EKU Privacy Statement

Google Analytics

The Eastern Kentucky University web properties use Google Analytics, a web analytics tool that provides data on user engagement and website usage. Google Analytics uses cookies, which store data on user computers, and transmits data to Google for processing and storage.

EKU uses multiple Google services, as well as other web services for purposes of advertising and improving marketing efforts. These services may include the following: Remarketing, Google Display Network Impression Reporting, the DoubleClick Campaign Manager integration, Google Analytics Demographics and Interest Reporting, User-ID Reporting, Conversion Tracking, or website experiments. These services are used to improve the website, customer service, and overall marketing and communications.

Website visitors may opt-out of Google Analytics for Display Advertising and customize Google Display Network ads by visiting the Ads Preferences Manager. By using our sites, you consent to the terms of the EKU Privacy Statement.

European Union General Data Protection Regulation Privacy Notice

The European Union’s General Data Protection Regulation (“GDPR”) is a data privacy law that applies to personal information collected in or from the European Union and European Economic Area. Eastern Kentucky University (“EKU”) is committed to safeguarding the privacy of personal information, including compliance with the GDPR. This Privacy Notice outlines the collection, use, and disclosure of personal information provided to EKU by individuals, (hereinafter “Information Providers”) including but not limited to: students, faculty and staff, alumni, and other members of our community.

When information is submitted to EKU or you use EKU's websites and other electronic data services, you consent to the collection, use, and disclosure of that information as described in this Privacy Notice.

Does the GDPR Notice Apply to Me?

This GDPR Privacy Notice applies to you if:

  • You are a “Person” or “Data Subject”—meaning a natural person, not a corporation, partnership, or other legal entity—who is physically present in the EEA;
  • It is with respect to your “Personal Information”—meaning any information relating to an identified or identifiable person—that is provided while you are physically present in the EEA;
  • Such Personal Information is not earlier or later provided to the University while you are outside the EEA; and
  • Such Personal Information is provided to the University:
  • During the course of the University offering you goods or services;
    • While the University is monitoring your behavior or health;
    • While you are associated with any of the University’s programs;
    • While you are participating in clinical research programs; or
    • While you are receiving health treatment.

Please note that information pertaining to current, former, or prospective employment with the University in the United States is not considered “Personal Information” and is excluded from this GDPR Privacy Notice.

Definition of Important Terms

EKU may use, collect and/or disclose “Information” and “Sensitive Information” for its legitimate business purposes. As used herein, “Information” refers to all personal data, excluding Sensitive Information, concerning a natural person, created by or provided to EKU by or about an Information Provider.

“Sensitive Information,” as used herein, is Information about an Information Provider’s race, gender, ethnic origin, religious affiliation, health data and criminal convictions.

EKU Use of Information

EKU Use of Information
Purpose of Processing Legal Basis

As part of the admissions process, we collect applicant Personal Information to evaluate applications. We also may obtain Personal Information from third parties, such as other schools, references, family members, and education as part of an application package.

Legitimate Interest: Personal Information collected through the application is necessary to evaluate candidates for admissions and for our internal statistical and analytics purposes.

Contract: Personal Information collected through the University application is necessary for the performance of a contract to provide you education services or to take steps at your request prior to entering into a contract to provide you education services.

 

To support course registration

Legitimate Interest: Personal Information collected for matriculated students, staff, faculty and members of the public, as appropriate for the course, to register in courses or classes

Contract: Personal Information collected through course-registration sites is necessary for the performance of a contract to provide you education services. Legitimate Interest: Personal Information collected for matriculated students, staff, faculty and members of the public, as appropriate for the course, to register in courses or classes

To evaluate and determine whether financial aid opportunities are available to an applicant

Legitimate Interest: Personal Information collected through the financial aid application is necessary to evaluate whether the applicant is eligible to receive financial aid and for our internal statistical and analytics purposes.

Contract: Personal Information collected through the financial aid application is necessary for the performance of a contract to provide you financial aid or to take steps at your request prior to entering into a contract to provide you financial aid.

To facilitate housing for individuals studying or participating in programs at or through the University

Legitimate Interest: Personal Information will be collected to facilitate housing.

Contract: Personal Information will be collected to perform on a contract or to take steps at your request

To provide training and educational programs

Legitimate Interest: To facilitate provision of on-line education courses to matriculated students, staff, faculty and members of the public, as appropriate for the course

Contract: Personal Information collected through the application is necessary for the performance of a contract to provide you education services or to take steps at your request prior to entering into a contract to provide you education services.

To facilitate application for and sponsoring of visas to study, work, and/or research at the University, including all functions necessary to comply with applicable immigration laws

Legitimate Interest: To facilitate employment, research, and study opportunities and comply with relevant laws

Contract: Personal Information will be collected to perform on a contract or to take steps at your request.

To process employment applications and independent-contractor information

Legitimate Interest: For individuals interested in employment opportunities, processing applications

To receive donations

Legitimate Interest: To collect and process donations/gifts and donor information

To purchase tickets to events

Contract: To process ticket payment for a variety of events

For event registration

Legitimate Interest: To process registration for sports, cultural, educational and other events

To purchase parking passes and permits

Contract: To facilitate payments for parking passes and permits

To submit requests for services (e.g., IT, help desk, help line, etc.)

Legitimate Interest: To process service requests from students, staff and faculty

Contract: If there is a contract that governs your use of such services, Personal Information is processed pursuant to that contract.

