Document Feedback - Review and Comment
Step 1 of 4: Comment on Document
How to make a comment?
1. Use this to open a comment box for your chosen Section, Part, Heading or clause.
2. Type your feedback into the comments box and then click "save comment" button located in the lower-right of the comment box.
3. Do not open more than one comment box at the same time.
4. When you have finished making comments proceed to the next stage by clicking on the "Continue to Step 2" button at the very bottom of this page.
Important Information
During the comment process you are connected to a database. Like internet banking, the session that connects you to the database may time-out due to inactivity. If you do not have JavaScript running you will receive a message to advise you of the length of time before the time-out. If you have JavaScript enabled, the time-out is lengthy and should not cause difficulty, however you should note the following tips to avoid losing your comments or corrupting your entries:
-
DO NOT jump between web pages/applications while logging comments.
-
DO NOT log comments for more than one document at a time. Complete and submit all comments for one document before commenting on another.
-
DO NOT leave your submission half way through. If you need to take a break, submit your current set of comments. The system will email you a copy of your comments so you can identify where you were up to and add to them later.
-
DO NOT exit from the interface until you have completed all three stages of the submission process.
(1) Processing student data is an integral part of the day-to-day operation of Hibernia College. As a (2) These guidelines are to support any Staff, Faculty or Adjunct Faculty member in the implementation of data protection principles in their role and in the day-to-day handling of student data. (3) The following seven principles underpinning data protection are dealt with in the Personal Data and Records Policy: (4) The following key data protection terms apply to this document: (5) Examples of students’ personal data held by Hibernia College includes but is not limited to: (6) Examples of Special Category Data (7) Examples of Criminal Offence Data (8) The GDPR gives individuals the right of access to their (9) (10) The College’s process for dealing with a DSAR is set out in the Data Subject Access Request (DSAR) Management Procedure. (11) Hibernia College Staff, Faculty and Adjunct Faculty should take care to ensure they are responding to a student’s official College email address, or students’ email as registered with the College, in all written communications. (12) When communicating with students on the phone, Staff, Faculty and Adjunct Faculty should ask two verification questions to verify the student’s identity before releasing any personal information. The first verification question should always be a request for their Student Number. Additional questions can include verification of registered address, telephone number and date of birth. (13) In instances where special category data is being requested, it may be appropriate to request the student to produce a copy of photographic identification in consultation with the Data and Records office, e.g. students requesting records of data they submitted as evidence in a formal process, such as requests for extensions and applications related to reasonable accommodations. (14) Whenever there is uncertainty about a person’s identity, the Records and Data Manager must be contacted without delay. (15) The Records and Data Manager will conduct an investigation and will notify all departments to hold all correspondence relating to the individual until their identity can be confirmed. (16) In cases where there is any doubt as to whether a personal data security breach has occurred, the Records and Data Manager should be consulted immediately. (17) Students can submit a Change of Personal Details Application Form to the Data and Records Office to update or amend their personal details. (18) Any requests received by other College Staff, Faculty and Adjunct Faculty should be forwarded to the Data and Records Office for processing. (19) Hibernia College Staff, Faculty and Adjunct Faculty should ensure that all documentation, records or correspondence which contain student data are drafted in consideration of the students’ right of access. (20) Accessing student data for usage outside of your contract with Hibernia College is strictly prohibited. Such prohibited usage includes but is not limited to personal interests or commercial interests. (21) Hibernia College Staff, Faculty and Adjunct Faculty should never discuss any aspect of a student’s grade or academic record with another person outside of the College. This includes the parent, spouse or friend of a student. Our contract is with the student alone. (22) If a student provides any Staff member with special category data, the Staff member should ensure that the special category data is passed to the appropriate Hibernia College Staff or Faculty member. Once the data has been passed to the appropriate person, the Staff member should permanently delete the data from their records. (23) When marking several (24) Ensure that feedback files are not mixed up with personal files on your device. (25) Do not save any (26) Once you have concluded marking an (27) Avoid paper records unless absolutely necessary. (28) Ensure that your password to Hibernia College systems including, but not limited to, Outlook, Quercus, MyHELMS and Inplace is strong and secure. Use a mixture of lowercase, uppercase, letters, numbers and special characters. Do not use a password that is the same as a password you use in other contexts. Ensure that your password is regularly changed. (29) Never allow another person to access the College information systems using your account. (30) If you suspect your account has been compromised, change your password immediately and contact the Hibernia College Information Technology department. (31) If you are accessing Hibernia College systems from a shared device, do not save your passwords. (32) Single Sign On (SSO) and Multi Factor Authentication (MFA) must be used where available. (33) Access to College Systems from outside Hibernia’s office network should be by a secure Virtual Private Network (VPN). (34) Never open unsolicited emails or click on any links within an email unless you are expecting the email and sure of the source. (35) Where possible, do not send files as attachments, but via a secure link. (36) Never leave your device unattended without ensuring it is password protected. Never leave your device unattended in an unsecure location for any reason. (37) Ensure your device is encrypted or password protected. (38) To safeguard against cyber-attacks, viruses and malwares, ensure your device is equipped with an adequate firewall and anti-virus software. (39) If your device is lost or stolen, contact the Records and Data Manager and the Information Technology department immediately. (40) When sending group emails, use MyHELMS wherever possible. (41) If, for a legitimate reason, you are required to use email for group correspondence, always send group emails via the ‘bcc’ field, not the ‘to’ field. If students can view the contact details of their classmates, this is a data breach. (42) Be very mindful when forwarding email threads from students as the content may contain protected or sensitive information that the subsequent recipient does not need to view or is not entitled to view. (43) If you discover, or even suspect a data breach, consult the Personal Data Security Breach Management Procedure and contact Data Protection Officer immediately at dpo@hiberniacollege.net (44) Where the College has determined that the data breach is likely to result in a risk to the rights and freedoms of data subjects, the data breach must be reported to the Data Protection Commission within 72 hours of first having become aware of the breach. (45) Data processors are also required to notify their customers, the controllers, ‘without undue delay’ after first becoming aware of a data breach. (46) Examples of data breaches include: (47) If you have any questions or concerns, feel free to contact the Data Protection Officer at dpo@hiberniacollege.net. Data Protection and the Handling of Student Data Guidelines
Section 1 - Introduction
Hibernia College and Student Personal Data
Who are these guidelines for?
Section 2 - What Is Data Protection?
Data Protection Principles
Definitions
Examples of Students’ Personal, Special Category Data and Criminal Offence Data
Top of PageSection 3 - Accessing Personal Data
Section 4 - How Can You Ensure You Are Handling Student Data Appropriately?
Part A - Taking Care in Identifying Student Personal Details
Verifying Student Identity
Cause for Concern for Student Identity
Change of Personal Details
Part B - Taking Care in Student Data Handling
Drafting Documentation
Unauthorised Use of Data
Confidentiality
Data Handling in Assessment
Part C - Practising Good Data Security
Keeping Your Access to Hibernia College Systems Secure
Device Safety
Email Correspondence with Students
Part D - Data Breaches
Discovering a Suspected Data Breach
Breach Notifications
Examples of Data Breaches
Part E - Questions or Concerns