Data Policies
Data management is guided by federal and state law, institutional and regents’ policies, industry best practices and ethical principles. To learn more about the principles followed by Institutional Research and Analytics, visit the Student Success Framework page.
FERPA Policy and Proxy Information
OSU Policies
OSU has established several policies that govern the use and storage of data. Other policies not listed below may address data within specific circumstances. Individual offices may also set standards and requirements as needed.
1-0130 Open Records (PDF)1-0136 Digital Accessibility (PDF)2-0701 Family Educational Rights and Privacy Act (Buckley Amendment) (PDF) 3-0322 Electronic Use of Social Security Numbers (PDF) 3-0601 Appropriate Use Policy (PDF)3-0602 Data Stewardship: Data Classification Policy, Responsibilities and Guidelines (PDF)3-0604 Information & Resources: Access Control Policy (PDF)3-0605 Information Security: Security Awareness (PDF)
State and Federal Regulations
OSU abides by all applicable state and federal law regarding the use of and storage of data.
Computer Fraud and Abuse Act 1986 (US) 18 USC 1030The Digital Millennium Copyright Act (DMCA) Family Education Rights and Privacy Act (FERPA) Gramm-Leach-Bliley Act (GLB)Health Insurance Portability and Accountability Act (HIPAA)Oklahoma Computer Crimes StatutesPayment Card Industry Data Security Standards (PCI)Sarbanes-Oxley Act
FERPA Policy and Proxy Instructions
The Family Educational Rights and Privacy Act (FERPA) is the federal law that protects student information. All employees (including student employees) at OSU must follow the guidelines established by FERPA, and a training and test must be completed and passed before they are granted access to student data. Students may designate individuals with whom the university may share their information. These designees are referred to as “proxies.” Visit theRegistrar’s Office’s website tolearn more about FERPAand to review instructions for students to identify proxies.
Record Retention
Record retention schedules are established by the Oklahoma Archives and Records Commission . These schedules establish the minimum length of time that documents and records must be stored and identifies the acceptable methods of destruction. The OSU Archives reviews all requests for record destruction to determine if the documents should be preserved, retained in the originating department, or destroyed. Confidential student and personnel records are never accepted to the archives. Learn more on the Library’s website.
Individual and aggregated data may be stored longer than the minimum guidelines in order to meet long-term reporting and analytics requirements, as identified by law or university need.
2-0214 Retention of Gradebooks and Records (PDF)3-0190 Records and Documents Retention, Security, and Control
Website Privacy Notice
OSU utilizes many vendors who may collect information from users in order to provide services. Each vendor has their own Terms of Service, which may include a privacy policy. Please be aware of each of these as there may be differences in expectations and methods to address grievances.
OSU-owned websites have a Privacy Notice and Terms of Service which you can review at this site.