Your privacy on the district network
The district network — computers, email, voicemail, telephones, internet access, and related systems — is owned and operated by the district in support of college and district programs. The district recognizes the privacy interests of faculty and staff, along with rights to free speech, participatory governance, academic freedom, and protected union activity. At the same time, the nature of electronic communication and the public character of district business make the network less private than many users expect, and no online activity on the district network should be relied upon as confidential. The district seeks to give email privacy protections comparable to those traditionally given to paper mail and telephone calls.
The district does not routinely inspect users' files, email, or messages, and does not disclose information stored in them without the user's consent. System administrators may access files or suspend services without notice only in limited circumstances: to protect system integrity, under critical operational circumstances, as required by law, or when there is reason to believe a violation of law or district policy has occurred. When the district must act without consent, it does so with the least review of contents necessary, and notifies the user as soon as possible afterward with the reason for the access.
Your responsibilities
Access to the district network is a privilege that requires responsible use. Users must respect the rights of other users, respect the integrity of district systems, and observe all applicable laws, regulations, and contractual obligations. For employees, intended use is what is reasonable and necessary for job duties; for students, what is reasonable and necessary for instruction. Incidental personal use is tolerated when it is occasional, ordinarily on the employee's own time, and does not interfere with or burden district operations.
Prohibited uses are defined in Administrative Procedure 3250 and include, among others: using accounts or passwords you are not authorized to use, attempting to gain unauthorized access to systems or to circumvent security protections, installing or spreading malicious software, forging email, harassment or threats by phone, email, or voicemail, commercial activity without written district authorization, and violating copyright law or software licenses — including illegal downloading or sharing of music, video, and other protected works. Misuse can result in loss of computing privileges, discipline under district policies and codes of conduct, and prosecution under applicable law.
If you believe this policy has been violated
Not all technical or security staff activity is misuse: actions authorized by district or college officials for security, enforcement, technical support, troubleshooting, or performance testing are not considered abuse of the network.
A user who believes the district or district personnel have violated this policy may file a complaint with their immediate supervisor, with copies to the Vice Chancellor of Human Resources and the employee's bargaining unit. The complainant's supervisor contacts the supervisor of the alleged violator, initiates an investigation if necessary, and determines a resolution in consultation with the Vice Chancellor of Human Resources. If the supervisor is part of the complaint, it is filed with the next level of supervision instead. Complainants are notified in writing when an investigation begins and of its outcome, and those dissatisfied with the resolution retain full recourse to contractual protections and legal action. The full complaint procedure is in AP 3250, linked below.
How the district protects personal information
The district retains selective personal information in electronic form on employees, students, contractors, and other individuals who do business with the district. Some types of personal information could cause significant harm if disclosed — financial loss, damaged credit, and other problems requiring extensive effort to repair — and state and federal laws, including the California Civil Code, FERPA, and PCI-DSS payment card standards, restrict how such information may be stored, displayed, or transmitted, and may require notifying affected individuals when it is compromised.
Protected personal information includes student records as defined in BP 5050 (Disclosure of Student Records), an employee's name in combination with their employee ID number, and payment card data such as card numbers, verification codes, and PINs. AP 3260 assigns layered responsibility for protecting this information: a Chief Information Security Officer at the district level, a designated lead authority for each college and for Central Services, and managers for each system and data resource that holds personal information. Colleges and departments are also urged to reduce the collection and retention of personal data that is not necessary for the district's educational and business needs.
Every employee's security responsibilities
All employees are responsible for protecting personal information under their control, destroying it when it is no longer needed, and cooperating with any investigation of a data breach. Employees must secure their own accounts: never share passwords or PINs, never reuse a district password on personal accounts, choose passwords that are hard to guess, and never send passwords in email or reveal them over the phone or in forms. Employees who handle payment cards have additional obligations under PCI-DSS, including never copying or storing card data and completing annual training.
If you suspect your account or password has been compromised, report it immediately to your manager and change your passwords.
Reporting a suspected security breach
A security breach is an incident in which someone's unencrypted personal information has been — or is reasonably believed to have been — exposed to or acquired by an unauthorized person, including through theft of a computer that may contain personal information. If you suspect a breach:
- Contact the ETS Call Center at (408) 864-8324 immediately during work hours, or the district police after hours.
- If the affected computer is on, disconnect it from the network by unplugging the network cable or turning off its wireless connection.
The ETS Incident Response Team analyzes the incident, and if personal information may have been compromised, the district follows the notification process in AP 3260, including notifying affected individuals as required by California law.
Policy documents
The information above is a summary. Final authority is determined by the Board of Trustees and the district policy documents, maintained in the district's official policy library (BoardDocs):