Kean University DG – Privacy Protection, Masking & Anonymization (SOP) 10
Table of Contents
- About This SOP
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Related Policies & Standards
- Compliance Mapping
- Metrics & KPIs
- Required Records & Storage
- Revision History
About This SOP
This Standard Operating Procedure (SOP) defines how Kean University protects personal and sensitive data using privacy‑preserving handling, including data masking and data anonymization.
This SOP operationalizes requirements from KU DG 02 – Data Access & Privacy Policy and classification‑based handling controls in KU DG 01 – Data Governance & Protection Policy.
Scope
- All University personnel handling Internal, Confidential, or Restricted data
- All systems processing personally identifiable or regulated data
- Reporting, analytics, testing, integrations, and data extracts
- Cloud, on‑premises, and hybrid environments
Definitions
- Personally Identifiable Information (PII) – Data that can identify an individual.
- Protected Health Information (PHI) – Health‑related data protected by HIPAA.
- Masking – Replacing sensitive values while preserving format.
- Anonymization – Removing or transforming data so individuals cannot be identified.
- Restricted Data – Legally regulated data requiring maximum protection.
- Quasi‑Identifiers – Attributes that may identify an individual when combined.
Roles & Responsibilities
Data Owners
- Approve when masking or anonymization is sufficient for a use case
- Validate classification and restrictions of source datasets
Data Stewards
- Apply and validate masking or anonymization techniques
- Maintain documentation of transformations performed
IT Security
- Validate privacy controls and re‑identification risk
- Monitor logs and DLP alerts for unmasked data movement
Procedure
Step 1 — Confirm Data Classification
Determine whether the dataset contains PII, PHI, or other Confidential or Restricted data.
Step 2 — Define the Use Case
If full identifiers are not required, default to masking or anonymization.
Step 3 — Apply Masking or Anonymization
Use approved techniques to minimize re‑identification risk while preserving usability.
Step 4 — Validate & Approve
Data Owners approve the dataset and documentation is retained.
Related Policies & Standards
- KU DG 01 – Data Governance & Protection Policy
- KU DG 02 – Data Access & Privacy Policy
- KU DG SOP 01 – Data Classification & Labeling
- KU DG SOP 06 – Data Storage & Encryption Compliance
- KU DG SOP 07 – Data Sharing & Transfer
Compliance Mapping
| NIST CSF Function | Category | Subcategory |
|---|---|---|
| Protect | PR.DS – Data Security | PR.DS01, PR.DS02, PR.DS05, PR.DS06 |
Metrics & KPIs
- Percentage of datasets using masking or anonymization
- Number of unmasked PII/PHI exposure alerts
- Time to remediate privacy violations
Required Records & Storage
- Masking and anonymization documentation
- Data Owner approvals
- Transfer and access logs
- DLP alerts and investigations
Revision History
| Version | Date | Description | Author (Role) | Approver (Role) |
|---|---|---|---|---|
| 1.0 | February 13, 2026 | Initial release | Data Governance Lead | Chief Information Security Officer |
``