"Sensitive information" is that data found upon review by the data trustees or general counsel to require restrictions on access. Sensitive information may not be subject to disclosure under the Public Records Act and is only available to CSU employees that have a business or educational need to access the data. Sensitive information is broadly defined as that which the university is legally obligated to protect. For example:
"Private information" is data that the data trustees judge to require special procedures for access. Private information may be subject to disclosure under the Public Records Act and is made available to certain Cleveland state employees based on their job function. Private information is broadly defined as that which should be reasonably protected from inadvertent disclosure beyond authorized Cleveland state university employees. For example:
"Public information" is all data that is neither restricted, nor judged by data trustees to be sensitive or private. The accessible data volume should be as great as possible to enable those who need the information to have access. Data should be part of an open atmosphere and readily available. Public information is subject to disclosure to all Cleveland state employees as well as the general public under the Ohio Public Records Act. Public information is broadly defined as that which is intentionally displayed for anyone to use, including:
Each data custodian shall be individually responsible for establishing data access procedures that are unique to a specific information resource or set of data elements.
The data custodians, in consultation with information services and technology, shall determine security requirements for administrative data and shall be responsible for monitoring and reviewing security implementation and authorized access.
It develops views of data as directed by the data custodians. IS&T and the data custodians ensure that the technical integrity of the data is maintained and that data security requirements are met.
Access to sensitive or private data by university employees or employees of university-related foundations requires that a formal request be made to the appropriate data custodian.
All requests for exceptions to data access policies shall be made in writing to the data custodian. Email requests are acceptable. The request shall specify the data desired and their intended use.
The data custodian shall provide a written record of the reason(s) for denial of any access request. Email records are acceptable.
The university expressly forbids the disclosure of unpublished administrative data or the distribution of such data in any medium, except as required by an employee's job responsibilities and approved in advance by the employees supervisor and the respective data custodian. In this context, disclosure means giving the data to persons not previously authorized to have access to it. The university also forbids the access or use of any administrative data for one's own personal gain or profit, for the personal gain or profit of others, or to satisfy personal curiosity. Users agree to use the information only as described in the request for data access. Failure to do so could result in disciplinary or legal sanctions as set forth in university policy.
Users shall respect the confidentiality and privacy of individuals whose records they access, observe any ethical restrictions that apply to data to which they have access, and abide by applicable laws and policies with respect to access, use, or disclosure of information. All data users having access to sensitive or private information shall formally acknowledge (by signed statement) their understanding of the level of access provided and their responsibility to maintain the confidentiality of data they access. Each data user shall be responsible for the consequences of any misuse. Users are expressly prohibited from releasing identifiable information to any third party.
Ohio Admin. Code 3344-8-02
Promulgated Under: 111.15
Statutory Authority: 115.10
Rule Amplifies: 3344
Prior Effective Dates: 6/1/2015