We help to enable, facilitate, and advise university stakeholders on privacy principles and data engineering practices that create and foster greater transparency of data practices and enhanced trust with the university community. We collaborate with data stewards and users, as well as application and service owners, to create awareness of privacy considerations, mitigate privacy risks, and develop a privacy-conscious community.
Privacy Everywhere Conference
Technology Service hosts an annual one-day privacy conference. Attendees learn from experts in the field and gain valuable insights into timely privacy topics.
The next conference will take place in January 2027.
Watch select sessions from 2024-2026 conferences.
Privacy consulting and assessments
Contact us at privacy@illinois.edu for more information about any of these consultative services.
We can consult on any matter that involves personal information. This can include new or revised processes, application settings and setup, or research projects. There are a few assessments to help you start a conversation:
- Privacy Threshold Assessment: This assessment asks a few basic questions that will help determine next steps.
- Privacy Impact Assessment: This assessment asks in-depth questions to probe how personal information is processed. The answers provided here are very important and aid us with understanding how privacy is impacted.
- Privacy Impact Assessment (Research): This assessment is a research-focused version of the Privacy Impact Assessment with questions specific towards the privacy impacts typically faced in research.
Privacy regulations and contracts
When contracting with a vendor, it is important to consider the privacy protections that should be in place. This can be situationally dependent based on the type and volume of data involved, how it will be processed, who will have access to it, how it is stored or transmitted, and other things. Below is a list of some contractual addendums that should be considered when processing certain data:
When student data will be involved:
A Family Educational Rights and Privacy Act Addendum is typically recommended when student data will be impacted by a contract. This addendum designates a vendor as a “school official” which assigns them responsibilities for the student data. Not all student data requires protection from a FERPA Addendum, so it is important you speak with your Business Office or the Purchasing and Contract Management Office.
When health data will be involved:
Working with health data at the University of Illinois Urbana-Champaign can be a little confusing. The university is considered a hybrid entity under the Health Insurance Portability and Accountability Act, meaning some units may be covered by HIPAA while others that handle health data may not be. When it comes to student health data, FERPA covers the health data that isn’t covered by HIPAA.
For units that are covered by HIPAA, also known as Health Care Components (HCCs), a contract with a vendor that will process health data (in these situations, health data is referred to as Protected Health Information, or PHI) should have a Business Associate Agreement added to the agreement.
For units that process health information under FERPA protections, sometimes additional contractual language not already included in the standard templates should be added to the agreement
In either case, the PCMO can help navigate these scenarios to help determine the best course of action for the contracts, including consultation with privacy.
When data collected in Europe will be involved:
Countries in Europe, specifically the European Economic Area have a comprehensive privacy law called the General Data Protection Regulation. When the United Kingdom left the European Union, they enacted a similar law referred to as the UK GDPR. The university’s compliance program is the same for both laws, so we refer to both collectively as GDPR when talking about data sourced from Europe.
GDPR and other European laws have strict requirements for data being sent from European countries to other non-EEA countries.
There are nuances and specifics that need to be explored prior to making the decision to add a Data Protection Agreement to a contract. When starting a contract process, you will be asked if data from Europe will be involved. If “Yes”, a parallel process will be triggered to engage in the GDPR review and that will determine if a DPA is necessary. Learn more about the EU and UK General Data Protection Regulations – EVPAA.
When data collected in China will be involved:
Compliance with China’s Personal Information Protection Law is complex, confusing, and time consuming. If your contract will involve data collected or sourced from China, start conversations with PCMO as early as possible. Many groups, including the Office of the CIO, the Office of University Counsel, the University Ethics and Compliance Office, and others, may need to be involved. The University System is considered one entity under PIPL, so compliance with the law could have impacts system-wide. Learn more about China’s Personal Information Protection Law.
When starting off the contract process, you will be asked if data from China will be involved. If you answer “Yes”, a parallel process will be triggered for us to engage in a PIPL review and that will ultimately determine what next steps are necessary.
