University Libraries Privacy Statement
The University Libraries recognize their role in the stewardship of your data and strive to be transparent about where that data is collected. Data is created and collected when you use library and University services and technology. The University Libraries may store and use data to understand trends in library use and evolve services and the resources we provide. With respect to our internal use, the University Libraries strive to uphold your privacy, confidentiality, and intellectual freedom as outlined in the American Library Association’s Code of Ethics (https://www.ala.org/tools/ethics) and Library Bill of Rights (https://www.ala.org/advocacy/intfreedom/librarybill). The University of Utah’s Information Privacy Portal describes how federal and state laws apply to protecting patron information (https://privacyportal.utah.edu/). Patron data and personally identifiable information (PII), as defined in Rule 4-004C (https://regulations.utah.edu/it/rules/Rule4-004C.php), are protected against release in accordance with the Utah Government Records Access Management Act (https://legal.utah.edu/university-legal-services/records.php) or as otherwise required by law. University Libraries comply with valid requests for records, subpoenas, search warrants, court orders, and other applicable legal processes that may require disclosure of patron data or PII.
Some services made available by the University Libraries are delivered through connections between library applications, University resources, and third-party vendors. Patron data and PII are managed differently across various systems, and we may share Patron Data and PII as required for the operability of those interconnected resources.
Library Systems
The University Libraries store and use patron data or PII for operations and services during transactions with the libraries. Examples include checking out library materials, reserving a room, logging into a library computer, or contacting us through library applications. Where practical, patron data or PII is de-identified, and the de-identified transaction record is maintained to inform collection management and improve services and spaces.
University Systems
PII is often shared with University systems when conducting routine transactions, such as signing in with a uNID, or when library services are hosted on University servers. The University's cybersecurity program is designed to protect the information of the University community using a standard suite of tools that allows the Information Security Office (ISO) to consolidate monitoring, logging, and response activities around cybersecurity incidents and to meet industry and regulatory standards. University of Utah security systems, such as card-controlled building access and camera monitoring, may also be used to monitor user access to University resources. These University systems collect data in accordance with University policies 4-002 Information Resource Policy and 4-004 Information Security Policy.
Third-Party Systems
When you leave the University Libraries or University websites through links, your interaction with these websites will be governed by their respective policies. It is your responsibility to review third-party policies to understand how information is collected and used. Electronic books, journals, and databases (content providers), payment systems (Clover, Nelnet), and software applications (Zoom, Microsoft products) are examples of services and systems provided by third-party publishers and vendors that may collect and use PII within their respective policies. The library will attempt to use randomized IDs with third-party vendors by default, but when not possible, we will share only identifiable data to the extent required for functionality of such services.
Policy References
- ALA Code of Ethics: https://www.ala.org/tools/ethics
- ALA Bill of Rights: https://www.ala.org/advocacy/intfreedom/librarybill
- University Information Privacy Portal: https://privacyportal.utah.edu/
- Information Resources Policy: https://regulations.utah.edu/it/4-002.php
- University of Utah Information Security Policy 4-004: https://regulations.utah.edu/it/4-004.php
- SSAC: https://regulations.utah.edu/administration/3-234.php
Policy Owner
History
- Policy reviewed by:
- Office of General Counsel
- Policy approved by:
- Marriott Library Executive Committee: August 24, 2026
Note: Policies should be reviewed at minimum every three (3) years.
Contact
Library Information & Operations801-581-8558
801-581-8203