{"id":669,"date":"2025-05-28T12:57:35","date_gmt":"2025-05-28T16:57:35","guid":{"rendered":"https:\/\/www.bu.edu\/privacy\/?page_id=669"},"modified":"2025-09-19T13:38:02","modified_gmt":"2025-09-19T17:38:02","slug":"privacy-laws","status":"publish","type":"page","link":"https:\/\/www.bu.edu\/privacy\/topics\/privacy-laws\/","title":{"rendered":"Privacy Laws"},"content":{"rendered":"<p>Privacy laws play a crucial role in how higher education institutions collect, store, use, and share student and employee information. Several key laws that apply in the United States, and some that apply abroad, are designed to protect the privacy rights of individuals in academic settings. Here are a few of the major privacy laws that Boston University is subject to:<\/p>\n<p>&nbsp;<\/p>\n<div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h2 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><strong>European General Data Protection Regulation (GDPR)<\/strong><\/h2><div class=\"bu_collapsible_section\" style=\"display: none;\"><br \/>\nGDPR is a data protection and<span> privacy law in the <\/span>European Union<span> (EU) and the <\/span>European Economic Area<span> (EEA). <\/span><\/p>\n<p><strong>Overview<\/strong><\/p>\n<p>The General Data Protection Regulation (GDPR) is a set of rules that establishes broad protections for the personal data of citizens and residents of the European Union (EU) and the European Economic Area (EEA).<a href=\"#_ftn1\" name=\"_ftnref1\"><span>[1]<\/span><\/a> The GDPR applies to organizations, including non-profit corporations, that process the personal data of individuals in the EU, or process personal data in connection with offering goods or services to individuals in the EU.<\/p>\n<p><strong>Key Definitions<\/strong><\/p>\n<p>As defined by GDPR:<\/p>\n<ul>\n<li>\u201cController\u201d means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law<\/li>\n<li>\u201cPersonal Data\u201d means any information relating to an identified or identifiable natural person (\u201cdata subject\u201d); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person<\/li>\n<li>\u201cProcessing\u201d means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction<\/li>\n<li>\u201cProcessor\u201d means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller<\/li>\n<\/ul>\n<p><strong>Processing of Personal Data<\/strong><\/p>\n<p>Under the GDPR, only processing of personal data is lawful only if at least one of the following applies:<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li>the data subject has given consent to the processing of his or her personal data for one or more specific purposes;<\/li>\n<li>processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;<\/li>\n<li>processing is necessary for compliance with a legal obligation to which the controller is subject;<\/li>\n<li>processing is necessary in order to protect the vital interests of the data subject or of another natural person;<\/li>\n<li>processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;<\/li>\n<li>processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p><strong>Does academic research fall under the GDPR?<\/strong><\/p>\n<p>Research that includes the collection of personal data from participants in the EU may fall under the GDPR as there is no general exemption for research. However, organizations that implement appropriate safeguards, such as data minimization, may be exempt from certain requirements such as GDPR\u2019s \u201cright to be forgotten\u201d (i.e., request that an organization delete your personal data).<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\"><span>[1]<\/span><\/a> The European Union includes the following countries: Austria, Belgium, Bulgaria, Croatia, Republic of Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain and Sweden. The European Economic Area includes the following countries: Iceland, Liechtenstein, and Norway. For convenience, we will refer to all the countries above as the \u201cEU.\u201d<br \/>\n<\/div>\n<\/div>\n\n<div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h2 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><strong>Chinese Personal Information Protection Law (PIPL)<\/strong><\/h2><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/p>\n<h3><strong>Overview<\/strong><\/h3>\n<p>In November 2021, the People\u2019s Republic of China (PRC) enacted a new, comprehensive data privacy law \u2013 the Personal Information Protection Law (PIPL). The PIPL is intended to protect the personal data of citizens of the PRC and address the PRC\u2019s concerns around exporting personal data outside of the PRC.