Elmhurst University Biometric Privacy Policy

Elmhurst University (“Elmhurst” or “the University”) may use biometric identification systems to increase security, control access to certain campus facilities, and other specialized uses.

The University recognizes the sensitivity of Biometric Data, as defined below, and takes seriously its obligations to maintain the confidentiality of this data and protect its security in accordance with various regulatory obligations and in fulfillment of its stewardship of information provided to it by students, employees, and other constituents.

Policy Statement

Wherever the University implements systems utilizing Biometric Data, it will implement suitable controls and take other appropriate steps to protect the security and privacy of this data in accordance with appropriate regulatory and other relevant obligations.

Purpose

In accordance with the Illinois Biometric Privacy Act, 740 ILCS 14/1 et seq., and other laws and regulations, the policy sets forth the University’s procedures for disclosure, storage, and destruction of Biometric Data, as defined below.

Scope

The scope of this policy includes students, faculty, staff, other relevant constituents, and relevant third-party contractors.

Definitions

  • Biometric Identifier. A retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry.
  • Biometric Information. Information, regardless of how it is captured, converted, stored, or shared, based on an individual’s biometric identifier used to identify an individual.
  • Biometric Data. A collective term for biometric identifier and biometric information.

Implementation

I. Consent

An individual’s Biometric Data will not be collected or otherwise obtained by Elmhurst University without prior written consent of the individual. The consent form will inform the individual of the specific reason the Biometric Data is being collected and the length of time the data will be stored.

II. Disclosure

In circumstances where Elmhurst retains Biometric Data, the University will not disclose or disseminate any Biometric Data to any third party unless:

  1. Disclosure is required by state or federal law or municipal ordinance;
  2. Disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction;
  3. The disclosed data completes a financial transaction requested or authorized by the student, employee, or other constituent; or
  4. The student, employee, or other constituent has consented to such disclosure or dissemination.

III. Storage

In circumstances where Elmhurst retains Biometric Data, the University will use a reasonable standard of care to store, transmit and protect from disclosure any paper or electronic Biometric Data collected. Storage, transmission, and protection from disclosure shall be performed in a manner that is the same as or more protective than the manner in which the University stores, transmits and protects from disclosure other confidential and sensitive information that is used to uniquely identify an individual.

IV. Retention Schedule

In circumstances where Elmhurst retains Biometric Data, the University will permanently destroy an individual’s Biometric Data within six (6) months of when the initial purpose for collecting or obtaining such Biometric Data has been satisfied, such as:

  1. The employee’s employment is terminated;
  2. The student graduates or otherwise leaves the University;
  3. The employee transfers to a position for which the Biometric Data is not used; or
  4. The University no longer uses the Biometric Data.

V. Vendors and/or Licensors

If any of the University’s vendors and/or licensors require access to Biometric Data from the University in order to satisfy any contractually obligated performance on behalf of the University, the University will require that they shall protect the data in a manner that is the same as or more protective than the above defined disclosure, storage and retention schedule sections, unless other specific arrangements are necessary to satisfy contractual and legal obligations.

Enforcement

This policy will be enforced in a collaborative approach across the University, including:

  • Information Services;
  • Departmental personnel;
  • Other University personnel

Updated March 4, 2021

Connect with #elmhurstu