RUL - 80.01.2 Student Employment, Volunteer, and Internship Confidentiality Rule

Authority:
Human Resources
Responsible Office:
Human Resources
Contact:
Office of Human Resources, 919-530-6334; [email protected]
History:
Effective: April 16, 2016; Revised: July 1, 2026

1. Purpose

The purpose of this Rule is to establish requirements governing student employment, internships, volunteer service, and the protection of confidential information at North Carolina Central University ("University"). This Rule outlines expectations regarding confidentiality, access to University records and information systems, professional conduct, training requirements, and compliance with applicable federal and state laws, University policies, and UNC System requirements.

Individuals granted access to confidential information hold positions of trust and are responsible for protecting the privacy, security, and integrity of University information.

2. Definitions

2.1 Confidential Information.

Information protected from disclosure by federal or state law, University policy, contractual obligation, or other legal authority, including but not limited to student education records, personnel information, financial information, donor information, research data, protected health information, information security information, and other non-public University records.

2.2 University Information.

University-owned or managed computers, networks, software, databases, electronic communication systems, cloud services, and other technology resources.

3. Scope

This Rule applies to individuals who perform work or services for or on behalf of North Carolina Central University and who are not otherwise covered by another University policy governing employees or faculty. This includes, but is not limited to:

  • Student Employees
  • Federal and State Work-Study Students
  • Graduate Assistants
  • Student Stipend Recipients performing University duties
  • Interns
  • Volunteers
  • Any individual granted access to University records, systems, or confidential information through these roles

3.1 Departmental Confidentiality Policies

Departments may develop supplemental confidentiality procedures specific to their operations provided such procedures are consistent with University policies, applicable law, FERPA requirements, information security standards, and this Rule.

3.2 Confidential Information

Documents and files (both electronic and hard copy) containing confidential information shall be accessed, used, and disclosed only as necessary to perform assigned University duties.

3.2.1 Nondisclosure of Confidential Information

Confidential information acquired during employment or service with the University shall not be disclosed to unauthorized individuals within or outside the University.

3.2.2 Authorized Access

Individuals shall access student, employee, financial, donor, research, and other sensitive information only when there is a legitimate business or educational need to do so.

3.3 Regulatory Compliance

Individuals with access to student education records shall comply with the Family Educational Rights and Privacy Act (FERPA), Research, HIPAA, applicable UNC System requirements, and University procedures governing student information.

Departments shall require FERPA training prior to granting access to student education records.

3.4 Documents and Files

Documents and files containing confidential information must be disposed of in accordance with the University's Records Retention and Disposition Schedule Regulation (REG 01.04.2) and in a manner that renders the information unreadable or unrecoverable.

3.5 Administrative Safeguards

All individuals covered by this Rule shall use appropriate physical, technological, and administrative safeguards to protect confidential information regardless of format or medium.

Such safeguards include, but are not limited to:

  • Protecting passwords and authentication credentials;
  • Securing paper and electronic records;
  • Preventing unauthorized access to University systems;
  • Reporting suspected data breaches or unauthorized disclosures to a supervisor immediately;
  • Complying with University information security requirements.
  • Using only University-approved systems and devices to store or transmit confidential information;
  • Locking or logging off University devices when unattended.

3.6 Employment and Service Condition

Individuals who are authorized to access confidential information shall sign a Confidentiality Agreement as a condition of employment, internship, assistantship, work-study participation, stipend-supported assignment, or volunteer service.

Departments shall maintain signed confidentiality acknowledgments in accordance with University records retention requirements.

3.7 Return of University Property

Upon separation from employment or service, individuals shall promptly return all University records, equipment, identification cards, keys, electronic devices, access credentials, and other University property in their possession unless otherwise authorized by the University.

4. Responsibilities

4.1 Human Resources

The Office of Human Resources shall provide oversight for this Rule and may establish procedures, forms, training requirements, and guidance necessary to support compliance.

4.2 Departments

Departments utilizing student employees, interns, graduate assistants, stipend recipients, work-study participants, and volunteers shall:

  • Ensure compliance with this Rule;
  • Limit access to confidential information to authorized individuals;
  • Maintain required documentation;
  • Provide appropriate supervision and training.

5. Violations

Violations of this Rule may result in the revocation of access to confidential information or University information systems; removal from employment, internship, assistantship, stipend-supported assignment, work-study participation, or volunteer service; corrective or disciplinary action; referral through applicable student conduct procedures; or any other action authorized by applicable law or University policy.