An institution that offers distance or correspondence education documents each of the following: has a written procedure for protecting the privacy of students enrolled in distance and correspondence education courses or programs.
Compliance Status
Louisiana State University and A&M College is in compliance with this principle.
Narrative
Louisiana State University and A&M College (LSU) has developed policies that conform to the privacy guidelines promulgated by the Family Educational Rights and Privacy Act (FERPA) [1]; these rights and protections extend to all students, including the distance and correspondence students. The intent of FERPA is to protect the rights of students and to ensure the privacy and accuracy of educational records. These policies prohibit the release of personally identifiable information from educational records without the student's permission, except as specified by law. Only parties with the right to receive educational records pursuant to these policy statements and identified as such shall be entitled to receive the information.
Information about FERPA is available to students [2], parents [3], and faculty and staff [4] on the Website of the LSU Registrar’s Office. An annual notification, Privacy and Release of Student Education Records, is also posted on the LSU Registrar’s Office Website [5]. The Registrar’s Office also has a FERPA tutorial for faculty and staff [6]. This information specifically details what information can and cannot be released on all students, including those enrolled in distance education or continuing education programs.
LSU has adopted a comprehensive set of policies and procedures designed to comply with federal laws and regulations protecting personally identifiable information. In most cases, the protection provided by these university policies and procedures extends beyond student records. The discussion below, however, focuses on the student records aspects of those policies and procedures.
Briefly, the laws and policies addressed by these university policies and procedures include the following:
Federal
State of Louisiana
Louisiana State University Board of Supervisors Policy
As a member institution of the Louisiana State University System, LSU must enforce policies and procedures in compliance with the information security standards set by the Board of Supervisors and with applicable federal and state laws. The LSU System information security standards are outlined in Permanent Memorandum 36 (PM-36): Louisiana State University System Information Security Plan [13]. Additional details are provided in the attachments to PM-36:
Policy Statements at LSU That Support Student Privacy, Including That of Distance Education or Continuing Education Students
Policy statement (PS) 30: Student Privacy Rights [18] outlines how to comply with this principle, how to inform all concerned parties of the rights and prerogatives of students under the FERPA, and how to outline procedures for those students who wish to inspect and review their educational records. Personally identifiable information from educational records cannot be released without the student's permission, except as specified by law. Only parties with the right to receive educational records pursuant to these policy statements and identified as such shall be entitled to receive the information.
Personally identifiable information is that which, when associated with an educational record, allows the record to be identified with a specific person. This information includes (a) the name of the student, the student's parent, or other family member; (b) the address of the student or student's family; (c) a personal identifier, such as a Social Security number or student number; (d) a list of personal characteristics which would make the student's identity easily traceable; and (e) other information which would make the student's identity easily traceable. This information is not released without the written consent of the student.
The provisions of this policy are further spelled out within the policy document itself, including those that would release educational records under the law without the student's permission.
PS-113: Social Security Number Policy [19] provides additional information as to how student privacy is protected. The purpose of this policy is “to establish policy governing the collection, maintenance, use, and disclosure of Social Security numbers (SSN) and to comply with the FERPA and the Privacy Act of 1974. The objectives are to eliminate the use of the SSN as the primary identifier for all individuals associated with the university, raise awareness of the confidential nature of the SSN, protect privacy interests, provide a consistent policy regarding treatment of SSNs, and promote confidence by the university community that SSNs are handled in a confidential manner. A waiver application process is available for those faculty members or administrators who must maintain SSNs of students. For example, in the Accreditation Council for Education in Nutrition and Dietetics (ACEND), accredited dietetics program verification statements certifying that the student is an LSU program graduate have SSNs and must be kept in perpetuity, so the director has a waiver through the Office of the Registrar to maintain these certificates in a locked file.
In lieu of using the students’ SSNs as unique identifiers, student numbers have been assigned to all students, including those participating in distance education or continuing education programs. This unique student identifier is to be accorded the same level of confidentially as the student’s SSN. Students are advised not to use their student numbers in emails; faculty and staff cannot use these numbers in emails, unless they can send encrypted email. PS 06.15, Use of Electronic Mail (E-mail) [20], clearly states that “Ordinary e-mail must NOT be considered a secure method for transmitting protected information.” This follows closely with the regulations outlined in PS 107, Computer Users’ Responsibilities [21], which establishes important guidelines and restrictions regarding any and all use of computing resources at, for, or through LSU; PS 06.10 (PS 114), Security of Computing Resources, which outlines the role and authority of ITS in supporting and upholding the security and integrity of the LSU information technology environment [22]; PS 06.20, Security of Data [23], which outlines the responsibilities of all users in supporting and upholding the security of data at LSU regardless of the user’s affiliation or relation with the university, and irrespective of where the data is located, utilized, or accessed; and PS 06.25 Privacy of Computing Resources, which facilitates teaching, research, and the overall mission of the university through the authorized use of computing resources and data consistent with the university’s need for limited access by persons other than the account holder when necessary to serve or protect operations within the university or to meet legal requirements. The policy applies to all authorized users of computing resources at LSU regardless of user’s affiliation or relationship with the university and irrespective of where the resources are located, utilized, or accessed [24].
Additional policies and procedures to protect all students, records, and other data are found in Comprehensive Standard 3.9.2.