eCommunications Policy

Original Effective Date

March 1, 2024

Approved By

Philip P. DiStefano, Chancellor

Policy Owner

Co-Owner Vice Chancellor and Chief Communications Officer, Strategic Relations and Communcations

Co-Owner Vice Chancellor and Chief Information Officer, Office of Information Technology

I. Purpose

This eCommunications Policy (鈥淧olicy鈥) defines the governance roles and responsibilities of organizational units to enable the University of baby直播app Boulder (鈥渦niversity鈥) to exercise proactive technology, method, and process controls for electronic communications (鈥渆Communications鈥), including the data and audiences associated with eCommunications. Electronic communications services include but are not limited to: email, text messaging, and authenticated web environments.听听

The university provides eCommunications services to campus community members to support the university鈥檚 work of teaching, scholarly research, and public service. eCommunications are coordinated by programs, departments, colleges, schools, and other organizational units to provide relevant and timely information to the appropriate audiences.听听

This Policy and its accompanying procedures (鈥淧rocedures鈥) apply to all University of baby直播app Boulder organizational units that create and distribute eCommunications related to the university鈥檚 work, including for teaching, research, university administration, university advancement, or any other university business.听

II. Definitions

  1. Audience:听the data query identifying individuals who comprise an eCommunication鈥檚 recipients, groups that receive communications related to a university business need or affiliation.听听
  2. Authenticated web environment:听a website that requires a username and password to verify the identity of the user and to personalize the content that is provided, e.g., Buff Portal.听
  3. 颁础狈-厂笔础惭:听Controlling the Assault of Non-Solicited Pornography and Marketing, a federal law that provides relief from unwanted spam email messages. Non-compliance with CAN-SPAM may constitute 鈥渦nfair or deceptive acts or practices鈥 that may result in criminal and civil penalties for the violating sender. More information about CAN-SPAM is available here:听.听 鈥
  4. Communications authority:听the authority to communicate on behalf of the university.听
  5. Designated authorities:听technology users or communications professionals who have privileges to access constituent audiences听
  6. Constituent audience:听a group of individuals who share common characteristics defined by their organizational functions -- e.g., members of a class, department, college, or school.听
  7. eCommunications:听messages sent by organizational units facilitated through technology: primarily email, text messaging, and authenticated web environments. 听
  8. Electronic communications services:听digital platforms facilitating communications through email, event registration, and other one-to-many or personalized mass communications.听
  9. Organizational function:听specific responsibilities or processes tasked to an organizational unit.听
  10. Organizational unit:听A subset of University operations. An organizational unit may be a college?, center?,department or any other distinct operational entity with the following characteristics: 1) organizational permanency; 2) programmatic autonomy; and 3) an annual operating budget that is fiscally independent.听
  11. Preferences:听options presented to audience members allowing them to indicate their choices in communications experiences, at a minimum including subscribe and unsubscribe indicators, and often including options such as frequency, modality, and interests.听
  12. Promotional communication:听communications that do not include university business information that must be acted on in a timely manner. Communication that contains the promotion of a product or service, event, or general information.听
  13. Text messaging:听the act of composing and sending short electronic messages between two or more users of mobile devices, tablets, desktops, and/or laptops. Encompasses both MMS (multimedia) and SMS (short) protocols. In the Policy and procedural context, this focuses on text messaging facilitated by a software platform, sending one message from an organizational unit to many recipients. This includes registration window reminders, emergency alert notifications, application deadline messages, etc. Does not include business communications from baby直播app or academic advisors to individuals in their rosters, i.e., notifications of class cancelation, critical deadlines, office hour changes, etc.听
  14. Transactional communication:听communications related to business information that must be acted upon in a timely manner or facilitates, completes, or confirms a commercial transaction. Can consist of information pertaining to the delivery of a good or service, information directly related to an employer or educator relationship, and legally mandated notices.听

III. Policy Statement

The university provides approved eCommunications platforms and electronic communications services to organizational units to protect the operational integrity and value of university communications, as well as university data and the availability and security of campus networks. Accordingly, per this Policy:听

  1. Communications authority ultimately rests with the Chancellor and the Chancellor鈥檚 designated authorities.听听
  2. Organizational units engaging in eCommunications must either:听听
    1. use approved eCommunications services听听
    2. receive an exception from using an approved eCommunications service.听听听
  3. Organizational units must follow this Policy and accompanying Procedures to support standard eCommunications operations for organizational functions and reduce the number of eCommunications sent to campus community members regarding business outside of their organizational unit.听听
  4. The university does not grant access to eCommunications resources (approved platforms, email addresses, mobile numbers, or data) to third parties, including for commercial use or research. As outlined in the accompanying Procedures, limited exceptions may be granted for university business use.听

