Data Governance & Data Security Policy
Data Governance & Data Security Policy
OVERVIEW
Updated October 2026
Data governance is the framework of people, knowledge, and processes that enables the availability, usability, integrity, and security of institutional data.
Rhodes College relies on institutional data for planning, decision-making, compliance, and strategic initiatives.
All institutional data are the property of the College, regardless of the office, system, or individual that creates, collects, or maintains them. Trustees and stewards hold delegated authority over a data domain and exercise that authority on the College's behalf.
PURPOSE
This policy applies to institutional data across all functional areas of the College, including, but not limited to:
Student Records
Academic, enrollment, and personal data
Admission & Enrollment
Prospective student and applicant data
Financial Aid
Awarding, eligibility, and disbursement data
Human Resources
Employee and personnel data
Finance & Payroll
Institutional financial and payroll data
Alumni & Development
Gift, pledge, and constituent data
DATA GOVERNANCE CHARGE
The Data Trustee Council and the Data Stewardship & Privacy Committee together provide leadership and oversight for institutional data.
They promote responsible stewardship of institutional data, recommend governance policies and standards, and resolve cross-functional data issues.
Responsibilities
- Establish governance policies and standards.
- Encourage ethical and responsible use of institutional data.
- Promote data as a strategic institutional asset.
- Recommend classification and security requirements.
- Promote common definitions and data standards.
- Improve institutional data quality.
- Support regulatory compliance.
- Review institutional data requests and access concerns.
- Consult subject matter experts, such as compliance officers, on an as-needed basis for matters that cross data domains.
GOVERNANCE PRINCIPLES
The first four principles map directly to the framework definition above: availability, usability, integrity, and security. Accountability and compliance are the two supporting principles that make them enforceable.
Availability
Authorized users have role-based access to current, up-to-date data necessary for their responsibilities, when they need it.
Usability
Institutional data are documented with common definitions, maintained in the College's business glossary and data dictionary, so they can be found, understood, and applied consistently across the institution.
Integrity
Institutional data are accurate, complete, and reliable, and protected from unauthorized alteration throughout their lifecycle. Stewards are responsible for the quality of their domain's data; every role is responsible for flagging quality concerns so they can be addressed.
Security & Privacy
Institutional data are protected against unauthorized access, disclosure, or loss, and individual privacy is respected in how data are collected, used, and shared.
Accountability
Institutional data shall have clearly assigned trusteeship and stewardship authority, exercised on the College's behalf.
Compliance
Data management activities (collection, retention, reporting, and disposal) meet legal, regulatory, accreditation, and institutional policy requirements.
GOVERNANCE STRUCTURE
The Provost serves as Executive Sponsor of the data governance program, with oversight of both the Chief Information Officer and the Chief Data Officer, who co-chair both the Data Trustee Council and the Data Stewardship & Privacy Committee.
Below that, governance operates at two levels: strategic and operational.
Data Trustee Council
Strategic governance body responsible for institutional oversight and policy direction.
Data Stewardship & Privacy Committee
Operational governance group responsible for implementing governance practices and addressing day-to-day data management issues.
The Chief Data Officer administers the program day to day: communicating standards, coordinating stewards, providing training, and escalating unresolved issues to the data trustee with designated authority over that domain within one week. For the rare issue that cannot be resolved at the steward or trustee level, it will be escalated to the Data Trustee Council.
The Chief Information Officer provides technical guidance and expertise, including security, systems, access controls, and infrastructure.
DATA CLASSIFICATION FRAMEWORK
All institutional data are classified into one of four levels. Each level carries its own rules for storage, sharing, and AI tool use. Restricted is the highest classification level used by the College.
The "Permitted for use by individuals in AI tools?" row in each table addresses an individual's choice to use an AI tool, such as a chatbot or an AI-assisted feature in an application like email, with data they have access to. It does not cover AI capabilities built into institutional systems as part of the platform itself, which are evaluated separately through the College's Institutional Systems Governance process.
Disabling a tool's model training or data-retention settings does not make it College-approved.