General privacy guidance
We offer the following privacy-based recommendations that are applicable to most situations. To set up a consultation for a specific use case (e.g., research project, a new/renewed contract with a vendor, new processing activity, etc.), to request a complete privacy review or to ask questions, contact privacy@illinois.edu.
- Data processing should always be restricted to the “need to know” principle – only process the data that is absolutely necessary to get the job done. We recommend that units: Consult the Privacy Team to ensure no additional obligations are created from any processing changes.
- Review proposed use cases and determine the specific purpose and the specific data required. Best practice is to restrict data collection/processing to the minimum required to complete the required processing of the use case (e.g., Collect age ranges or birth year rather than a full birth date.)
- Be consistent with notices provided to data subjects. If the data processing changes, updated notices should be provided.
University privacy policies
Campus/University Policies: More information about University of Illinois policies.
Cookie Policy: Describes the University of Illinois System’s use of Cookies and related data sharing and tracking technologies.
Social Security Number Policy: Information on the University’s commitment to protecting the privacy of members of the university community.
Information Security Policy: University-wide policy on the use of data, applications, networks and computer systems.
Privacy principles
We are guided by three privacy pillars:
- Trust – Individuals should be able to trust that the university handles their data with the utmost care and protection.
- Transparency – Individuals should be notified and understand how the university collects personal data, and for what processing purpose(s) the data is collected.
- Consent – Individuals should be able to freely consent or withdraw consent wherever practical, and especially when consent is used as the legal basis for collecting and processing personal data.
What’s behind the privacy principles?
The privacy pillars are based upon the Organization for Economic Cooperation and Development’s eight Fair Information Practices Principles. These principles are, summarized:
- Collection limitation: There should be limits to the collection of personal data and it should be lawfully obtained.
- Data quality: Personal data collection should be relevant to the purposes for which it is collected and should be accurate, complete, and kept up to date.
- Purpose specification: The purposes for collecting personal data should be specified at the time of data collection.
- Use limitation: Personal data should not be disclosed, made available or otherwise used for purposes other than those specified, except with the consent of the data subject; or by the authority of law.
- Security safeguards: Personal data should be protected by reasonable security safeguards against such risks as loss or unauthorized access, destruction, use, modification or disclosure of data.
- Openness: There should be a general policy of openness establishing the existence and nature of personal data, and the main purposes of their use.
- Individual participation: Individuals should have the right to obtain data relating to them within a reasonable time, and to request that data be erased, rectified, completed or amended as appropriate.
- Accountability: A data controller should be held accountable to the principles stated above.
Privacy by design
Collecting personal data brings added responsibilities which can increase requirements, overhead and maintenance costs for new initiatives. Privacy by design is a framework that can be used to reduce project costs and risks while improving default privacy offerings. PbD involves thinking about data throughout its entire lifespan – from collection through destruction. Our team can help you develop plans that consider:
- Data minimization and purpose limitation: Is collecting personal data a requirement for a new offering, or can you reach the same or similar outcomes without collecting data or by using anonymized data? If anonymized data will not meet business requirements, is it possible to limit the amount of data collected? Can the principles of least access and separation of duties minimize access to data? Consider evaluating policies around user access review.
- Full lifecycle protection: How will data that is collected be protected throughout its full lifecycle? Obviously personal data must be encrypted at rest and in flight, but don’t forget to encrypt snapshots, backups and limit writing PII to log files. Consider whether there might be secondary, downstream uses of user data. Keep in mind how long user data can or should be retained per contractual, legal and business requirements?
- Positive-sum, not zero-sum: Could a high standard for privacy result in a competitive advantage and distinguish your offering from similar competing efforts? Would enhancing your default privacy settings also improve your information security posture? Could offering high standards for privacy unlock partnerships with our peers, especially internationally where some countries have stricter privacy regulations?
