Introduction: Data Stewardship
Data stewardship at the University of Vermont (UVM) is comprised of several different roles, each of which has specific responsibilities. Data Stewards understand the scope of data within their departments, schools, and divisions (herein referred to as “units”), including governance, collection, use, storage, disposal, and access of UVM data. Data Stewards recognize that data comes in any form: electronic, paper, recorded, and verbal and that data in all forms needs to be safeguarded. They participate in data governance initiatives, ensure compliance with technology procurement, privacy, security, access controls, and accessibility policies, and promote proper data use through planning, policies, guidelines, and protocols. Responsible for data quality and integrity, they ensure consistent data definitions and application across systems, collaborate and integrate with other department, school, and division data stewards those needs that overlap, and work with security, privacy and compliance, general counsel, and data governance leaders to classify data appropriately and provide training. The following Data Stewardship roles are intended to establish clear lines of accountability.
Data Trustees
At UVM, Data Trustees include Chief Officers, Vice Presidents, Vice-Provosts, and Deans, each responsible for the data collected, accessed, used, stored, and disclosed in their units. They ensure data is managed as an institutional asset in line with University policies, procedures, guidelines, and standards. Data Trustees appoint Data Stewards for their units and work with Data Stewards to ensure security requirements are met, develop security practices, and communicate effectively about access restrictions.
Data Trustees develop and maintain current data classification and ensure privacy, information security, and regulatory compliance practices are upheld and are consistent with existing Information Security, Privacy, Procurement, Computer and Network Acceptable Use and Accessibility Policies and Procedures. As needed, they obtain and ensure appropriate monitoring and enforcement of data use and/or confidentiality agreements. They disseminate information and guidance related to restrictions on information access and oversee proper removal of non-public protected data (NPPD) from University computing devices (e.g., computers, laptops, tablets, and smartphones) identified for sale, transfer, destruction, or disposal.
Data Trustees ensure staff have minimal access to data and restrict that access to that which is necessary for their roles. Data Trustees ensure that their units have processes to identify those individuals who have access to regulated or sensitive data and to ensure that these individuals have executed appropriate confidentiality agreements.
Data Trustees promptly report suspected data breaches and any evidence of compromised information or suspicious activity that could potentially expose, corrupt, or destroy information. They participate in breach investigations whenever necessary.
Data Stewards
Data Stewards are designated by and accountable to the Data Trustees. Data Stewards are employees(1) of UVM who serve in an administrative or business operations role with managerial and decision-making authority and who also have direct operational-level responsibility for the management of one or more categories of UVM data. Most often, Data Stewards will be an Assistant Dean, Director, Department Head, or Chair; however, a Data Trustee may determine that another individual is more appropriate to serve in this role. A unit may have more than one Data Steward depending on the type, sensitivity, and applicable policy/regulatory requirements.
Data Stewards recognize that data is both an institutional asset and a resource. Data Stewards must possess broad institutional knowledge of the data they oversee, including how it is collected, used, shared, and governed across the University. They are expected to understand how their data supports University business processes, and they are responsible for ensuring compliance with applicable policies and regulations.
It is crucial for Data Stewards to work effectively both within a team and across other unit teams to perform required tasks, communicate effectively in response to data-related questions, and convey information clearly in an easily understood format. Additionally, they should be able to target their style and communication methods to promote the proper use of the University's information resources. Their work must be sufficiently detailed to ensure the integrity and completeness of data, identifying inconsistencies when they arise.
There are five main areas of responsibility for a Data Steward. For each area, Data Stewards will work with Technology Managers(2) and other key stakeholders such as Data Trustees, the Information Security Council, and the Data Governance Council to define practices appropriate for their domains and to implement, over time, these rules and guidelines. These areas include: (i) Operational Oversight, (ii) Data Quality, (iii) Privacy, Security, and Risk Management, (iv) Policies and Procedures, and (v) Training and Communication.
