30
Privacy, Policy, and Data Governance in the University Privacy Implications of Research Data NISO – RDA Joint Interest Group September 11, 2016 Christine L. Borgman Distinguished Professor and PresidentialChair in InformationStudies University of California, Los Angeles http://christineborgman.info https://knowledgeinfrastructures.gseis.ucla.edu/ @scitechprof

Borgman - Privacy, Policy and Data Governance in the University

Embed Size (px)

Citation preview

Page 1: Borgman - Privacy, Policy and Data Governance in the University

Privacy,Policy,andDataGovernanceintheUniversity

PrivacyImplicationsofResearchDataNISO– RDAJointInterestGroupSeptember11,2016

ChristineL.BorgmanDistinguishedProfessorandPresidentialChairinInformationStudiesUniversityofCalifornia,LosAngeleshttp://christineborgman.infohttps://knowledgeinfrastructures.gseis.ucla.edu/@scitechprof

Page 2: Borgman - Privacy, Policy and Data Governance in the University

• AustralianResearchCouncil– CodefortheResponsibleConductofResearch– Datamanagementplans

• NationalScienceFoundation– Datasharingrequirements– Datamanagementplans

• U.S.Federalpolicy– Openaccesstopublications– Openaccesstodata

• EuropeanUnion– EuropeanOpenDataChallenge– OpenAIRE

• ResearchCouncilsoftheUK– Openaccesspublishing– Provisionsforaccesstodata

2

Openaccesspolicies

Page 3: Borgman - Privacy, Policy and Data Governance in the University

3

Page 4: Borgman - Privacy, Policy and Data Governance in the University

4

• HowshouldUCLAcollect,organize,anduseresearchanalyticsaboutourcommunity?

• Whoshouldhaveaccesstothesedata?– WithinUCLA?– Inpartnershipwithpublicandprivateentities?

• Whatarethegovernanceprinciples?

• Whatarethegovernanceprocesses?DataGovernanceTaskForceSite:

https://ccle.ucla.edu/course/view/datagov

Page 5: Borgman - Privacy, Policy and Data Governance in the University

UCLADataGovernanceTaskForce*

5

Faculty StaffChristineBorgman,Co-Chair,InformationStudies

KentWada,Co-Chair,ChiefPrivacyOfficer

ChristinaChristie,Education,IRB AmyBlum,SeniorCampusCounselVickieMays,Psychology, Health MegBuzzi,

AcademicPersonnelSystemNeilWenger,Medicine,Ethics MikeLee,

SocialScienceComputingKristenMcKinney,StudentAffairsInfoSystem

*AnnaJoyce,PolicyAnalyst,StafftotheTaskForce

KellyWahl,Statistical Analysis,AcademicPlanning&Budget

Page 6: Borgman - Privacy, Policy and Data Governance in the University

Datacollectedby ourcommunity• Datatypes– Researchdata– Analyticsforteachingandlearning– Evaluationofindividuals,programs,services

• Policyandmanagementresponses– Mandatesoffundersandjournals– Researchdatamanagementservices– Releaseandretentionpractices– Lawsandpolicies

• Humansubjectsregulations• Openrecordslaws• HIPAA,FERPA,PII…

Page 7: Borgman - Privacy, Policy and Data Governance in the University

Datacollectedaboutourcommunity

• Studentrecords– Registrar– Coursemanagementsystems– IDcardbasedservices:library,dorms,food,health…– Internetservices:email,socialmedia,music,…

• Facultyrecords– Publications– Grants– Teachingevaluations– Serviceactivities– Financial,medical– Internetservices

Page 8: Borgman - Privacy, Policy and Data Governance in the University

Datagovernancescenarios

• Studentrecords• Facultyrecords

8http://www.rrcc.edu/sites/default/files/studentRecords_Banner.jpg

Page 9: Borgman - Privacy, Policy and Data Governance in the University

Studentrecords

• Whatdoestheuniversitycollect?• Whatcanotherentitiescollect?• Whohasaccesstotheserecords?• Whatusesmightbemadeoftheserecords?• Howshouldusebygoverned?

9

Page 10: Borgman - Privacy, Policy and Data Governance in the University
Page 11: Borgman - Privacy, Policy and Data Governance in the University
Page 12: Borgman - Privacy, Policy and Data Governance in the University

Facultyrecords

• Whatdoestheuniversitycollect?• Whatcanotherentitiescollect?• Whohasaccesstotheserecords?• Whatusesmightbemadeoftheserecords?• Howshouldusebygoverned?

12

Page 13: Borgman - Privacy, Policy and Data Governance in the University

Bibliometrics,Scientometrics,Informetrics,Webometrics…

Ohm,P.(2010).BrokenPromises ofPrivacy:Responding totheSurprising FailureofAnonymization.UCLALawReview,57,1701.

Borgman,C.L.(2015).BigData,LittleData,NoData:ScholarshipintheNetworkedWorld.CambridgeMA:MITPress.

Page 14: Borgman - Privacy, Policy and Data Governance in the University

MappingScholarship

Börner,K.(2010).AtlasofScience:VisualizingWhatWeKnow.Cambridge,Mass:TheMITPress.

