---
language: "en"
---
# Acceptable Use Policy

## Purpose

All people who are granted access to or use of UTRGV or UT System Information Resources must understand and comply with the acceptable-use requirements in this policy. The policy establishes conditions for institutional resource use, protection of UTRGV data, email and incidental use, personal-device use, remote work, international travel, credentials, prohibited technologies, artificial intelligence, and technology assessment.

## Scope and Applicability

This policy applies to any **User**, defined below, who is granted access to UTRGV Information Resources. Its requirements apply to UTRGV information and systems regardless of whether UTRGV data is located on institutionally managed resources or, where allowed, on personally owned resources.

## Authority and Governing Requirements

Users must comply with applicable UTRGV and UT System information-resource use and security policies, procedures, and standards and with applicable law. Related UT System authority includes:

* [UTS 165 Information Resources Use and Security Policy](https://www.utsystem.edu/sites/policy-library/policies/uts-165-information-resources-use-and-security-policy)

* [UTS 200 Prohibited Technologies](https://www.utsystem.edu/sites/policy-library/policies/uts-200-prohibited-technologies)

## Definitions

Click to expand...  
**UTRGV:** The University of Texas Rio Grande Valley.

**UT System:** The University of Texas System.

**UTRGV Information Resources:** Computer and telecommunications equipment, software, data, and media that UTRGV owns or controls, or that is maintained on UTRGV's behalf.

**UTRGV Data:** Data or information held on behalf of UTRGV or created as a result of, or in support of, UTRGV business, regardless of storage location. It also includes information residing on UTRGV Information Resources, including paper records.

**Confidential Data / Confidential Information:** UTRGV data that applicable law requires to be maintained as private or confidential.

**User:** Any person granted access to UTRGV Information Resources.

**Prohibited Technology:** Software, hardware, or another technology resource that is not allowed for University use. Examples include unauthorized security tools or utilities, technologies that circumvent UTRGV security measures, and technologies contrary to the University's mission or applicable law.

**Artificial Intelligence (AI):** Computer systems that perform activities commonly associated with human intelligence, including learning from information, reasoning, problem solving, self-correction, and natural-language understanding. AI applications can include expert systems, natural-language processing, speech recognition, and machine vision.

## Policy Requirements

### 1. General Use

1. UTRGV Information Resources are provided to conduct UTRGV and/or UT System business. Incidental personal use is allowed only as permitted by this policy.

2. Users have no expectation of privacy for UTRGV data residing on UTRGV-owned computers, servers, or other resources owned by or held for UTRGV. Users likewise have no expectation of privacy for personal information they store on UTRGV or UT System resources, including UTRGV email accounts. UTRGV may access and monitor its Information Resources, without notice or user permission, for purposes consistent with its responsibilities, duties, or mission.

3. Users have no expectation of privacy for UTRGV data residing on personally owned devices, regardless of why the data was placed on the device.

4. Users must comply at all times with applicable UTRGV and UT System information-resource use and security policies, procedures, and standards.

5. Users shall not use UTRGV Information Resources to deny access to people otherwise entitled to use them, circumvent security measures, or act contrary to UTRGV's mission or applicable law.

6. Intentionally accessing, creating, storing, or transmitting sexually explicit material using UTRGV Information Resources is prohibited unless the activity is required for the user's official UTRGV duties and is approved in writing by the President or a specifically designated approver. Such activity is never permitted as incidental use.

7. Email or social-media content produced through incidental use must make clear that it is not provided on behalf of UTRGV and does not state UTRGV's position. The source provides this example disclaimer: "The opinions expressed are my own, and not necessarily those of The University of Texas Rio Grande Valley." Users should consult University Marketing and Communications for additional guidance.

8. Users should report misuse of UTRGV Information Resources or policy violations to their supervisors or through an approved reporting method.

### 2. Confidentiality and Security of Data

1. Users shall access UTRGV data only for UTRGV business and only as allowed by applicable confidentiality and privacy laws.

2. Users must not attempt to access systems or data for which they have not been expressly authorized.

3. Records containing UTRGV data shall be maintained in accordance with:

   * UTRGV information and data security policies, procedures, and standards;

   * the UTRGV Records Retention Policy; and

   * the Records Management Guidelines.

4. Confidential data shall not be disclosed except when legally permitted or required and only as part of the user's official UTRGV duties.

5. When feasible, Confidential Information and other information essential to UTRGV's mission shall be stored on centrally managed servers or another UTRGV-approved storage location instead of on a local hard drive or portable device.

6. When a user must create or store Confidential or mission-essential UTRGV data on a local drive or portable device, including a laptop, tablet, or smartphone, the data must be encrypted and secured in accordance with UTRGV, UT System, and other applicable requirements.

