Student Privacy Issues Sailing away the winter blues with ISFAA … 2015 Winter Conference Topics • The Challenges of Protecting Privacy • Policy and Procedure • Marrying Customer Service with Managing Security Inquiry Methods • • • • • • • Telephone Email Postal mail Fax In person Social Media Subpoena Directory Information • Institutions may disclose information on a student without violating FERPA if it has designated that information as directory information – Name, email address, address, telephone number – college/school and curriculum, enrollment status and credit hour load – enrollment status and credit hour load – dates of attendance, classification – receipt or non-receipt of a degree – academic awards received (dean’s list, honors students) – participation in officially recognized activities – sports photograph, position, weight, and height of athletes Personally Identifiable Information • PII is information that can be used to distinguish a person’s identify – name, social security number, biometric data, etc., alone, or when combined with other personal data, linked or linkable to a specific person, such as date and place of birth, mother’s maiden name, etc.” The Challenges of Data Security • Determining identity and right to information • Fraud and abuse • Disinclination and disregard • Policy and regulations • System and physical limitations Setting Policy • Put controls in place to minimize fraud and abuse before they can occur • NASFAA’s Statement of Ethical Principles – Manifest the highest level of integrity • Protect the privacy of individual student financial records. Insuring Policy Compliance • • • • Train and frequently reinforce Model behavior Insure staff buy-in Consistently verify ID Identity Confirmation Policy for Student Specific Information Person Method of Communication In Person Student Present their photo ID OR name, DOB and last 4 of their SSN Present their photo ID OR name, Parent on FAFSA DOB and last 4 of their SSN Email On Phone Send email from their purdue.edu Provide PUID, full name and DOB OR email address and include the PUID full name, DOB and last 4 of SSN Send email from the address that Provide student's PUID, and DOB, they used on the FAFSA application their name, DOB and the last 4 and the student's name and PUID numbers of their SSN General information only unless General information only unless they are a PLUS borrower, then General information only unless they are a PLUS borrower, then student's name, and DOB, their they are a PLUS borrower, then student's full name and DOB, their name, DOB, the address used on the present photo ID OR name, DOB and full name, DOB and address used on PLUS application and the last 4 Parent not on FAFSA last 4 of their SSN their PLUS application numbers of their SSN Spouse of Independent Student General information only General information only General information only Parent of Independent Student General information only General information only General information only Marrying Customer Service & Security • Explain why you need to verify ID • Emphasize what you can provide • Give suggestions on how individuals can get information you cannot provide them • Explain why you cannot provide the information they seek • Provide empathy Email Inquiry Forms • https://www.purdue.edu/dfa/email.php • https://contact.scu.indiana.edu/contact/index .shtml • http://cms.bsu.edu/admissions/scholarshipsa ndfinancialaid/aboutouroffice/contactus Case Study • Listen to the scenario • Discuss it with your neighbor and decide how you would respond • Share your ideas with the group Questions or Comments? Thank you for your attendance and participation. Marcia Osman, Assistant Director of Client Services and State Aid Programs Purdue University, Division of Financial Aid mlosman@purdue.edu