05 January 2022

[Notice] University Personal Data Protection Policy

  1. University Personal Data Protection Policy
    The university’s Personal Data Protection Policy (see attached), along with related procedures and forms, has been revised in 2021 (110th Academic Year) in accordance with the “Regulations on Information Security and Personal Data Management in the Education System.” All updated files have been uploaded to the Personal Data Management System. Please access them via the portal: https://portal.ncu.edu.tw/login → Convenience Window / Personal Data Management System for download.

  2. Key Points of This Revision:

    1. Mandatory Training: All faculty and staff must participate in at least 3 hours of related education or promotional courses annually. [Reference: Personal Data Security Control Operation Manual]

    2. Personal Computer Passwords: Operating system passwords must be at least 8 characters long, cannot be the same as the previous password, and should generally be changed at least once a year. [Reference: Personal Data Security Control Operation Manual]

    3. Database Account Passwords: Accounts containing personal data must use alphanumeric passwords, cannot be the same as the account name, must be at least 8 characters long, and should be changed at least once every six months. Administrators are strictly prohibited from sharing passwords. [Reference: Personal Data Security Control Operation Manual]

    4. New “Sharing Data with Third Parties” Regulation: When the university shares personal data with third parties under agreements or contracts, the purpose of data use and related restrictions must be clearly stated in writing, and the sharing must comply with the Personal Data Protection Act. Requests must be submitted via the “Personal Data Usage Information Service Application Form” in accordance with the Personal Data Document Management Procedure and approved by the responsible authority before data can be provided.

    5. Accurate Data Recording: Personal data must be accurately recorded and only the most up-to-date personal data should be used for important decision-making concerning the individual. [Reference: Personal Data Collection, Processing, Use, and Security Management Procedure]

    6. Masking of National ID Numbers: According to MOE Letter No. 臺教資(四)字第1100125917號, to comply with the Government Information Disclosure Act and the Personal Data Protection Act, all documents and website information containing National ID numbers must mask all but the last four digits. If special uses require otherwise, handle according to relevant regulations. [Reference: Employee Personal Data Confidentiality Consent Form, Outsourced Contractor/Personnel Confidentiality Agreement, Personal Data Usage Information Service Application Form]

Attachment Download Link:    ncu-pims-a-001國立中央大學個人資料保護政策v1.3_1101222.pdf