<\/p>\n<h3><strong>Key Definitions<\/strong><\/h3>\n<p>As defined by the PIPL:<\/p>\n<ul>\n<li>\u201cPersonal Information\u201d means information related to identified or identifiable natural persons recorded by electronic or other means, excluding information processed anonymously<\/li>\n<li>\u201cAnonymized Information\u201d means personal information processed so that it is impossible to identify certain natural persons and that such identification cannot be recovered<\/li>\n<li>\u201cSensitive Personal Information\u201d means personal information whose disclosure or illegal use could infringe the dignity of data subjects or damage their safety or property interest, including the following types of information:\n<ul>\n<li>biometrics<\/li>\n<li>religious beliefs<\/li>\n<li>specific identities<\/li>\n<li>medical health<\/li>\n<li>financial accounts<\/li>\n<li>whereabouts<\/li>\n<li>personal information of minors under the age of 14<\/li>\n<\/ul>\n<\/li>\n<li>\u201cHandler\u201d means individuals or organizations who independently determine the purposes and means of processing information (similar to GDPR\u2019s definition of \u201ccontroller\u201d)<\/li>\n<li>\u201cHandling\u201d means the collection, storage, use, refining, transmission, provision, public disclosure or deletion of personal information (similar to GDPR\u2019s definition of \u201cprocessing\u201d)<\/li>\n<\/ul>\n<h3><strong>Handling Personal Data<\/strong><\/h3>\n<p>Under the PIPL, consent must be obtained from the data subjects to handle their personal data in the following manner:<\/p>\n<ul>\n<li>to transfer a data subject\u2019s PII to cloud service providers, a third-party processing the PII on behalf of the handler, or recipients outside of the country; and<\/li>\n<li>to process data subjects\u2019 PII (e.g. analytics, internal data related assessments, potential job opportunities, etc.)<\/li>\n<\/ul>\n<p>In addition, to handle \u201csensitive personal information,\u201d the following conditions must be met:<\/p>\n<ul>\n<li>the handling is necessary to achieve a specific purpose<\/li>\n<li>strict protection measures must be in place<\/li>\n<li>the data subjects must be notified about the need to process their sensitive personal information and the impact such processing may have on their rights and interests<\/li>\n<li>the data subjects must provide their specific separate consent to the processing of their sensitive personal information for the purpose disclosed<\/li>\n<\/ul>\n<h3><strong>Does the PIPL provide any rights to individuals?<\/strong><\/h3>\n<p>Yes, under the PIPL, data subjects must be provided with notice about the processing of personal information and able to:<\/p>\n<ul>\n<li>obtain access to and a copy of any personal information processed by handlers<\/li>\n<li>withdraw consent\u00a0to the processing of personal information where consent was previously provided (does not affect personal information that was previously collected with consent)<\/li>\n<li>request an amendment or correction of any personal information collected<\/li>\n<li>request that certain uses of personal information are restricted<\/li>\n<li>ask handlers transfer personal information to others<\/li>\n<li>ask handlers to delete their information<\/li>\n<\/ul>\n<h3><strong>Does academic research fall under the PIPL?<\/strong><\/h3>\n<p>The PIPL does not have a general exemption for research. However, if the research data is de-identified, it is not governed by the PIPL.<\/p>\n<h3><strong>Does the PIPL require a data protection impact assessment or other risk assessment?<\/strong><\/h3>\n<p>Yes, the PIPL requires handlers to conduct a data protection impact assessment if the handler:<\/p>\n<ul>\n<li>Handles sensitive personal information<\/li>\n<li>Uses personal information for automated decision-making<\/li>\n<li>Entrusts personal information handling, provides personal information to other personal information handlers, or discloses personal information<\/li>\n<li>Provides personal information abroad<\/li>\n<li>Engages in activities that involve personal data and could have a &#8220;major influence&#8221; on individuals<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><\/div>\n<\/div>\n\n<div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h2 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><strong>Family Educational Rights and Privacy Act (FERPA)<\/strong><\/h2><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/p>\n<p>The Family Educational Rights and Privacy Act (FERPA) is a federal law that protects the privacy of a student\u2019s education records. In compliance with FERPA, Boston University does not disclose personally identifiable information contained in student education records, except as authorized by law. The Office of the University Registrar <a href=\"http:\/\/www.bu.edu\/reg\/academics\/ferpa\/\">maintains a FERPA Policy<\/a>.