Information Data Protection & Privacy Standard (SFA 06-107.1.5)

Quick Overview
  • This standard sets the specific requirements for how SFA protects data and safeguards privacy: controlling how data moves, who can share it, how confidential data is handled, how it is encrypted, and how long it is kept.
  • It carries out the goals in the SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy.
  • It applies to everyone who touches SFA data, but the detailed work is led by security, privacy, and data-management staff.
  • These requirements are the minimum baseline SFA must meet; the university may choose to do more.
  • Meeting this standard is mandatory unless a formal exception is granted.

This standard is about keeping SFA's data safe and handling people's private information responsibly. It spells out what the university must do to control where data flows, to put the right agreements and notices in place before sharing it, to handle confidential information carefully, to encrypt data when it moves or sits at rest, and to keep data only as long as needed before disposing of it securely. In short, it protects student, employee, research, and institutional information from being lost, leaked, or misused, and it helps SFA meet privacy laws like FERPA, HIPAA, GLBA, and GDPR.

i
Policy vs. Standard
The matching policy (06-107.1) says what SFA wants to achieve. This standard says how, the concrete requirements. Day-to-day steps live in procedures.

Who This Applies To

This standard applies to all SFA employees, users, third-party service providers, research partners, and other authorized users of SFA information resources, systems, and data. Anyone working in SFA IT facilities, including vendors, visitors, and contingent workers, must follow it. In practice, the detailed requirements below are carried out mostly by the people who define, enforce, and monitor data protection and privacy: the CISO and Office of Information Security, Privacy Officers, Data Protection and Data Management Officers, and IT teams.

i
Baseline, not a ceiling
Everything here is the minimum SFA must do. Departments may add stricter requirements, but never anything weaker. See the SFA 06-107 Controls Crosswalk for higher control tiers.

Who Is Responsible

Key roles & responsibilities ⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.
  • Office of Information Security (ISO) / CISO: Develops, implements, and maintains the processes that govern how data is collected, processed, stored, released, and disposed of, working with Data Management Officers and Privacy Officers.
  • Data Protection Officers (DPO): Make sure data is collected, used, and shared in line with privacy laws; run the process and inventory for tagging data with security and privacy attributes; and manage external data exchange and public posting. (At some institutions the DPO may also be the Privacy Officer or part of the Office of Information Security.)
  • Privacy Officers (PO): Keep SFA's data-protection practices aligned with current privacy laws, advise on sharing and disclosure, and ensure vendor and third-party contracts include the right protections and liability terms. (A PO may also serve a legal or compliance role.)
  • Data Management Officers (DMO): Partner on classifying, publishing, releasing, and de-identifying data.
  • IT Management / Teams: Collect and handle only the data needed for the task and watch systems for unusual data activity.
Full role definitions Complete responsibilities for each role are in the attached standard PDF.

What This Standard Requires

The requirements are grouped into five areas. Expand any area for a plain-language summary of what it requires. The official requirement numbers (like 06-107.1.5.1.1) are shown so you can match them to the attached PDF.

1  Data Flow Enforcement  Controlling where data can move ⌄

SFA must control how data moves between systems, matching the level of protection to how sensitive the data is.

  • Control how data flows within and between systems, and fix any flow failures, with protections that match whether the data is confidential, controlled, or published (06-107.1.5.1.1).
  • Review those data-flow controls at least once every 12 months to confirm they still fit the data's classification (06-107.1.5.1.2).
  • Put restrictions in place (such as firewalls, data loss prevention software, or other authorization limits) on data moving between systems with different security levels (06-107.1.5.1.3).
  • Build a process, with Data Management Officers and Privacy Officers, to tag data with security and privacy attributes (identify, classify, label, and handle it) whether stored, in use, or in transit (06-107.1.5.1.4).
  • Use controls or technical settings to block the use of unapproved systems or components that process, store, or transmit SFA data (06-107.1.5.1.5).
  • Keep those security and privacy tags attached to the data as it is created, combined, or transformed, allow only authorized people or processes to change them, and display them in readable form when law or classification requires (06-107.1.5.1.6).
  • Interpret those tags consistently across systems that exchange data, including cloud and third-party services, so their meaning and enforcement stay uniform (06-107.1.5.1.7).
2  Data Agreements, Notices, Publishing & Consent  The paperwork before sharing ⌄

Before data is shared, published, or collected, SFA must have the right agreements, notices, and consent in place.

