Kean University Regulatory Compliance Policy
Table of Contents
- 1. What This Policy Is About
- 2. Why This Matters for All Staff
- 3. Who This Policy Applies To
- 4. Key Responsibilities for Staff
- 5. What the University Must Do
- 6. How This Policy Fits into Kean’s Governance Structure
- 7. Enforcement
- 8. Exceptions
- 9. Policy Review & Maintenance
1. What This Policy Is About
The Regulatory Compliance Policy (RC‑01) defines how Kean University protects personal information, student records, financial data, health data, research data, and all other institutional information. It ensures compliance with:
- FERPA
- HIPAA
- GLBA
- GDPR, PIPL, CCPA/CPRA
- New Jersey breach‑notification laws
It also aligns Kean practices with the NIST Cybersecurity Framework 2.0.
[Link to authoritative RC‑01 document]
Back to top2. Why This Matters for All Staff
Every Kean employee interacts with data. RC‑01 helps you understand:
- What laws apply to the information you handle
- How to handle student, employee, financial, health, or research data
- Your responsibilities for protecting confidential or restricted data
- How to report security incidents or breaches
- Why vendor systems must undergo security review
[Link to authoritative RC‑01 document]
Back to top3. Who This Policy Applies To
3.1 Personnel
- Faculty and staff
- Student employees
- Contractors and consultants
- Volunteers
- Vendors with access to Kean data
3.2 Systems & Data
- On‑campus, cloud, and hybrid systems
- Public, internal, sensitive, and restricted data
- Academic, administrative, research, and operational data
3.3 Data Activities
- Collection, creation, and storage
- Sharing and transmission
- Retention, archival, and deletion
3.4 Account Types
- Human accounts
- Shared accounts
- Privileged accounts
- Service and API‑based accounts
- Automated accounts
[Link to authoritative RC‑01 document]
Back to top4. Key Responsibilities for Staff
4.1 Handle Data Lawfully and Transparently
- Only access data needed for your job.
- Follow privacy notices and approved procedures.
- Do not share personal or student data without authorization.
4.2 Protect Student Records (FERPA)
- Do not access student data without a legitimate educational or job‑related reason.
- Never share student information externally without authorization.
4.3 Protect Financial & Sensitive Data (GLBA)
Financial data requires secure storage, approved systems, and monitoring for suspicious activity.
4.4 Protect Health Data (HIPAA)
PHI must be handled using secure channels and approved systems.
4.5 Report Security Incidents Immediately
- Report unauthorized access or data loss immediately.
- Timely reporting ensures compliance with breach‑notification laws.
4.6 Use Approved Systems and Vendors Only
- Vendors must pass security review (HECVAT/SOC 2).
- Do not upload Kean data to personal or unapproved platforms.
4.7 Complete Required Training
All staff must complete annual security and privacy training.
[Link to authoritative RC‑01 document]
Back to top5. What the University Must Do (for Staff Awareness)
- Maintain risk assessments and safeguards
- Conduct vendor risk reviews
- Monitor systems for threats (SIEM)
- Manage incidents and breach notifications
- Handle international data transfers
- Support GDPR/CCPA data rights (access, correction, deletion)
- Maintain DPIAs and ROPAs for high‑risk processing
[Link to authoritative RC‑01 document]
Back to top6. How This Policy Fits into Kean’s Governance Structure
RC‑01 is the umbrella policy for all related policies:
- Information Security
- Data Governance
- Identity and Access Management
- Logging & Monitoring
- Incident Response
- BCDR
- Vendor/Supplier Risk
- Exception Management
- Training & Awareness
- Cybersecurity Glossary
[Link to authoritative RC‑01 document]
Back to top7. Enforcement
- Corrective or disciplinary action
- Access restriction
- Contract consequences (vendors)
- Legal or regulatory action
[Link to authoritative RC‑01 document]
Back to top8. Exceptions
- Follow the Exception Management Policy
- Include risk analysis and compensating controls
- Require CIO + Legal approval
- Include an expiration date
[Link to authoritative RC‑01 document]
Back to top9. Policy Review & Maintenance
The CISO and ISO review RC‑01 annually or when laws change. Evidence such as logs, assessments, and vendor records must be maintained in Kean’s Governance Repository.
[Link to authoritative RC‑01 document]
Back to top