Purpose

This policy establishes guidelines for safeguarding personal, financial, and operational data collected, stored, and processed by the Ogdensburg Public Library to ensure compliance with data protection regulations and maintain public trust.

Article 1. Scope

This policy applies to:

  • All library employees, contractors, and volunteers
    • All systems handling sensitive information (e.g., library cards, circulation records, computer reservations)
    • All data formats (digital, paper, cloud-based)

Article 2. Definitions

2.1 Personal Identifiable Information (PII): Any information that can be used to identify an individual (e.g., name, address, phone number, library card number)

2.2 Sensitive Data: Includes PII, login credentials, patron reading history, and payment details

2.3 Authorized Users: Individuals permitted to access specific data based on their role

Article 3. Data Collection and Use

3.1 Only data necessary for library operations (e.g., account creation, program registration) shall be collected.

  • The library will inform patrons about what data is collected and how it is used, in accordance with privacy laws and local policies.

Article 4. Access Control

  • Access to sensitive data is role-based and limited to authorized personnel only.
    • Strong password policies are enforced; multi-factor authentication (MFA) is recommended for administrative access.

Article 5. Data Storage

  • PII and sensitive data must be encrypted at rest and in transit.
    • Backups are performed regularly and stored securely.
    • Paper records with sensitive information must be stored in locked cabinets with restricted access.

Article 6. Network and System Security

  • All public and staff systems must have up-to-date antivirus and security patches.
    • Firewalls and secure wireless networks are required.
    • Regular audits of software and hardware for vulnerabilities will be conducted.

Article 7. Vendor and Third-Party Services

7.1Third-party vendors (e.g., for e-book lending or ILS) must adhere to equivalent or higher security standards.

7.2Contracts must include data protection clauses and breach notification requirements.

Article 8. Data Retention and Disposal

8.1 Data is retained only as long as necessary for operational purposes.

  • Secure methods (e.g., shredding, wiping) are used for data and equipment disposal.

(RESOLVED, By the Ogdensburg Public Library, that Retention and Disposition Schedule for New York Local Local Government Records (LGS-1), issued pursuant to Article 57-A of the Arts and Cultural Affairs Law, and containing minimum periods for local government records, is hereby adopted for use by all officers in legally disposing of valueless records listed therein.  FURTHER RSOLVED, that in accordance with Article 57-A: (a) only those records will be disposed of that are described in Retention and Disposition Schedule for New York Local Government Records (LGS-1), after they have met the minimum retention periods described therein; (b) only those records will be disposed of that do not have sufficient administrative, fiscal, or historical value to merit retention beyond established legal minimum periods.)

Article 9. Incident Response

  • Any data breach or unauthorized access must be reported immediately to the Library Executive Director and IT department.
    •  An incident response plan will guide mitigation, communication, and legal compliance steps.

Article 10. Staff Training

  1. All staff must undergo annual training on data privacy and security best practices.
    1. Specialized training is provided for staff handling sensitive information.

Article 12. Compliance

This policy complies with:

  • Local government regulations
  • State data protection laws
  • Federal laws including the Children’s Online Privacy Protection Act (COPPA) and applicable sections of the GDPR if international users are involved

  • Adopted by the Board of Trustees on:  September 3, 2025