Web Privacy

Sponsor: Information Technology Services
Contact: Chief Information Officer and Vice President for Information Technology Services
Category: Information Security and Technology
Number: 1000.006
Review Date: March 2024, biannually.
Implementation History: Approved: June 14, 2002 under the title “SUNY Empire State College Privacy Policy.” Revised: January 18, 2008 and title changed to “Web Privacy Policy." Revised March 2024.
Keywords: Web Privacy Policy

Purpose

This policy is consistent with the provisions of the Internet Security and Privacy Act, the Freedom of Information Law, and the Personal Privacy Protection Law

Background Information

This policy was last revised September 2023.

Definitions

The following definitions apply this policy:

Personal Information: Personal information collected by Empire State University typically includes an individual's name, email address, phone number, transcript, academic record, student organization membership, work history, work performance, letters of recommendation, demographic information, financial information, documentation provided to support financial aid applications (e.g., home address, social security number), donor information, IP addresses, browser and computer information, how users interact with the SUNY Empire website and electronic communications, and in some cases medical and health information and information observed as part of a research study. 

SUNY Empire: Shall mean Empire State University. 

User: Shall have the meaning set forth in subdivision 8 of section 202 of the State Technology Law, which is, any natural person who uses the internet to access a state agency website. 

Policy Statements

SUNY Empire is committed to protecting users’ privacy while making it easier and more efficient to interact with SUNY Empire. Users can access much of SUNY Empire's website without providing personal information. On occasion, SUNY Empire requires information to provide services users request (e.g., an application to attend SUNY Empire or technical assistance). Our commitment to privacy is the core principle of SUNY Empire's online information practices.  

On SUNY Empire’s website, users are prompted to enable cookies and similar tools (e.g., trackers) to allow SUNY Empire to understand our users’ experience.  

SUNY Empire does not collect personal information unless users provide that information voluntarily by sending an email, completing an online form, or completing an online application.  

This policy is consistent with the provisions of the Internet Security and Privacy Act, the Freedom of Information Law and the Personal Privacy Protection Law.

What We Collect and Why 

When a user visits the SUNY Empire website, SUNY Empire may automatically collect the following information about the visit: 

  • The internet protocol address of the computer that accessed the website.
  • The web page/URL from which the user accessed the current webpage. 
  • The type of browser, browser version, and browser operating system.
  • The date and time of the user's request. 
  • The pages visited and the amount of time spent on each page. 
  • Links and buttons clicked by the user. 

 
In addition, when users access a password-protected part of the website (e.g., MySUNYEmpire, Service Management Ticketing System), their username is collected automatically.  

None of the above-mentioned information constitutes personal information under the Internet Security and Privacy Act.  
 
Information collected automatically is used to improve website content and to help SUNY Empire understand how users interact with it. This information is collected for statistical analysis and to determine what information is most important to our users. The information is not collected for commercial marketing purposes, and SUNY Empire is not authorized to sell or disclose this information.  
 
Information collected is automatically deleted within 30 days of initial collection. Anonymized data is retained through a web analytics tool. This data is not associated with specific users but is presented in aggregate.

Information Collected When Users Complete an Online Form or Transaction  

If a user voluntarily completes an online form, the personal information they provide will be retained in a manner appropriate to complete their transaction.  

Caution: If a user submits personal information in an email, the information will be treated as if submitted by an adult and may, unless exempted from access by federal or state law, be subject to public access. 

Cookies

Cookies are text files stored on a user’s web browser to distinguish SUNY Empire’s website users. This is standard practice. SUNY Empire may use cookies to enhance or customize a user’s visit to SUNY Empire’s website. Some web browsers retain cookies by default; users can adjust their browser settings to refuse or delete cookies, although this may limit the user’s ability to use some website features. 

Information and Choice

SUNY Empire does not collect personal information unless a user provides that information voluntarily by sending an email, responding to a survey, or completing an online form. A user’s choice not to participate in these activities may limit ability to receive specific services or products through SUNY Empire’s website, although it should not impact ability to browse or download information.

Disclosure of Information Collected Through SUNY Empire Website 

Information collected through SUNY Empire’s website and disclosure of that information are subject to provisions of the Internet Security and Privacy Act. SUNY Empire will only collect or disclose personal information collected through SUNY Empire’s website if the user has consented to collection or disclosure of such personal information (e.g., logging into a password-protected page or disclosing information in a web form). 

Voluntary disclosure of personal information to SUNY Empire by the user, whether solicited or unsolicited, constitutes consent for SUNY Empire to collect and disclose the information for the stated purposes, as was reasonably ascertainable from the nature and terms of the disclosure. SUNY Empire may collect or disclose personal information without consent if the collection or disclosure is:  

  1. Necessary to perform the statutory duties of SUNY Empire, or necessary for SUNY Empire to operate a program authorized by law, or authorized by state or federal statute or regulation.
  2. Made pursuant to a court order or by law.
  3. For the purpose of validating the identity of the user. 
  4. Information to be used solely for statistical purposes in a manner that does not identify any particular person. 

