Data Security Policy
- Home
- Offices and Services
- Technology & Innovation
- IT Guidelines & Policies
- Data Security Policy
- About
- Fellowships & Scholarships
-
Academics
- Advising, Tutoring & Support
- Study Abroad
-
Research Opportunities
- Undergraduate Research
- External Funding Opportunities
- Faculty Funding Opportunities
- Catalyst
-
Campus Life
- Campus and Surroundings
- Health & Wellness
- Activities & Organizations
- Financial Wellness
- Get Involved
- International Student Experience
- Explore Davidson
-
Academic Departments
- Africana Studies
- Linguistics
- Public Health
- Anthropology
- Applied Mathematics
- Arab Studies
- Art Department
- Biology
- Chemistry
- Chinese Studies
- Classics
- Communication Studies
- Dance
- Data Science
- Economics
- Educational Studies
- Engineering
- English Department
- Environmental Studies
- Film, Media and Digital Studies
- French and Francophone Studies
- Gender and Sexuality Studies
- Genomics
- German Studies
- Global Literary Theory
- Hispanic Studies
- History
- Humanities
- Interdisciplinary Studies
- Latin American, Latinx, and Caribbean Studies
- Mathematics and Computer Science
- Military Science (ROTC)
- Music
- Neuroscience
- Philosophy
- Philosophy, Politics, and Economics
- Physical Education, Recreation & Wellness
- Physics
- Political Science
- Prelaw
- Premedicine and Allied Health Professions
- Religious Leadership and Service
- Pre-veterinary Medicine
- Psychology
- Religious Studies
- Russian Studies
- Structured Independent Language Program
- Sociology
- South Asian Studies
- Theatre
- Writing Program
-
Offices and Services
- Art Galleries
- Division of Student Life
- Institutional Biosafety Committee
- Ombuds Office
- Special Events & Event Services
- The Jay Hurt Hub for Innovation and Entrepreneurship
- The Office of Equity Compliance
- Archives and Special Collections
- College Communications
- College Store
- Arts & Creative Engagement
- Academic Access & Disability Resources
- Academic Affairs
- Lula Bell's Resource Center
- Animal Care and Use
- Auxiliary Services
- Controller's Office
- Post and Print
- Carnegie Guest House
- Human Subjects IRB
- CatCard Services
- Matthews Center for Career Development
- Center for Teaching and Learning
- Chidsey Center for Leadership Development
- Civic Engagement
- College Relations
- Davidson Outdoors
- Dean Rusk International Studies Program
- Dining
- Center for Student Diversity and Inclusion
- Education Abroad
-
Environmental Health and Safety
- Fire & Life Safety
-
Occupational Safety
- Contractor Safety
- Confined Space Entry Program
- Electrical Safety
- Lockout Tagout Procedure
- Ladders and Scaffolding
- Personal Protective Equipment
- Respiratory Protection
- Hearing Conservation Program
- Hand and Power Tools
- Steam System Safety
- Welding, Cutting and Brazing
- Compressed Gas Cylinders
- Construction and Excavation
- Fork Lift Safety
- Motor Vehicle Safety
- Golf Cart Safety
- Biological, Chemical & Laboratory Safety
- Chemical Inventory
- Safety Data Sheets
- Training
- Environmental
- Indoor Air Quality
- Ergonomics
- Forms and Policies
- Incident Reporting
- EHS Committee
-
Office of Fellowships
- Appointments & Contact Information
-
Fellowship Opportunities
- Beinecke Scholarship
- Boren Fellowships
- Churchill Scholarship
- Critical Language Scholarship Program
- DAAD Rise Germany
- Fulbright U.S. Student Program
- Gaither Junior Fellows Program
- Gates Cambridge Scholarships
- Goldwater Scholarships
- Knight-Hennessy Scholars
- Luce Scholarships
- Marshall Scholarships
- McCall MacBain Scholarships
- National Science Foundation Graduate Fellowships
- NOAA Hollings Scholarship
- Paul & Daisy Soros Fellowships for New Americans
- Pickering Fellowship Program
- Rangel Fellowship Program
- Rhodes Scholarships
- Schwarzman Scholars
- Smith Scholarship
- Truman Scholarships
- Udall Scholarships
- UK Summer Institutes
- Watson Fellowship
- Fellowship Resources for Faculty & Staff
- Finance & Administration
-
Office of Sponsored Programs
- Research Compliance
- Proposal Development
-
Policies
- NSF and NIH Sexual Harassment Notification Policy
- NSF and NIH Breach of Personally Identifiable Information (PII) Policy
- Conflict of Interest
- NIH and NSF Public Access Policy
- Policy and Procedure for Responsible Conduct of Research
- Effort Reporting Policy
- Export Control Policy
- Ethical Conduct in Research and Scholarship
- Financial Conflict of Interest Policy
- Full Year Sabbatical Fringe Benefits
- Grants Record Management Policy
