We have a campus policy on data protection that expressly prohibits sending/receiving SSNs and other equally sensitive data via email. We can't prevent someone from sending SSNs yet, but I do have a Gmail DLP rule that alerts me when that happens. I then work with the department to figure out what their needs are and how we can do it more safely and securely. And I make sure to tell them to not solicit this kind of information over e-mail. We have an in-house tool that allows people to upload files for sensitive uses such as this. I know that's not very helpful for you.
Mark
FWIW, I believe on the employment side of things, our HR uses its onboarding/background check systems for handling I-9s. These are SSL/browser-driven systems which avoid having documents directly in email for the most part.
Thanks,
Andrew
________________________________________
From: USHE-ISO <ushe-iso-bounces@lists.dixie.edu> on behalf of James Wilkinson via USHE-ISO <ushe-iso@lists.dixie.edu>
Sent: Monday, November 16, 2020 1:31 PM
To: ushe-iso@lists.dixie.edu
Subject: [USHE-ISO] HR onboarding and PII data collection for I-9 etc.
Question:
I am curious if any of our sister institutions have found a convenient method for handling the collection or verification of sensitive documents without using email. Immigration and Customs Enforcement suggests email or Zoom for the I-9. A solution that provides an easy method for the secure transfer of sensitive documents when shares or in house encryption cannot be utilized could be very helpful. Adobe Sign has been suggested so far. Anyone have another suggestion?
... employers must inspect the Section 2 documents remotely (e.g., over video link, fax or email, etc.) and obtain, inspect, and retain copies of the documents, within three business days for purposes of completing Section 2.
https://www.ice.gov/news/releases/dhs-announces-flexibility-requirements-related-form-i-9-compliance
James Wilkinson | SLCC
--
USHE-ISO mailing list
USHE-ISO@lists.dixie.edu
http://lists.dixie.edu/cgi-bin/mailman/listinfo/ushe-iso