Data Security
Purpose
This policy governs the privacy, security and integrity of Seton Hall University data stored on University information technology (“IT”) systems and outlines the responsibilities of the individuals and organizational units that manage, use, access, store or transmit that data.
Scope
This is a University-wide policy.
Definitions
-
- Artificial Intelligence and AI-enabled tools are any tool that produces human-like outputs (e.g., text, images, code) based on
user inputs, including platforms like Claude, ChatGPT, Gemini, Grok, Perplexity, Bard,
Stable Diffusion, and others embedded in other University provisioned software suites.
- Directory Data is data that is used for University communication or to link records between University
systems or reports. Such directory information is widely available to members of the
University community, but nevertheless should be handled with care, since exposure
could result in an increased risk of financial fraud or identity theft for the University
and members of the community. Examples of Directory Data include:
- Users’ short names
- Campus wide IDs
- ID photos
- Class Rosters/Advisor Rosters
- Protected Data is data that (1) if compromised would expose members of the University and its community
to a high risk of identity theft or financial fraud and (2) is protected by federal
or state law or regulations. Applicable law and regulatory requirements include, but
are not limited to, the Family Educational Rights and Privacy Act (FERPA), the Fair
and Accurate Credit Transactions Act (FACTA), the Health Insurance Portability and
Accountability Act (HIPAA), and other applicable Federal and NJ State laws. Examples
of Protected Data include:
- Social Security Number
- Driver’s License Number, Passport Number, or any State ID Number
- Credit Card Information (Number, expiration date, security code)
- Date of Birth
- Users’ Systems Passwords (Active Directory, Banner, Oracle, Cognos, Raiser Edge, etc.)
- Medical history
- Disability
- Student and family financial history
- Student account balances
- Donor financial history
- Student Financial Aid history
- Student academic history, including student grades
- Public Data is data that the University may or must make available to the public with no legal
or other restrictions, via its web site or various reports, press releases, and the
like. Examples of Public Data include:
- Information posted on the University’s website (www.shu.edu)
- The University phone directory
- The University’s annual financial filings
- The University Fact Book
- Data published in the Integrated Postsecondary Education Data System (IPEDS) documents
- Copyrighted materials that are publicly available
- Sensitive Data is data that, while not explicitly protected by federal or state law, is proprietary
to the University and would, if released, expose the University and members of the
community to a heightened risk of identity theft or financial fraud. Examples of Sensitive
Data include:
- Employee salary or employment history
- Permanent or Local Address of employees and students
- Department budgets
- Student registration Personal Identification Numbers (PINs)
- Internal operating procedures and operational manuals
- Internal memoranda, emails, reports and other documents
- Technical documents such as system configurations and floor plans
- Artificial Intelligence and AI-enabled tools are any tool that produces human-like outputs (e.g., text, images, code) based on
user inputs, including platforms like Claude, ChatGPT, Gemini, Grok, Perplexity, Bard,
Stable Diffusion, and others embedded in other University provisioned software suites.
Policy
-
- Individual Responsibility. Any person who uses, stores or accesses data contained in the University’s technology
systems has the responsibility to safeguard that data.
-
Classification of Data. Data classification is one method of determining the safeguard required for certain data and the appropriate University response to the unauthorized release of that data. Such safeguards and response plans are not only good stewardship for University data but are required by certain state and federal law and regulations.
All University data is classified into four levels of security classification: Protected Data, Sensitive Data, Directory Data, and Public Data. For the purposes of this policy, all data not formally classified (“Unclassified Data”) will be considered Sensitive Data. In accordance with the University’s Confidential Information, all data except Public Data is to be considered confidential.
- Security, University data are assets belonging to the University. Departments which collect, use, store and transmit University data should classify their data according to the level of risk associated with handling that data and implement appropriate safeguards to that data based on that risk. Data are generally stored in sets. The classification of a data set should be to the highest level of any data element in that set; for example, a report containing a combination of protected, sensitive directory and public data should be considered protected and provided with the safeguards appropriate for protected data. Individuals and departments must implement appropriate safeguards for accessing, transmitting and storing University data. Examples of appropriate safeguards for Protected and Sensitive Data include:
- The data must be protected to prevent loss, theft, and/or unauthorized access, disclosure, modification, and/or destruction.
- The data may only be accessed or disclosed if necessary for University business purposes and consistent with applicable University policies.
- The data must not be downloaded, stored or transmitted unless appropriately secured and/or encrypted.
- The data must not be posted on any website or shared file storage space unless University standard authentication methods are used.
- The data must be destroyed when no longer needed and in accordance with University
policies.
- Prohibited Conduct. Confidential, personal, or sensitive information must not be input into external
technology platforms and services unless explicitly authorized and only after assurance
that the tool meets the University’s data security requirements.
- Purchase of Advanced Digital and AI-enabled Tools: The purchase of all technology, including advanced digital and AI-enabled tools,
is governed by the University’s Technology Procurement Policy.
- Assessment of AI Outputs: Outputs generated by automated or algorithmic tools must be critically reviewed for
accuracy, completeness, and reliability. Such content may contain errors, biases,
or outdated information.
- Respect for Intellectual Property. Technology-assisted content might infringe on existing copyrights or may not be protected.
Users are responsible for ensuring appropriate use and attribution of any technology-assisted
work in accordance with University policies, including the University’s Copyright
Policy, and applicable laws.
- Reporting Responsibilities in the Event of a Data Breach
- Individual Responsibility. Any person who uses, stores or accesses data contained in the University’s technology
systems has the responsibility to safeguard that data.
Protected Data
The loss, unauthorized access to, or disclosure of, Protected Data must be immediately
reported to [email protected], the University’s Chief Information Officer (CIO),
and, if an employee, to the employee’s division leader, so that the appropriate response to the incident, including required notification
of appropriate federal and state agencies, can be initiated.
Sensitive Data
The loss, unauthorized access to or disclosure of Sensitive Data should be reported
to the management of the organizational unit in which the data breach was discovered
for their appropriate response.
- Responsive Action. The University reserves the right to take appropriate action for violation of this policy. Such action may include discipline, up to and including the following: the termination of employment or engagement; or expulsion from the University, University offices or other University space.
Related Policies
Responsible Offices
Department of Information Technology
Approval
Approved on December 16, 2013. Amended and approved by Monsignor Joseph R. Reilly, S.T.L., Ph.D., President, on the recommendation of the Executive Cabinet, on August 26, 2026.
Effective Date
December 16, 2013. First amended: August 26, 2026.

