Privacy of Electronic Information and Information Technology Resources
IT-07

About This Policy
- Effective Date:
- 01-31-2008
- Date of Last Review/Update:
- 06-29-2026
- Responsible University Office:
- University Information Policy Office
- Responsible University Administrator:
- Vice President for Information Technology and Chief Information Officer
- Policy Contact:
University Information Policy Office
uipo@iu.edu
Scope
This policy applies to all authorized users of Indiana University information technology resources regardless of affiliation. It applies whether the resources or data are stored on-campus or off-campus, or accessed from those locations. Unauthorized users are not protected by this policy.
Policy Statement
Stored electronic files and voice or data network communications may be accessed only by:
- The individual assigned to the account where the information is stored
- The individual who sent or received the communication, or
- The individual assigned to the device that contains the stored electronic files
This policy applies to:
- Data and other files, including electronic mail and voice mail, that are stored on, encrypted on, or in transit to or from:
- University-owned systems or devices
- Systems or devices managed by the university for affiliated organizations, such as the Indiana University Foundation or Indiana University Alumni Association
- University-owned computers assigned to an individual or group to support job functions
- University data and files stored on personally owned devices
- Telecommunications traffic, including voice and data traffic, that travels from, to, or between devices connected to Indiana University technology infrastructure.
The university may allow access by others in limited circumstances when access is necessary to support or protect important university values and operations described in this policy.
University personnel must comply with all applicable laws and university policies when they access or authorize access to electronic information and information technology resources.
Reason for Policy
Indiana University values the diversity of ideas and perspectives that are essential to an academic institution. The university respects intellectual freedom and freedom of expression. The university does not support censorship or routine inspection of electronic files or monitoring of individual network activity.
At times, however, legitimate reasons require access to computers, electronic files, or network data by individuals other than the account holder. These reasons may include:
- Protecting the confidentiality, integrity, and availability of university systems and operations
- Securing user and system data
- Ensuring lawful and authorized use of university systems
- Providing properly de-identified data for institutionally approved research projects
- Responding to valid legal requests or legal requirements
This policy balances individual privacy and freedom with the university’s need to access information when necessary to protect university operations, support core institutional values, or meet legal obligations.
Procedures
1. Access by technicians and administrators that requires authorization
A technician or administrator may access, or allow access to, information technology resources and electronic information covered by this policy under the following conditions:
- Permission granted by owner - The technician or administrator receives written authorization from the individual assigned to the account, device, or communication.
- Violations of law or policy - The technician or administrator receives written authorization from the appropriate campus chancellor, provost, Human Resources director, dean of students, or equivalent official. The authorization must be based on a reasonable belief that the individual assigned to the account or device has engaged, is engaging, or intends to engage in illegal activity or violations of university policy.
- Critical operational necessity - The technician or administrator receives written authorization from the senior executive officer of a department. The authorization must state that access to the material is critical to department operations and that the account holder is deceased, terminated, incapacitated, unavailable, or unwilling to provide access. When accessing storage containing comingled data potentially containing intellectual property as defined by olicies UA-23: Intellectual Property: Copyrightable Works and UA-24: Intellectual Property: Inventions and Patents, strive to limit the scope of access to the material critically required for operations.
- Deceased or incapacitated individual - The technician or administrator receives written authorization from the senior executive officer of a department or school. The officer must consult with the campus Human Resources director, vice provost or vice chancellor of faculty and academic affairs, campus equivalent, or dean of students before approving access for a lawful representative of a deceased or incapacitated employee, faculty member, or student.
Examples of lawful representatives include:
- A spouse
- A parent
- An executor, or
- A person holding power of attorney
e. Internal audit need - The technician or administrator receives a directive from the associate vice president and chief audit officer for information related to a specific audit or investigation.
f. Response to lawful demand - The Office of the Vice President and General Counsel (OVPGC) confirms that access is required under a valid subpoena, warrant, court order, contract, law, regulation, or university policy.
g. Substantial university risk - The technician or administrator receives authorization, either written or verbal with later written confirmation, from the IU superintendent for public safety, an appropriate campus chancellor, provost, vice president, or equivalent official. The authorization must conclude that access is necessary to address an emergency or reduce substantial risk of harm or liability to the university.
h. Institutionally approved research - The technician or administrator receives written authorization from the Institutional Review Board, another applicable research administration office, or the OVPGC. The authorization must conclude that access is necessary to support an institutionally approved research project and complies with applicable laws and university policies, including protections for human research subjects.
i. Archiving university records - The technician or administrator receives written authorization from the university records manager for archival preservation of records that have historical or other lasting value to the university, or records that must be retained under applicable law or university records management policies.