Restricted
Level 4 (highest)
| Definition | The highest sensitivity level. Unauthorized disclosure would violate law, regulation, or contract, or cause significant harm to the College or an individual. |
|---|---|
| Examples | Including but not limited to: Social Security numbers, protected health information, banking and credit card information, Title IX records. See restricted data examples for additional examples by category. |
| Where data may be stored | Systems specifically authorized for Restricted data, with encryption required. |
| Shareable with external users or vendors? | No, except for mandatory reporting or critical College business approved through data governance. |
| Storable on College-managed devices? | Only with steward approval and encryption. |
| Storable on personal devices or cloud services? | No |
| Permitted for use in AI tools? | No |
Confidential
Level 3
| Definition | Sensitive data where disclosure could cause operational, financial, or reputational harm. |
|---|---|
| Examples | Including but not limited to: employee performance records, contracts, non-directory student information, donor giving history. See confidential data examples for additional examples by category. |
| Where data may be stored | College-approved systems with access controls and encryption enabled. |
| Shareable with external users or vendors? | No, only with steward approval and an agreement in place. |
| Storable on College-managed devices? | Yes, encrypted. |
| Storable on personal devices or cloud services? | Limited, encrypted storage only. |
| Permitted for use in AI tools? | College-approved AI tools only. |
Internal
Level 2
| Definition | Data restricted to College business use. Disclosure would not violate law or cause reputational harm, but the data are not intended for public release. |
|---|---|
| Examples | Including but not limited to: internal directories, department budgets, meeting minutes, non-public policies and procedures, and instructional materials and scholarship that have not been made public by the faculty member, when used as data. |
| Where data may be stored | College-approved systems that require authentication to access. |
| Shareable with external users or vendors? | No, unless approved by the data steward. |
| Storable on College-managed devices? | Yes |
| Storable on personal devices or cloud services? | Limited, encryption recommended. |
| Permitted for use in AI tools? | College-approved AI tools only. |
Public
Level 1
| Definition | Data approved for open distribution to the campus community and the general public. No harm results from disclosure. |
|---|---|
| Examples | Including but not limited to: public website content, press releases, the course catalogue, public event calendars. |
| Where data may be stored | Any College-approved technology service. |
| Shareable with external users or vendors? | Yes |
| Storable on College-managed devices? | Yes |
| Storable on personal devices or cloud services? | Yes |
| Permitted for use in AI tools? | Yes: public and College-approved AI tools. |
Quick Reference
The table above spells out each level in full; this is the same information for a fast look-up.
| Requirement | Restricted | Confidential | Internal | Public |
|---|---|---|---|---|
| Shareable externally | No | Steward approval | Steward approval | ✓ |
| Storable on College-managed devices | Steward approval + encryption | ✓ (encrypted) | ✓ | ✓ |
| Storable on personal devices or cloud | No | Limited (encrypted) | Limited | ✓ |
| Permitted in AI tools | No | College-approved | College-approved | ✓ |
RESTRICTED DATA EXAMPLES
Examples of data that are classified as Restricted. This list is not exhaustive.
- Social Security numbers
- Passport information
- Visa information
- Federal tax information
- Protected health information
- Disability services records
- Leave of absence documentation
- Title IX records
- Student conduct investigations
- Social Security numbers
- Tax records
- Banking information
- Payroll garnishments
- Credit card information
- Credit card information
- Donor banking information
CONFIDENTIAL DATA EXAMPLES
Examples of data that are classified as Confidential. This list is not exhaustive.
- Rhodes ID
- Letter Grades
- Grade Point Average
- Test Scores
- Course Schedule
- Citizenship
- Race/ethnicity
- First-Generation Status
- Pell Status
- Rhodes ID
- Citizenship
- Race/Ethnicity
- Salary
- Age
DATA ROLES & RESPONSIBILITIES
The College owns all institutional data. The roles below hold delegated trusteeship, stewardship, or access authority within a domain; none of them confers ownership. Access under every role is role-based: granted according to what the position requires, not by default.
Provides executive oversight of data within their functional area and is ultimately accountable for it. Sets strategic direction for data governance, resolves issues escalated by the Chief Data Officer that stewards cannot, and ensures alignment with institutional goals.
