Data Governance & Data Security Policy

Data Governance & Data Security Policy

OVERVIEW

Updated October 2026

Data governance is the framework of people, knowledge, and processes that enables the availability, usability, integrity, and security of institutional data.

Rhodes College relies on institutional data for planning, decision-making, compliance, and strategic initiatives.

All institutional data are the property of the College, regardless of the office, system, or individual that creates, collects, or maintains them. Trustees and stewards hold delegated authority over a data domain and exercise that authority on the College's behalf.

PURPOSE

This policy applies to institutional data across all functional areas of the College, including, but not limited to:

Student Records

Academic, enrollment, and personal data

Admission & Enrollment

Prospective student and applicant data

Financial Aid

Awarding, eligibility, and disbursement data

Human Resources

Employee and personnel data

Finance & Payroll

Institutional financial and payroll data

Alumni & Development

Gift, pledge, and constituent data

DATA GOVERNANCE CHARGE

The Data Trustee Council and the Data Stewardship & Privacy Committee together provide leadership and oversight for institutional data.

They promote responsible stewardship of institutional data, recommend governance policies and standards, and resolve cross-functional data issues.

Responsibilities

  • Establish governance policies and standards.
  • Encourage ethical and responsible use of institutional data.
  • Promote data as a strategic institutional asset.
  • Recommend classification and security requirements.
  • Promote common definitions and data standards.
  • Improve institutional data quality.
  • Support regulatory compliance.
  • Review institutional data requests and access concerns.
  • Consult subject matter experts, such as compliance officers, on an as-needed basis for matters that cross data domains.

GOVERNANCE PRINCIPLES

The first four principles map directly to the framework definition above: availability, usability, integrity, and security. Accountability and compliance are the two supporting principles that make them enforceable.

01

Availability

Authorized users have role-based access to current, up-to-date data necessary for their responsibilities, when they need it.

02

Usability

Institutional data are documented with common definitions, maintained in the College's business glossary and data dictionary, so they can be found, understood, and applied consistently across the institution.

03

Integrity

Institutional data are accurate, complete, and reliable, and protected from unauthorized alteration throughout their lifecycle. Stewards are responsible for the quality of their domain's data; every role is responsible for flagging quality concerns so they can be addressed.

04

Security & Privacy

Institutional data are protected against unauthorized access, disclosure, or loss, and individual privacy is respected in how data are collected, used, and shared.

05

Accountability

Institutional data shall have clearly assigned trusteeship and stewardship authority, exercised on the College's behalf.

06

Compliance

Data management activities (collection, retention, reporting, and disposal) meet legal, regulatory, accreditation, and institutional policy requirements.

GOVERNANCE STRUCTURE

The Provost serves as Executive Sponsor of the data governance program, with oversight of both the Chief Information Officer and the Chief Data Officer, who co-chair both the Data Trustee Council and the Data Stewardship & Privacy Committee.

Below that, governance operates at two levels: strategic and operational.

Data Trustee Council

Strategic governance body responsible for institutional oversight and policy direction.

Data Stewardship & Privacy Committee

Operational governance group responsible for implementing governance practices and addressing day-to-day data management issues.

The Chief Data Officer administers the program day to day: communicating standards, coordinating stewards, providing training, and escalating unresolved issues to the data trustee with designated authority over that domain within one week. For the rare issue that cannot be resolved at the steward or trustee level, it will be escalated to the Data Trustee Council.

The Chief Information Officer provides technical guidance and expertise, including security, systems, access controls, and infrastructure.

DATA CLASSIFICATION FRAMEWORK

All institutional data are classified into one of four levels. Each level carries its own rules for storage, sharing, and AI tool use. Restricted is the highest classification level used by the College.

The "Permitted for use by individuals in AI tools?" row in each table addresses an individual's choice to use an AI tool, such as a chatbot or an AI-assisted feature in an application like email, with data they have access to. It does not cover AI capabilities built into institutional systems as part of the platform itself, which are evaluated separately through the College's Institutional Systems Governance process.

Disabling a tool's model training or data-retention settings does not make it College-approved.

