Alumni Database Privacy and Access¶
Classification¶
The alumni database is a National-restricted system under the Information Classification Guide. A public guide may describe the process, but records, screenshots, exports, access links, and personal information stay restricted.
Access model¶
| Role | Default access |
|---|---|
| National Alumni Relations | Program and record-management access needed for approved alumni work |
| National Technology | Administrative access needed for security, availability, integrations, and support |
| National President | Oversight or escalation access when required; not automatic use for unrelated outreach |
| Authorized chapter alumni owner | Chapter-scoped submission or review access where the platform supports it |
| Other National or chapter officers | No standing access; request the minimum data or service needed for an approved purpose |
| Companies, sponsors, and outside organizations | No direct access; any sharing requires explicit approved purpose, consent, and authorization |
Access must be individual, role-based, reviewed at transitions, and removed promptly when no longer needed. Shared accounts should not be the default.
Export and sharing rules¶
- Prefer filtered views or program-specific routing over full exports.
- Export only fields necessary for an approved, time-bounded purpose.
- Record the owner, recipient, purpose, fields, and deletion date.
- Do not send exports through ordinary chat or personal email.
- Do not upload records to public repositories, general AI tools, or unapproved services.
- Delete temporary exports when the approved task is complete.
- Do not share alumni information with companies or sponsors merely because they support KTP.
Access requests¶
- State the requester, role, chapter, purpose, fields needed, and time period.
- Alumni Relations confirms the program purpose and minimum information.
- Technology confirms the technical access level and system controls.
- Broader or novel uses go to the President and appropriate Board approval.
- Set an expiration or review date.
- Record approval in the National-restricted system.
Alumni requests¶
Provide an approved route for alumni to ask what information is maintained, correct inaccurate information, change communication preferences, restrict optional use, or request deletion subject to applicable retention requirements. Verify identity without collecting unnecessary new sensitive information.
Retention and review¶
The exact retention schedule must be approved and documented in the National-restricted policy. Until then:
- retain only information with a current defined purpose;
- review access at least each officer transition;
- review stale records and unused fields periodically;
- preserve no-contact and restriction controls so imports do not recreate unwanted outreach; and
- pause new uses that lack a documented owner, purpose, audience, and retention plan.
If information is exposed¶
- Stop further sharing and reduce access without deleting evidence needed for review.
- Notify National Technology and Alumni Relations through the restricted escalation route.
- Identify the records, fields, audience, time window, and systems involved.
- Rotate credentials or revoke links when exposure includes access.
- Follow approved legal, school, and National notification requirements.
- Record corrective actions and update the process that allowed the exposure.
Correcting the exposure is the priority. Incident review should focus on improving controls rather than blaming the person who reported it.