Private Personal Information (PPI)

Private Personal Information (PPI) is a category of sensitive information that is associated with an individual person, such as an employee, student, or donor. PPI should be accessed only on a strict need-to-know basis and handled with care.

PPI is information that can be used to uniquely identify, contact, or locate a single person. Personal information that is “de-identified” (maintained in a way that does not allow association with a specific person) is not considered sensitive.

Appropriate protection of PPI that is not publicly available is required by Laws and Regulations Related to Handling Sensitive Protected Data, contractual obligations, and university policies. These regulations apply to PPI stored or transmitted on any type of media: electronic, paper, microfiche, and even verbal communication.

Frequently Used by: 

Faculty
Staff
Students
Researchers

Category: 

Sensitive

Examples: 

For Employees:

  • Social Security Number
  • National ID Number
  • Bank account numbers
  • Tax information (W2, W4, 1099)
  • Date and location of birth
  • Country of citizenship
  • Citizenship status
  • Visa permit data
  • Driver’s license
  • Gender
  • Ethnicity
  • Disability information
  • Marital status
  • Military status
  • Criminal record
  • Home address
  • Grievance information
  • Discipline information
  • Leave-of-absence reason
  • Benefit information
  • Health information

For Students:

  • Grades/transcripts
  • Class lists or enrollment information
  • Student Financial Services information
  • Athletics or department recruiting information
  • Credit card numbers
  • Bank account numbers
  • Wire transfer information
  • Payment history
  • Financial aid, grant, and loan information
  • Student tuition bills
  • Ethnicity
  • Advising records
  • Disciplinary records

M+Box Core Apps: 

Permitted

M+Google Mail and Calendar: 

Permitted

M+Google Drive (Docs): 

Permitted

M+Google Sites, Talk, Groups, Tasks: 

Permitted

M+Google Additional Services (Non-Core): 

Not Permitted

M+Box Additional Apps (Non-Core): 

Not Permitted

Personal Device (phone, tablet, laptop, etc.): 

Not Permitted

Personal Account (Dropbox, Evernote, etc.): 

Not Permitted

UMHS Exchange Email and Calendar: 

Permitted

CTools: 

Permitted

Wolverine Access: 

Permitted

MiDatabase: 

Permitted

MiServer: 

Permitted

Desktop Virtualization (VDI): 

Permitted

TSM Backup: 

Permitted

MiWorkspace: 

Permitted

Sitemaker: 

Not Permitted

Virtualization as a Service (VaaS): 

Permitted

Value Storage: 

Not Permitted

Mainstream Storage: 

Permitted

Data Warehouse: 

Permitted

ITS Exchange Email and Calendar: 

Permitted

Desktop Backup (Powered by CrashPlan): 

Permitted

Flux: 

Permitted