  • Approve and manage sharing data with outside systems using the right agreement for the situation (such as memoranda of understanding, service level, data sharing, data protection, business associate, user, or nondisclosure agreements), document the security requirements and responsibilities in each, and review them on a set schedule with Privacy Officers (06-107.1.5.2.1).
  • Name and train the people allowed to post data publicly, review content with Data Management Officers before it goes up, and re-check public sites at least once every 12 months so no confidential or controlled data slips through (06-107.1.5.2.2).
  • Set restrictions on data mining (excluding purchased data), in line with privacy frameworks and with Privacy and Data Management Officers as needed (06-107.1.5.2.3).
  • Get people's consent before collecting and processing their confidential or individual-identifying information, as required by law (06-107.1.5.2.4).
  • Give people a clear, plain-language notice about how their data is processed, including the authority for it, where to send questions, and the purposes of processing (06-107.1.5.2.5).
  • Where SFA keeps a system of records with personally identifiable information (PII), provide privacy notices (and a system-of-records notice where applicable) describing what is kept, why, and people's rights, and include Privacy Act-equivalent statements on forms that collect PII (06-107.1.5.2.6).
3  Handling of Confidential Data  Rules for the most sensitive data ⌄

Confidential data gets extra care: clear handling rules, and only authorized people may touch it.

  • Write down the rules for how authorized users handle and process confidential data, and restrict or prohibit unauthorized users from handling it (06-107.1.5.3.1).
  • Enforce minimum protections for confidential data: publish privacy notices, tell people how their data is used, collect only what is essential, and track any changes in how confidential data is processed (06-107.1.5.3.2).
!
Important
SFA institutions are strongly encouraged to prohibit tracking technologies (such as Meta Pixels, cookies, or any script that collects user data) on websites or apps that contain confidential data.
4  Transmission & Encryption Methods  Scrambling data so others can't read it ⌄

SFA must encrypt and safely transmit confidential data, and manage the keys that lock and unlock it.

  • Protect confidential data with encryption and other safeguards suited to the asset, data type, and sensitivity; at a minimum, confidential data must be encrypted when sent to a vendor or third party, including by email (06-107.1.5.4.1).
  • Exchange data over secure, approved connections when high confidentiality or integrity is needed, using cryptographic measures that match the data's sensitivity (06-107.1.5.4.2).
  • Establish and manage cryptographic keys under a defined key-management process whenever encryption is used (06-107.1.5.4.3).
  • Keep data available if keys are lost, using methods such as key backups or alternative encryption, so data is not lost (06-107.1.5.4.4).
  • Protect the confidentiality and integrity of data at rest with protections that match its classification (06-107.1.5.4.5).
  • AI  Limit the data used in artificial intelligence systems by classification: published data may be used freely, controlled data only where access is restricted to authorized personnel, and confidential data only with heightened security and documented CISO approval (06-107.1.5.4.6).
  • Where out-of-band channels (a separate delivery path) are used to send information, authenticators, or components, use controls so only authorized recipients get the delivery and its integrity is preserved (06-107.1.5.4.7).
5  Data Management & Retention  Keeping, minimizing & disposing of data ⌄

SFA must keep data only as long as required, use as little confidential data as possible, and dispose of or de-identify it properly.

