Purpose Limitation
Collect and use information only for legitimate, documented, and authorized institutional purposes.
The JR Institute intends to govern personal, research, operational, archival, financial, and technical data through clear ownership, controlled access, secure systems, responsible use, and accountable incident response.
This page presents a planned public standard. Final data classifications, security controls, incident procedures, vendor requirements, and responsible officers should be approved before active operations.
Data may support research, learning, operations, preservation, public reporting, security, fundraising, and collaboration. It can also expose people and institutions to harm when collected or handled carelessly.
The Institute should collect only what is justified, protect it according to sensitivity, use it for authorized purposes, and dispose of it when retention is no longer required.
Collect and use information only for legitimate, documented, and authorized institutional purposes.
Avoid collecting, copying, or retaining more information than the work reasonably requires.
Give users and systems only the access needed for their assigned responsibilities.
Build privacy, encryption, logging, authentication, backups, and recovery into systems from the beginning.
Assign owners, maintain records, review access, document decisions, and correct failures.
Evaluate privacy, bias, security, consent, autonomy, and misuse risks before deploying new technology.
This policy is intended to apply to personal information, research data, financial records, donor information, personnel files, archival collections, operational systems, security records, communications, websites, cloud services, devices, and technical infrastructure.
Information should be classified according to sensitivity, legal obligations, contractual restrictions, potential harm, and operational importance.
Classification should guide storage, sharing, encryption, retention, access review, backup, and destruction requirements.
Access should be based on verified identity, assigned responsibilities, least privilege, separation of duties, and periodic review.
The Institute should collect information fairly, explain its intended use where appropriate, and avoid using it for materially incompatible purposes without additional authority, notice, or consent.
Disclosure should be limited to authorized recipients, legal obligations, approved partners, or other legitimate institutional purposes.
Sensitive information should not be placed in public AI tools, personal email, unapproved cloud storage, or consumer messaging systems without explicit authorization and appropriate safeguards.
Research-data controls should reflect consent, participant risk, sponsor terms, ethics approval, intellectual property, reproducibility, publication, security, and disciplinary standards.
De-identification, pseudonymization, controlled-access repositories, data-use agreements, and secure computing environments may be required for sensitive research.
Vendors handling Institute information should be evaluated for security, privacy, hosting location, incident response, subcontractors, access controls, encryption, retention, deletion, continuity, and auditability.
Contracts should define data ownership, permitted use, breach notification, return or export, deletion, confidentiality, and transition at termination.
AI systems should be evaluated for privacy, confidentiality, accuracy, bias, security, explainability, intellectual property, human oversight, and potential misuse.
Security controls should be proportionate to the system, information, user population, threat environment, and consequence of failure.
Suspected loss, theft, unauthorized access, malware, phishing, data exposure, service compromise, or destructive activity should be reported promptly.
Response should include containment, evidence preservation, impact assessment, legal and contractual review, notification decisions, recovery, corrective action, and documented lessons learned.
Data should be retained according to legal, research, financial, operational, contractual, and archival requirements.
Expired sensitive information should be deleted, destroyed, anonymized, or transferred to controlled archival custody using approved procedures.
Framework date: July 2026
Inquiries may concern personal information, research data, account access, vendors, cloud services, AI use, retention, cybersecurity, or suspected data exposure.
Identify the system, data type, date, people involved, suspected exposure, urgency, and supporting information.
Contact the Institute