2. Notification
A technician or administrator who accesses information covered by this policy must make reasonable efforts to notify the affected individual before access occurs, except in the following situations:
- Prior notice is not appropriate or practical because of the urgency of the situation
- Prior notice could lead to destruction, removal, or alteration of data, or
- Other circumstances make prior notice inappropriate or impractical
When prior notice is not appropriate or practical, the university will make reasonable efforts to notify the affected individual as soon as possible after access occurs, unless circumstances make follow-up notification inappropriate.
3. Preservation of electronic information and of information technology resources
The university may copy and securely store the contents of an individual’s email, computer accounts, office computer, or transient network traffic to prevent destruction or loss of information under the following conditions:
- The university receives credible notice of a university or law enforcement investigation involving alleged illegal activity or violations of university policy
- The OVPGC advises that preservation is necessary to comply with legal obligations or to secure information technology resources
- A campus chancellor, provost, vice president, or equivalent official authorizes preservation after determining that preservation appears reasonably necessary to protect university operations
- There is a reasonable belief that illegal activity or violations of university policy have occurred, are occurring, or are about to occur
Access to preserved materials must comply with this policy. The university must securely destroy preserved materials when they are no longer needed.
4. Access by technicians and administrators that does not require authorization
Technicians and administrators may access information technology resources and electronic information within the scope of their legitimate university responsibilities in the following situations:
a. Emergency problem resolution
Technicians may access information technology resources and electronic information during emergencies, including public safety emergencies, when they reasonably believe that a program or process is causing or may cause:
- Significant system or network degradation
- Loss of data, or
- Damage to systems or other users’ data
This authority includes forensic analysis and other analysis related to security incidents, sensitive data exposure, or system compromise.
b. Collaborative information or resources
Technicians may access shared resources that are not private by nature, such as shared computers or shared document folders, for legitimate university purposes.
c. System-generated, content-neutral information
Technicians may access and use system-generated logs and other content-neutral information to:
- Analyze system and storage use
- Troubleshoot problems
- Support security administration
- Support audits
Technicians may not disclose or allow access to specific resources or electronic information associated with an individual unless Section 1 authorizes the access.
d. Incident response
The incident response function within the University Information Security Office (UISO) investigates reports of misuse or abuse of university information technology resources.
Incident response staff may use system-generated, content-neutral information to investigate technology misuse incidents and support audits. Staff may not disclose or allow access to specific information technology resources or electronic information associated with an individual unless Section 1 authorizes the access.
e. Network communications
Security engineers within the UISO may observe, capture, and analyze network communications.
Network communications may contain content data, and security engineers may need to view that content to complete their analysis. If they must store data to complete assigned tasks, they must store it securely and delete it as soon as possible.
Security engineers may not disclose content or log data except as authorized under Section 1.
f. Implied consent
Technicians may access information technology resources and electronic information when:
- A user requests help diagnosing or resolving a technical problem, or
- The technician performs required maintenance or troubleshooting
Technicians should limit access to the minimum necessary to address the problem.
5. Other Provisions
a. Advice and interpretation
The chief privacy officer in the Office of the Vice President for Information Technology represents the university Chief Information Officer (CIO) on privacy matters. The chief privacy officer also provides advice and policy interpretation to the CIO’s campus delegate, department management, and members of the Indiana University community.
Technicians who receive requests for access to accounts, files, or network traffic and are uncertain how to proceed under this policy must consult with the university information policy officer or the CIO’s campus delegate before granting access.
b. Legal requests
All legal requests or demands for access to information technology resources or electronic information must be delivered immediately to the OVPGC. These requests include:
- Requests under the Indiana Access to Public Records Act
- Subpoenas
- Warrants
- Court orders
- Other legal documents requesting access for law enforcement agencies or other parties
University administrators may not initiate a public records request under Indiana’s Access to Public Records Act for electronic information associated with Indiana University students, faculty, or staff. This restriction does not apply when students, faculty, or staff submit requests in their personal capacity and not on behalf of Indiana University.
If legal documents are served on technicians or other individuals, those individuals must immediately send the documents to the OVPGC for review.
The OVPGC will review the request or order and advise relevant personnel regarding the appropriate response.