- Drug Free Workplace
- Intellectual Property Policy
- Indirect Cost
- Postdoctoral Positions Policy
- Determination of Allowable Costs Policy
- Summer Salary Distribution
-
Post Award Management
- Procurement Policy
- Suspension and Debarment Policy and Procedure
- Grant-Related Expenditure Approval and Monitoring Procedure
- Unallowable Cost Policy
- Cost Transfer Policy
- Sub-Recipient Monitoring Policy
- Award Cash Management Service Procedure
- Hiring New Personnel
- Rebudgeting and Program Revisions
- Reporting and Closeout
- Staff
- Guest Services
- Student Health and Well-Being
- Housing and Relocation
-
Human Resources
- Benefits
- Retirement
-
Employee Guide
- Americans with Disabilities (ADA)
- Leave Accruals
- Attendance
- Background Checking Policy
- Confidentiality of Information
- Conflict of Interest
- Consensual Relationships
- Copyrights
- Dependent Tuition Assistance Policy
- Disciplinary Action
- Dress Code
- Drug-free Workplace
- Employee Designations
- Employee Files
- Employee Honor Code
- Employment and Recruitment
- Employment of Minors
- Employment of Relatives
- Family Medical Leave Act
- Firearms and Dangerous Weapons
- Funeral and Bereavement Leave
- Grievance Procedure
- Identification Cards/CatCards
- Immigration Sponsorship for College Employees
- Inclement Weather
- Jury Duty
- Long Term Disability
- Military Leave
- Non-Discrimination Policies
- Occupational Health and Safety
- Other Employment
- Overtime
- Parental Leave
- Pay During Special Circumstances
- Pet Policy
- Political Activity
- Reduced Hours and Voluntary Time Off
- References for Former Employees
- Relocation and Moving Expense Policy
- Resignation
- Retirement Health Insurance
- Short Term Disability
- Sick Leave
- Smoking Policy
- Sports Betting Policy
- Staff Tuition Policy
- Support for Lactation Policy
- Remote Work Policy
- Transfer, Promotion and Classification
- Use of College-owned Equipment and Work Areas
- Vacation
- Vehicles/Parking
- Volunteer Policy
- Voting
- Work Schedules
- Workers Compensation
- Employee Resources
- Manager Resources
- Work at Davidson
- Student Employment
- HR Staff
- Institutional Effectiveness
- International Student Engagement
- Investment Office
- July Experience
- Laundry Self-Service Facilities
- Motor Pool Services
- Physical Plant
- Public Safety
-
Registrar
- Academic Calendars
- Course Offerings
- Course Registration and WebTree Overview
- Holistic Advising
- Student Schedules, Grades, Add/Drop
- Transcripts
- Record Requests & Forms
- Graduation Requirements
- Transfer Credit
- New Student Resources
- Faculty Resources
- College Catalog
- Academic Regulations
- FERPA
- Graduating Class Profiles
- Staff
- Religious and Spiritual Life
- Residence Life
- Staff Council
-
Student Activities
-
Student Organizations
- Academic Clubs and Societies
- Affinity & Identity Organizations
- Civic Engagement Council
- Fraternity & Sorority Life (Patterson Court Council)
- Health & Wellness Organizations
- Media Organizations
- Performance Groups
- Political Organizations
- Pre-Professional Organizations
- Religious Organizations
- Special Interest and Recreational Organizations
- Programs
- Student Activities Staff
-
Student Organizations
- Sustainability Office
-
Technology & Innovation
- Getting Started
- Services
-
IT Guidelines & Policies
- Artificial Intelligence Policy
- Emeriti Technology Policy
- Davidson College Technology Terms of Service
- Account Management
- College Access to Electronic Communications Policy
- Computer Workstation Purchasing
- Copyright Compliance with Laws and Acts
- Data Privacy Statement
- Data Security Policy
- Desktop Computer Support
- Guidelines for Mass Email Communications
- Information Security Plan
- Information Systems Security Policy
- Log Retention Guidelines
- Moodle Usage Tracking
- Purchasing Technology
- About
- Staff
- The Farm at Davidson
- Wildcat Wellness
- Accessibility
-
Library
- The George Lawrence Abernethy Library
- Using The Library During Construction
- About the Library
- Faculty Services
- Letterpress Lab
- Staff Benefits & Resources
- Staff by Department
-
Admission and Financial Aid
- Request Information
- Apply
- Visit
- Admission Process & Help
- Commitment to Affordability
- Access & Belonging
- En Español
- Admission & Aid Timeline
-
Financial Aid
- Applying for Aid
- Types of Financial Aid
- Policies & Resources
- Financial Aid Frequently Asked Questions
- Contact Financial Aid
- Cost of Attendance
- Counselor Resources
- Contact Admission & Ambassadors
-
