UMass Boston

Acceptable Use Policy (AUP) FAQ

University of Massachusetts Boston Acceptable Use Policy (AUP)

This FAQ is intended to provide general guidance regarding the University's Acceptable Use Policy (AUP). It is designed to answer common questions and clarify expectations regarding the use of University technology resources. Nothing in this FAQ supersedes applicable laws, collective bargaining agreements, University policies, or contractual obligations.

General Questions

1. Why is the University updating the Acceptable Use Policy?

The Acceptable Use Policy (AUP) helps ensure that University technology resources are used securely, responsibly, and in compliance with applicable laws and regulations.

The policy supports the University's mission of teaching, learning, research, public service, and administration by protecting information systems and shared resources while enabling innovation and collaboration.

2. Does this policy change or limit academic freedom?

No.

The AUP is intended to support teaching, learning, research, and the open exchange of ideas. It is not intended to restrict scholarly inquiry, classroom discussion, or legitimate academic activities.

Authorized instructional and research activities are permitted, including those involving cybersecurity, artificial intelligence, data science, and other specialized disciplines.

3. Who does the policy apply to?

The AUP applies to all users of University technology resources, including:

  • Faculty
  • Staff
  • Students
  • Contractors
  • Visiting scholars
  • Third-party affiliates

4. Will the policy evolve over time?

Yes.

Technology, cybersecurity threats, legal requirements, and artificial intelligence continue to evolve. The University expects that the AUP and supporting guidance will continue to be refined over time in consultation with stakeholders across the University community.

5. Is the purpose of this policy to "catch" people doing something wrong?

No.

The primary purpose of the AUP is to promote responsible use of shared resources, protect members of the University community, and support teaching, research, and administrative activities.

The overwhelming majority of interactions under the policy focus on education, guidance, and risk reduction rather than enforcement.

Privacy, Monitoring, and Public Records

6. Does the University routinely monitor faculty, staff, or students?

No.

The University employs automated cybersecurity tools to detect threats and protect systems. These tools are designed to identify suspicious activity and do not involve routine monitoring of individual behavior.

Reviews of institutional data are rare and occur only when there is a documented need, such as:

  • Information security investigations
  • Legal obligations
  • Public records requests
  • Credible evidence of policy violations

Such reviews are conducted only by authorized personnel in accordance with applicable laws and University procedures.

7. What does "credible evidence" or "specific cause" mean?

These terms refer to a documented and legitimate basis for initiating a review.

Examples include:

  • Evidence of unauthorized access
  • A reported cybersecurity incident
  • Compliance with legal obligations
  • A public records request

These reviews are not routine and are intended to protect both the University and its members of the University community.

8. Do ITS staff look through my files whenever they want?

No.

ITS personnel do not conduct routine searches of user files.

Any access to institutional systems must have a legitimate purpose and be performed by authorized personnel in accordance with University procedures and applicable law.

9. Does the University own everything on my computer or OneDrive?

No.

The fact that information is stored on a University device or within a University system does not automatically transfer ownership of intellectual property.

Ownership of content continues to be governed by:

  • University intellectual property policies
  • Applicable laws
  • Research agreements and grant terms
  • Faculty intellectual property protections

University systems may contain a mix of:

  • University administrative records
  • Research data
  • Scholarly work and teaching materials
  • Personal files

Faculty and staff should understand that information related to University business, including documents stored on University devices or systems, may be subject to public records laws and other legal obligations.

Personal materials stored on University systems may also become subject to legal discovery or records requests if they are responsive to a lawful request.

Not all records are disclosable. Applicable laws provide protections and exemptions for certain categories of information, including some research data, draft materials, and confidential records.

10. Does the University claim ownership of faculty intellectual property?

No.

Ownership of scholarly works, teaching materials, research products, and other intellectual property remains governed by University intellectual property policies, applicable laws, grant agreements, and faculty protections.

Storing materials on University systems does not automatically transfer ownership to the University.

11. Are draft manuscripts, peer review materials, and unpublished work protected?

Yes.

Certain categories of scholarly work may receive legal protections or exemptions under applicable law.

The existence of a public records request does not automatically mean that all materials are subject to disclosure.

12. Are research data and grant-funded projects protected?

Yes.

Research data may be governed by:

  • Grant agreements
  • IRB requirements
  • Participant consent agreements
  • Data use agreements
  • Applicable laws and regulations

The AUP does not override these protections.

