University Directory Service (UDS) - Responsible Use
The UDS provides applications and services at the University of Wisconsin-Madison with demographic, role and contact data to support identity management, authentication, and authorization1. The following policy is designed to ensure judicious and compliant use of that information, protecting the security and privacy of that data where necessary.
- UDS data use must be authorized by the appropriate data custodians for student, employee or other data using the UDS authorization request form. This form specifies what data elements are needed for what purpose. UDS consumers2 will be notified annually to reapply for authorization. The data obtained must be used only for the specific purpose identified on the request form and not for any other purpose, and must not be supplied to other applications.
- UDS data use must comply with the applicable State of Wisconsin and Federal laws and regulations concerning privacy and security as well as complying with University policy. UDS data use is specifically bound by the University FERPA Policy and the UW-Madison Responsible Use of Information Technology Policy.
- UDS data may be used for purposes of providing identity management, which includes, for example, directory authentication and authorization services, and contact information.
- UDS consumers must provide details on what UDS data they store locally.
- UDS consumers must take all necessary precautions to secure UDS data in transmission and in storage. This includes utilizing security best practices as posted at http://www.cio.wisc.edu/security.
- Consumers of UDS data will be held responsible for any security breach traceable to their use or specific authorization and will be held liable for any willful misuse or deliberate system damage traceable to their use and specific authorization.
- Periodic and random audits will be performed on use of UDS data by DoIT Security.
- Consumers of UDS data must provide access logs and access to systems containing UDS data upon request to DoIT Security.
1 - Identity management refers to the policies, processes and technologies by which the identities of persons are proofed, registered and maintained. Authentication is the process of validating that identity. Authorization is providing access rights and privileges based on that identity.
2 - UDS consumers refers to applications or services that use data from the UDS.
The University of Wisconsin-Madison, effective July 7, 2005, revised June 28, 2013,