 

Restricted

Level 4 (highest)

DefinitionThe highest sensitivity level. Unauthorized disclosure would violate law, regulation, or contract, or cause significant harm to the College or an individual.
ExamplesIncluding but not limited to: Social Security numbers, protected health information, banking and credit card information, Title IX records. See restricted data examples for additional examples by category.
Where data may be storedSystems specifically authorized for Restricted data, with encryption required.
Shareable with external users or vendors?No, except for mandatory reporting or critical College business approved through data governance.
Storable on College-managed devices?Only with steward approval and encryption.
Storable on personal devices or cloud services?No
Permitted for use in AI tools?No

Confidential

Level 3

DefinitionSensitive data where disclosure could cause operational, financial, or reputational harm.
ExamplesIncluding but not limited to: employee performance records, contracts, non-directory student information, donor giving history. See confidential data examples for additional examples by category. 
Where data may be storedCollege-approved systems with access controls and encryption enabled.
Shareable with external users or vendors?No, only with steward approval and an agreement in place.
Storable on College-managed devices?Yes, encrypted.
Storable on personal devices or cloud services?Limited, encrypted storage only.
Permitted for use in AI tools?College-approved AI tools only.

Internal

Level 2

DefinitionData restricted to College business use. Disclosure would not violate law or cause reputational harm, but the data are not intended for public release.
ExamplesIncluding but not limited to: internal directories, department budgets, meeting minutes, non-public policies and procedures, and instructional materials and scholarship that have not been made public by the faculty member, when used as data. 
Where data may be storedCollege-approved systems that require authentication to access.
Shareable with external users or vendors?No, unless approved by the data steward.
Storable on College-managed devices?Yes
Storable on personal devices or cloud services?Limited, encryption recommended.
Permitted for use in AI tools?College-approved AI tools only.

Public

Level 1

DefinitionData approved for open distribution to the campus community and the general public. No harm results from disclosure.
ExamplesIncluding but not limited to: public website content, press releases, the course catalogue, public event calendars.
Where data may be storedAny College-approved technology service.
Shareable with external users or vendors?Yes
Storable on College-managed devices?Yes
Storable on personal devices or cloud services?Yes
Permitted for use in AI tools?Yes: public and College-approved AI tools.

Quick Reference

The table above spells out each level in full; this is the same information for a fast look-up.

RequirementRestrictedConfidentialInternalPublic
Shareable externallyNoSteward approvalSteward approval✓
Storable on College-managed devicesSteward approval + encryption✓ (encrypted)✓✓
Storable on personal devices or cloudNoLimited (encrypted)Limited✓
Permitted in AI toolsNoCollege-approvedCollege-approved✓

 

RESTRICTED DATA EXAMPLES

Examples of data that are classified as Restricted. This list is not exhaustive.

Student data
  • Social Security numbers
  • Passport information
  • Visa information
  • Federal tax information
  • Protected health information
  • Disability services records
  • Leave of absence documentation
  • Title IX records
  • Student conduct investigations
HR / business data
  • Social Security numbers
  • Tax records
  • Banking information
  • Payroll garnishments
  • Credit card information
Development data
  • Credit card information
  • Donor banking information

CONFIDENTIAL DATA EXAMPLES

Examples of data that are classified as Confidential. This list is not exhaustive.

Student and Personal
  • Rhodes ID
  • Letter Grades
  • Grade Point Average
  • Test Scores
  • Course Schedule
  • Citizenship
  • Race/ethnicity
  • First-Generation Status
  • Pell Status
HR / business data
  • Rhodes ID
  • Citizenship
  • Race/Ethnicity
  • Salary
  • Age

DATA ROLES & RESPONSIBILITIES

The College owns all institutional data. The roles below hold delegated trusteeship, stewardship, or access authority within a domain; none of them confers ownership. Access under every role is role-based: granted according to what the position requires, not by default.

Data Trustee

Provides executive oversight of data within their functional area and is ultimately accountable for it. Sets strategic direction for data governance, resolves issues escalated by the Chief Data Officer that stewards cannot, and ensures alignment with institutional goals.

