Policy Regarding University Information on Personal Information Technology Resources

Policy Regarding University Information on Personal Information Technology Resources

Policies & guidelines
Woman works on her laptop in a library.

Overview

This policy sets out requirements for University access to electronic information to ensure business continuity and compliance with the University’s contractual and legal obligations.  This policy is adopted in recognition of (1) the essential role that information technology plays in the day-to-day operations at Harvard; (2) the vast range of IT tools, systems, platforms, and other resources adopted and used across the University; and (3) the University’s need to ensure the availability of and ready access to digital information created, received, and stored in the conduct of University Business. 

Background

The University expects that Covered Persons will use IT Resources provided or administered by the University to conduct University Business, including but not limited to email and other communications platforms provided by Harvard.  The University recognizes that the use of personally-owned computers and smartphones and other non-Harvard IT Resources for University Business may be warranted, and, in such cases, electronic information related to University Business on those IT Resources must be available to the University where required for legitimate and important business purposes. 

Policy Statement

When requested for legitimate and important University purposes, Covered Persons are required to provide their assistance and cooperation to ensure that the University can access electronic information related to University Business on IT Resources, whether or not such IT Resources are provided or administered by the University.

Required University access will be undertaken subject to the same principles, safeguards, and documentation and reporting requirements as are set forth in the University’s Policy on Access to Electronic Information. 

Implementation of Policy

Configuration of University IT Resources  

When procuring or provisioning IT Resources for the University, representatives of Harvard University Information Technology and the several Chief Information Officers (CIOs) should take reasonable steps to ensure that each IT Resource enables systems administrators to preserve and collect electronic information from the IT Resource.

Right of Access to IT Resources

As necessary, the University will preserve and collect electronic information from IT Resources provided or administered by the University in accordance with the AEI Policy, where applicable.

In the event that either an IT Resource provided or administered by the University does not support University-initiated preservation and collection of electronic information or a Covered Person conducts or engages in University Business using a non-University IT Resource (including but not limited to using outside or personal email to communicate on University Business), Harvard may request that the Covered Person provide the University with access to electronic information related to University Business, and the Covered Person shall be required to provide such access, provided that such access is undertaken subject to the same principles, safeguards, and documentation and reporting requirements as are set forth in the AEI Policy.

In addition, upon learning that electronic information related to University Business is stored on a non-Harvard IT Resource, Harvard may require such information to be removed from such IT platform or user account, and stored within an IT Resource provided or administered by the University. 

Definitions

Covered Persons” include Harvard officers, administrators, employees, faculty, fellows, and other academic appointees, when they are conducting or engaging in University Business.

IT Resources” includes any application, platform, service, network, computer, tablet, smartphone, or other device that generates, stores, or transmits electronic information. IT Resources may be owned, provided, or administrated by the University or may be personal or third-party IT Resources.

University Business” means the carrying out of Harvard activities, including for example, teaching, research, administrative services, programs and events, and business operations.  It includes activities carried out by a Covered Person in connection with their employment or appointment at the University.

AEI Policy” means the current and effective version of Harvard University’s Policy on Access to Electronic Information. 

Other Policies

This Policy should not be read to supersede any provision of the following policies:

In addition, this Policy is intended to be read consistently with the Office of the Vice Provost for Research’s Retention and Maintenance of Research Records and Data: Principles and Frequently Asked Questions (“FAQ”) guidance document. 

Oversight/Amendments

This policy and its implementation shall be subject to periodic review and amendment as needed by the University’s Chief Information Officer, in consultation with the Office of the General Counsel.