General Data Protection Regulation ("GDPR")

The General Data Protection Regulation (“GDPR”) applies when processing “Personal Data” about people who are in the European Economic Area (“EEA”). Personal Data includes any data that identifies a person or could be used with other available information to identify a person. Additional safeguards apply to “Sensitive Personal Data,” which is Personal Data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, health data, or data concerning a person’s sex life or sexual orientation.

The GDPR applies to the University’s activities that (i) intentionally target goods or services to persons within the EEA when making the offer and regardless of whether payment is required, or (ii) purposefully monitor the behavior of persons located in the EEA.

The Office of General Counsel oversees the University’s compliance with the GDPR.

 

Policy

 

Legal References

 

Other Compliance Resources