Guidelines for faculty: protecting student personal information

What is personal information (PI)? 

Personal information is defined in BC FIPPA is any recorded information about an identifiable individual. This includes names, student numbers, grades, email addresses, demographic details, instructor’s evaluative comments, and other direct or indirect identifiers. 

What are direct and indirect identifiers? 

Information that can identify someone on its own, such as name or student number, is a direct identifier. An indirect identifier is information that cannot identify a student on its own but can reveal who they are when combined with other details in the class or program. 

For example, details such as a student’s program or year of study; a unique project or research topic; or demographic combinations such as age, gender, hometown, etc. are discrete pieces of information could be linked together to identify someone. This is also known as the “mosaic effect.” 

Who is responsible for protecting student’s PI?  

All VIU employees share responsibility for protecting personal information. Under s. 25.1 of FIPPA, we may collect, use, or disclose personal information only when authorized. Reviewing this part of the Act is a good way to familiarize yourself with our lawful obligations. 

Below are some practical suggestions for how you can protect student’s PI in your everyday teaching and learning practice.  

What are the risks of not protecting student’s PI?  

The biggest risk is related to data security.  

Data security is one of the fastest growing threats to student safety at Canadian universities. In 2025, the global education sector faced over 4,400 cyberattacks per organization each week; a 73% increase from the previous year. 

Cybersecurity incidents are a rapidly escalating risk in higher education and have direct, serious consequences for students, not just institutions. When students are targeted, they often bear the full impact without access to legal, financial, or technical support. Impacts could include things like fraud, damaged credit, academic disruption, reputational harm, and so on.  

Faculty play a critical role in reducing these risks. Careful handling of student personal information, use of approved tools, and secure communication practices significantly lower the likelihood of harm to students. Protecting data is not only a compliance obligation, but also a core component of student safety and academic integrity. 

Additional risks include things like reputation and personal safety. 

Practice the data minimization principle: collect only what you need 

Under FIPPA, VIU may collect personal information only when it is necessary for a program or activity, which means instructors should gather only the information required to teach, assess, or support students. The data minimization encourages faculty to ask: Do I truly need this information, and why? 

In teaching and learning practice, data minimization means: 

  • Use VIULearn for digital submissions, where it’s clear who the student is so there is no need to require student numbers on assigned work.  
  • Keep feedback and grades in VIULearn, where only the student can see them. 
  • Use group names for group work, rather than listing everyone’s personal details on the assignment.  
  • Limit personal information on paper submissions by avoiding cover pages with identifying details. Request only the last four digits of the student number when identification is needed. 
  • Return marked work directly to students, instead of leaving it out where others could see grades or comments.  
  • Avoid posting grades publicly, but if necessary, use only the last four digits of the student number and avoid alphabetical lists that could make it easy to figure out who’s who. 
  • Bottom line: student ID numbers are confidential PI and must not be publicly displayed or shared unnecessarily. 

When questioning what information is appropriate to collect, it may be helpful to use the “necessity test” developed by the Canadian Privacy Commissioner 

Four-point necessity test for collecting Personal Information (PI): 

  1. Is the information necessary for the program or activity? 
  1. Will it help achieve the program’s objectives? 
  1. Are less privacy‑intrusive alternatives available? 
  1. Is the loss of privacy proportionate to the objectives? 

Use VIU approved teaching and learning technologies 

To safeguard student’s personal information and comply with FIPPA, follow these essential practices when using technologies and managing access to information. 

  • Use VIU supported learning technologies, such as VIULearn, VIUBlogs, and VIUTube. These tools have completed Privacy Impact Assessments (PIAs) to ensure compliance with FIPPA and reduce privacy risk. Support for these tools is available through CIEL at learnsupport@viu.ca
  • Use VIU licensed Microsoft 365 tools (Outlook, OneDrive, Teams, SharePoint, Copilot, etc.) as it is essential for protecting student personal information and meeting VIU’s legal obligations. M365 is the only approved cloud environment for storing or processing student data, as it is covered by VIU’s enterprise license and includes industry standard security protections, encrypted storage, and servers located in Canada. In contrast, personal or non-licensed tools such as iCloud or Google Drive lack these safeguards and introduce significant privacy, security, and compliance risks. A full list of approved software is available on the VIU Software Information Hub.

Email best practices 

The following email practices help protect student personal information, reduce privacy risk, and ensure BC FIPPA compliance in daily communications. 

  • Use only your VIU email account for all university business and student communication. Avoid personal email addresses, as they may not comply with FIPPA and could expose student information. 
  • Avoid auto‑forwarding VIU emails to personal accounts, as this can compromise data storage jurisdiction and security. 
  • Use descriptive subject lines and avoid names, student numbers and other identifying information. 
  • Include only the minimum necessary personal information in emails. When necessary to use student numbers, use only the last four digits.  
  • Use BCC when emailing multiple students to prevent sharing their addresses with others.  
  • Protect attachments with sensitive or confidential information by encrypting with a password; make sure to share the password in a separate communication such as through Teams or in-person.  
  • Email is a communication forum not a storage facility: regularly delete transitory email records and move official records to a more secure storage medium such as your VIU drives.  
  • Verify recipient addresses before sending, especially for emails containing sensitive student information, to reduce risk of mis-delivery. 

Where to get help 

VIU Privacy Office: Privacy.Officer@viu.ca 

CIEL Support: LearnSupport@viu.ca 

We appreciate your help to meaningfully and intentionally reduce risks to our students and our institution. Things like FIPPA are in place to keep you and your students safe. Taking these small steps can have a big impact on security and privacy at VIU.  

This post was co-authored by the VIU Privacy Office and CIEL.

VIU resources

Access and Privacy at VIU – https://gov.viu.ca/access-and-privacy-viu

The Protection of Privacy at VIU – https://gov.viu.ca/access-and-privacy-viu/protection-privacy-viu

Privacy Management Program – https://gov.viu.ca/access-and-privacy-viu/privacy-management-program

Access and Privacy Best Practices – https://gov.viu.ca/access-and-privacy-viu/privacy-best-practices-summary

Learning technology support – https://ciel.viu.ca/pages/learning-technology-support

How VIU Online Learning Tools Manage Your Data – https://ciel.viu.ca/pages/how-viu-online-learning-tools-manage-your-data

Attribution

North Island College, Teach anywhere. (n.d.). FIPPA – Privacy of student information.

University of British Columbia, Learning Technology Hub. (n.d.). UBC privacy compliance guidelines.

University of Waterloo. (n.d.). Returning assignments and posting grades.

University of Waterloo. (2022, September 14). Managing student information for faculties, academic departments and schools.

Vancouver Island University. (2026). Access and privacy at VIU.

Vancouver Island University. (2026). The protection of privacy at VIU.

York University, Information and Privacy Office. (n.d.). FIPPA for faculty 2: FIPPA and student information.

Posted

in

, ,

by