If a law enforcement agency seeks to execute a warrant or order immediately and will not wait for review by the OVPGC, university personnel must not obstruct the action. Personnel should:
- Document law enforcement actions
- Notify the OVPGC as soon as possible
- Take reasonable steps, when possible, to preserve copies of removed data for appropriate university use
c. Expectation of privacy
Indiana University seeks to maintain an atmosphere of privacy regarding information and information technology resources. However, users should understand that complete privacy is not possible because:
- Indiana University is a public institution
- Institutional and academic research projects may require access to certain de-identified user data
- The university must protect the integrity and continuity of university operations
In addition to the forms of access permitted elsewhere in this policy, users should understand that incidental personal use of university email may expose email contents to disclosure under Indiana’s open records law.
Users of Indiana University information technology resources should not expect privacy beyond the protections described in this policy. Although the university takes reasonable steps to protect privacy, it does not guarantee privacy.
d. Initiating access
Individuals seeking access to information technology resources or electronic information associated with an individual and maintained by University Information Technology Services (UITS) must send requests to uipo@iu.edu.
Acting on behalf of the CIO, the University Information Policy Office (UIPO) ensures compliance with applicable policy and procedures and coordinates approved access.
Individuals seeking access to information technology resources or electronic information that are not maintained by UITS should direct requests to:
- The technology director for the unit that maintains the resources on the Bloomington or Indianapolis campuses, or
- The CIO’s campus delegate on regional campuses
Persons seeking access include:
- System administrators
- Database administrators
- Technicians performing university responsibilities
- Individuals requesting access to university resources or information
Definitions
Authorized users: Authorized users are individuals who:
- Act within the scope of a legitimate university affiliation
- Use assigned and approved credentials, such as network IDs, passwords, or other access codes
- Access approved university information technology resources
Individuals acting outside their legitimate affiliation or approved access are unauthorized users.
Content-neutral information: Content-neutral information includes information about the operation and use of systems rather than the content itself. Examples include:
- Operating system logs
- User login records
- Dial-up logs
- Network activity logs
- Non-content network traffic, such as source and destination IP addresses, ports, and protocols
- Email logs that identify senders, recipients, and dates
- Account and system configuration information
- Audit logs
Critical operational necessity: Critical operational necessity means an urgent need that is indispensable or vital to the operation of a university unit.
Indiana University information technology resources: Indiana University information technology resources include all facilities and technologies the university uses to accept, store, transmit, process, manage, display, or share data or information.
These resources include all hardware, software, and firmware used in the university technology environment. This applies whether the university owns and manages the resources or obtains them from third parties through licensing, leasing, or similar arrangements.
Information technology resources may be:
- Individually assigned
- Shared by one or more users
- Centrally managed
- Standalone
- Connected to a network
Information technology resources include, but are not limited to:
- Computers, servers, workstations, web servers, peripherals, and related equipment and software
- Voice communication infrastructure, peripherals, and related equipment and software
- Data communication and network infrastructure, peripherals, and related equipment and software
- Classroom technologies and computer labs
- Applications, systems, programs, and databases
- Electronic communication devices and services, including:
- Phones
- Voicemail
- Fax services
- Related equipment and software
University Chief Information Officer: The university chief information officer leads the development and use of information technology in support of the university’s mission of research, teaching, outreach, lifelong learning, and civic engagement.
The University Information Policy Office represents the CIO on policy matters.
Sanctions
Indiana University handles reports of misuse and abuse of information technology resources under existing policies and procedures issued by appropriate authorities.
Depending on the situation, this may involve:
- Human Resources
- Vice provost or vice chancellor of faculties (or campus equivalent)
- Dean of students (or campus equivalent)
- Office of the Vice President and General Counsel
- Law enforcement agencies
Failure to comply with Indiana University information technology policies may result in one or more sanctions, including:
- Suspension or termination of access to information technology resources
- Removal of online material
- Employment action, up to and including termination
- Student disciplinary action
- Civil or criminal liability
See policy IT-02, Misuse and Abuse of Information Technology Resources, for additional information.
History
- Reviewed and revised December 6, 2024.
- Updated references to the renamed IU Indianapolis campus in July 2024.
- Revised December 13, 2021: updated Legal Requests section.
- Reviewed December 2011.
- Revised August 17, 2011: changed titles in Sanctions section to more accurately reflect current usage.
- Revised July 23, 2010: updated Institutionally Approved Research language.
- Revised March 4, 2010: enhancing language in Sanctions section
- Updated procedures section for "Persons affiliated with external entities collaborating with Indiana University" to match academic no-pay process — September 23, 2008
- (1) Updated Alumni email eligibility to reflect new Alumni Association service — March 2, 2007
- Revised March 12, 2006
- Approved May 23, 2006
- Posted as an interim policy November 15, 2000
- Substantive revisions June 2026