Alumni and Families
- Alumni Careers & Networking
- Events & Programming
- Volunteer for Davidson
- Alumni Communities
- Young Alumni & Current Students
- Parents & Families
- Resources & Contacts
- Commencement
- The Arts
- New Students
- Live Stream
- Alert
- 'Cat Cam Live Video
- Diversity, Equity, Inclusion
- Giving
-
News & Events
-
Davidson Journal
- Spring/Summer 2026 Issue
- Fall/Winter 2025 Issue
- Spring/Summer 2025 Issue
- Fall/Winter 2024 Issue
- Spring/Summer 2024 Issue
- Fall/Winter 2023 Issue
- Spring/Summer 2023 Issue
- Fall/Winter 2022 Issue
- Spring/Summer 2022 Issue
- Fall/Winter 2021 Issue
- Spring/Summer 2021 Issue
- Fall/Winter 2020 Issue
- All Davidson Journal Stories
- My Davidson
- Social Media Hub
-
Davidson Journal
- Discover Davidson College
- Athletics
- Name the Wildcat
- AI
- April 18, 2024 – Historic Gifts to Transform Library
- April 23, 2025 – Campus Update and Webinar Invitation
- August 1, 2022 – Message from President Doug Hicks '90
- August 19, 2025 – New School Year Update: Building on Strength
- August 22, 2023 – Key Initiatives & Strategic Planning for This Academic Year
- August 23, 2024 – Fostering A Community of Trust
- August 27, 2024 – Launching Into The New Year, and The Future
- December 1, 2022 – Inauguration Information and Planning
- Institute for Public Good
- January 21, 2025 – Welcome to Spring 2025 at Davidson College
- June 19, 2023 – Juneteenth and Our Continuing Work at Davidson
- June 3, 2025 – Summer Update from President Hicks
- March 20, 2025 – Our Commitments to Freedom of Expression and Mutual Respect
- March 7, 2023 – Our Commitment to Freedom of Expression
- October 5, 2023 – Update on Davidson College’s Strategic Planning
- September 2, 2024 – Strategic Plan and Updates
- TEDxDavidson College
Data Security Policy
Background
Davidson College has adopted this Data Security Policy to (i) identify certain categories of data that Davidson owns, hosts, stores, processes, or is otherwise responsible for protecting and (ii) set expectations and restrictions for the storage, dissemination and protection of data by category.
Purpose
This policy regulates a wide range of data (“Davidson data”), including but not limited to:
- Administrative data include data that supports the functions, business and operations of the college, and is non-instructional in nature. This includes financial, personnel, facilities, advancement and related records.
- Education records include data that pertain to a student’s academic performance or progress or to many aspects of their residential life on campus. It also includes admissions-related information and financial information, including financial aid and tuition billing information.
- Research data includes data relevant to funded or unfunded research activities where Davidson has an explicit or implicit requirement to ensure that data remain confidential and protected.
This policy does not include instructional materials prepared by faculty or other data where the College does not own the information or have legal liability or reputational risk if the data are breached or accessed improperly.
Policy
Davidson data are intended solely for the authorized use by employees to conduct Davidson business.
- Some Davidson information is protected by law, regulation, contract, or Davidson policy in ways that restrict its use, access, download and sharing.
- Davidson manages data in accordance with its data classification, described below. Davidson’s General Counsel’s office or the information security program manager (ISPM) can advise employees and departments as to the appropriate classification of data.
- All employees are responsible for ensuring they are accessing, using and storing data in accordance with Davidson policy. This includes only using systems, services, devices and other technology appropriate to the security requirements of certain data classifications.
- This policy designates employees with access to Davidson data as members of one of several roles as defined by the Data Governance Committee: data consumers, managers, stewards, or trustees. These roles are defined in the appendix of this policy.
- Employees are responsible for immediately notifying their supervisor and the Technology & Innovation Support Center if they believe any Davidson data (including devices or systems containing such data) have been lost, stolen, altered/destroyed, or made available for unauthorized access. (If a device has been lost/stolen, employees must also report this to Public Safety.)
