OSU IT Data Governance and Privacy — Key Concepts and Practices
Purpose and scope of data collection
- Institutions gather feedback and data from students for multiple important reasons.
- Primary purpose: to improve the institution by ensuring programs are effective, relevant, and updated.
- Achieved through assessments of what students are actually learning, what they think they're learning, and what faculty want to teach.
- Also verify that student academic and support services are valuable and useful to students.
- OSU IT aims to ensure graduates have what they need to be successful and that employers find what they are looking for in our graduates (OSUHU graduates).
Data lifecycle and continuous improvement
- Data are tracked over time to identify trends.
- Look for consistent and continuous improvement or identify areas of decline.
- Declines may indicate a need to implement changes.
- Much of the data collected is used for reporting and is required (e.g., accreditation, funding, compliance).
Accreditation and its implications
- Accreditation is essential to colleges and universities.
- Impacts:
- Student financial aid (private, state, and federal funding opportunities).
- Future employment opportunities for graduates.
- Ability to transfer and continue education at a higher level.
- Note: The module mentions to click the term “accreditation” in the sidebar to learn more.
Third-party studies and benchmarking
- Reporting is also done for third-party studies to compare data and student outcomes with:
- Nationally, or with institutions similar to OSU IT.
- Note: The module mentions to click the term “third parties” in the sidebar to learn more.
Types of data collected
- Personal information is information about you that is often publicly available and cannot be identified on its own; this is often referred to as demographic data.
- Examples: age, gender, race.
- Sensitive information (numbers you wouldn’t share because they uniquely identify you) include:
- Social security number, home address, driver’s license number, banking information.
- When you enroll, OSU IT collects additional sensitive information.
- Student ID numbers should not be shared and are used internally to track enrollment and academic records; this is considered sensitive PII (personally identifiable information).
- Direct feedback on satisfaction with institutional services and resources is collected throughout your time in college.
- Raw feedback is not published; it is summarized into themes to identify common concerns and ideas.
Feedback, reporting, and data usage
- Direct feedback helps decision making and improvements at OSU IT.
- Raw feedback is transformed into themes to spot common trends.
Data publication, aggregation, and privacy protections
- OSU IT publishes aggregate data only (not raw data).
- This means data are summarized and analyzed before publication.
- Example of aggregate statistics:
- 30% of students indicated they were unsatisfied with the service in that department.
- 60% of those enrolled were male.
- 50% were white.
- De-identification: PII is completely redacted or hidden in published data.
- Anonymization: when more detailed trends are needed, we may assign a random number to replace a name or a student ID number.
- To eliminate any risk of identification, we may exclude all uniquely identifying data entirely.
Data publication locations and accessibility
- The Office of Institutional Research (OIR) website hosts almost all official and approved OSU IT data, including:
- Campus statistics
- Results of student feedback surveys and evaluations
- Annual reports to state and federal agencies and accreditors
- These published reports are easily downloadable.
- Potential students and their families use this information to decide if OSU IT is the right fit.
- If you have questions, you can contact OSU IT directly.
- Sidebar links also provide second-party data locations where OSU IT data are published.
Practical implications, ethics, and governance
- Data governance and privacy concerns:
- Aggregation reduces identifiability and protects privacy.
- De-identification and anonymization are used to mitigate re-identification risks.
- Ethical considerations include informed use of data, transparency about what is collected, and minimizing harm through data handling practices.
- Practical implications include compliance with accreditation requirements, funding eligibility, and maintaining trust with students and stakeholders.
Final reminders
- You have completed all data literacy module lessons.
- Review all content before submitting the final assignment.
- You are encouraged to contact OSU IT with questions.