Data Governance & Privacy in Higher Ed
University data governance software routes GDPR breach notification, impact assessments, GLBA Safeguards Rule risk reviews, and FERPA disclosure logging to the right office before a deadline is missed. GDPR applies to any US institution processing personal data of people in the EU, including exchange students and research participants, and requires notifying a supervisory authority within 72 hours of becoming aware of a breach. GLBA and FERPA govern financial and education records domestically. Few institutions track all three under one process.
Key takeaways
-
A university does not opt into GDPR. If it enrolls a single EU exchange student, hosts a study-abroad program, or runs research involving EU participants, it is processing personal data under GDPR and inherits deadlines most US institutions have never operationalized.
-
GDPR's breach notification clock starts at 72 hours from the moment the institution becomes aware of an incident, not from when the incident occurred, and that clock does not wait for the institution to finish figuring out what happened.
-
GDPR does not replace FERPA or the GLBA Safeguards Rule. It sits on top of them for a specific slice of data, which means most institutions are now governed by three overlapping privacy regimes with three different triggers, three different timelines, and no single office tracking all three at once.
Why data governance became a CIO problem, not just a registrar's problem
Ten years ago, "student data privacy" mostly meant FERPA, and FERPA mostly meant the registrar's office. That framing does not hold anymore. A university with an international exchange program, a study-abroad office, or a lab running a study with participants in Germany or France is processing personal data under a regulation that has nothing to do with the registrar and everything to do with a supervisory authority the institution has likely never contacted. A university handling federal financial aid is separately obligated under a cybersecurity rule enforced by the FTC that has nothing to do with FERPA either. None of these three regimes were designed with each other in mind, and none of them will wait for the institution to sort out which office owns the response.
When GDPR actually applies to a US institution
The trigger is not where the institution is located. It is whose data the institution is processing. A US university is subject to GDPR when it processes personal data belonging to people located in the EU in connection with offering them goods or services, or monitoring their behavior, which in practice covers EU exchange students enrolled at the institution, EU participants in a funded research study, and EU nationals employed through an international program.
An institution with none of these relationships has no GDPR exposure. An institution with even one active EU exchange agreement or one grant-funded study recruiting EU participants does, whether anyone in general counsel's office has flagged it or not.
GDPR obligations that carry real deadlines
Three GDPR obligations are the ones that actually bite an institution that is not tracking them.
Under GDPR Article 33, a controller must notify the relevant supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. The clock starts from awareness, not from the incident itself, and any delay past 72 hours has to be justified with reasons when the notification is finally made. Every breach, notified or not, has to be logged internally regardless of whether it crossed the notification threshold.
Before starting any processing that is likely to result in a high risk to individuals, particularly processing that uses new technology or is conducted at scale, Article 35 requires the controller to carry out a Data Protection Impact Assessment before the processing begins, not after. A research protocol involving sensitive EU participant data that skips this step is not compliant on day one, independent of whatever IRB approval it separately holds.
Article 30 requires the institution to maintain a record of its processing activities, including the purposes of processing, categories of data and recipients, and any international transfers, and that record has to name the institution's data protection officer if one has been designated. Article 37 requires a public authority to designate a data protection officer regardless of size, which captures most public universities outright rather than leaving DPO appointment as a judgment call based on data volume. Where the institution transfers EU personal data back to US systems, that transfer has to rely on an approved mechanism such as the EU-US Data Privacy Framework.
The domestic layer GDPR does not replace
GDPR governs a specific slice of an institution's data, EU personal data, and it sits alongside two domestic regimes that keep applying regardless of GDPR exposure. The GLBA Safeguards Rule, codified at 16 CFR 314, requires institutions handling Title IV financial aid to maintain a written information security program. The FTC's 2021 Safeguards Rule update set nine required program elements covering risk assessment, encryption, multi-factor authentication, and incident response planning, and FSA Partners guidance ties Safeguards Rule compliance to an institution's continued Title IV eligibility.
FERPA continues to govern education records for every enrolled student regardless of nationality, on its own separate disclosure and consent framework.