All Davidson data meet one of four classifications, each with more stringent requirements for the storage, use and protection of such data:
- Public: Any data that is permitted to be shared freely with all members of the campus and the general public.
- Internal: Data that Davidson chooses to restrict to internal access, but where disclosure would not violate state or federal laws or cause reputational harm. Internal data always require a Davidson login to access, but are typically shared widely such as with all persons with a Davidson email account, all employees, all staff in a division, etc.
- Restricted: Data that must be shared only with specific individuals who have a business need to access, and where breach or inadvertent disclosure would impact Davidson’s reputation or violate educational privacy requirements (FERPA).
- Confidential: Data the breach or inadvertent disclosure of which would violate state or federal privacy or data security laws (including certain research grant obligations) and may involve civil or criminal penalties. These data may be shared only with specific individuals who have a business need to access. Includes data protected by the Gramm-Leach-Bliley Act (GLBA), HIPAA, the NC Identity Theft Act, or similar laws. These data must not be stored beyond time required by federal or state laws such as the GLBA or Davidson College retention policies.
For more details on the classifications, please see the sections below.
Public Data
| Definition |
Any data that is permitted to be shared with all members of the campus and the general public. |
| Examples |
Material authorized for public websites (www.davidson.edu or Davidson Domains), Library government documents, public event calendar. |
| Where Data May be Stored and Processed |
Any Davidson-approved technology service. |
| Shareable with External Users or Vendors? |
Yes |
| Storable on Davidson-Managed Laptops, Desktops and Devices? |
Yes |
| Storable on Employee-Owned Laptops, Desktops and Devices or Cloud Services? |
Yes |
| Permitted for use in AI tools? | May be used in public and Davidson licensed AI tools. |
Internal Data
| Definition |
Data that Davidson chooses to restrict to internal access, but where disclosure would not violate state or federal laws or cause reputational harm. These data require a Davidson login to access but are often shared with broad groups of campus users (such as all students and/or all employees, or specific divisions, departments or committees.) |
| Examples |
Building floor plans, internal policies, licensed Library databases, public computer workstations, internal campus-only event calendar. |
| Where Data May be Stored and Processed |
Any Davidson-approved technology service requiring a Davidson login. |
| Shareable with External Users or Vendors? |
With permission of manager/supervisor. |
| Storable on Davidson-Managed Laptops, Desktops and Devices? |
Yes |
| Storable on Employee-Owned Laptops, Desktops and Devices or Cloud Services? |
Yes |
|
Permitted for use in AI tools? |
May only be used in Davidson licensed AI tools requiring a Davidson login. |
Restricted Data
| Definition |
Data that may be shared only with specific individuals who have a business need to access, and where breach or inadvertent disclosure would impact Davidson’s reputation or violate educational privacy requirements (FERPA). |
| Examples |
Most educational records (FERPA)*, personnel records*, alumni/donor records*, departmental budgets, employee salaries, most research data (varies by grant requirements). *excluding Confidential data elements |
| Where Data May be Stored and Processed |
Google Drive, Moodle, Banner, Etrieve, Blackbaud CRM, Office 365 email (use caution), and any other Davidson IT service authorized for Restricted data. (If you are uncertain if a technology service may be used for Restricted data: Search for the overview article for the service at https://support.ti.davidson.edu for the types of data that may be used with each system. For non-T&I managed systems, consult T&I Information Security.) |
| Shareable with External Users or Vendors? | With permission of the Data Steward (see Appendix: Data Roles and Responsibilities). |
| Storable on Davidson-Managed Laptops, Desktops and Devices? |
Yes; whole drive encryption preferred. |
| Storable on Employee-Owned Laptops, Desktops and Devices or Cloud Services? |
Phones/mobile devices: Yes, if encrypted and passcode or biometric login enabled. Home computers: Minimize use and never store data here. |
|
Permitted for use in AI tools? |
May only be used in Davidson licensed AI tools requiring a Davidson login. |
Confidential Data
| Definition |
Data whose breach or inadvertent disclosure would violate state or federal privacy or data security laws (including certain research grant obligations) and may involve civil or criminal penalties. These data must be shared only with specific individuals who have a need to access. Includes data protected by Gramm-Leach-Bliley Act, HIPAA, the NC Identity Theft Act, or similar laws. |
| Examples |
Social Security Numbers, passport numbers, family/student income or tax data, combinations of sensitive personal identifiable information (SPII) regulated by law, protected health information (PHI), credit card data (PCI), sensitive FERPA/educational records (e.g., student health, counseling, Title IX), certain research data (varies by grant requirements). |
| Where Data May be Stored and Processed |