Travel arrangements

Legitimate Interest: To facilitate travel arrangements and coordination for students and affiliated travelers through University programs

Contract: If there is a contract that governs your use of travel sites, Personal Information is processed pursuant to that contract.

Emergency situations

Vital Interest: Our processing of your Personal Information to protect an interest that is essential to your life or the life of someone else

To stay connected with University alumni

Legitimate interest: To maintain strong relationships with University alumni and for communicating unsolicited non-commercial messages.

To provide treatment and health services

Legitimate interest: Our processing of your Personal Information for the purposes of preventative or occupational medicine, for assessing the working capacity of an employee, for medical diagnosis, for providing health or social care or treatment, or for managing health or social care systems and services on the basis of United States and state laws

Contract: If there is a contract that governs the terms of treatment, Personal Information is processed pursuant to that contract.

To protect vital interests when the subject is incapable of providing consent

Legitimate interest: Our processing Personal Information, such as health related personal information, when necessary to protect the vital interests of a data subject who is physically or legally incapable of giving consent

Information made public by you

Legitimate interest: Our processing of data made public by you for purposes of processing admissions, sponsoring of visas, processing applications for employment, responding to emergency situations, providing treatment and health services, protecting vital interests when the subject is incapable of consent, as necessary for judicial proceedings, as necessary for public health, or for other reasons that are described when you are asked to provide the data.

Judicial proceeding

Legitimate interest: Our processing that is necessary for the establishment, exercise, or defense of legal claims or where courts are acting in their judicial capacity

Public interest and as required by law

Legitimate interest: Our processing Personal Information necessary for reasons of substantial public interest on the basis of United States or state laws that is proportionate to the aim pursued and which contains appropriate safeguarding measures

Public health

Legitimate interest: Our processing Personal Information that is necessary for public interest reasons in the area of public health, including protection against threats to health or ensuring high standard of quality and safety of health care, medicinal products, or medical devices

Research

Legitimate interest: Our processing Personal Information for scientific and historical research purposes or statistical purposes

Who Processes Your Sensitive Information?

We may disclose your Sensitive Information and other Information as follows:

  • Consent: We may disclose Sensitive Information and other Information if we have your consent to do so.
  • Emergency Circumstances: We may share your Information, and Sensitive Information when necessary to protect your interests and you are physically or legally incapable of providing consent.
  • Employment Necessity: We may share your Sensitive Information when necessary for administering employment or social security benefits in accordance with applicable law, subject to the imposition of appropriate safeguards to prevent further unauthorized disclosure.
  • Charitable Organizations: We may share your Information with not-for-profit organizations in connection with charitable giving to EKU subject to the imposition of appropriate safeguards to prevent further unauthorized disclosure.
  • Public Information: We may share your Information and Sensitive Information if you have manifestly made it public.
  • Archiving. We may share your Information and Sensitive Information for archiving purposes in the public interest, and for historical research, and statistical purposes.
  • Performance of a Contract: We may share your Information when necessary to administer a contract you have with EKU.
  • Legal Obligation: We may share your Information when the disclosure is required or permitted by international, federal, and state laws and regulations.
  • Service Providers: We use third parties who have entered into a contract with EKU to support the administration of EKU operations and policies. In such cases, we share your Information with such third parties subject to the imposition of appropriate safeguards to prevent further unauthorized disclosure.
  • EKU Affiliated Programs: We may share your Information with parties that are affiliated with EKU for the purpose of contacting you about goods, services, charitable giving or experiences that may be of interest to you.
  • De-Identified and Aggregate Information: We may use and disclose Information in de-identified or aggregate form without limitation.

Data Security

We implement appropriate technical and organizational security measures to protect your information when you transmit it to us and when we store it on our information technology systems.

Cookies and Other Technology

EKU's use of cookies and certain other data from websites and email can be found in the EKU Privacy Statement found here.

Retention and Destruction of Your Information

Your information will be retained by EKU in accordance with applicable federal and state laws and regulations, and the applicable retention periods in the EKU University Records Retention Policy. Your information will be destroyed upon your request unless applicable law requires destruction after the expiration of an applicable retention period. The manner of destruction shall be appropriate to preserve and ensure the confidentiality of your information given the level of sensitivity, value and criticality to EKU. The EKU University Records Management Policy can be found here.   

Your Rights

You have the right to request access to, a copy of, rectification, restriction in the use of, or erasure of your information in accordance with all applicable laws. The erasure of your information shall be subject to the retention periods of applicable federal and state laws and regulations. If you have provided consent to the use of your information, you have the right to withdraw consent without affecting the lawfulness of EKU's use of the information prior to receipt of your request. Certain information, such as official transcript information, student financial aid records, student discipline records and employment records will be permanently retained by EKU without regard to this right.

You may exercise these rights by contacting EKU’s Chief Privacy Officer:

Mark B. Maier, Associate Counsel Office of University Counsel and Compliance Coates Administration Building, Room 212 Eastern Kentucky University 521 Lancaster Ave. Richmond, KY 40475 859-622-6693

Information created in the European Union will be transferred out of the European Union to EKU. If you feel EKU has not complied with applicable foreign laws regulating such information, you have the right to file a complaint with the appropriate supervisory authority in the European Union.

Updates to This Notice

We may update or change this notice at any time. Your continued use of EKU's website and third-party applications after any such change indicates your acceptance of these changes.

Last updated April 1, 2019.