Educause Security Discussion mailing list archives

Re: Sample GDPR consent forms for Higher Education


From: Jim Williams Jr <Jim.Williams () PCT EDU>
Date: Thu, 26 Apr 2018 18:57:18 +0000

Thank you Joanna,
I appreciate the document that you shared.  The consent language is of a great help, but we are also looking at the 
format that other institutions are using.  We are really starting from scratch, and that type of guidance would be of a 
great help.
I have found some templates from online searches,  but if anyone has some templates that they used as a starting point 
for their own process we would appreciate the information.

Take care everyone and thank you,

James Williams, MPS
Pennsylvania College of Technology
Manager of IT Security | Information Technology Services
Jim.Williams () pct edu<mailto:Jim.Williams () pct edu> | 570-329-4997





From: The EDUCAUSE Security Constituent Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Andrew 
Luchsinger
Sent: Thursday, April 26, 2018 1:58 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Sample GDPR consent forms for Higher Education

Thank you!
On Thu, Apr 26, 2018 at 12:53 PM Joanna Grama <jgrama () educause edu<mailto:jgrama () educause edu>> wrote:
Hello,
The University of Cambridge recently shared their GDPR toolkit with EDUCAUSE. You can find it here:  
https://library.educause.edu/resources/2018/4/toolkit-to-help-university-institutions-prepare-for-new-data-protection-legislation-gdpr

There is some example consent language in the templates at the back of the toolkit.  They are broken up by type of 
consent needed, because the consent requirements for GDPR require specific consent for a specified purpose.  It looks 
like the creators of the Cambridge toolkit tried to outline some of the most common scenarios.

If you have general counsel that belongs to NACUA, ask them to check the NACUA library for documentation examples. My 
understanding is that there are a number available there for NACUA members.

Kind regards,
Joanna


Joanna Grama, JD, CISSP, CRISC, CIPT
Director of Cybersecurity and IT GRC Programs

EDUCAUSE
Uncommon Thinking for the Common Good
282 Century Place, Suite 5000, Louisville, CO 
80027<https://maps.google.com/?q=282+Century+Place,+Suite+5000,+Louisville,+CO+80027&entry=gmail&source=g>
direct: 720.406.6769<tel:(720)%20406-6769> | jgrama () educause edu<mailto:jgrama () educause edu>

Become a Member- Everyone at your organization is an EDUCAUSE member when you join | Access discounts, resources, and 
valuable peer networks | Discover membership<https://www.educause.edu/about/discover-membership>



From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () 
LISTSERV EDUCAUSE EDU>] On Behalf Of Jim Williams Jr
Sent: Thursday, April 26, 2018 1:09 PM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: [SECURITY] Sample GDPR consent forms for Higher Education

My apologies in advance if this is a repeat subject.

Does anyone have any resources or templates to assist in the creation of a GDPR Consent form?  We are in need of 
creating a consent form, but I would like to find some direction from other Higher Ed organizations.

Thank you in advance for any help that you would be able to give.

James Williams, MPS
Pennsylvania College of Technology
Manager of IT Security | Information Technology Services
Jim.Williams () pct edu<mailto:Jim.Williams () pct edu> | 570-329-4997<tel:(570)%20329-4997>


________________________________
This email may contain confidential information about a Pennsylvania College of Technology student. It is intended 
solely for the use of the recipient. This email may contain information that is considered an “educational record” 
subject to the protections of the Family Educational Rights and Privacy Act Regulations. The regulations may be found 
at 34 C.F.R. Part 99 for your reference. The recipient may only use or disclose the information in accordance with the 
requirements of the Federal Educational Rights and Privacy Act Regulations. If you have received this transmission in 
error, please notify the sender immediately and permanently delete the email.

________________________________
This email may contain confidential information about a Pennsylvania College of Technology student. It is intended 
solely for the use of the recipient. This email may contain information that is considered an “educational record” 
subject to the protections of the Family Educational Rights and Privacy Act Regulations. The regulations may be found 
at 34 C.F.R. Part 99 for your reference. The recipient may only use or disclose the information in accordance with the 
requirements of the Federal Educational Rights and Privacy Act Regulations. If you have received this transmission in 
error, please notify the sender immediately and permanently delete the email.

Current thread: