Federal Privacy Act of 1974 / en Social Security Number Policy /policy/social-security-number-policy <span class="field field--name-title field--type-string field--label-hidden">Social Security Number Policy</span> <span class="field field--name-uid field--type-entity-reference field--label-hidden"><span>Anonymous (not verified)</span></span> <span class="field field--name-created field--type-created field--label-hidden"><time datetime="2019-09-30T11:24:35-04:00" title="Monday, September 30, 2019 - 11:24" class="datetime">Mon, 09/30/2019 - 11:24</time> </span> <div class="field field--name-field-policy-image-media field--type-entity-reference field--label-hidden field__item"><div class="media media--type-image media--view-mode-policy-image"> <div class="field field--name-field-media-image field--type-image field--label-visually_hidden"> <div class="field__label visually-hidden">Image</div> <div class="field__item"> <img loading="lazy" src="/sites/default/files/styles/policy_page_logo/public/images/geneseo-and-suny-logo_0.png?itok=JceXUryZ" width="300" height="100" alt class="img-fluid image-style-policy-page-logo"> </div> </div> </div> </div> <div class="field field--name-field-policy-number field--type-string field--label-hidden field__item">1-020</div> <div class="field field--name-field-policy-approved-by field--type-string field--label-hidden field__item">Cabinet</div> <div class="field field--name-field-policy-effective-date field--type-datetime field--label-hidden field__item">01-01-2009</div> <div class="field field--name-field-policy-date-last-revised field--type-datetime field--label-hidden field__item">02-07-2017</div> <div> <div>Category</div> <div>General College</div> </div> <div class="field field--name-field-policy-responsible-office field--type-string field--label-hidden field__item">Chief Information Officer</div> <div class="field field--name-field-responsible-office-number field--type-telephone field--label-hidden field__item"><a href="tel:585-245-5577">585-245-5577</a></div> <div class="clearfix text-formatted field field--name-field-policy-scope field--type-text-long field--label-hidden field__item"><p>This policy applies to all departments, faculty, staff, and students at the College. Social Security Numbers are highly confidential and legally protected data. 麻豆传媒团队 is committed to protecting the privacy and legal rights of its community members and to protecting community members from identity theft, one of the fastest-growing crimes.</p> </div> <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item"><p>The purpose of this policy is to:</p> <ol> <li>To protect the privacy and legal rights of the members of the College community.</li> <li>To generate broad awareness of the confidential nature of the Social Security Number.</li> <li>To reduce the use of the Social Security Number (including partial SSN) for identification purposes.</li> <li>To promote confidence by students and employees that Social Security Numbers are handled in a confidential manner.</li> </ol> </div> <div class="field field--name-field-policy-definitions field--type-entity-reference field--label-hidden field__items"> <div class="field__item"><a href="/taxonomy/term/424" hreflang="en">Federal Privacy Act of 1974</a></div> <div class="field__item"><a href="/taxonomy/term/425" hreflang="en">FERPA</a></div> <div class="field__item"><a href="/taxonomy/term/426" hreflang="en">NY State Law: Chapter 16, Article 1, Title 1, Section 2b</a></div> <div class="field__item"><a href="/taxonomy/term/427" hreflang="en">NY State Information Security Breach and Notification Act</a></div> <div class="field__item"><a href="/taxonomy/term/428" hreflang="en">Social Security Number</a></div> </div> <div class="clearfix text-formatted field field--name-field-policy field--type-text-long field--label-hidden field__item"><p>It is the policy at 麻豆传媒团队 that the use of the Social Security Number as a common identifier and the primary key to databases be discontinued, except where required for employment, financial aid, and a limited number of other business transactions.</p> <p>Disclosure statements will be provided whenever a Social Security Number is requested, in compliance with the Federal Privacy Act of 1974.</p> <ol> <li>Control and approval of the use of Social Security Number in any electronic system or form is assigned to the Information Security team. Social Security Numbers should be collected only for the purpose of processing student loans, employment, and to meet other legal obligations. The collection, use, and dissemination of student SSNs or any part thereof for other purposes is strongly discouraged. For SSN access in Banner, a director or department head must submit a Banner Social Security Number Access Request Form. To request approval to use SSN on any other electronic system or to request SSN on a form (electronic or paper), a director or department head must submit a <a href="https://docs.google.com/forms/d/e/1FAIpQLSdn3_aWnnwBcJUVQj_snG40qT9IdNMr2ZJ9SQZXHYzhRH0aMA/viewform" media_library="Media Library">Social Security Number Request to Use Form</a>.</li> <li>A 麻豆传媒团队 ID Number will be assigned to all students, employees, and associated individuals at the earliest point possible in the individual鈥檚 contact and association with the College. The 麻豆传媒团队 ID Number replaces the Social Security Number as the preferred common, unique identifier and key to 麻豆传媒团队 databases. Where possible, the 麻豆传媒团队 ID Number will be used in all future electronic and paper data systems to identify, track, and service individuals associated with the College.