Scope


This procedure is used for authorizing access to information in Geneseo's various databases and logs including Banner, Human Resources, phone logs, email logs, Canvas logs and others. It covers requests for any database or service managed by CIT. Example requests include:  adding application accounts, providing query/update access to given application forms or screens, providing access to reports or data extracts, providing information to third parties, providing information as part of an investigation and others.

The Geneseo Banner Steering Committee recommends that any other department that provides access to information follow this authorization policy or implement a policy specific to their situation. Institutional Reporting and Human Resources, are specific example of departments that fulfill information requests.


Policy

1. If access is being provided to information for someone directly affiliated with Geneseo, CIT will consult the office designated as the data custodian.  Geneseo affiliations include the following examples:  faculty, non-academic employees, Campus Auxiliary Services, Foundation, students, SUNY or New York State agencies, and others. It does not include third-party vendors.  The offices and contacts for data custodians are listed in the following table:

Data Custodians

Data Subject AreaOfficeContacts
Alumni - Demographics (name, address, phone, email), Activities, Giving HistoryAdvancementLynn Myers
Applicant and RecruitAdmissionsMargaret Foster
EmployeeHuman ResourcesJulie Briggs
Financial AidFinancial AidSusan Romano
NCAA Athletic StandingIntercollegiate AthleticsMike Mooney

Student Activities and Organizations (e.g. athletics, greek organizations, clubs)

(this area is somewhat shared and depends on topic area)

Student and Campus Life
Advancement

Chip Matthews

Lynn Myers (??)

Student Academics, Demographics including names, addresses, phones, emails and student data not otherwise specifiedRegistrarKeely Soltow
Student/Employee CAMP EmailCITSue Chichester
Student Disability InformationDisability ServicesCelia Easton
Student Financial Information including billing and paymentsStudent AccountsSandy Argentieri
Student HousingResidence LifeSarah Frank
Student ID PhotosCampus Auxiliary ServicesPam Connor
Student Medical RecordHealth and CounselingSteven Radi, Susan Palmer


2. If the information is being provided to a third-party other than a New York State agency (e.g. SUNY), CIT will require approval from the campus risk manager and FOIL officer. Approval will also be required from the appropriate data custodians as specified above.

3. If access is being requested for students PII (personally identifiable information) fields protected by federal or state law such as social security number (SSN) approval will be required from the Dean of Students and the Registrar.  This specific procedure was established in 2008 to limit access to SSN within the application and all reporting processes. Access is only provided if warranted based on the person's job role (i.e. need to know).  Examples include: payroll functions, financial aid, records management responsibilities, required for NYS systems, sole means to identify student in third party system (e.g. NYS Teacher Certification database).

4. Access to data protected under FERPA also requires approval by the designated campus FERPA officer. Examples of data protected under FERPA include the following:

  • grades
  • test scores
  • I.D. numbers or social security numbers
  • financial records
  • class schedules
  • semester, cumulative, or major GPA
  • housing information
  • conduct records (or results of reviews)
  • date and place of birth
  • enrollment status
  • class attendance information

5. Requests for information from CIT managed database information and logs as part of an investigation must be made directly to the CIO or CIO's designee. Requests will only be acted upon from University Police with subpoena, the Dean of Students regarding students, the Director of Human Resources regarding employees, and the President or the President's designee.

Contact

Paul Jackson
Assistant Director Information Systems, Computing & Information Technology, jackson@geneseo.edu

Sue Chichester
CIO & Director, Computing & Information Technology, sue@geneseo.edu


Effective Date: October 1, 2014
Last Updated: February 24, 2021