7. At minimum, the following UTRGV data must be encrypted when transmitted across an unsecured network:

   * Social Security numbers;

   * personally identifiable medical and medical-payment information;

   * driver's license numbers and other government-issued identification numbers;

   * education records governed by FERPA;

   * credit or debit card numbers together with any code or PIN that would enable access to financial accounts;

   * bank-routing numbers; and

   * other UTRGV data about an individual that is likely to expose that individual to identity theft.

8. Email between UTRGV/UT System institutions using institutionally provided email accounts is automatically encrypted. The Office of Information Technology provides tools and processes to send encrypted data across unsecured networks to or from other locations.

9. Users storing UTRGV data in cloud services must use services supplied, sanctioned, and approved by UTRGV through an approved purchase or authorization process rather than personally acquired cloud services.

10. Users must not use security programs or utilities unless those tools are required for official UTRGV duties. Such use requires written approval by the UTRGV Chief Information Security Officer.

11. Computers and other electronic devices that connect to a UTRGV network must run current operating systems, patches, and security software as prescribed by the Information Security Office.

12. UTRGV may immediately disconnect, without notice, devices that do not meet required security standards, lack required software, or otherwise threaten UTRGV Information Resources. Any exception must follow the Information Security Office Security Exception Process.

### 3. Email

1. Email sent or received while conducting UTRGV business is UTRGV data and is subject to state records-retention and security requirements.

2. Users are to conduct UTRGV business with UTRGV-provided email accounts rather than personal email accounts.

3. The following activities are prohibited when using a UTRGV-provided email account:

   * sending email under another person's name or address unless that account owner has authorized it for a work-related purpose;

   * accessing another user's email content except as part of an authorized investigation, an approved monitoring process, or another activity specifically associated with the user's official UTRGV duties;

   * knowingly sending or forwarding email that the user suspects contains viruses, malware, or other potentially harmful material;

   * incidental use prohibited by this policy; and

   * any use prohibited by applicable UTRGV or UT System policy.

### 4. Incidental Use of UTRGV Information Resources

1. Incidental use must not interfere with official UTRGV work, create direct cost to UTRGV, expose UTRGV to unnecessary risk, violate law, or violate UTRGV/UT System policy.

2. Users have no expectation of privacy in personal information stored on UTRGV or UT System Information Resources, including UTRGV email.

3. A user's permission for incidental personal use does not extend to family members or other people, regardless of where the UTRGV resource is located.

4. Incidental use to conduct or promote outside employment, including self-employment, is prohibited.

5. Incidental use for political lobbying or campaigning is prohibited.

6. Email, voice messages, files, or documents created as incidental use must consume only nominal storage, defined by the source as less than 5 percent of the user's allocated mailbox space.

7. Files unrelated to UTRGV or UT System business may not be stored on network file servers.

### 5. Personal Portable Computing / BYOD

1. Any electronic device, including a personally owned computer, smartphone, or similar device, that is used to access, create, or store UTRGV Information Resources, including email, must be password protected according to UTRGV requirements. The password must be changed when compromise is suspected. The source refers to these devices as Bring Your Own Device (BYOD).

2. UTRGV data created or stored on a user's personal device or in a database outside UTRGV Information Resources remains subject to public-information requests, subpoenas, court orders, litigation holds, discovery requests, and other requirements applicable to UTRGV Information Resources.

3. UTRGV-issued mobile-computing devices must be encrypted and follow all applicable UTRGV and UT System device and security policies, procedures, and standards.

4. A personally owned computing device that stores or creates Confidential UTRGV Data must be encrypted and must follow prescribed UTRGV and UT System policies, procedures, and standards.

5. UTRGV data created or stored on personal computers, other personal devices, or non-UTRGV databases should be moved to UTRGV Information Resources as soon as feasible.

6. Unattended portable computers, smartphones, and other computing devices must be physically secured.

7. Remote access to networks owned or managed by UTRGV or UT System must use a remote-access method approved by the applicable institution.

See also the [Data Protection Standard for Personally Owned Mobile Devices](../standards/data-protection-standard-for-personally-owned-mobile-devices.md).

### 6. Remote Workers

Remote work requires the following additional safeguards for UTRGV Information Resources.

#### 6.1 Security Measures

1. Electronic devices used to access, create, or store UTRGV Information Resources must be password protected according to UTRGV requirements, and passwords must be changed if compromise is suspected.

2. UTRGV-issued mobile devices must be encrypted and comply with UTRGV and UT System device and security policies, procedures, and standards.

3. Personally owned devices that store or create Confidential UTRGV Data must be encrypted and comply with prescribed UTRGV and UT System policies, procedures, and standards.