<\/p>\n<p><\/div>\n<\/div>\n\n<div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h2 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\">Gramm-Leach-Bliley Act (GLBA)<\/h2><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/p>\n<h3><strong>Overview<\/strong><\/h3>\n<p>The Gramm-Leach-Bliley Act (GLBA) requires that financial institutions be transparent about how they collect and share personal financial data, give consumers control over information sharing, and implement strong protections to maintain the confidentiality and security of the personal financial information they retain.<\/p>\n<p>GLBA applies to universities that operate a financial institution or provide financial services, handle financial information (i.e. student financial aid) or share financial information with financial institutions or other entities covered by GLBA.<\/p>\n<p>GLBA\u2019s requirements are additional to those of the\u00a0<a href=\"http:\/\/www.bu.edu\/reg\/academics\/ferpa\/\"><\/a>, the federal law governing educational and student records.<\/p>\n<h3><strong>Key Definitions<\/strong><\/h3>\n<p><strong>Financial Institution:<\/strong> Any institution engaged in financial activities as defined by the Act, including banks, securities firms, insurance companies, and other companies significantly engaged in financial activities, such as lending, investing, or brokering financial products.<\/p>\n<p><strong>Nonpublic Personal Information:<\/strong> Any personally identifiable financial information provided by a consumer to a financial institution, resulting from a transaction or service, or otherwise obtained by the financial institution. This excludes information that is publicly available.<\/p>\n<p><strong>Consumer:<\/strong> An individual who obtains or has obtained a financial product or service from a financial institution primarily for personal, family, or household purposes.<\/p>\n<p><strong>Affiliate:\u00a0<\/strong> Any company that controls, is controlled by, or is under common control with another company. For example, subsidiaries or parent companies related to a financial institution.<\/p>\n<p><strong>Nonaffiliated Third Party:<\/strong> A party that is not an affiliate of the financial institution and is unrelated to the institution&#8217;s operations or corporate structure.<\/p>\n<p><strong>Opt-Out Notice:\u00a0<\/strong> A notice given to consumers explaining their right to direct the financial institution not to disclose their nonpublic personal information to nonaffiliated third parties.<\/p>\n<h3><strong>Handling Personal Data<\/strong><\/h3>\n<p>GLBA includes specific rules about handling personal financial data, primarily designed to protect consumers&#8217; nonpublic personal information. These rules are generally enforced through two main provisions: the **Privacy Rule** and the **Safeguards Rule**.<\/p>\n<p>The <strong>Privacy Rule<\/strong> requires financial institutions to respect the privacy of customers&#8217; nonpublic personal information and protect it accordingly.\u00a0 Financial institutions must provide clear, conspicuous privacy notices to their customers that explain:<\/p>\n<ul>\n<li>What types of nonpublic personal information they collect,<\/li>\n<li>How they use it,<\/li>\n<li>With whom they share it, and<\/li>\n<li>How they protect this information.<\/li>\n<li>Opt-Out Rights: Consumers must be given an opportunity to opt out of having their information shared with certain non-affiliated third parties.<\/li>\n<li>Timing : Privacy notices must be provided when the customer relationship is established and annually thereafter.<\/li>\n<\/ul>\n<p>The <strong>Safeguards Rule<\/strong> requires financial institutions to create, implement, and maintain a comprehensive written information security program to protect customer information.\u00a0 Institutions are required to perform risk assessments, to take protective measures, to designate employees responsible for oversight of a security program, and to monitor, test and periodically adjust the security program as needed.<\/p>\n<p>The GLBA prohibits the practice of **pretexting** (obtaining information under false pretenses). Institutions must have measures to detect and prevent attempts to gain access to customer information through deception.<\/p>\n<h3><strong>Does academic research fall under GLBA?<\/strong><\/h3>\n<p>GLBA applies to financial institutions and their handling of consumer financial information.\u00a0 Pure academic research is normally not covered by GLBA, unless the researcher is handling nonpublic financial information originating from a financial institution under GLBA\u2019s scope.\u00a0 Other privacy and ethical rules typically govern academic research involving personal data.