Op12.02-8 Privacy


As an educational institution, Missouri State University encourages our students, faculty, staff and guests to advance learning and understanding through communication and collaborative teamwork. Missouri State acknowledges that these functions may require a certain level of privacy and protection, and it strives to provide a reasonably safe information systems environment. Please remember that access to university computer systems and facilities is a privilege, not a right, and abuse of that privilege can result in its loss.

Additionally, this policy is subject to all other information services policies. Please review all the information technology policies.

Policy statement

While authorized users cannot assume an expectation of privacy regarding data, information or electronic communications contained on university computers and systems, the university does take reasonable precautions to protect its accounts, personally identifiable records and personal communications from unauthorized access or disclosure:

  • University web sites that display personal information, such as the My Missouri State website, will only display an individual's records after the proper password has been entered. These sites will also ensure data communication security by using server authentication, encryption and data/message integrity.
  • University email, accounts and voice mailboxes may only be accessed after the appropriate user ID and password have been entered.
  • System administrators and data custodians follow procedures to protect the confidentiality of personal or confidential information encountered in the performance of their duties.
  • The university does not rent or sell personally identifiable university data to anyone. Per a contractual agreement, the university does provide data on students 18 years and older to the university's affinity credit card company for promotional mailings, usually a couple times per year. The university also provides data on graduates for use by the Missouri State Alumni Association and Missouri State Foundation so that graduates can receive regular information about their alma mater.

If the chief information officer believes a system has been compromised, the university will notify the authorized users.

However, the university does not attempt to protect data that have been made public by a user or generic data that are not personalized to a specific user. Examples of generic data include log files, network jack data and IP address assignments. Additionally, the university cannot guarantee the security of commercial wireless services.

Authorized users also play a key role in protecting data and records. They should not share their passwords with others. Also, they should close the web browser every time they finish using a web application that required a password for access and logoff their accounts when they finish using a computer.

Disclosure and publishing guidelines

Certain types of information have specific disclosure and publishing guidelines, which are outlined below. The university's policy is to not publish or disclose data unless it meets these disclosure requirements or the university is following the access to electronic information conditions outlined in the next section.

University records

The university will disclose all University records, including electronic records, with these exceptions:

Directory information

The categories of information that have been designated as directory can be found in the university's FERPA/confidentiality of student education records policy.

Image, voice or likeness

The university attempts to obtain releases before publishing images, voices or likenesses of identifiable human subjects.

As such, each website's supervisor should ensure that the identifiable subject(s) featured has/have provided written consent before publishing that person's image, voice or likeness on an official university website. This consent is necessary for any image, voice or likeness, regardless of whether it was obtained through a free information request, personal camera or other means.

The supervisor of the website publishing the likeness must provide notice, obtain consent and keep a record of the consent--unless photographic services or the office of web and new media has already obtained consent for that likeness. For more information see the privacy and releases page.

If you discover your image, voice or likeness in one of the university's online publications and would like it removed, please notify the office of web and new media.

University access to electronic information

The university does not routinely seek out, examine, disclose, use or modify the contents of individually assigned accounts, personal communications, records or university computers. The university does reserve the right to view, scan or otherwise access any file, hardware, software or communication on university computers/systems or transmitted over university networks in the following conditions:

  • When data custodians, university auditors, legal counsel or information technology employees access data as part of their employment, and then only to the extent as necessary to perform work activities.
  • When the Board of Governors, president, director of internal audit and compliance or applicable vice president/chancellor (or designee if the vice president/chancellor is unavailable) has authorized a review because the university has reasonable cause to believe that an individual may be violating the law or university policy. Any request for a review must follow the appropriate procedures. University employees will not disclose information accessed during a review other than to university administrators and/or proper authorities investigating the matter.
  • As permitted by applicable policy or law. For example, the university may be required to disclose public records, including electronic versions such as email, when requested under the Sunshine Law (chapter 610 of the Missouri Revised Statutes). The university may also be required to disclose closed records or personally identifiable educational records to comply with a court order or subpoena.

Electronic information may be quickly deleted or modified. As such, the university will notify an individual about a review/disclosure after the university accesses the individually assigned electronic information.

Additionally, if the university has reason to believe a system security breach has occurred or could occur, the university retains the right to access any university system and, upon evaluation of the situation, shut down any system and/or require its modification to mitigate any perceived risk.