4. Unattended portable computers, smartphones, and other computing devices must be physically secured.

#### 6.2 Data Management

1. UTRGV data on personal devices or non-UTRGV databases remains subject to public-information requests, subpoenas, court orders, litigation holds, discovery requests, and other requirements applicable to UTRGV Information Resources.

2. UTRGV data created or stored on personal devices or non-UTRGV databases should be transferred to UTRGV Information Resources as soon as feasible.

#### 6.3 Remote Access

Remote access to UTRGV- or UT System-owned or managed networks must use an approved remote-access method.

#### 6.4 Incident Reporting

Users should report security incidents to the Information Security Office at [is@utrgv.edu](mailto:is@utrgv.edu) and policy violations to their supervisors or through an approved reporting method.

#### 6.5 Compliance

Remote users must comply with UTRGV and UT System Information Resources policies, procedures, and standards at all times, including Prohibited Technology requirements, HIPAA requirements, AI requirements, International Travel requirements, and other applicable standards.

### 7. International Travel

#### 7.1 Travel to Countries Not Designated as Adversary / Countries of Concern

Before and during international travel, users must protect the security and integrity of UTRGV Information Resources.

**Pre-travel preparation:**

1. Obtain required permissions and clearances, including, as applicable:

   * International Oversight Committee;

   * Export Control;

   * Information Security;

   * Information Technology; and

   * any other required approval.

2. Ensure laptops, smartphones, tablets, and other electronic devices are encrypted and password protected according to UTRGV requirements.

3. Update operating systems, security patches, and antivirus software before departure.

4. Back up essential data to a secure UTRGV-approved storage location before travel.

5. A traveler planning travel to a designated adversary country/country of concern cannot take UTRGV Information Resources or access UTRGV Information Resources while there. The source directs travelers to the Office of Research Integrity and Export Compliance for the current list of countries of concern.

**Data management:**

1. Avoid storing sensitive or confidential UTRGV data on personal devices; use UTRGV-approved cloud services for storage and access.

2. Transfer UTRGV data created or stored on personal devices to UTRGV Information Resources as soon as feasible.

**Remote access:**

1. Use only UTRGV-approved remote-access methods to connect to UTRGV networks while abroad.

2. Avoid public Wi-Fi when accessing UTRGV Information Resources; use a UTRGV-provided secure VPN connection.

3. Access to UTRGV systems will be suspended while a traveler is in an adversary country/country of concern because access from such a country is not permitted.

**Incident reporting:**

Report security incidents or policy violations immediately to the Information Security Office or through an approved reporting method.

#### 7.2 Special Requirements for Adversary Countries / Countries of Concern

Business travel to an adversary country/country of concern is prohibited. Personal travel requires prior notification and a post-travel debriefing.

**Pre-travel briefing and training:** After personal-travel notification, obtain a pre-travel briefing from the appropriate offices regarding destination-specific risks and requirements, and complete required international-travel training, including Information Security Office International Training.

**Device and access restrictions:**

1. Do not take UTRGV Information Resources to, or access UTRGV systems or data from, an adversary country/country of concern.

2. Accessing UTRGV data, including email, from a country of concern is treated as a business purpose and is prohibited. This includes access to email, the LMS, and the Human Capital Management system (Oracle).

3. Do not take devices or storage media containing sensitive or confidential UTRGV data; the source treats this as a prohibited business purpose.

**Post-travel actions:** On return, perform a thorough security check of personal devices before connecting them to UTRGV resources. Report suspicious activity or potential compromise to the Information Security Office immediately, and contact the International Oversight Committee for the required post-travel debriefing.

### 8. Password Management

1. Electronic devices used to access, create, or store UTRGV Information Resources must be password protected according to UTRGV requirements. Passwords must be changed when compromise is suspected.

2. UTRGV-issued or required credentials and authentication items, including passwords for digital certificates, PINs, digital certificates, security tokens such as smart cards, and similar authentication information or devices, shall be secured and shall not be shared or disclosed.

3. Each user is responsible for activity performed using that user's password or other credentials.

See also the [Multi-Factor Authentication Standard](../standards/multi-factor-authentication-standard.md).

### 9. Prohibited Technologies

1. Prohibited Technology includes disallowed software, hardware, or other technology resources, including unauthorized security programs/utilities, technology that circumvents UTRGV security measures, and technology contrary to UTRGV's mission or applicable law.

2. Use of Prohibited Technologies is strictly banned to protect UTRGV Information Resources. Security programs and utilities may be used only when required for official duties and when approved in writing by the Chief Information Security Officer.