<\/p>\n<p>If an academic researcher is handling financial information obtained from a financial institution or working directly with a financial institution\u2014and that information includes nonpublic personal financial data covered by GLBA\u2014then the financial institution remains responsible for GLBA compliance.<\/p>\n<p>If the researcher is directly affiliated with or acting on behalf of a financial institution (e.g., through a research partnership, receiving data under a data-sharing agreement), GLBA obligations may apply to that financial institution\u2019s data handling and sharing practices.<\/p>\n<p>However, academic researchers themselves are not typically regulated by GLBA, especially if the data involved does not come from or relate to a financial institution\u2019s consumer information.<\/p>\n<h3><strong>Does GLBA provide any rights to individuals?<\/strong><\/h3>\n<p>GLBA provides certain rights to individuals, mainly centered on their privacy and control over nonpublic personal financial information.\u00a0 Individuals have the right to receive privacy notices at the time the customer relationship is established, and annually thereafter, as well as the right to opt-out of information sharing, and the right to protection from pretexting.<\/p>\n<p>GLBA does not give an individual the right to access or correct their own financial records held by the institution, the right to extensive control over all types of data sharing, and it does not provide a private right of action against an institution.\u00a0 GLBA is enforced mostly by regulatory agencies.<\/p>\n<h3><strong>Does GLBA require a data protection assessment or risk impact assessment?<\/strong><\/h3>\n<p>Under the Safeguards Rule, institutions must develop, implement, and maintain a comprehensive information security program focused on protecting customer information.<\/p>\n<h3><strong>GLBA at Boston University<\/strong><\/h3>\n<p>Boston University has a <a href=\"https:\/\/www.bu.edu\/policies\/safeguarding-information-gramm-leach-bliley-act\/\">Safeguarding Information \u2013 Gramm-Leach-Bliley Act (GLBA) Policy<\/a> (GLBA Policy), in place since 2003 to comply with the Gramm-Leach-Bliley Act. The Policy affirms that the University has an active Safeguarding Program to (1) insure the security and confidentiality of certain customer information, such as student loan-related information, (2) protect against any anticipated threats to the integrity of such information and (3) protect against unwarranted, unlawful and\/or unauthorized disclosure, misuse, alteration, destruction or other compromise of such information. Under the Safeguarding Program, all Boston University departments with access to student loan data or other customer information must adhere to the requirements and the elements of the Safeguarding Program\u00a0 that are outlined within the GLBA Policy. The Safeguarding Program must also be adhered to by outside service providers, such as loan servicing agents and collection agencies to which student loan data may be transferred or who may gather it on behalf of the University.<\/p>\n<p>Pursuant to the GLBA Policy, each Department at the University who is required to adhere to a Safeguarding Program must have a designated Departmental Security Administrators (DSA). The DSA is responsible for coordinating the GLBA Policy compliance efforts of the department.<\/p>\n<p>The <a href=\"https:\/\/www.bu.edu\/policies\/safeguarding-information-gramm-leach-bliley-act\/\">GLBA Policy<\/a> is available on the Policies website.<\/p>\n<p><\/div>\n<\/div>\n\n<div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h2 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\">Massachusetts General Law Ch. 214 s. 1B<\/h2><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/p>\n<p>Under Massachusetts law, a person shall have a right against unreasonable, substantial, or serious interference with their privacy.<\/p>\n<p><\/div>\n<\/div>\n\n<div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h2 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\">Massachusetts General Law 93H \u2013 Security Breaches<\/h2><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/p>\n<h3>Overview<\/h3>\n<p>Massachusetts General Law 93H is a Commonwealth law that sets forth requirements for the protection of personal information and mandates procedures for institutions in the event of a data breach involving the personal information of Massachusetts residents.