Per WSU Policy 19.20 (19.20 / Data Sensitivity Classification) all employees will be required to label all WSU documents and emails by January 2027.

It is highly recommended to take labeling training before this requirement is in place to avoid disruption in your workflow. Training is available in a 40-minute, self-paced online course or a 30-minute in-person training session.

Please work with your department or division leaders to coordinate a training strategy and reach out to askinfosec@wichita.edu to schedule an in-person session or setup online training.

This is a picture of the WSU privacy logo with a black fingerprint embedded with wheat shocks on a gold background. The words Wichita State University and the contact information for the privacy office is listed on it which is 316-978-4HIP and hipaaprivacy@wichita.edu.

Back-to-school is a great time to refresh privacy practices. As part of the ongoing commitment to protecting the institution’s information, please collect, use and retain only the personal data needed to support academic and administrative activities.

For more information on the data minimization principle, visit the WSU Privacy SharePoint site. If you have questions or concerns regarding privacy, reach out to privacy@wichita.edu.

Compliance training has often felt fragmented and time-consuming. To improve this experience in the future, all required training will be delivered through a single platform during a coordinated training session in August.

This streamlined approach will:

  • Eliminate confusion about where and when to complete training
  • Reduce duplicate and repetitive work
  • Provide a clear, predictable timeframe before the academic year begins

By completing training in August, you can begin the semester confident that your requirements are in place — without ongoing interruptions throughout the year.

Renewal trainings:

This August will mark the inaugural renewal training month for all non-student employees. It will include interactive renewals for training such as HIPAA, Information Security, Research Security, Title IX and PCI that were created in collaboration with WSU’s Office of Instructional Resources. In future years, the plan is to expand the August cycle to include additional required training courses, such as FERPA. Note that not all compliance training will transition to the new platform in the first year. Things will begin with a phased rollout to ensure a smooth and successful transition.

New employee or first time training:

New employees at WSU or in your area will continue to complete first-time training as part of the established onboarding process, according to current practices. They will complete these training courses at the time of hire or onboarding to your area, and will then transition to the August renewal cycle, starting the first August following their initial training completion.

Look out for more information coming via email soon.

The Microsoft Teams and Microsoft SharePoint logos

Keeping Microsoft SharePoint or Teams sites set to “public” can unintentionally expose sensitive information to a wider audience than intended. When a site or its content is accessible without proper restrictions, it increases the risk of oversharing and unauthorized access, editing or deletion by individuals who should not have visibility or access into that information.

To protect organizational data and maintain compliance, you should always follow the principle of least privilege by configuring SharePoint or Teams sites as private by default, granting access only to those who truly need it. This ensures better control over who can view, edit, or share content.

Being mindful of SharePoint and Teams visibility settings is a simple but critical step in safeguarding company information. If you have any questions about how to do this, email privacy@wichita.edu or visit the ITS training site.

This is a picture of a black graduation hat sitting on a tall stack of white papers.

Graduation is all about moving forward — leaving behind what you no longer need and taking only what matters into the future. The same mindset applies to how we handle personal data.

Privacy tip: don’t carry everything forward

Just because you can keep personal data doesn’t mean you should. Storage limitation is a core privacy principle: retain personal data only for as long as it serves a clear purpose — then securely delete it. Remember to exercise caution before deleting personal information from shared systems. Approval is needed from data owners to do so.

Level up your data practices by addressing personal information in your personal OneDrive:

  • Review the personal data you collect and store
  • Remove data that’s no longer needed
  • Follow defined retention schedules
  • Avoid “just in case” data storage

Why it matters:

Holding onto unnecessary data increases risk — for individuals and for the organization. Practicing good personal data hygiene helps reduce exposure, strengthen compliance and build trust.

Take the next step:

As the campus celebrates milestones and new beginnings, commit to smarter data stewardship: Keep what you need. Let go of what you don’t. Protect what matters.

This is a picture of the WSU privacy logo with a black fingerprint embedded with wheat shocks on a gold background. The words Wichita State University and the contact information for the privacy office is listed on it which is 316-978-4HIP and hipaaprivacy@wichita.edu.

At the heart of the mission as a higher education institution is trust — trust from students, faculty, staff, alumni, and research partners. That trust depends on how responsibly personal information is handled. One of the most effective ways to protect privacy while supporting academic and operational excellence is through data minimization.

