Code of Massachusetts Regulations
610 CMR - BOARD OF HIGHER EDUCATION
Title 610 CMR 10.00 - Privacy, Confidentiality, and Data Security
Section 10.02 - Definitions
For the purposes of 610 CMR 10.00, the following terms will mean:
Agency. The Commonwealth or any of its departments, authorities established by the General Court to serve a public purpose having either state-wide or local jurisdiction, boards, and commissions, or other entities, except criminal justice agencies as defined in M.G.L. c. 6, § 167, to the extent described in 610 CMR 10.01(2).
Audit Trail. A recording by a holder of all persons who obtain access to the personal records of a data subject.
Board of Higher Education (Board). The Agency established by M.G.L. c. 15A, § 4 and all of its divisions.
Collects. Gathers, obtains or receives.
Commissioner of the Board of Higher Education (Commissioner). The chief executive and administrative officer of the Department of Higher Education and Board of Higher Education, pursuant to M.G.L. c. 15A, § 6.
Data Security. Reasonable precaution from unauthorized access, theft, removal or other security threat.
Data Subject. Any person concerning whom personal data is held for any purpose, whether or not he has knowledge of such holding.
Directory Information. May include an individual's name, address, telephone number, date of birth, place of birth, major field of study or employment position, participation in officially recognized activities and sports, name of institution, weight and height of members of the athletic team, dates of attendance, degree and awards received, the most recent previous educational agency or institution attended by the student, or other similar information. The Board may, at its option, define certain data as Directory Information to include the data described above; provided, however, that nothing contained in 610 CMR 10.00 shall require the Board to disclose individualized personal data not otherwise exempt by applicable federal or state law.
Disclosure. Access or release of data:
(a) Access. Inspection or copying of data or reports generated therefrom.
(b) Release. The written disclosure, in whole or in part, of data or reports generated therefrom.
Disseminates. Transfers for any purpose from a holder to any other agency, person, or entity.
Educational Data. All available educational data, aggregate and individualized, collected from data holders on paper, magnetic tape and/or in computerized or electronic form, relevant to the careful and responsible discharge of the purposes, functions, and duties of the Board.
Holder. Any agency to which 610 CMR 10.00 applies pursuant to 610 CMR 10.01(2) and as defined in 610 CMR 10.02 and any other person or institution, organization or other entity that holds or is involved in the aggregation or maintenance of personal data.
Holds. Collects, maintains, or disseminates, whether manually, mechanically, or electronically.
Independent Institution of Higher Education. Any degree-granting institution of higher education located or offering degree programs or courses in Massachusetts excluding public institutions of higher education set forth in M.G.L. c. 15A, § 5.
Institution under the Board of Higher Education. Any institution within the system of public institutions of higher education as set forth in M.G.L. c. 15A, § 5.
Individual. A student or employee:
(a) Student. Any person enrolled or formerly enrolled in an institution of higher education in Massachusetts.
(b) Employee. Any person (faculty, administrative, or support staff) employed by an institution or other data holder including faculty, administrative or support staff.
Legal Proceeding. Any litigation, arbitration, or state or federal administrative proceeding.
Maintains. Stores, updates, or corrects.
Official Data. Standard reports prepared and released by the Board in consultation with appropriately involved institutions or other data holders. The Board and the institutions shall rely upon this data in public statements and reports wherever reasonably practicable. Official data shall not contain individualized data unless or until the Board, at its option, designates certain data as Directory Information following consultation with each institution.
Personal Data. Any data regarding an individual including but not limited to personal identifiers, which relate to the examination, care, custody, treatment, support, or rehabilitation of the individual, medical, psychological, psychiatric, social, financial, and vocational data, and which is normally contained in case files, personnel files, or similar files. Personal Data shall be applied to data maintained in either manual or computerized or electronic form or any combination thereof.
Personal Data System. A collection of records, a substantial number of which contain personal data, where access to the records can be gained by the use of a personal identifier.
Personal Identifier. Any element or data which may be used to fix a person's identity either by itself or when combined with other data accessible to the holder of such data and which may include, but is not necessarily limited to: name, address, social security number, date of birth, race, zip code, mother's given name, mother's maiden name, or any letters of the mother's given or maiden name.