Student organizations collecting personal information for any events or programs—such as names, email addresses, phone numbers, or other identifying and sensitive details (e.g., grades, health information, etc.)—must handle this data responsibly and according to MIT policies. Before collection, you should prepare a clear privacy statement that explains what information you are gathering and how it will be used; a template privacy statement is available here. For all collection of personal information, you should adhere to the following guidelines:
- Collect only the minimum personal information necessary for your specific event or purpose.
- Store and secure all personal data exclusively on MIT-supported servers and applications; do not use personal devices or non-MIT platforms.
- Once the event concludes and the data is no longer needed, securely delete all records.
For guidance on data handling practices, privacy statements, or compliance questions, contact MIT’s Risk Management and Compliance Services (RMCS) or the Office of the General Counsel (OGC). Promptly report any data incident(s) to infoprotect@mit.edu.