Responsibilities of Data Handlers
All data handlers who can access or update the data as part of their job should at all times ensure that:
- data are only used for the purpose(s) for which they are collected ;
- data confidentiality is maintained at all times;
- data accuracy is maintained;
- data are held securely; and
- health and medical record;
- confidential data is retained for the legitimate interests of the University, whether held in paper format or electronically, are securely destroyed when no longer required.
Security of data
All data handlers should ensure that personal data are:
- kept in a locked filing cabinet, drawer or room, whether it is in paper or electronic when not being worked on or when the office is left unattended (even for a short time);
- not visible, either on desks or on computer screens, to anyone not authorized to see it — ensure screen savers and computer screen locks are used;
- sent in a sealed envelope, if transmitted either internally or externally (i.e transporting of grade sheet, class record, grade slip and other academic records of students);
- not sent via e-mail if it is sensitive information;
- not disclosed orally or in writing without the permission of the data subject unless it is part of a legitimate University process (i.e releasing of grade slip to the student must ascertain the identity of the student with his/her valid ID and must be properly documented);
- not left on shared printers/photocopiers; and
- disposed of securely in line with the University Personal Data Disposal Policy.