KU RC 01 - Kean University Regulatory Compliance Policy


Skip to main content

Kean University Regulatory Compliance Policy

Table of Contents

1. What This Policy Is About

The Regulatory Compliance Policy (RC‑01) defines how Kean University protects personal information, student records, financial data, health data, research data, and all other institutional information. It ensures compliance with:

  • FERPA
  • HIPAA
  • GLBA
  • GDPR, PIPL, CCPA/CPRA
  • New Jersey breach‑notification laws

It also aligns Kean practices with the NIST Cybersecurity Framework 2.0.

[Link to authoritative RC‑01 document]

Back to top

2. Why This Matters for All Staff

Every Kean employee interacts with data. RC‑01 helps you understand:

  • What laws apply to the information you handle
  • How to handle student, employee, financial, health, or research data
  • Your responsibilities for protecting confidential or restricted data
  • How to report security incidents or breaches
  • Why vendor systems must undergo security review

[Link to authoritative RC‑01 document]

Back to top

3. Who This Policy Applies To

3.1 Personnel

  • Faculty and staff
  • Student employees
  • Contractors and consultants
  • Volunteers
  • Vendors with access to Kean data

3.2 Systems & Data

  • On‑campus, cloud, and hybrid systems
  • Public, internal, sensitive, and restricted data
  • Academic, administrative, research, and operational data

3.3 Data Activities

  • Collection, creation, and storage
  • Sharing and transmission
  • Retention, archival, and deletion

3.4 Account Types

  • Human accounts
  • Shared accounts
  • Privileged accounts
  • Service and API‑based accounts
  • Automated accounts

[Link to authoritative RC‑01 document]

Back to top

4. Key Responsibilities for Staff

4.1 Handle Data Lawfully and Transparently

  • Only access data needed for your job.
  • Follow privacy notices and approved procedures.
  • Do not share personal or student data without authorization.

4.2 Protect Student Records (FERPA)

  • Do not access student data without a legitimate educational or job‑related reason.
  • Never share student information externally without authorization.

4.3 Protect Financial & Sensitive Data (GLBA)

Financial data requires secure storage, approved systems, and monitoring for suspicious activity.

4.4 Protect Health Data (HIPAA)

PHI must be handled using secure channels and approved systems.

4.5 Report Security Incidents Immediately

  • Report unauthorized access or data loss immediately.
  • Timely reporting ensures compliance with breach‑notification laws.

4.6 Use Approved Systems and Vendors Only

  • Vendors must pass security review (HECVAT/SOC 2).
  • Do not upload Kean data to personal or unapproved platforms.

4.7 Complete Required Training

All staff must complete annual security and privacy training.

[Link to authoritative RC‑01 document]

Back to top

5. What the University Must Do (for Staff Awareness)

  • Maintain risk assessments and safeguards
  • Conduct vendor risk reviews
  • Monitor systems for threats (SIEM)
  • Manage incidents and breach notifications
  • Handle international data transfers
  • Support GDPR/CCPA data rights (access, correction, deletion)
  • Maintain DPIAs and ROPAs for high‑risk processing

[Link to authoritative RC‑01 document]

Back to top

6. How This Policy Fits into Kean’s Governance Structure

RC‑01 is the umbrella policy for all related policies:

  • Information Security
  • Data Governance
  • Identity and Access Management
  • Logging & Monitoring
  • Incident Response
  • BCDR
  • Vendor/Supplier Risk
  • Exception Management
  • Training & Awareness
  • Cybersecurity Glossary

[Link to authoritative RC‑01 document]

Back to top

7. Enforcement

  • Corrective or disciplinary action
  • Access restriction
  • Contract consequences (vendors)
  • Legal or regulatory action

[Link to authoritative RC‑01 document]

Back to top

8. Exceptions

  • Follow the Exception Management Policy
  • Include risk analysis and compensating controls
  • Require CIO + Legal approval
  • Include an expiration date

[Link to authoritative RC‑01 document]

Back to top

9. Policy Review & Maintenance

The CISO and ISO review RC‑01 annually or when laws change. Evidence such as logs, assessments, and vendor records must be maintained in Kean’s Governance Repository.

[Link to authoritative RC‑01 document]

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.