Data minimization means intentionally limiting the personal data collected, used, stored and shared to what is directly relevant and necessary to fulfill a legitimate institutional purpose. Rather than asking, “What data could we collect?”, instead ask, “What data do we truly need — and for how long?”

Why data minimization matters

In a university environment, vast and diverse data sets are managed — student records, employee information, learning analytics, research data, health information and digital activity logs. While this information supports teaching, research and operations, unnecessary or excessive personal information collection increases risk without increasing value.

Practicing data minimization:

  • Reduces privacy and security risk by limiting exposure in the event of a data breach or misuse.
  • Supports regulatory and contractual obligations, including FERPA, HIPAA, GDPR (where applicable) and state privacy laws.
  • Strengthens institutional trust by demonstrating respect for individual privacy and autonomy.
  • Improves data quality and governance by focusing attention on accurate, relevant and purposeful information.

Simply put, the less sensitive personal information held without a clear need, the better positioned the university is to protect the community.

What data minimization looks like in practice

Data minimization is not about limiting innovation or academic freedom; it is about disciplined, intentional data practices. Across the institution, this means:

  • Purpose-driven collection: Clearly defining why personal information is needed before collecting it, especially in surveys, digital tools, learning technologies and research support platforms.
  • Least-necessary use: Ensuring access to personal information is limited to individuals and units with a legitimate role.
  • Retention with intent: Keeping personal information only as long as required by policy, law or documented business need — and securely disposing of it when no longer needed.
  • Third-party accountability: Evaluating vendors and partners to ensure they align with our data minimization and privacy expectations.

Everyone has a role

Data minimization is not solely an IT or compliance obligation — it is a shared institutional responsibility.

  • Faculty and researchers should consider whether identifiable personal data elements are essential to their academic or research goals.
  • Staff and administrators should review forms, systems and processes and work with data owners and stewards to determine what personal information can be kept and what could be redacted.
  • Leadership should model privacy-conscious decision-making and support governance structures that embed minimization into procurement, system design and policy.

By integrating data minimization into everyday decisions, everyone strengthens both privacy and operational resilience.

Moving forward

The commitment to data minimization reflects broader values: stewardship, accountability and respect for the individuals who entrust WSU with their information. As technologies evolve and data use becomes more complex, minimizing what is collected and retained is one of the most practical and impactful ways to uphold privacy.

Together, by collecting less, managing smarter and retaining only what is necessary, everyone protects the community and reinforce trust in the institution today and for the future.

For more information and resources on data minimization as it relates to privacy, visit WSU Privacy Website Information – Home. For more information on how to contact the Privacy Office or report a privacy concern, check out the Privacy Office website.

Information Security has released a new mandatory training for all WSU student employees. The training runs for about 40 minutes and will be delivered via a Blackboard course. Students who are required to take it should receive an email notifying them to take it. The training is due March 25.

This is the same training that employees were assigned through the KnowBe4 system, but student employees are required to take it through Blackboard instead.

If you have any questions or concerns about the training, reach out to askinfosec@wichita.edu.

A round information security logo with wheat shocks in the middle

The Information Security Department launched a new Information Security and Compliance training at the beginning of February replacing the current IT Security Awareness (ITSA) course in the Employee Required Training section of the myWSU portal.

In about 40 minutes, you will gain the essential knowledge to help protect WSU data and maintain compliance with regulatory requirements. Complete both modules assigned in the training campaign. Instructions have been compiled to help you navigate the system.

A round information security logo with wheat shocks in the middle

The Information Security Department launched a new Information Security and Compliance training at the end of last week replacing the current IT Security Awareness (ITSA) course in the Employee Required Training section of the myWSU portal.

In about 40 minutes, you will gain the essential knowledge to help protect WSU data and maintain compliance with regulatory requirements. Complete both modules assigned in the training campaign. Instructions have been compiled to help you navigate the system.

Now that you are familiar with the three most common types of WSU data sensitivity classifications, you can start to be proactive managers of the personal information you interact with. The foundation for achieving suitable privacy management comes from labeling information with the appropriate labels to help drive how it is accessed, stored and used.

Visit the Data Labeling Guide to find more specific information about how to apply labels to documents and emails. Data labeling is currently available to everyone and will be required for staff and faculty by the end of the year. If you have any questions about data labeling, or to request an in-person training for your department, reach out to askinfosec@wichita.edu. If you have any privacy related questions or concerns, reach out to privacy@wichita.edu or call 316-978-4447.

Thank you for being proactive privacy protectors over the information you hold.