The University Directory Service (UDS) provides applications and services at the University of Wisconsin-Madison with demographic, role and contact data to support identity management, authentication and authorization.1 The following policy is designed to ensure judicious and compliant use of that information, protecting the security and privacy of that data where necessary.
- UDS data use must be authorized by the appropriate data custodians for student, employee or other data using the UDS authorization request form. This form specifies what data elements are needed for what purpose. UDS consumers2 will be notified annually to reapply for authorization. The data obtained must be used only for the specific purpose identified on the request form and not for any other purpose, and must not be supplied to other applications.
- UDS data use must comply with the applicable State of Wisconsin and Federal laws and regulations concerning privacy and security as well as complying with University policy. UDS data use is specifically bound by the University FERPA Policy and UW System Acceptable Use Policy.
- UDS data may be used for purposes of providing identity management, which includes, for example, directory authentication and authorization services, and contact information.
- UDS consumers must provide details on what UDS data they store locally.
- UDS consumers must take all necessary precautions to secure UDS data in transmission and in storage. This includes utilizing security best practices as posted online.
- Consumers of UDS data will be held responsible for any security breach traceable to their use or specific authorization and will be held liable for any willful misuse or deliberate system damage traceable to their use and specific authorization.
- Periodic and random audits will be performed on use of UDS data by the Office of Cybersecurity.
- Consumers of UDS data must provide access logs and access to systems containing UDS data upon request to the Office of Cybersecurity.
Issued by the UW-Madison Vice Provost for Information Technology.
See provisions 6, 7 and 8 of the policy.
Please address questions or comments to email@example.com.
1 Identity management refers to the policies, processes and technologies by which the identities of persons are proofed, registered and maintained. Authentication is the process of validating that identity. Authorization is providing access rights and privileges based on that identity.
2 UDS consumers refers to applications or services that use data from the UDS.