by a University Privacy Officer, or in encrypted or other secure form.
Paper copies containing this information must be either attended or stored in locked rooms or locked cabinets at all times.
DISPOSE of Social Security Number and Personal Identifying Information in a secure manner, one that makes the information unreadable and unrecoverable.
In addition, a Custodian of Social Security Number must:
REPORT to a Privacy Officer the location and method by which SSN information is stored, the legal or University purpose that justifies its retention, and the protections that are in place to assure confidentiality and prevent misuse.
ACKNOWLEDGE in WRITING to a Privacy Officer that he/she has read the Policy on Social Security Number and Personal Identifying Information and agrees to be responsible for compliance with this Policy with respect to SSN information in his/her custody.