FERPA Notice and Data Privacy and Security Best Practices

Aloha UH Faculty, Staff, and Administrators:

Welcome to the start of the new semester! A quick reminder: all UH employees are required to maintain up-to-date Information Security Awareness Training (ISAT) under UH Administrative Procedure 2.215. Please verify that your certification is current to maintain compliance and access to essential UH systems (eBanner, eTravel, KFS, myGRANT, PeopleSoft, STAR, and select Kuali Build/TDX (TeamDynamix) forms).

The University of Hawaiʻi is responsible for maintaining the confidentiality of student education records and monitoring the release of information from those records, in compliance with the Family Educational Rights and Privacy Act (FERPA). 

UH employees with access to student education records have a legal responsibility to protect the privacy of students by using information only for legitimate educational reasons to instruct, advise, or otherwise assist students. FERPA also assures certain rights to students regarding their education records. These rights do not transfer to parents, guardians, spouses, or other family members without express written permission.

  • What is FERPA? The Family Educational Rights and Privacy Act of 1974 affords students the right to inspect records, control disclosures, request amendments, and file complaints with the U.S. Department of Education. Learn more about FERPA at the UH FERPA Overview page and Guidance for Online Lectures and Recordings.

  • Graduate Assistants (GAs) and Student Employees: Employment and business contact information are protected education records under FERPA. Graduate assistants are given the option to publish their business contact information in the UH Faculty/Staff Directory upon hiring and through the semesterly FERPA notice to students. In selected cases where student employees need to disclose their business contact information (e.g., for tutoring services), supervisors need to obtain prior written consent and maintain that consent on file. The Graduate Assistant/Student Employee Authoriza tion and Consent to Release form may be used. For further guidance, you or your supervisor may contact the Data Governance Office at datagov@hawaii.edu.

Data Privacy and Security Best Practices
Protecting your UH username safeguards institutional data. Follow these best practices:

  • Use unique passwords. Never re-use your UH password on third-party sites. Data breaches on external platforms can expose compromised UH credentials. Advise students to create unique passwords when establishing third-party accounts.

  • Never re-use exposed credentials. Hackers actively target credentials leaked in past breaches.

  • Stay alert. Review UH phishing resources and adhere to UH Cyber Hygiene Best Practices.

Instructional Tools and Generative AI

  • Third-Party Online Tools. Faculty should check the Instructional Third-Party Online Tools list before adopting software for instruction. If an unlisted tool is needed, submit an application for review. Once the semester ends, request that vendors delete student accounts, coursework, and exam data. (Note: Departments and other administrative units should follow the Decision Tree for Institutional Data rather than the Instructional Third-Party Online Tools list which was reviewed specifically for instruction.)

  • Tools with AI Features. Data entered into generative AI tools may be used for model training or shared publicly, depending on vendor terms. Prioritize using ITS-approved tools which offer enterprise protection (e.g., Google Gemini or Notebook) or vendors vetted through the Data Governance Process (DGP). For more information, refer to a matrix of popular AI tools by UH Data Classification Categories.

Questions?
Email the UH Data Governance Office at datagov@hawaii.edu.

Sincerely,
Alan Rosenfeld
Associate Vice President for Academic Programs and Policy
University of Hawaiʻi System