</li> <li>All forms on which persons are required to provide Social Security Numbers must contain or have appended to them a statement explaining the College request; e.g., the legal obligation on which the request is based, if there is one and the use that will be made of the Social Security Number. <ul> <li>For example, on an employment form, the following text can be used: <em>The Federal Privacy Act of 1974 requires that you be notified that disclosure of your Social Security Number is required pursuant to the Internal Revenue Service Code. The Social Security Number is required to verify your identity</em>.</li> <li>If the Social Security Number is not required, but requested, the fact that supplying it is voluntary should be noted and the option of assigning a temporary, 鈥渄ummy number鈥 should be offered. <ul> <li>For example, when SSN is voluntary, the following text may be used: <em>The Federal Privacy Act of 1974 requires that you be notified that disclosure of your Social Security Number is voluntary and not required on this form. If you do not choose to disclose your Social Security Number, a temporary identification number will be generated for you.</em></li> </ul> </li> <li>If the Social Security Number is not mandated by law, but is needed for a business purpose, e.g., in the early stages of the admissions process (e.g., to match standardized test scores such as SATs, ACTs, etc.), a disclosure statement of the following form may be used: <em>The Federal Privacy Act of 1974 requires that you be notified that disclosure of your Social Security Number is not mandated by law, however, the College uses your Social Security Number to match your application credentials correctly and quickly</em>. <ul> <li>Except where the College is legally required to collect a Social Security Number, individuals will not be required to provide their Social Security Number, verbally or in writing, at any <em>point of service</em>, nor will they be denied access to those services should they refuse to provide a Social Security Number. However, individuals may volunteer their Social Security Number, if they wish, if the primary means for identification is unavailable.</li> <li>Social Security Numbers will be stored as a confidential attribute associated with an individual. They will be used as allowed and mandated by law.</li> <li>Social Security Numbers will not be publicly displayed on any list or roster.</li> <li>Encryption of Social Security Numbers is required between server and client workstations and whenever data are transmitted over public unsecured networks. Web applications transmitting SSN must use https encryption. Email must be encrypted if transmitting SSN over email is unavoidable.</li> <li>Paper and electronic documents containing Social Security Numbers will be handled, used, and disposed of in a proper fashion. Proper disposal is defined as any method that shreds the record before the disposal of the record; or destroys the personal identifying information contained in the record; or modifies the record to make the personal identifying information unreadable; or takes actions consistent with commonly accepted industry practices to ensure that no unauthorized person will have access to the personal identifying information contained in the record. For more information on handling private information, view&nbsp;<a href="http://www.geneseo.edu/info_security/best_practices" media_library="Media Library"><em>Information Security Best Practices</em></a>&nbsp;document.</li> <li>Records or reports containing SSNs or other confidential information will not be downloaded or stored on College or personal computers or other electronic devices that are not secured against unauthorized access. Devices storing SSN or confidential information must be encrypted.</li> <li>Social Security Numbers will be released by the College to entities outside the College only as allowed by law, when the individual grants permission, when the external entity is acting as the College鈥檚 contractor or agent and adequate security measures are in place to prevent unauthorized dissemination to third parties or when Legal Counsel has approved the release.</li> <li>Social Security Number breaches must be immediately reported to the <a href="/info_security/team" media_library="Media Library">Chair of the Information Security Program Team</a> directly or by completing the <a href="https://docs.google.com/forms/d/e/1FAIpQLSdMJE4rsGy7Y5uZqxp8nf6d8O9HEBBbC-etOsZ4PAWnDadT8A/viewform" media_library="Media Library">Information Security Incident Reporting Form</a>.</li> </ul> </li> </ul> </li> </ol> <h2>Compliance</h2> <p>An employee or student who has substantially breached the confidentiality of Social Security Numbers will be subject to disciplinary action or sanctions up to and including discharge and dismissal in accordance with College policy and procedures.</p> <p>Violation may also result in criminal prosecution. It is a felony, punishable by up to 5 years in prison, to compel a person to provide a Social Security Number in violation of Federal Law.</p> </div> <div class="clearfix text-formatted field field--name-field-frequency-review-update field--type-text-long field--label-hidden field__item"><p>Every 3 years</p> </div> <div class="field field--name-field-periodic-review-completed field--type-datetime field--label-hidden field__item">01-14-2022</div> <div class="field field--name-field-policy-signed-by field--type-string field--label-hidden field__item">Susan E. Chichester</div> <div class="field field--name-field-name-title field--type-string field--label-hidden field__item">CIO &amp; Director, CIT</div> <div class="field field--name-field-policy-date-signed field--type-datetime field--label-hidden field__item">02-01-2017</div> Mon, 30 Sep 2019 15:24:35 +0000 Anonymous 87341 at