The primary authority for the management, integrity, and use of data within a domain. Establishes governance policies, ensures data quality, and safeguards compliance with applicable regulations and standards. Approves access to data within their domain. Fulfills ad-hoc data requests and works with Data Administrators and Data Custodians to facilitate access, maintaining the accuracy, consistency, and security that support data-informed decisions.
Trained and authorized by the Data Steward to administer routine access to and release of data under established policies. May independently fulfill routine requests that meet the steward's approved criteria, but may not set policy, grant exceptions, or make other steward-level decisions. Requests outside that criteria are referred to the Data Steward.
Manages and safeguards the technical infrastructure for a specific system, keeping it reliable, secure, and accessible per policy. Implements the technical configuration needed to carry out steward-directed business rules, such as system-of-record designations, data flow between systems, and field-level edit permissions. Works with Data Stewards and Data Administrators to meet reporting needs, but does not independently set those rules or approve access to or release data.
Has permission to access and use data only for the approved business purpose for which access was granted, and may not release, disclose, redistribute, or repurpose it without the Data Steward's explicit permission.
A full list of data roles is maintained by the data stewards.
TRUSTEES & STEWARDS BY DOMAIN
These are delegated trusteeship and stewardship assignments, not ownership; every domain's data remains the property of the College.
| Data domain | Trustee | Steward |
|---|---|---|
| Academic Records | Provost | Registrar |
| Admission | Vice President for Enrollment Management | Director of Enrollment Services |
| Alumni & Development | Vice President for Development | Executive Director of Development Operations and Donor Relations |
| Athletics | Director of Athletics | Athletics Business Manager |
| Finance | Vice President for Business & Finance | Senior Associate Comptroller/Director of Accounting & Payroll |
| Financial Aid | Vice President for Enrollment Management | Director of Financial Aid |
| Human Resources | Vice President for Business & Finance | Director of Human Resources |
| Marketing & Communications | Vice President for Marketing & Communications | Chief of Digital Strategy |
| Student Life | Vice President for Student Life | Director of Operations & Strategic Initiatives |
FREQUENTLY ASKED QUESTIONS
APPENDIX: COMMITTEE MEMBERSHIP
Membership of the Data Trustee Council and Data Stewardship & Privacy Committee, updated as roles change.
| Unit | Job Title | Data Trustee Committee | Data Stewardship & Privacy Committee |
|---|---|---|---|
| Academic Affairs | Provost and Vice President for Academic Affairs | ✓ | |
| Administrative Services | Vice President for Finance & Business Affairs | ✓ | |
| Athletics | Director of Athletics | ✓ | |
| Athletics | Athletics Business Manager | ✓ | |
| Development | Vice President for Development | ✓ | |
| Development | Executive Director of Development Operations and Donor Relations | ✓ | |
| Enrollment Management | Vice President for Enrollment Management | ✓ | |
| Enrollment Services | Director of Enrollment Services | ✓ | |
| Finance Office | Senior Associate Comptroller/Director of Accounting & Payroll | ✓ | |
| Finance Office | Bursar | ✓ | |
| Financial Aid | Director of Financial Aid | ✓ | |
| Human Resources | Director of Human Resources | ✓ | |
| Information Services | Systems Programmer Analyst | ✓ | |
| Information Services | Database Analyst | ✓ | |
| Information Services | Chief Information Officer (committee co-chair) | ✓ | ✓ |
| Information Services | Director of Academic Technologies | ✓ | |
| Information Services | Director of Infrastructure and Enterprise Applications | ✓ | |
| Information Services | Information Systems Security Manager | ✓ | |
| Institutional Research & Effectiveness | Associate Vice President and Chief Data Officer (committee co-chair) | ✓ | ✓ |
| Institutional Research & Effectiveness | Data Analyst | ✓ | |
| Institutional Research & Effectiveness | Associate Director of Institutional Research | ✓ | |
| Marketing & Communications | Vice President for Marketing & Communications | ✓ | |
| Marketing & Communications | Chief of Digital Strategy | ✓ | |
| President's Office | Chief of Staff to the President | ✓ | |
| Registrar | Registrar | ✓ | |
| Student Life | Director of Student Life Operations and Strategic Initiatives | ✓ | |
| Student Life | Vice President for Student Life | ✓ |