Mission

The mission of the Privacy Program is to balance the collection, sharing, and use of Institute personal data assets and the appropriate level of privacy afforded to individuals who trust the Institute with their personal data, while also taking into consideration the Georgia Tech community's legitimate business need to collect, share, and use personal data.

The Privacy Program must also ensure compliance with applicable data privacy laws and regulations and University System of Georgia requirements.

Vision and Goals

  • Ensure the Institute's compliance with all applicable legal requirements and University System of Georgia requirements concerning data privacy.
  • Establish a data privacy culture that allows for the creative and innovative uses of data for Institute business while respecting the individuals who trust us with their information.
  • Create awareness and educate the Georgia Tech community about the importance and value of privacy, the ethics of privacy, compliance with applicable laws and regulations, and that privacy is everyone's responsibility.
  • Create a process where data subjects can engage with the Institute concerning their privacy inquiries and understand and execute their rights concerning their data.

FAQs

*These FAQs are not an exhaustive list, nor do they pose the only correct answer or solution to a problem. They are simply suggestions of how to handle common scenarios when looking through a privacy lens.

1. What is an example of accidental or intentional misuse or improper disclosure or exposure of PII data?

PII data can be disclosed to an unauthorized individual intentionally or unintentionally. For example, an unintentional disclosure might be an email that was sent to the wrong individual(s) with a spreadsheet attached that contains PII related to students or employees. Conversely, an intentional disclosure might come from a bad actor looking to hack a Georgia Tech system, or it could be from someone within Georgia Tech that snoops or accesses information that they don’t have a legitimate business need to see that PII data.

2. How do you define the who, what, and why of PII processing?

Let’s look at a common scenario to help understand this language. For example, a faculty member would like to use a third-party software program for their class to help students submit and manage assignments.

  • First, the faculty member needs to identify the population of Data Subjects whose data will be Processed. In this scenario, it will be students in the faculty member’s classes. It is student information that will be used and Processed within the tool. 
  • Then, the faculty member will need to identify specifically what PII data will be processed. This is the information that will be uploaded into the tool. In this scenario, it might be student first and last name, GTID, email, and potentially student assignments and coursework.
  • Lastly, the Processing activity of uploading student coursework and managing assignments should also have a legitimate purpose. In this instance, it might be that this software is made to manage and assess assignments specific to this particular course, and utilizing the software will help streamline and enhance the educational course experience.  

3. What does it mean to articulate who has access to PII that is being Processed?

Utilizing the same scenario as the question above, the faculty member needs to determine who will have access to the data. Will just the individual student and faculty member be able to see the information? Or, will the entire class of students be able to access the data? Additionally, will the third-party vendor be able to access the data? Is there a way to put protections around some data, while allowing access to other data elements? 

4. What does the principle of Data Minimization look like in practice?

Sticking with the same scenario, the faculty member should consider what PII is necessary in order to utilize the software and accomplish the specific purpose. Implementing the principle of data minimization means that the faculty member uses the PII that is needed to operate and educate but nothing more. So, if the software requires student name, email, and GTID in order to login, the faculty member should not also collect additional information such as phone number, address, or date of birth. The faculty member should only Process the minimum amount of information necessary to accomplish the purpose. 

5. What does it mean to De-identify data?

To De-identify data means to strip the PII of all identifying elements so that a specific individual cannot be identified by looking at the data set. Sticking with the same classroom scenario, the faculty member should consider if there are ways to minimize the Processing of PII. Does the software allow the data to be de-identified? Can course submissions and assignments be anonymized so that others cannot identify who submitted what assignments or answers?