Three regimes, three triggers
|
Regime |
What triggers it |
Signature deadline |
|
GDPR |
Processing personal data of anyone located in the EU |
72-hour breach notification to the supervisory authority |
|
GLBA Safeguards Rule |
Handling Title IV financial aid or other covered financial data |
Written information security program with nine required elements, reviewed on an ongoing basis |
|
FERPA |
Maintaining education records for any enrolled student |
Disclosures logged and limited to legitimate educational interest or consent |
A governed data governance workflow
Data inventory tied to processing purpose
Every dataset the institution holds is classified by what regime governs it: EU personal data under GDPR, Title IV financial data under GLBA, education records under FERPA, and datasets can sit under more than one regime at once.
Breach detection routes to the right clock
An incident involving EU personal data starts the GDPR 72-hour notification clock automatically. An incident involving financial data routes to the institution's GLBA incident response process. The workflow does not wait for someone to manually determine which regime applies before the clock starts running.
DPIA triggered before high-risk processing begins
A new research protocol or system involving EU participant data is flagged for a Data Protection Impact Assessment before data collection starts, not after a compliance office discovers the project already underway.
Processing records maintained continuously
The institution's Article 30 record of processing activities is built as a byproduct of how data is classified and used, rather than reconstructed from memory when a supervisory authority asks for it.
GLBA risk assessment and program elements tracked on a cycle
The nine required Safeguards Rule elements are reviewed on a defined schedule, with ownership assigned to the qualified individual the rule requires the institution to designate.
FERPA disclosures logged alongside everything else
School-official disclosures under FERPA are logged in the same system tracking GDPR and GLBA activity, so an audit of any one regime does not require reconstructing data flows the other two regimes already documented.
Kissflow and the data governance stack
Kissflow is the governed execution layer at the edges of the data governance stack. It does not replace the institution's data protection officer, its legal counsel's judgment on GDPR applicability, or the IT security tools that detect and contain a breach. It replaces the spreadsheet tracking which datasets fall under which regime and the email thread that currently coordinates a breach response across offices that have never run a joint incident before.
If your institution runs a dedicated GRC platform for security risk, Kissflow does not compete with it for that function. It sits alongside it as the layer that routes an incident to the correct regulatory clock, tracks DPIA and Safeguards Rule review cycles against their deadlines, and keeps the processing records a supervisory authority or a Title IV program review would actually ask to see.
The differentiation that matters to a CIO: when the institution takes on a new EU research partnership or a new financial aid product changes what counts as covered data under GLBA, the office that owns data governance updates the workflow directly, instead of waiting for a security platform vendor to add higher-ed-specific regulatory logic that was never central to what that platform was built for.
Frequently asked questions
-
Does GDPR apply to a US university with no campus in Europe?
Yes, if the institution processes personal data belonging to people located in the EU, commonly EU exchange students, study-abroad participants, or EU nationals in a funded research study. Physical location of the institution is not the trigger.
-
How fast does an institution have to report a GDPR breach?
Without undue delay, and where feasible within 72 hours of becoming aware of it, to the relevant supervisory authority. The 72-hour clock starts at awareness, not at the moment the breach actually occurred, and every breach has to be logged internally regardless of whether it meets the notification threshold.
-
Does every university need a data protection officer under GDPR?
Public authorities must designate one under Article 37 regardless of size, which covers most public universities outright. Private institutions evaluate the requirement based on the nature and scale of their processing.
-
Does GLBA replace FERPA for financial aid records?
No. GLBA's Safeguards Rule governs the security program protecting financial data tied to Title IV administration. FERPA continues to govern the education record itself, including financial aid information that also qualifies as part of a student's education record.
-
What is a Data Protection Impact Assessment, and when is one required?
A DPIA is an assessment of privacy risk that GDPR requires before starting any processing likely to result in high risk to individuals, particularly new technology or large-scale processing. It has to happen before the processing begins, not as a retroactive justification.
-
Does Kissflow replace our security or GRC platform?
No. Kissflow is the workflow layer that routes incidents, deadlines, and processing records across GDPR, GLBA, and FERPA obligations. Security detection and containment tools, and any dedicated GRC platform, remain the systems that do that work.
Request a 30-minute walkthrough to see how Kissflow routes GDPR, GLBA Safeguards Rule, and FERPA obligations through one workflow with deadlines tracked automatically. Book a demo today.