Volume VIII: Records Chapter A: Records Responsible Executive: Chief Financial Officer and Treasurer Responsible Office: Office of the Bursar Date Issued: March 16, 2009 Date Last Revised: July 15, 2019
Contacts Statement of Policy Reason for This Policy Individuals and Entities Affected Exclusions Responsibilities Definitions (defined terms are capitalized throughout the document) Related Documents, Forms and Tools Website Address for This Policy History and Updates Appendix
Office of the Bursar765-494-7574 | askbursar@purdue.edu
Fort Wayne: Office of the Bursar260-481-6824 | bursar@pfw.edu
Northwest: Office of the Bursar219-989-2560 or 219-785-5338 | bursar@pnw.edu
West Lafayette: Office of Bursar765-494-7574 | askbursar@purdue.edu
The Identity Theft Prevention Program detects, prevents and mitigates Identity Theft related to Covered Accounts. The Program considers the following risk factors in identifying relevant Red Flags for Covered Accounts as appropriate:
The Program incorporates relevant Red Flags from sources such as:
The Program addresses the detection of Red Flags in connection with the opening of Covered Accounts and existing Covered Accounts by:
The Program provides for appropriate responses to detected Red Flags to prevent and mitigate Identity Theft as outlined in the Procedures for Identity Theft Prevention. The response will be commensurate with the degree of risk posed.
Purdue University maintains procedures for processing a Notice of Address Discrepancy received from a consumer reporting agency indicating the address given by the Consumer differs from the address contained in the consumer report.
The University also maintains procedures intended to assess the validity of a change of address upon receipt of a request for an additional or replacement University ID card within 30 days of a notification of an address change. An additional or replacement card will not be issued until an assessment of the validity of the address change has occurred.
Refer to the Procedures for Identity Theft Prevention for detailed information.
Staff training is provided annually by each campus to all employees, officials, and contractors who might reasonably come into contact with Covered Accounts that may constitute a risk to Purdue University or its Customers. Additional training will be made available if significant changes are made to the Program.
Purdue University will exercise appropriate and effective oversight of service provider arrangements involving those service providers with access to Covered Accounts or information regarding Purdue’s Customers under this Program.
The Identity Theft Prevention Program is established to detect, prevent and mitigate Identity Theft in connection with the opening of a new Covered Account or maintenance of an existing Covered Account and to provide continued administration of the program in compliance with the Fair and Accurate Credit Transactions (FACT) Act of 2003, as implemented through 16 CFR Part 681.1, 681.2, and 681.3.
All individuals and entities who have a Covered Account with the University and all units, individuals and contractors responsible for creating and/or monitoring Covered Accounts for the University.
There are no exclusions to this policy.
Chief Financial Officer and Treasurer
Assigned Resources
Information Security Governance Committee
Third-party Contractors and Service Providers
All defined terms are capitalized throughout the document. Refer to the central Policy Glossary for additional defined terms.
Assigned Resource A unit of the University or a contracted third-party entity identified by the Information Security Governance Committee as responsible for addressing Red Flags. Assigned Resources include, but are not limited to:
Creditor A person or entity that arranges for the extension, renewal, or continuation of credit, which in some cases could include third-party debt collectors.
Consumer An individual.
Covered Account General activity relating to tuition/fee or receivable billing, student loan origination and servicing, and ID card deposit account maintenance.
Customer A person that has a “covered account” with a financial institution or creditor.
Identity Theft Fraud committed or attempted using the identifying information of another person without authority.
Information Security Governance Committee The committee, as defined in the policy on Information Security and Privacy (VII.B.8), tasked with oversight of this Program.
Notice of Address Discrepancy A notice sent to a user of a consumer report by a Consumer Reporting Agency pursuant to 15 U.S.C. 1681c(h)(1), that informs the user of a substantial difference between the address for the Consumer provided by the user in requesting the consumer report and the address or addresses the Consumer Reporting Agency has in the Consumer’s file.
Personally Identifiable Information An individual’s first name and last name or first initial and last name and at least one of the following data elements: Social Security Number, driver’s license number or identification card number, and account number, credit card number, debit card number, security code, access code, or password of an individual’s Covered Account.
Program The Identity Theft Prevention Program.
Red Flag A pattern, practice, or specific activity that indicates the possible existence of identity theft. The following Red Flags have been identified for inclusion in the Program:
Procedures for Identity Theft Prevention
Information Security and Privacy Program
Identity Theft Red Flags and Address Discrepancies Under 16 CFR Part 681
www.purdue.edu/vpec/policies/records/viiia2
July 15, 2019: Updated Contacts. Updated definition of Information Security Governance Committee and Red Flags, and added definition of Assigned Resource. Incorporated language from the procedures into Statement of Policy and Responsibilities sections and removed remaining procedures to separate document.
November 18, 2011: Policy number changed to VIII.A.2 (formerly VI.2.2).
March 16, 2009: This is the first such policy for this Program. The BOT approved the Program at its stated meeting on April 10, 2009.
There are no appendices to this policy.