Skip to main content
NCDIT logo NCDIT

Topical Navigation

  • Home
  • Services
  • Programs
    Programs
    • Broadband & Digital Equity
    • CJLEADS
    • Enterprise Strategy
    • FirstTech
    • IT Volume Purchasing
    • N.C. 911 Board
    • N.C. Health Information Exchange Authority
    • NC360
    • Optimization
    • Project Portfolio Management
  • Resources
    Resources
    • COVID-19 Resources
    • Cybersecurity & Risk Management
    • Data Protection & Privacy
    • Statewide IT Strategic Plan
    • Statewide IT Procurement
    • State IT Policies
    • IT Application Portfolio Management
    • Standards
    • Resources Guide
    • Knowledge College
    • Documents
    • Reports
  • About
    About
    • Commitment to Customers
    • Leadership
    • Boards & Commissions
    • Climate Change & Clean Energy
    • NCDIT Strategic Plan
    • Work for NCDIT
    • Annual Report
    • Rules Review
  • News & Events
    News & Events
    • Events
    • Press Releases
  • Support
    Support
    • NCID
    • Training & User Resources
    • Submit a Service Desk Ticket
    • Report a Cybersecurity Incident
    • Services Status
  • Contact
    Contact
    • Media Inquiries
    • Public Records Requests
    • Speaker Requests
  • PASSWORD HELP
  • SERVICE PORTAL
  • CAREERS
  • NC.GOV
NCDIT »   Resources »   Data Protection & Privacy

Data Protection & Privacy

Have a Question or Comment About Privacy?

Data privacy and protection are important to NCDIT, and we want to hear from you to help strengthen our privacy program for the state. 

Let Us Know Your Thoughts

Fair Information Practices Support Data Protection & Privacy

Across the U.S. and around the world, privacy laws have been enacted to govern the collection, maintenance, use and dissemination of information about individuals. 

The concept of Fair Information Practice Principles (FIPPs) is at the heart of these laws and has been implemented in the N.C. Department of Information Technology to guide privacy and security policy. 

The FIPPs strengthen the privacy protections of those who have entrusted the state of North Carolina with their personally identifiable information (PII). They provide a mechanism to ensure data quality and integrity while enhancing the state’s ability to responsibly share data with educational institutions and industry throughout the state. 

Implementing these principles reduces the risk of unauthorized disclosure of information and supports the creation of reliable records to inform decision-making.   

The eight guiding principles that are commonly accepted and form the Fair Information Practice Principles in the United States are:1 

  • Transparency: The organization should be transparent and provide notice to the individual regarding its collection, use, dissemination and maintenance of personally identifiable information (PII).
  • Individual Participation: Consent should be sought from the individual for the collection, use, dissemination and maintenance of PII. A mechanism should also be provided for appropriate access, correction and redress regarding the organization's use of PII.
  • Purpose Specification: The organization should specifically articulate the authority that permits the collection of PII and the purpose(s) for which the PII is intended to be used.
  • Data Minimization: The organization should only collect PII that is directly relevant and necessary to accomplish the specified purpose(s) and only retain PII for as long as it is necessary to fulfill those purpose(s).
  • Use Limitation: The organization should use PII solely for the purpose(s) specified in the notice. Sharing PII outside of the organization should be for a purpose compatible with the purpose(s) for which the PII was collected.
  • Data Quality and Integrity: The organization, to the extent practicable, should ensure that PII is accurate, relevant, timely and complete.
  • Security: The organization should protect PII (in all media) through appropriate security safeguards against risks such as loss, unauthorized access or use, destruction, modification, or unintended or inappropriate disclosure.
  • Accountability and Auditing: The organization should be accountable for complying with these principles, providing training to all employees and contractors who use PII, and auditing the actual use of PII to demonstrate compliance with these principles and all applicable privacy protection requirements.

1Adapted from Teufel, H. (2008, December 29) The Fair Information Practice Principles: Framework for Privacy Policy at the Department of Homeland Security [Memorandum]. Department of Homeland Security. 

History

The Fair Information Principles gained traction in the early 1970s in response to the growing use of computers in the collection and use of personal information. 

The U.S. Department of Health, Education and Welfare's Advisory Committee on Automated Personal Data Systems found that individuals’ privacy was poorly protected under existing law and record keeping practices and recommended basic principles for a code of information practice. 

Those principles are at the core of the Privacy Act of 1974 and govern the collection, maintenance, use and dissemination of information about individuals that is maintained in systems of records by federal agencies.

The principles have been refined, expanded, and widely adopted in the U.S. and around the world. 

Related Resources

  • Protecting Your Privacy
  • Blogpost: Dedicate Time to Data Privacy
     

Resources

  • COVID-19 Resources
  • Cybersecurity & Risk Management
    • Cyber Incident Reporting
    • Statewide Cybersecurity Incident Report Form
    • Cybersecurity Awareness
    • About the ESRMO
    • ESRMO Initiatives
    • Information & Risk Management Services
    • N.C. Information Sharing & Analysis Center
    • Contact
  • Data Protection & Privacy
  • Statewide IT Strategic Plan
  • Statewide IT Procurement
    • IT Procurement Forms & Templates
    • IT Procurement Rules
    • IT Procurement Training
    • Short-Term IT Staffing Contract
    • Statewide IT Contracts
  • State IT Policies
  • IT Application Portfolio Management
  • Standards
  • Resources Guide
  • Knowledge College
  • Documents
  • Reports

Share this page:

  • Facebook
  • Twitter
  • Email

How can we make this page better for you?

Back to top

Contact

N.C. Department of Information Technology

P.O. Box 17209
Raleigh, NC 27619-7209
919-754-6000
800-722-3946

 

@NCDIT

Tweets by @NCDIT

Quick Links

NCDIT Service Portal
NCDIT Service Desk
NCID Assistance
Training & User Resources
Statewide IT Strategic Plan
Cybersecurity Incident Reporting
NCDIT Communications Hub

Follow Us

  • Facebook
  • Twitter
  • Flickr
  • YouTube
  • LinkedIn
  • Accessibility
  • Terms of Use
  • Privacy Policy
  • Open Budget
https://it.nc.gov/resources/data-protection-privacy