  • Work with Data Management, Record Management, and other offices to retain data in line with all applicable laws and retention rules (for example, federal grant records for at least 3 years, healthcare records for 6 years, and financial records for 5 years) (06-107.1.5.5.1).
  • Limit the confidential data used across its life cycle to only the elements that are absolutely necessary (06-107.1.5.5.2).
  • Use techniques to minimize the use of confidential data for research, testing, and training (06-107.1.5.5.3).
  • Set up a disposal, destruction, or erasure process with Record and Data Management Officers; within 30 days of a vendor contract ending, vendor data must be returned or securely destroyed, and if that is not feasible, it must stay protected, be limited in further use, and be de-identified where possible (06-107.1.5.5.4).
  • Correct or delete confidential data at an individual's request, after consulting Privacy Officers, and notify the individual once the update is made (06-107.1.5.5.5).
  • Define procedures, with Privacy and Data Protection Officers, for de-identifying data, including removing certain confidential elements and confirming the de-identification worked (06-107.1.5.5.6).
  • Remove confidential data elements from a dataset before its release when those elements are not needed, as far as technically feasible (06-107.1.5.5.7).
  • Remove, mask, encrypt, hash, or replace direct identifiers in a dataset, as far as technically feasible (06-107.1.5.5.8).
  • Adjust numerical data, tables, and statistics so no individual or organization can be identified from the results (06-107.1.5.5.9).

Conformance & Exceptions

Meeting this standard is mandatory and effective as of the standard's publication, unless a written contract says otherwise or a formal exception has been granted. If a requirement genuinely can't be met and there's no workable fix, follow the exception process in the SFA 06-107.1 policy; requests go to the SFA Chief Information Security Officer (CISO).

!
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.

Compliance Mapping (Reference)

For auditors and security staff. Everyday users can skip this section.

Frameworks & control references ⌄

The requirements in this standard map to one or more of these authoritative sources:

  • NIST 800-53 Rev 5.1.1, for example the AC (Access Control), PT (Personally Identifiable Information Processing & Transparency), SC (System & Communications Protection), SI (System & Information Integrity), CA, and PM control families.
  • TAC 202, Subchapter C, for example 202.72, 202.77.
  • Texas DIR Security Controls Catalog, for example AC-4, AC-16, PT-5, SC-8, SC-12, SI-12.
  • NIST CSF and NIST 800-171, and for supply-chain retention NIST 800-161.
  • NIST AI RMF 1.0 for the use of data in artificial intelligence systems.
  • Privacy and regulatory frameworks: FERPA, HIPAA, GLBA, GDPR, and UTS 165.

The full requirement-by-requirement control mapping is in the attached standard PDF and the SFA 06-107 Controls Crosswalk.

Related Policies & Standards

Supporting policy: SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy

Other references:

  • Texas Department of Information Resources (DIR) Data Classification Guide
  • U.S. Department of Health and Human Services (HHS) Guidance on the Use of Online Tracking Technologies
  • Texas State Records Retention Schedule
  • Basic Concepts and Definitions for Privacy and Confidentiality in Student Education Records, National Center for Education Statistics
  • Best Practices for Data Destruction · Minimizing Access to PII, U.S. Department of Education
  • SFA 06-107 Controls Crosswalk Reference

Responsible office: Privacy Officer, Data Management Officer, Office of Information Security  ·  Contact: privacyofficer@utsystem.edu, itsecurity@sfasu.edu

📎
Official document
The complete, official standard is attached to this article as a PDF, including its full requirement text, role definitions, and control mappings. This article summarizes that standard in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about this standard, contact the Office of Information Security at itsecurity@sfasu.edu.
Print Article

Related Articles (3)

Sets SFA's objectives for governing the security program and protecting its people, vendors, data, and privacy, including awareness and training, acceptable use, AI governance, and research security; carried out by Standards 06-107.1.1 through 06-107.1.6.
Definitions of the key terms used throughout the SFA 06-107 information security program; any term shown in italics in a policy or standard is defined here.
Sets SFA's objectives for identifying and managing the security and privacy risks introduced by vendors and third-party services, from pre-purchase review through ongoing oversight; carried out through the Cybersecurity Risk Management (06-107.1.2) and Personnel & Third-Party Security (06-107.1.3) Standards.