Data Governance, Privacy & Cybersecurity Policy

Protect information. Preserve trust.

The JR Institute intends to govern personal, research, operational, archival, financial, and technical data through clear ownership, controlled access, secure systems, responsible use, and accountable incident response.

Developing Framework

This page presents a planned public standard. Final data classifications, security controls, incident procedures, vendor requirements, and responsible officers should be approved before active operations.

Policy Purpose

Information is an institutional asset and a responsibility.

Data may support research, learning, operations, preservation, public reporting, security, fundraising, and collaboration. It can also expose people and institutions to harm when collected or handled carelessly.

The Institute should collect only what is justified, protect it according to sensitivity, use it for authorized purposes, and dispose of it when retention is no longer required.

Core Principles

Minimize, classify, secure, monitor, and respond.

01

Purpose Limitation

Collect and use information only for legitimate, documented, and authorized institutional purposes.

02

Data Minimization

Avoid collecting, copying, or retaining more information than the work reasonably requires.

03

Least Privilege

Give users and systems only the access needed for their assigned responsibilities.

04

Security by Design

Build privacy, encryption, logging, authentication, backups, and recovery into systems from the beginning.

05

Accountability

Assign owners, maintain records, review access, document decisions, and correct failures.

06

Responsible Innovation

Evaluate privacy, bias, security, consent, autonomy, and misuse risks before deploying new technology.

Scope

This policy is intended to apply to personal information, research data, financial records, donor information, personnel files, archival collections, operational systems, security records, communications, websites, cloud services, devices, and technical infrastructure.

Data Classification

Information should be classified according to sensitivity, legal obligations, contractual restrictions, potential harm, and operational importance.

  • Public: approved for unrestricted release
  • Internal: intended for routine institutional use
  • Confidential: requires controlled access and protection
  • Restricted: highly sensitive, regulated, security-critical, or legally protected

Classification should guide storage, sharing, encryption, retention, access review, backup, and destruction requirements.

Identity and Access Control

Access should be based on verified identity, assigned responsibilities, least privilege, separation of duties, and periodic review.

  • Use strong authentication and multifactor authentication where appropriate
  • Remove or change access promptly when roles change
  • Restrict privileged and administrative accounts
  • Review inactive, shared, vendor, and emergency accounts
  • Log access to sensitive systems where feasible

Collection, Use, and Disclosure

The Institute should collect information fairly, explain its intended use where appropriate, and avoid using it for materially incompatible purposes without additional authority, notice, or consent.

Disclosure should be limited to authorized recipients, legal obligations, approved partners, or other legitimate institutional purposes.

Sensitive information should not be placed in public AI tools, personal email, unapproved cloud storage, or consumer messaging systems without explicit authorization and appropriate safeguards.

Research Data

Research-data controls should reflect consent, participant risk, sponsor terms, ethics approval, intellectual property, reproducibility, publication, security, and disciplinary standards.

De-identification, pseudonymization, controlled-access repositories, data-use agreements, and secure computing environments may be required for sensitive research.

Cloud Services, Vendors, and Third Parties

Vendors handling Institute information should be evaluated for security, privacy, hosting location, incident response, subcontractors, access controls, encryption, retention, deletion, continuity, and auditability.

Contracts should define data ownership, permitted use, breach notification, return or export, deletion, confidentiality, and transition at termination.

Artificial Intelligence and Automated Systems

AI systems should be evaluated for privacy, confidentiality, accuracy, bias, security, explainability, intellectual property, human oversight, and potential misuse.

  • Do not upload restricted data to unapproved models
  • Verify important outputs before operational use
  • Disclose material AI assistance where appropriate
  • Maintain human responsibility for consequential decisions
  • Review model and vendor data-retention practices

Technical and Administrative Security Controls

Security controls should be proportionate to the system, information, user population, threat environment, and consequence of failure.

  • Asset inventory and system ownership
  • Patch management and secure configuration
  • Encryption in transit and at rest where appropriate
  • Endpoint protection and network segmentation
  • Logging, monitoring, alerting, and vulnerability management
  • Tested backups and disaster recovery
  • Security awareness and role-based training

Incident Response

Suspected loss, theft, unauthorized access, malware, phishing, data exposure, service compromise, or destructive activity should be reported promptly.

Response should include containment, evidence preservation, impact assessment, legal and contractual review, notification decisions, recovery, corrective action, and documented lessons learned.

Retention, Archival Preservation, and Destruction

Data should be retained according to legal, research, financial, operational, contractual, and archival requirements.

Expired sensitive information should be deleted, destroyed, anonymized, or transferred to controlled archival custody using approved procedures.

Framework date: July 2026

Security Lifecycle

Know what exists, protect what matters, and respond when controls fail.

  • Inventory and classify. Identify systems, data, owners, dependencies, and sensitivity.
  • Control access. Authenticate users, minimize privileges, and review permissions.
  • Protect and monitor. Patch, encrypt, back up, log, test, and watch for anomalies.
  • Respond and recover. Contain incidents, preserve evidence, restore service, and notify appropriately.
  • Improve continuously. Review failures, update controls, train users, and test readiness.
Privacy or Security Questions

Report incidents, access concerns, unsafe systems, or improper data use.

Inquiries may concern personal information, research data, account access, vendors, cloud services, AI use, retention, cybersecurity, or suspected data exposure.

Submit a Data or Security Inquiry

Identify the system, data type, date, people involved, suspected exposure, urgency, and supporting information.

Contact the Institute