Skip to main content

IntegrityStar, July 2026 edition

 

doors lined up with different university department names showing possible access to student records.

 

Access is a necessary part of our work at the university. It allows us to support students, manage operations, and do our jobs effectively. But access should never be treated as a convenience; it should always be tied to a clear purpose.

One of the most important principles in privacy is ensuring that access to information is based on an individual’s role and responsibilities. If you need access to perform your job, you should have it. If you don’t, then access shouldn’t be retained. While that sounds straightforward, in practice, access often stays in place longer than it should.

This tends to happen gradually. An employee transitions into a new role but keeps access from their previous position. A project wraps up, but permissions remain. Someone leaves one department and moves to another, and access isn’t removed as quickly as it should be. Over time, access accumulates not because it’s needed, but because it was never revisited.

There’s also a mindset that contributes to this. It can feel easier to leave access in place “just in case” or because it might be needed at some point in the future. But convenience is not a valid reason to maintain access to information, especially when that information may be sensitive or restricted.

When access is broader than necessary, the risk increases. Information may be viewed or used in ways that were never intended, and the likelihood of errors grows. It also puts the university at greater risk when it comes to meeting our obligations under laws and regulations like the Family Educational Rights and Privacy Act (FERPA) and the Health Insurance Portability and Accountability Act (HIPAA).

Maintaining appropriate access requires ongoing attention. Supervisors and data owners play an important role in ensuring that access aligns with current job duties, particularly when roles change or employees leave the university. Just as important, individuals should be mindful of their own access. If it is no longer needed, it is worth raising the question.

A helpful way to think about this is to shift the question from “Why not give access?” to “Why is this access needed right now?” That small change keeps the focus where it belongs on necessity, not convenience.

At the end of the day, access should reflect what is required to do the job today, not what was needed in the past or what might be useful someday. Taking a more intentional approach helps protect the information we are entrusted with and supports a stronger culture of privacy across the university. If you haven’t reviewed access in your area recently, now is a good time to do so, particularly for supervisors managing team access.