Data Stewards understand that data residing in institutional systems has been assigned to a responsible office as specified in the Data Trustee, Steward & Custodian List. While Data Trustees are responsible for determining access levels, Data Stewards have responsibility for assigning and monitoring this access and for destruction; however, data stewards retain responsibility for developing rules and guidelines for data originating from these enterprise-wide systems that has been copied, downloaded, printed, or otherwise stored on local devices or in local locations. As it relates to destruction, Data Stewards may delegate these responsibilities to Data Custodians as outlined below.
Operational Oversight:
Within the framework of UVM’s Data Governance and Records Management (Records Management and Retention Policy, Records Retention Schedule, and Records Management Guidelines) Programs, Data Stewards oversee the lifecycle of the data for which they are responsible. This includes defining and implementing local policies and procedures for the day-to-day operational and administrative management of systems and data, including the collection, access, use, disclosure, storage, and destruction of data in all formats including, but not limited to, internal and external technology systems, paper, verbal and recorded. For processes in which the Data Steward is not the sole owner of the data, this also includes coordination with other process owners to ensure compliance with institutional policies and alignment with other local policies.
Data Quality:
Data Stewards are ultimately responsible for ensuring that data-quality metrics and requirements are appropriate and implemented. This includes defining acceptable values, ranges, and parameters for each data element. They work with other data offices and groups (such as the Office of Institutional Research and Assessment, Enterprise Technology Services, and the Data Governance Council) to detect and correct data quality issues, and collaborate with process owners to establish policies, procedures, guidelines, and internal controls affecting the quality of data. Data Stewards evaluate data regularly, identify anomalies and discrepancies, and contribute expertise to understand the root cause and implement corrective measures when issues are identified.
Data Destruction:
Data Stewards are responsible for the timely and complete destruction of records for which they are responsible. Most institution-level records are included in the records retention schedule and retention limits are determined in accordance with UVM’s Records Retention policy. Data Stewards are further responsible for developing and consistently applying retention practices for department records not listed in the schedule. Destruction responsibility may be delegated by the Data Steward to Data Custodians; however, the Data Steward maintains oversight responsibility.
Privacy, Security, and Risk Management:
Data Stewards are responsible for implementing UVM’s Information Security and Privacy Policies and Procedures within their areas of responsibility. They manage privacy, information security, and risk for the data they oversee. They are also responsible for developing local unit privacy and security policies and procedures for any data specific to that particular unit that has legal or regulatory privacy/security requirements. Local policies must be at least as restrictive as institutional policies and cannot be less restrictive.
Policies and Procedures:
Data Stewards, in alignment with the Chief Privacy Officer and the Chief Information Security Officer, are required to create procedures, guidelines, and controls at the unit level to maintain privacy and security measures in downstream systems and processes. Data Stewards must be knowledgeable about policies related to retention, archival, disposal, and destruction of data, technology procurement, information security, and accessibility requirements. They must implement data management programs, policies, procedures, and guidelines to ensure compliance with university and regulatory standards throughout the data lifecycle.
Training and Communication:
Based on roles, types of data, level of risk, university policies, and/or regulatory requirements, the Data Steward must ensure that awareness and other training has been assigned and completed by those who are provided access to UVM institutional data. The Data Steward is also responsible for constant communication and dissemination of information as it relates to privacy, information security, and other data governance areas.
(1) Students (including graduate students in their role as a student), student employees, affiliates, volunteers, contractors, temporary employees, vendors, or any other third party are never appropriate to serve in a Data Steward role. Graduate students who are also employees may be appointed Data Steward as long as they possess all the other requirements.
(2) Includes both Enterprise Technology Services (ETS) and non-ETS managers who are responsible for deploying IT systems.