Disclosure of information collected through SUNY Empire’s website is subject to provisions of the Freedom of Information Law and the Personal Privacy Protection Law. For additional information about SUNY Empire’s legal basis for collecting information, please see SUNY Empire’s General Data Protection Regulations Privacy Policy. www.sunyempire.edu/policies/?search=cid=121764 

SUNY Empire may disclose personal information to federal or state law enforcement authorities to enforce its rights against unauthorized access or attempted unauthorized access to SUNY Empire’s information technology assets and in accordance with SUNY Empire’s Acceptable Use policies for employees and students. https://www.sunyempire.edu/policies/?search=cid=35729 

Retention and Destruction of Personal Information 

Information collected through SUNY Empire’s website is retained by SUNY Empire in accordance with the records retention and disposition requirements of the New York State Arts and Cultural Affairs Law. SUNY Empire’s internet service logs are retained for 30 days and then destroyed. Information about record retention and disposition schedules can be obtained through the internet privacy policy contact listed in this policy. 

SUNY Empire will retain personal information for as long as there is a legitimate need to do so and in accordance with the SUNY Empire Records Retention and Disposition Policy and applicable federal and state law. Retention periods vary and are established considering our legitimate interests and all applicable legal requirements. 

Access to and Correction of Personal Information Collected Through this Website

SUNY Empire is committed to facilitating the exercise of the rights granted to users by the General Data Protection Regulation (GDPR) in a timely manner. In the context of our processing activities subject to GDPR, users have the following rights regarding personal information:

  • Access, correction and other requests. Users have the right to obtain confirmation of whether we processed their personal data, as well as the right to obtain information about the personal data we process about them. Users also have a right to obtain a copy of this data. Under certain circumstances, users may have the right to obtain erasure, correction, restriction, and portability of personal data. 
  • Right to object. Users have the right to object to receiving marketing materials from us by following the opt-out instructions in our marketing emails and text messages, as well as the right to object to processing personal data. In the latter case, we will assess the user’s request and reply in a timely manner, according to our legal obligations. 
  • Right to withdrawal consent. For all processing operations based on user consent, users have the right to withdraw consent at any time, and we will stop those processing operations as allowable by law. 

In addition to the rights provided by the GDPR, users may also have rights with respect to personal information pursuant to U.S. federal law, state law, and/or SUNY Empire policy. These include policies pertaining to student education records and policies pertaining to certain health records that SUNY Empire maintains. 

To exercise these rights, except the right to file a complaint with an EU supervisory authority, users must submit a request to the GDPR SUNY Empire contact listed at the bottom of this notice. If we are not certain of the requestor’s identity, we may ask for further personal information to be used for the purposes of replying to the request.  

Confidentiality and Integrity of Personal Information Collected Through SUNY Empire Website 

SUNY Empire is committed to protecting personal information collected through this website against unauthorized access, use, or disclosure. SUNY Empire limits employee access to personal information collected through SUNY Empire’s website to employees who require access to the information to perform their official duties. Employees who have access to this information must follow appropriate procedures in connection with personal information disclosures. 

SUNY Empire does not sell users’ personal information and only shares personal information with third parties if there is a legitimate institutional need to do so. SUNY Empire may share users’ personal information with the following recipients: 

  • SUNY System Administration and other campuses within SUNY to govern, administer, and improve the SUNY system. 
  • SUNY Empire's affiliated entities, including the SUNY Research Foundation, individual campus foundations, campus faculty/student associations, and other affiliated entities to provide ancillary services. 
  • SUNY Empire service providers that need access to a user’s personal information to provide services necessary to fulfill SUNY Empire’s mission or improve the student or employee experience. 
  • Accrediting agencies to obtain or maintain accreditations for SUNY Empire's (and its affiliates’) programs. 
  • Federal, state, and local governments or regulatory authorities as required by law or as necessary to fulfill SUNY Empire’s mission. 

SUNY Empire may provide anonymized data developed from personal information to third parties, such as government entities and research collaborators. Such anonymized data is outside the scope of this policy. Users have the ability to opt out of Google Analytics data collection through the Google Analytics Opt-out Browser Add-on

Security of Users’ Personal Information 

SUNY Empire has implemented procedures to safeguard the integrity of its information technology assets, including multi-factor authentication, monitoring, auditing, and encryption. Security procedures have been integrated into the design, implementation, and day-to-day operations of SUNY Empire’s website as part of SUNY Empire’s continuing commitment to the security of electronic content and electronic transmission of information. 

For website security purposes and to maintain website availability, SUNY Empire uses software to monitor traffic to identify unauthorized attempts to upload, change information, or damage SUNY Empire’s website. 

Disclaimer

Information provided in this privacy policy should not be construed as giving business, legal, or other advice, or warranting as failproof the security of information provided through this website. 

Contact Information

If you have questions regarding this internet privacy policy, email privacypolicy@sunyempire.edu or contact: 
Privacy Officer 
Empire State University  
3 Union Avenue  
Saratoga Springs, NY 12866 

Applicable Legislation and Regulations

This policy is consistent with the provisions of the Internet Security and Privacy Act, the Freedom of Information Law, and the Personal Privacy Protection Law.

Related References, Policies, Procedures, Forms and Appendices

Technology Acceptable Use - Employees 
Technology Acceptable Use - Students 
Password and Information Security Practices at Empire State University 
General Data Protection Regulations Privacy Policy  
Web Presence and Publishing Policy 
State Technology Law – Section 202 
Enterprise Data Classification Policy