UI-Green Metric
|
Policy Subject |
Data Protection Policy |
|
Effective Date |
1/7/2025 |
|
Department |
Information and Documentation Center |
|
Approved By |
Director of Information and Documentation Center |
|
Version |
1.0 |
Overview
The Information and Documentation Center (IDC) faces an increasing demand to provide software in a timely, secure, and reliable manner for Staff and students. Thus, IDC pay attention to Data as critical asset by implementing a policy to safeguard institutional data from unauthorized misuse or loss, in collaborating with Computer Networks and Data Center (CNDC)
Scope
This policy applies to all the AASTMT employees, students and IT Staff who interact with AASTMT Digital systems
Purpose
The main aim of data protection policy is to guideline AASTMT employees, students and IT Staff to be aware of interacting with Data through AASTMT Digital systems to become protected at the appropriate level. And ensure Data is vital to the University, and any unavailability or unauthorized disclosure could seriously damage its reputation. It establishes clear policy for managing and safeguarding data at AASTMT including student records, academic information, and administrative system against unauthorized access, alteration, or loss. From an IDC perspective, the Data Protection Policy focuses on implementing comprehensive data security measures. IDC ensures strict enforcement of access controls, authentication, authorization and accounting implement strong and complex passwords, encryption, and routine data backup guidelines using our IDC backup policy to mitigate the risk.
Data Protection Principles
We adhere to the following principles of data protection:
Lawfulness, Fairness, and Transparency: We shall process personal data lawfully, fairly, and in a transparent manner.
Purpose Limitation: We shall only collect personal data for specified, explicit, and legitimate purposes and not further process it in a manner incompatible with those purposes.
Data Minimization: We shall ensure that personal data is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
Accuracy: We shall take reasonable steps to ensure personal data is accurate and, where necessary, kept up to date.
Integrity and Confidentiality: We shall process personal data in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical and organizational measures.
Accountability: We shall be responsible for, and be able to demonstrate, compliance with these principles.
Data Security (Technical and Organizational Measures)
IDC will implement appropriate technical and organizational measures to protect personal data, including:
Access Controls: Restricting access to personal data to authorized personnel on a need-to-know basis.
Encryption: Encrypting critical data.
Physical Security: Securing physical locations where data is stored (e.g., locked offices, secure data centers).
Staff Training: Regular training for all staff on data protection and information security.
Backup and Recovery: Maintaining secure backups of data to ensure business continuity.
Password Management
Passwords are a common form of verification and are considered the only barrier between a user and his/her personal information.
Enforce adequate password controls in systems and user level.
Protect information and information assets related to the user.
Ensure that only authorized users can access certain information, applications, services and systems.
Protect the Confidentiality, Integrity and Availability of information, systems, services, and applications within the organization’s network.
Data Breach Response
In the event of a data breach, the Company will follow a defined incident response plan. The key steps include:
Containment: Take immediate steps to contain the breach and limit the damage.
Assessment: Assess the risk to data subjects.
Notification: Notify the relevant supervisory, and affected data subjects where legally required, within the mandated timeframe.
Review: Investigate the cause of the breach and take steps to prevent future incidents.
All staff are required to immediately report any suspected data breach to the Data Protection Officer.
Roles and Responsibilities
Data Protection Officer (DPO): [Director of Information and Documentation Center] The DPO is responsible for overseeing this policy, providing guidance, and acting as the point of contact for staff and supervisory authorities.
Management: Is responsible for providing the necessary resources and support for compliance.
All Staff: Are responsible for understanding and complying with this policy in their day-to-day work.