|Title:||Use of the Social Security Number at the University of Connecticut, Policy on|
|Policy Owner:||Information Technology Services|
|Applies to:||Faculty, Staff, Students|
|Campus Applicability:||Storrs and Regionals|
|Effective Date:||August 31, 2008|
|For More Information, Contact||Director of IT Security, Policy and Quality Assurance|
|Contact Information:||(860) 486-4357|
Background and Reasons for the Policy: As defined in the Data Classification policy, Social Security numbers are restricted confidential and legally protected data under federal laws such as the Federal Privacy Act of 1974 and FERPA.
Social Security numbers have been used to uniquely identify students and employees in various University systems. As systems have been updated and replaced the reliance on Social Security numbers as the primary identifier has been reduced.
Purpose of Policy: The purpose of this policy is to protect the confidentiality and privacy of students and employees of the University of Connecticut and to ensure that steps are taken concerning the collection, use and disclosure of Social Security numbers.
Expected Institutional Outcome: It is expected that this policy will over time:
- Ensure a consistent approach toward the collection, use and disclosure of the Social Security number;
- generate a broad understanding of the confidential nature of the Social Security number;
- reduce reliance on, and ultimately eliminate the use of, the Social Security number for identification purposes, except where required by law; and
- increase confidence by students and employees that Social Security numbers are handled in an appropriate manner.
Applicability of Policy: This policy applies to all departments and all computer systems throughout the University.
Policy Statement: In order to protect the Social Security number of its students, staff, faculty and affiliates, the University of Connecticut will:
- Discontinue the collection of Social Security numbers except where necessary for employment records, financial aid records, and other business and governmental transactions as required by law or to satisfy a business requirement when permitted by law.
- Develop a University of Connecticut identifier to be assigned to all students, faculty, staff and other individuals associated with the University, to uniquely and permanently identify the individual. This identifier will be considered public information and be assigned and distributed to the individual upon initial association with the University. It will be used in all electronic and paper data systems to identify, track and service the individual.
- Ensure that no new systems or technology will be purchased or developed by the University of Connecticut that use the Social Security number as its primary key to the database except where required by law. Any exemption to this policy must be approved by the Council of Data Stewards.
- Ensure that new systems or technologies purchased or developed by the University of Connecticut will use Social Security numbers as data elements only (not as keys to databases) when required by law or business necessity. Approval by the Council of Data Stewards is required for inclusion of the Social Security number in databases.
- Ensure that all requests (verbal or written) for which faculty, staff or students are required to provide their Social Security number contain or have appended to them a statement explaining the University’s request; e.g., the legal obligation on which the request is based, if there is one and the use that will be made of the Social Security Number.
- Ensure that all requests (verbal or written) for which faculty, staff or students are requested to voluntarily provide their Social Security number contain or have appended to them a statement explaining the University request and its purpose. The statement must indicate that no service or privilege will be withheld upon failure to provide the Social Security number and that the person may use the identifier provided by the University of Connecticut in place of the Social Security number.
- Ensure that any request for any form or document that contains the Social Security number, where the Social Security number is not the primary reason for the request, be accompanied by a statement indicating that the Social Security number is not required and should be blanked out on the form or document prior to being provided.
- Ensure that no new systems purchased or developed by the University of Connecticut display Social Security number visually, whether on computer monitors or on printed forms or other output, unless required by law.
- Develop an implementation plan to ensure compliance with this policy for existing systems.
Responsibilities: The Council of Data Stewards has overall responsibility for overseeing Social Security number usage at the University of Connecticut and for implementation and enforcement of this policy.
Enforcement and Review:
Review of this policy by the Council of Data Stewards will occur bi-annually.
Any individual who suspects a violation of this policy may report it to the Compliance Office in the Office of Audit, Compliance and Ethics at (860) 486-4526, or anonymously through the Reportline (https://www.compliance-helpline.com/uconncares.jsp). Violations of this policy may result in appropriate disciplinary measures in accordance with University Laws and Bylaws, General Rules of Conduct for All University Employees, applicable collective bargaining agreements, and the University of Connecticut Student Conduct Code.