<\/p>\n<h3>Key Definitions<\/h3>\n<ul>\n<li><strong>Personal information<\/strong> generally includes an individual\u2019s first and last name combined with one or more of the following when either name or number is not encrypted or redacted:\n<ul>\n<li>Social security number,<\/li>\n<li>Driver\u2019s license number, state-issued identification number,<\/li>\n<li>Financial account number, credit card or debit card number, with access code or password, in combination with the account number.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Breach of Security\/Data Breach <\/strong>is the unauthorized acquisition or unauthorized access to personal information maintained by an individual or entity that compromises the security, confidentiality, or integrity of that personal information.<\/li>\n<li><strong>Computerized data<\/strong> includes data stored or transmitted in electronic form, including data stored on computers, networks, or other digital media. This includes data processed or stored in any digital format.<\/li>\n<\/ul>\n<h3>Handling Personal Data<\/h3>\n<ul>\n<li>If there is a breach of security resulting in the unauthorized acquisition or access of personal information, including computerized data, the institution must:<\/li>\n<li>Notify affected Massachusetts residents in the most expedient time possible, consistent with the legitimate needs of law enforcement or measures necessary to determine the scope of the breach and to restore the integrity of the system.<\/li>\n<li>Notify the Massachusetts Attorney General and the Office of Consumer Affairs and Business Regulation if the breach affects Massachusetts residents.<\/li>\n<\/ul>\n<p>The notice shall include the consumer\u2019s right to obtain a police report, how a consumer may request a security freeze and the necessary information to be provided when requesting the security freeze, and that there shall be no charge for a security freeze, and mitigation services to be provided pursuant to the law.<\/p>\n<h3>Does academic research fall under 93H?<\/h3>\n<p>Academic research institutions handling computerized personal information about Massachusetts residents are subject to M.G.L. c. 93H and must comply with its security and breach notification requirements if personal information as defined under the law is involved. Purely anonymized or de-identified research data generally falls outside of 93H\u2019s scope.<br \/>\nIf you are involved in academic research and handling Massachusetts residents\u2019 personal information, it is important to coordinate with Boston University\u2019s Office of Research Compliance to ensure compliance with 93H and other applicable laws prior to commencing research.<\/p>\n<h3>Does 93H provide any rights to individuals?<\/h3>\n<p>Individuals have a right to be notified of a data breach in the most expedient time possible and without unreasonable delay. The Attorney General of the Commonwealth of Massachusetts handles enforcement of 93H. The law does not provide an individual the right to sue.<\/p>\n<h3>Does 93H require a data protection plan?<\/h3>\n<p>Institutions are required to develop and maintain a comprehensive information security program that includes administrative, technical, and physical safeguards to protect personal information.<\/p>\n<p><\/div>\n<\/div>\n\n<p>&nbsp;<\/p>\n<p>Boston University community members with questions about privacy laws and how they apply to University activities should contact the <a href=\"https:\/\/www.bu.edu\/ogc\/\" target=\"_blank\" rel=\"noopener noreferrer\">Boston University Office of the General Counsel (OGC)<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Privacy laws play a crucial role in how higher education institutions collect, store, use, and share student and employee information. Several key laws that apply in the United States, and some that apply abroad, are designed to protect the privacy rights of individuals in academic settings. Here are a few of the major privacy laws [&hellip;]<\/p>\n","protected":false},"author":12908,"featured_media":0,"parent":97,"menu_order":5,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/privacy\/wp-json\/wp\/v2\/pages\/669"}],"collection":[{"href":"https:\/\/www.bu.edu\/privacy\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bu.edu\/privacy\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/privacy\/wp-json\/wp\/v2\/users\/12908"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/privacy\/wp-json\/wp\/v2\/comments?post=669"}],"version-history":[{"count":12,"href":"https:\/\/www.bu.edu\/privacy\/wp-json\/wp\/v2\/pages\/669\/revisions"}],"predecessor-version":[{"id":735,"href":"https:\/\/www.bu.edu\/privacy\/wp-json\/wp\/v2\/pages\/669\/revisions\/735"}],"up":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/privacy\/wp-json\/wp\/v2\/pages\/97"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/privacy\/wp-json\/wp\/v2\/media?parent=669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}