Qualtrics is a HOSTED CLOUD system.; As a HOSTED CLOUD system, it is recommended that you, as the survey owner, back up your data regularly to Piratedrive.
ECU has NOT approved storage and transmission of the following data types on Qualtrics: FERPA, HR/Personnel. GDPR, and HIPAA. Examples of these data types include, but are not limited to the information below:
FERPA (Level 3)
Examples include:
- Student grades and transcripts
- Course schedules and enrollment records
- Financial aid information
- Academic standing and disciplinary records
- Student identification numbers
Family Educational Rights & Privacy Act. Office of the Registrar. (2026, January 4). Family Educational Rights & Privacy Act of 1974 (FERPA) | Office of the Registrar | ECU
What is an education record? What is an education record? | Protecting Student Privacy. (n.d.). What is an education record? | Protecting Student Privacy
HR/Personnel (Level 3)
Examples include:
- Employee name and age
- Original date of employment
- Current position and job title
- Salary and compensation history
- Performance evaluations and personnel records
Article 7. The Privacy of State Employee Personnel Records. NC General Assembly. (n.d.). https://www.ncleg.net/enactedlegislation/statutes/html/byarticle/chapter_126/article_7.html
GDPR (Level 3)
Examples include:
- Names, home addresses, phone numbers, and email addresses
- Digital identifiers such as IP addresses, device identifiers, and web tracking cookies collected by ECU
- University-related identifiers, including student IDs (Banner IDs), employment records, and financial aid data associated with individuals residing in the European Economic Area (EEA)
- Biometric data, and political or religious beliefs collected during international studies or research activities
What is GDPR? General Data Protection Regulation (GDPR). (2019, May 8). Home | General Data Protection Regulation (GDPR) | ECU
HIPAA (Level 4)
Yes; Department Chair Approval Required and IRB Approval Required for Research Projects
Examples include:
- Patient medical records
- Clinical documentation containing diagnoses, treatments, or procedures
- Protected Health Information (PHI) linking an individual's name, date of birth, medical record number, or other identifiers to health-related information
- Research data containing identifiable health information
HIPAA. ECU HIPAA. (2024, November 18). Health Insurance Portability and Accountability Act (HIPAA) | HIPAA | ECU
East Carolina University requires that all data collected or stored in Qualtrics meet federal, state or industry requirements. As a research best practice, all sensitive or confidential research data should be de-identified prior to collection or use. Please follow IRB research guidelines and contact the Pirate Techs at 252-328-9866 | 800-340-7081 to request an IT security consultation if you have questions concerning appropriate protocols for the collection and storage of sensitive or confidential data.
In addition to the above regulations, YOU AGREE NOT TO USE DATA that includes, but is not limited to, the information below:
- Social Security Numbers (SSN)
- Credit card numbers
- Debit card numbers
- Driver’s license numbers
- Personally identifiable patient information
- Personally identifiable student information
- Personnel information
- Confidential legal data
- Proprietary data that should not be shared with the public
- Employer taxpayer identification numbers
- State identification card numbers or passport numbers
- Checking account numbers
- Savings account numbers
- Personal identification (PIN) codes
- Digital signatures
- Any other numbers or information that can be used to access a person’s financial resources
- Biometric data
- Fingerprints
- Passwords
Export Controls
Qualtrics provides services and uses software and technology that may be subject to U.S. export controls administered by the U.S. Department of Commerce, the U.S. Department of Treasury Office of Foreign Assets Control, and other U.S. agencies and the export control regulations of Switzerland and the European Union.
Subscriber acknowledges and agrees that the Software and the Services shall not be used, and none of the underlying information, software, or technology may be transferred or otherwise exported or re-exported to countries which the United States, Switzerland, and/or the European Union maintains an embargo (collectively, “Embargoed Countries”), or to or by a national or resident thereof, or any person or entity on the U.S. Department of Treasury’s List of Specially Designated Nationals or the U.S. Department of Commerce’s Table of Denial Orders (collectively, “Designated Nationals”).
The lists of Embargoed Countries and Designated Nationals are subject to change without notice. By using the Service, Subscriber represents and warrants that Subscriber is not located in, under the control of, or a national or resident of an Embargoed Country or Designated National. Subscriber agrees to comply with all U.S., Swiss, and European Union export laws and assume sole responsibility for obtaining licenses to export or re-export as may be required.