3. UTRGV may immediately disconnect without notice devices that lack required security controls or software or otherwise threaten UTRGV Information Resources.

4. Additional requirements are in the [Prohibited Technologies Policy](prohibited-technologies-policy.md).

### 10. Appropriate and Permissible Use of Artificial Intelligence

1. AI should be used consistently with University policy, ethical guidance, and legal requirements. Appropriate use may improve productivity, decision-making, and University outcomes, but must maintain data privacy, security, and regulatory compliance. AI use must not compromise the confidentiality, integrity, or availability of UTRGV Information Resources.

2. Permissible AI uses include:

   * automating repetitive tasks;

   * analyzing large data sets for useful insights;

   * improving customer service with AI-enabled chatbots;

   * supporting decisions with predictive analytics;

   * improving cybersecurity through real-time threat detection and response; and

   * approved activities supporting UTRGV's academic, research, and medical missions.

3. AI must be used responsibly and ethically. Users must consider and mitigate AI-related risks and support transparent, fair, non-discriminatory outcomes.

4. At minimum, ethical AI use must address:

   * **Human rights:** use AI in ways that respect privacy, dignity, equality, and other human rights; illegal or unethical use may result in discipline.

   * **Transparency and accountability:** respect transparency concerning AI development, use, data sources, algorithms, and decision processes, and maintain accountability for AI-related outcomes and consequences.

   * **Bias mitigation:** where appropriate, identify, report, and mitigate bias in AI algorithms and data and seek fair, objective systems.

   * **Informed consent:** when collecting or using human data, obtain clear and understandable informed consent and comply with applicable legal and ethical standards.

5. Further requirements are in the [Artificial Intelligence (AI) Policy](artificial-intelligence-ai-policy.md), Information Security Office requirements, and division-specific guidance.

### 11. Technology Assessment

All technology - including software, hardware, appliances, cloud or local services, and tools that process, store, or transmit data - must be assessed and approved by the appropriate offices before purchase or installation on UTRGV Information Resources. This requirement includes open-source and free products, paid software, browser plug-ins/extensions, applications, and services.

## Roles and Responsibilities

The source policy assigns obligations primarily to **Users**. Users are responsible for complying with this policy, safeguarding credentials, protecting UTRGV data, following approved technology and access processes, and reporting incidents or misuse. The Information Security Office defines security requirements, approves specified security-tool uses and exceptions, and receives security-incident reports. The Office of Information Technology provides approved technical services such as secure transmission and remote access. Other approval and oversight responsibilities identified in the requirements include the President or designee, supervisors, University Marketing and Communications, the International Oversight Committee, Export Control, and the Office of Research Integrity and Export Compliance.

## Compliance and Enforcement

UTRGV may monitor institutional Information Resources, disconnect non-compliant or threatening devices without notice, and address violations through supervisors or approved reporting channels. Illegal, unethical, or otherwise prohibited conduct may result in disciplinary action under applicable UTRGV rules and policies.

## Exceptions

The source explicitly identifies several exception/approval routes:

* sexually explicit material required for official duties requires written approval by the President or a specific designee;

* security programs or utilities used for official duties require written Chief Information Security Officer approval; and

* devices that cannot meet security requirements must follow the Information Security Office Security Exception Process.

Other topic-specific approval requirements remain within the relevant sections above.

## Related UTRGV Documents

* [Artificial Intelligence (AI) Policy](artificial-intelligence-ai-policy.md)

* [Prohibited Technologies Policy](prohibited-technologies-policy.md)

* [Computer Security Standard](../standards/computer-security-standard.md)

* [Data Protection Standard for Personally Owned Mobile Devices](../standards/data-protection-standard-for-personally-owned-mobile-devices.md)

* [Multi-Factor Authentication Standard](../standards/multi-factor-authentication-standard.md)

* [Data Governance Roles Definitions](../guidance/data-governance-roles-definitions.md)

* UTRGV Records Retention Policy

* UTRGV Data Classification Standard

* UTRGV Information Security Office Security Exception Process

## External References

* [UTS 165 Information Resources Use and Security Policy](https://www.utsystem.edu/sites/policy-library/policies/uts-165-information-resources-use-and-security-policy)

* [UTS 200 Prohibited Technologies](https://www.utsystem.edu/sites/policy-library/policies/uts-200-prohibited-technologies)

## Review and Revision History

|  **Date**  |                              **Revision**                              |
|------------|------------------------------------------------------------------------|
| 2026-08-12 | Initial migration to [https://docs.utrgv.edu](https://docs.utrgv.edu/) |

## Contact Information

Information Security Office

Email: [is@utrgv.edu](mailto:is@utrgv.edu)

Phone: 956-665-7823