Privacy Protections for Distance Students

SMU protects the privacy of all students, including those in distance and online programs, through a comprehensive framework of federal law compliance, institutional policy, technical safeguards, staff training, and operational governance.

 

Governing Policies

Policy 8.1

Policy 8.1

Acceptable Use

Establishes that student information must be protected whether the student is on campus, enrolled in a distance education or correspondence course, or a continuing education student. Section 6(h) explicitly states that no additional charges are assessed for identity verification.

Policy 8.2

Policy 8.2

Information Security

Mandates encryption, role-based access controls, breach response procedures, and vendor security requirements for all systems handling personally identifiable information. Requires annual security training for all employees.

Policy 8.6

Policy 8.6

Institutional Data Governance

Establishes the Data Governance Committee, three-tier data classification (Restricted, Private, Public), and formal Data Stewards. Student data stewardship is assigned to the University Registrar. FERPA training is required before access to student data is granted.

Policy 1.10

Policy 1.10

Privacy of Education Records (FERPA)

Establishes SMU's institutional FERPA compliance framework, including annual notification to students of their rights, training requirements for all staff with access to education records, and procedures for inspection and disclosure.

FERPA and Student Rights

The Family Educational Rights and Privacy Act (FERPA) grants students the right to inspect their education records, request corrections, and control disclosure of personally identifiable information. These rights apply equally to students in on-campus and distance education programs.

  • The right to inspect and review your education records within 45 days of a written request.
  • The right to request amendment of records you believe are inaccurate or misleading.
  • The right to consent to disclosures of personally identifiable information, with limited exceptions (e.g., school officials with legitimate educational interest).
  • The right to restrict directory information disclosure via my.SMU Self-Service.
  • The right to file a complaint with the U.S. Department of Education regarding alleged FERPA violations.

Review the full FERPA guidance at SMU

Education records include any records directly related to a student that are maintained by SMU or its agents, in any format — paper, electronic, or otherwise. This includes grades, transcripts, class lists, course schedules, financial aid records, and disciplinary records.

FERPA-protected records do not include sole-possession notes, employment records unrelated to enrollment, law enforcement records, or post-attendance records.

Training, Governance & Vendor Controls

All SMU employees complete annual data security and privacy training, delivered through the Vector Solutions LMS. New employees complete training within 90 days of hire; all employees renew annually. The training requirement was established by presidential directive in 2015 and covers student data confidentiality, credential security, and appropriate data handling. Duo MFA is required to access the training system itself.

SMU's Institutional Data Governance Policy (Policy 8.6) establishes a formal Data Governance Committee and assigns Data Stewards for every institutional data domain. The publicly accessible Data Stewards registry contains 147 entries; student data stewardship is assigned to the University Registrar.

All third-party vendors that host or access University data are assessed by the Chief Security Officer and must meet SMU information security requirements. Contracts include required information security provisions per Policy 8.1, Section 14. Student records may not be stored on non-University-owned resources without CIO approval.