13. If I text or email a colleague about work using my personal phone, can those communications become public records?

Possibly.

Whether a communication constitutes a public record depends on its content and applicable law, not on the device used.

Personal accounts and personal messaging services are not routinely monitored.

14. Can the University seize my laptop or phone?

Such actions are rare.

In limited circumstances, the University may preserve or secure devices or systems to comply with:

  • Legal obligations
  • Information security investigations
  • Public records requirements

These actions are coordinated through appropriate University authorities and are limited in scope.

Personal Devices and Security

15. Does the policy apply to personal devices?

Only with respect to University-related activities conducted on those devices.

The AUP does not grant the University unrestricted access to personal devices or to personal content.

16. Does using my phone for Multi-Factor Authentication (MFA) make it a University device?

No.

Using a personal device solely for Multi-Factor Authentication (MFA) does not make the device a University device and does not grant the University access to personal information stored on the device.

17. Does this policy prohibit reasonable personal use of University computers?

No.

Reasonable personal use of University technology resources is generally permitted, provided that such use:

  • Does not interfere with University operations;
  • Does not violate laws or University policies; and
  • Does not compromise security or consume excessive resources.

18. What information is considered sensitive?

Examples include:

  • FERPA-protected student records
  • Personnel records
  • Financial information
  • Protected health information
  • Confidential or restricted University information

Users should take appropriate precautions when handling such information.

19. What should I do if I suspect a cybersecurity incident?

Users should promptly report suspected information security incidents, including phishing, data breaches, or the loss or theft of devices containing University data, to the IT Service Desk or the Information Security Office.

Prompt reporting helps protect individuals and the University community.

Artificial Intelligence

20. Can I use ChatGPT, Copilot, or other AI tools?

Yes.

Artificial intelligence tools may be used to support teaching, research, and administrative activities.

However, sensitive or regulated information should not be entered into external AI systems unless those systems have been approved for that purpose.

Institutionally supported AI tools (Microsoft Co-Pilot and Google Gemini when signed in with your umb.edu account) should be used when working with University data or internal documents.

 

People will push back.

21. What information should never be entered into external AI systems?

Examples include:

  • Student records protected by FERPA
  • Personnel records
  • Protected health information
  • Financial account information
  • Restricted or confidential University information

When in doubt, consult ITS or the Information Security Office before entering information into external AI services.

22. Are locally run AI models or research systems allowed?

Generally, yes.

Locally hosted tools or models that process information entirely on a user's device and do not transmit data externally are generally outside the scope of restrictions on external AI services.

23. Must I notify others when AI transcription or meeting summary tools are being used?

Yes.

Meeting participants should be notified whenever AI transcription or meeting summarization tools are enabled.

24. Will AI-generated transcripts or meeting summaries be subject to public records requests?

Possibly.

As with other records related to University business, AI-generated transcripts and summaries may be subject to public records laws and other legal obligations.

Teaching, Research, and Enforcement

25. Will this policy prevent cybersecurity teaching or research?

No.

Authorized teaching and research activities involving cybersecurity, ethical hacking, penetration testing, data science, artificial intelligence, and related disciplines are permitted.

Appropriate authorization and safeguards should be used when conducting such work.

26. Can I install software or use cloud services that are not provided by ITS?

Many research and instructional activities require specialized software and services.

Faculty, researchers, and staff are encouraged to work with ITS to ensure that applications and cloud services are implemented securely and in compliance with applicable laws, regulations, and contractual obligations.

The policy is intended to support innovation while managing institutional risk.

27. Does this policy override collective bargaining agreements or tenure protections?

No.

The policy is intended to operate in conjunction with applicable collective bargaining agreements, faculty rights, and existing University procedures.

28. What happens if someone violates the policy?

Responses are handled in accordance with University policies, applicable laws, collective bargaining agreements, and established disciplinary procedures.

Potential responses may include education, administrative review, temporary restriction of access to technology, or disciplinary action.

29. Who should I contact if I have questions?

Questions regarding the Acceptable Use Policy may be directed to:

  • Information Technology Services (ITS) - Office of the CIO
  • The Information Security Office
  • The IT Service Desk

The University encourages members of the community to seek guidance whenever they are uncertain about the appropriate use of technology resources.