Banner, Etrieve, Blackbaud CRM, approved campus file servers, specially-requested Google Drive shared drives with special access rights not synced to workstations. (If you are uncertain if a technology service may be used for Confidential data: Search for the overview article for the service at https://support.ti.davidson.edu for the types of data that may be used with each system. For non-T&I managed systems, consult T&I Information Security.) |
| Shareable with External Users or Vendors? |
Authorization of Data Steward and Data Trustee required (see Appendix: Data Roles and Responsibilities). Consult T&I Information Security. |
| Storable on Davidson-Managed Laptops, Desktops and Devices? |
Not recommended (must discuss with T&I Information Security); device must have Davidson-managed whole-drive encryption enabled. |
| Storable on Employee-Owned Laptops, Desktops and Devices or Cloud Services? |
Never |
|
Permitted for use in AI tools? |
No, unless explicit permission of T&I Information Security is given. |
Administration of Policy
The CIO shall oversee this policy and review it at least once every two years. Changes to this policy shall be made in accordance with the college’s Policies: Creation, Promulgation, Review, and Format documentation (Davidson login required) prior to implementation. As part of implementation, faculty, staff, and students will be notified of the policies.
Appendix: Data Roles and Responsibilities
Program Manager, Information Security
The information security program manager implements policies and procedures to comply with the Family Education Rights and Privacy Act (FERPA), the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Gramm-Leach-Bliley Act (GLBA), and others governing the treatment of individually identifiable information.
Data Trustees
Data Trustees are senior college staff members who have planning, policy-level and management responsibility for data within their functional areas.
Data Trustee responsibilities include:
- Assigning and overseeing Data Stewards and Managers
- Remaining aware of the legal and regulatory requirements for data in their areas
- Ensuring that data policies are established, and kept up to date, in their areas and if appropriate, delegating such responsibility
- Promoting appropriate use, data integrity, and data quality
Data Stewards
Data Stewards are college staff members having direct operational-level responsibility for the management of one or more types of data in their area. Data Stewards are assigned by the Data Trustee and are generally associate deans, associate vice presidents, directors or key technical staff.
Data Steward responsibilities include:
- The application of policies to the systems, data, and other information resources under their care or control
- Overseeing the establishment of data policies in their areas
- Understanding legal and regulatory requirements for data in their areas
- Classifying data using the College's data classification system
- Identifying safeguards for Restricted and Confidential data
- Ensuring the deletion of Confidential data elements as required by federal or state law or college policy
- Promoting appropriate use, data integrity, and data quality
- Attending the data governance committee operational meetings or sending an appropriate data manager delegate
In some cases Data Stewards will also be responsible for Data Manager tasks. In areas with more staff Data Managers may work alongside Data Stewards with responsibility over the same data set.
Data Managers
Data managers are college staff members who are responsible for day-to-day operational data collection and management, overseeing the life cycle of a particular set of institutional data. They have the authority from the data steward and/or data trustee to grant internal access to data for their functional area. Data managers are generally managers of data systems or data analysts within business departments.
Data Manager responsibilities include:
- Implementing the established data policies in their areas
- Developing data definitions and standards for data elements in their functional area
- Regularly striving to improve the way data is defined, produced, and used in their functional area
- Resolving data quality issues pertaining to data in their functional area
- Safeguarding data by ensuring appropriate access, following established authorization procedures, and maintaining physical and system security appropriate to the classification level of the data in their custody
- Following data handling and protection policies and procedures established by Data Stewards and information security
- Communicating and providing education on the required minimum safeguards for protected data to authorized data users
- Supporting access by providing appropriate documentation and training to data consumers
- Promoting appropriate use, data integrity, and data quality
- Attending Data Governance Committee operational meetings as requested by the committee and/or Data Steward
Data Consumers
Data Consumers are the individual college community members who have been granted access to college data in order to perform assigned duties or in fulfillment of assigned roles or functions at the college. This access is granted solely for the conduct of college business.
Data Consumer responsibilities include:
- Following the policies and procedures established by the relevant Data Steward and information security team
- Complying with federal and state laws, regulations, and policies associated with the college data used
- Applying safeguards prescribed by appropriate data steward for Restricted and Confidential data
- Reporting any unauthorized access or data misuse to information security or the appropriate Data Steward for remediation
Last Revised: March 2026