Page 15: Borgman - Privacy, Policy and Data Governance in the University

15

Page 16: Borgman - Privacy, Policy and Data Governance in the University

Bibliometrics bySource

Searchesforauthor:ChristineBorgman,ChristineL.Borgman,CLBorgman(excludingotherCBorgmanauthors)onJuly28,2014andFebruary25,2016forGoogleScholar,Web ofScience,ScopusUCLAcancelledScopussubscriptionby2016

Source Publications20142016

Citationsreceived20142016

H-index20142016

GoogleScholar(Google)

380 443 7766 9701 39 43

WebofScience(Thomson-Reuters)

145 150 1629 1967 20 23

Scopus– July2014(Elsevier)

77 1314 14(after1995)

16

Page 17: Borgman - Privacy, Policy and Data Governance in the University

17

Page 18: Borgman - Privacy, Policy and Data Governance in the University

Recommendation1:Scope• Thescopeofdatatobegovernedincludes:

– Datathecampuspossesses aboutanyUCLAperson;i.e.,staff,faculty,students

– Datathatareidentifiable bynameorthatcaneasilybelinkedtoaperson

– Datathatthecampuspossessesonanypersonthatwasgeneratedduringthescopeoftheperson’sbusinesswiththeUniversity,includingdatathatweresenttosomeoneattheUniversity

• Thescopeofdatatobegovernedexcludes:– ResearchdataunderthepurviewofIRBregulations– ProtectedHealthInformation(PHI)governedbyHIPAA,or

individuallyidentifiablehealthinformationincampusstudenthealthcarefacilities

18

Page 19: Borgman - Privacy, Policy and Data Governance in the University

Recommendation2:Inventory

• Extenddatamanagement workalreadyundertakenbycampustoincludedatathatareinthestatedscopeofdatagovernance.

19

Page 20: Borgman - Privacy, Policy and Data Governance in the University

Recommendation3:Bestpractices

• Builduponestablishedfairinformationpracticesprinciplesforprivacyandextendtheseprinciplestoaccountforappropriateusesofthedataastechnology,practice,andpolicyevolve.

20

Page 21: Borgman - Privacy, Policy and Data Governance in the University

PrivacyandInformationSecurity

UniversityofCaliforniaPrivacyandInformationSecurityCommittee

http://ucop.edu/privacy-initiative/

Page 22: Borgman - Privacy, Policy and Data Governance in the University

Triggersforreview• Whendataareusedtomakedecisionsaboutpeople• Whendataarecollectedaboutpeoplewithouttheirknowledgeorconsent

• Whendataaboutpeopleareusedinunexpectedwayswithoutsubjects’knowledgeorconsent– Newapplicationsofdataorsystems– Mining,analysis,andaggregation

• Whendataaresharedwithexternalentities– Privatesectorpartners– Publicsectorpartners– Otheruniversitie

Page 23: Borgman - Privacy, Policy and Data Governance in the University

Recommendation4:Existingstructures

• ExtendexistingstructuresandpracticesforgoverninginformationtechnologyatUCLAtotheoperationalframeworkfordatagovernance.

23

Page 24: Borgman - Privacy, Policy and Data Governance in the University

BoardonPrivacyandDataProtection

ExecutiveViceChancellorandProvost*

*decision-making authority

Votingmembers• FacultyChair– AppointedbyEVC+Senate• AdministrativeViceChair– ViceProvost, IT• 6facultymembers• 6administrativemembers• 1undergraduatestudentrepresentative• 1graduatestudentrepresentative

Non-votingmembers• UCLAChiefPrivacyOfficer• ChiefInformationSecurityOfficer• DesigneeoftheEVCandProvost• DesigneefromAudit&AdvisoryServices

Page 25: Borgman - Privacy, Policy and Data Governance in the University

BoardonPrivacyandDataProtection

ExecutiveViceChancellorandProvost*

*decision-making authority

OversightCommitteeonAudit, ITGovernance,

ComplianceandAccountability*

ITPlanning Board

AcademicSenate*

Page 26: Borgman - Privacy, Policy and Data Governance in the University

BoardonPrivacyandDataProtection UCLAChiefPrivacyOfficer

• Trainingandawareness• Governancesupport• Privacybreachanalysis• Policydevelopmentandinterpretation• Datausequestions• UCprivacyandinformationsecurityreportrecommendationsimplementation

Page 27: Borgman - Privacy, Policy and Data Governance in the University

BoardonPrivacyandDataProtection

*decision-making authority

UCLAChiefPrivacyOfficer

InstitutionalReviewBoard*

TheOfficeoftheUCLACPObecomesthetriagepointforincomingrequests

Page 28: Borgman - Privacy, Policy and Data Governance in the University

Recommendation5:Activities

• Developprogrammaticactivitiesnecessarytosupporteffectivedatagovernance.

28

Page 29: Borgman - Privacy, Policy and Data Governance in the University

Discussiontopics• Problem:dataorusesofdatanotcoveredbyexistinglawsorpolicies(e.g.,FERPA,HIPAA,PII)

• HowtoextendFIPSprinciples?– Notice– Consent

• Howtoscopethedatagovernanceproblem?– Bysubjectsofdatacollection?– Byusesofdata?– Bypartiescollectingdata?Usingdata?

• Whatareappropriatecriteria,values,practices?• Whatareworkablegovernanceprocesses?

Page 30: Borgman - Privacy, Policy and Data Governance in the University

Acknowledgements

• KentWada,UCLAChiefPrivacyOfficerandChiefInformationSecurityOfficer

• JamesF.Davis,UCLAAssociateViceProvostforInformationTechnology

• UCLAPrivacyandDataProtectionBoard• UCInitiativeonPrivacyandInformationSecurity

DataGovernanceTaskForceSite:https://ccle.ucla.edu/course/view/datagov