Technology Managers
Technology managers include both UVM Enterprise Technology Services (ETS) and non-ETS managers. They ensure deployed IT systems are secure, have appropriate controls in line with University policies including, but not limited to, technology procurement, information security, and accessibility policies. This includes physical security, backup and recovery processes, provisioning access to UVM IT Resources, and implementing controls over UVM data. Technology Managers understand business needs and ensure operational procedures comply with university policies and standards. In consultation with Data Stewards, Technology Managers review Data Sharing Agreements for compliance with data handling and protection requirements outlined in the agreement.
Data Custodians
Data Custodians include employees and distributed campus technology personnel who are assigned responsibilities specific to their unit’s user areas. This includes data management, access management, records retention and destruction, privacy, and/or information security responsibilities. Data Stewards may delegate destruction responsibilities to Data Custodians. In this case, the Data Custodian is responsible to ensure that regulated, protected, or sensitive data is destroyed in accordance with UVM policy.
Data Guardians
Data Guardians are supportive, but parallel, to the rest of the roles outlined under UVM’s Data Stewardship Program. Data Guardians include personnel from the following units: Enterprise Technology Services (ETS), Office of Compliance and Privacy Services (OCPS), Office of Institutional Research and Assessment (OIRA), and the Larner College of Medicine Technology Services (LCOM-TS). Data Guardians monitor data activities and implement system- and institutional-level access, security, and privacy controls required by Data Stewards.
Subject Matter Expert (SME)
For data governance purposes, a subject-matter expert (SME) or domain expert is a person who is an expert in a particular area, topic, or regulation (e.g., Privacy, Data Security, Access Management, Copyright, Research Compliance).
Data Users
Data Users include any person granted access to UVM IT resources (including systems, technology, information, and/or data) and to UVM NPPD in any format (e.g., paper, verbal, recorded). Data Users include faculty, staff, students (undergraduate and graduate), and other third parties and affiliates (e.g., affiliated organization employees, contractors, partners, volunteers). These individuals play a critical role in protecting the confidentiality, privacy, and security of University data while ensuring appropriate access, accuracy, and timeliness.
All Data Users are responsible for completing required University-administered cybersecurity, privacy, and data governance training related to their roles in University business. They must report unauthorized access, data misuse, or potential privacy and security incidents to UVM InfoSec Incident Information or by submitting a report to UVM’s Privacy Office. Reports can also be made using UVM’s Ethics and Compliance Reporting and HelpLine (the HelpLine).
In the event a Data User uses a personal device to access NPPD, the personal device must also meet UVM’s security requirements.
Data Users are tasked with safeguarding Non-Public Protected Data (NPPD) as defined in UVM’s Privacy Policy throughout its lifecycle. Responsibilities include:
- Ensuring login credentials, including those for personal devices if used to access UVM NPPD, are secure and never shared, and workstations are properly protected.
- Encrypting transmitted NPPD and using appropriate physical controls, such as locking doors and filing cabinets.
- Ensuring that devices used to access NPPD, including personal devices if applicable, are set up to require authentication (e.g., username/password, PIN, biometric identifier) and that they automatically lock after five minutes of inactivity.
- Avoiding the storage of NPPD on unencrypted devices or locations and refraining from transmitting it via unencrypted methods such as email, text, or chat.
- Using encryption methods approved by the Information Security Office for all transfers of NPPD.
If unsure of specific security requirements, Data Users must treat information as maximally protected until verified by a Data Steward, Data Trustee, or a member of the Information Security Office or the Privacy Office.
Data Governance Council
The Data Governance Council (DGC) is comprised of individuals from across key functions and departments of the University, many of whom also have the role of Data Trustee, Data Steward, or Data Custodian. More information regarding the Data Governance Program can be found on UVM’s Data Governance website. The Data Governance Council will be responsible for facilitating institution‑wide coordination and decision‑making related to shared data systems, common data definitions, and enterprise metrics. The Council focuses on governance of the data itself (its meaning, use, and consistency) rather than the technical design, operation, or maintenance of systems, which remain the responsibility of Enterprise Technology Services (ETS).