Data Steward

The primary authority for the management, integrity, and use of data within a domain. Establishes governance policies, ensures data quality, and safeguards compliance with applicable regulations and standards. Approves access to data within their domain. Fulfills ad-hoc data requests and works with Data Administrators and Data Custodians to facilitate access, maintaining the accuracy, consistency, and security that support data-informed decisions.

Data Administrator

Trained and authorized by the Data Steward to administer routine access to and release of data under established policies. May independently fulfill routine requests that meet the steward's approved criteria, but may not set policy, grant exceptions, or make other steward-level decisions. Requests outside that criteria are referred to the Data Steward.

Data Custodian

Manages and safeguards the technical infrastructure for a specific system, keeping it reliable, secure, and accessible per policy. Implements the technical configuration needed to carry out steward-directed business rules, such as system-of-record designations, data flow between systems, and field-level edit permissions. Works with Data Stewards and Data Administrators to meet reporting needs, but does not independently set those rules or approve access to or release data.

Data User

Has permission to access and use data only for the approved business purpose for which access was granted, and may not release, disclose, redistribute, or repurpose it without the Data Steward's explicit permission.

A full list of data roles is maintained by the data stewards.

TRUSTEES & STEWARDS BY DOMAIN

These are delegated trusteeship and stewardship assignments, not ownership; every domain's data remains the property of the College.

Data domainTrusteeSteward
Academic RecordsProvostRegistrar
AdmissionVice President for Enrollment ManagementDirector of Enrollment Services
Alumni & DevelopmentVice President for DevelopmentExecutive Director of Development Operations and Donor Relations
AthleticsDirector of AthleticsAthletics Business Manager
FinanceVice President for Business & FinanceSenior Associate Comptroller/Director of Accounting & Payroll
Financial AidVice President for Enrollment ManagementDirector of Financial Aid
Human ResourcesVice President for Business & FinanceDirector of Human Resources
Marketing & CommunicationsVice President for Marketing & CommunicationsChief of Digital Strategy
Student LifeVice President for Student LifeDirector of Operations & Strategic Initiatives

FREQUENTLY ASKED QUESTIONS

APPENDIX: COMMITTEE MEMBERSHIP

Membership of the Data Trustee Council and Data Stewardship & Privacy Committee, updated as roles change.

UnitJob TitleData Trustee CommitteeData Stewardship & Privacy Committee
Academic AffairsProvost and Vice President for Academic Affairs✓ 
Administrative ServicesVice President for Finance & Business Affairs✓ 
AthleticsDirector of Athletics✓ 
AthleticsAthletics Business Manager ✓
DevelopmentVice President for Development✓ 
DevelopmentExecutive Director of Development Operations and Donor Relations ✓
Enrollment ManagementVice President for Enrollment Management✓ 
Enrollment ServicesDirector of Enrollment Services ✓
Finance OfficeSenior Associate Comptroller/Director of Accounting & Payroll ✓
Finance OfficeBursar ✓
Financial AidDirector of Financial Aid ✓
Human ResourcesDirector of Human Resources ✓
Information ServicesSystems Programmer Analyst ✓
Information ServicesDatabase Analyst ✓
Information ServicesChief Information Officer (committee co-chair)✓✓
Information ServicesDirector of Academic Technologies ✓
Information ServicesDirector of Infrastructure and Enterprise Applications ✓
Information ServicesInformation Systems Security Manager ✓
Institutional Research & EffectivenessAssociate Vice President and Chief Data Officer (committee co-chair)✓✓
Institutional Research & EffectivenessData Analyst ✓
Institutional Research & EffectivenessAssociate Director of Institutional Research ✓
Marketing & CommunicationsVice President for Marketing & Communications✓ 
Marketing & CommunicationsChief of Digital Strategy ✓
President's OfficeChief of Staff to the President✓ 
RegistrarRegistrar ✓
Student LifeDirector of Student Life Operations and Strategic Initiatives ✓
Student LifeVice President for Student Life✓