IV. Procedures

  1. Designated Authority
    鈥淒esignated authorities鈥 refers to technology users or communications professionals who have privileges to access constituent audiences, facilitating communications related to organizational functions and reducing the number of communications outside of organizational units.听听
    1. Communications authority ultimately rests with the Chancellor and the Chancellor鈥檚 designated authorities.听听
    2. These procedures do not apply to one-to-one communications for the purpose of university business.听
    3. Communications with select audiences may require coordination with, or execution by, specific designated authorities due to special legal or procedural conditions (e.g., FERPA-protected data points). These audiences, when referred to as a whole, and their designated authorities, include but are not limited to the following:听
      1. Athletic recruits: Department of Intercollegiate Athletics听
      2. Prospective students, their parents/guardians, and the pre-collegiate counseling team: Enrollment Management听
      3. Admitted and confirmed students: Division of Student Affairs; Enrollment Management听
      4. The enrolled student body: Student Affairs; Office of the Registrar; Strategic Relations and Communications听
      5. The campus baby直播app, or campus staff: Office of the Provost; Faculty Affairs; Human Resources; Strategic Relations and Communications听
      6. Emergency communications: Strategic Relations and Communications; Integrity, Safety, and Compliance听
      7. Audiences defined by protected classes: Office of the Registrar; Strategic Relations and Communications; Office of Institutional Equity and Compliance听听
      8. Alumni and Donors: Office of Advancement听
    4. Access to student, baby直播app, or staff鈥檚 personally identifiable biographic-demographic data for communications purposes is not granted to third parties, including for commercial use or research.听
      1. Exceptions to the approved technology platforms may be made for university business or to meet federal or state legal requirements in accordance with the exception process articulated in section B.3.听
  2. Technology and Digital Communcation Channels
    鈥婳rganizational units engaging in eCommunications on the Boulder campus must either听use approved technology platforms and digital communications channels as outlined in this section, or听receive exceptions from the requirement per the process outlined in this section.听

    1. Approved technology platforms are:听
      1. Canvas, Coursera, and other learning management systems and their integrated platforms, provided in partnership with the Office of Information Technology听
      2. Oracle CommGen and StarRez (supporting student services)听
      3. Slate CRM prospective student communications platforms (supporting Admissions, Graduate School, and Continuing Education)听
      4. Salesforce CRM Buff Advising听
      5. eComm service (Salesforce, Marketing Cloud, and Cvent) provided by the University of baby直播app University Information Systems (UIS), Strategic Relations and Communications, and CU Boulder Advancement听
      6. Salesforce CRM Boulder campus electronic communications support provided by the Office of Information Technology and Strategic Relations and Communications听听
      7. Google Groups, Grouper, Exchange Distribution Lists, and other mailing list services provided by the Office of Information Technology听
      8. RAVE and Alertus services for CU Boulder Alerts, provided by Integrity, Safety and Compliance and Strategic Relations and Communications听
      9. Vendini and Paciolan for event ticketing and ticket management, provided by CU Presents, Athletics, and the baby直播app Shakespeare Festival听
      10. Cision PR for news releases and news management, provided by Strategic Relations and Communications听
      11. Qualtrics survey management for CU Boulder, provided by the Office of Information Technology听
      12. Medicat, Maxient, DocuSign, Concur, and Avature business process platforms, provided by Student Affairs, Office of Information Technology, University Information Systems, and Human Resources听
      13. Handshake career management platform, provided by Career Services, the Leeds School of Business and the College of Media, Communication and Information听
      14. ServiceNow for service management, provided by the Office of Information Technology听
    2. Approved campuswide digital commucations channels听
      1. Enrollment Management/Academic Affairs (Office of Admissions, Bursar, Financial Aid, and Office of the Registrar)听听
      2. CU Boulder Today and Administrative eMemo service provided by Strategic Relations and Communications听听
      3. Buff Portal and Buff Portal Advising, provided by the Office of Information Technology听
    3. Exception Process
      1. When an organizational unit determines a unique need to use a technology platform or digital communications channel outside of the approved technology and channels listed in Section II.1 and II.2, the organizational unit may request an exception through either the Chief Communications Officer or Chief Information Officer (or their designee) who will initiate a discussion with the Provost and COO.听

        To initiate the exception process, the requesting organizational unit contacts the Chief Communications Officer or Chief Information Officer.听

        To be eligible for an exception, the requesting organizational unit must meet at least one of the following criteria:

    4. Necessary data integrations cannot be completed in the time period required to meet communication objectives.

    5. Because of privacy and/or confidentiality implications, information security cannot be maintained solely through managed permissions.

    6. Communications are directed towards a small, highly specialized audience that does not substantively overlap with larger campus audiences.听

      1. If the requesting unit can demonstrate sufficient eligibility criteria, SRC and OIT will grant an exception for an agreed-upon time period (dependent on the exception review) and exemption from flagging as an external sender, along with a signed acknowledgment by the organizational unit head agreeing to the following:听听

    7. A scope of work and functional requirements for integrating the organizational unit into an approved eCommunications technology platform by the end of the time period for which the exception has been granted.听

    8. The technology platform approved for exception will be able to send communications preferences (opt-out, opt-in, interests) and data back to the appropriate university system of record, as determined through a mutual discovery process.

    9. The technology platform approved for exception will meet the following required electronic communications controls:听

      1. Documentation (including originating IP range, domains, and other related information) must be provided to the Office of Information Technology to be recognized as an official sender of the university.听
      2. Messages coming from a third-party vendor or shared service must have a unique identifier in the return-path attribute.听
      3. Messages must pass authentication (SPF and/or DKIM) or they will be subject to the recipient鈥檚 SPAM filtering rules, which may include messages dropping, quarantining or junk mail routing.听
      4. Messages to audiences containing over 15,000 university email addresses may not be sent during business hours.听
      5. Messages must not directly include attachments. Documents, images, and other media should reside on other services (for example, a web server), and messages should include links and/or references to the content.听
      6. Sending rates must not exceed thirty messages per minute.听
      7. The ability to throttle sending rate to balance server loads
  3. eCommuncations Standards听
    When organizational units send eCommunications, either via approved technology platforms or digital communications channels under Sections II.1 and II.2, or for which the unit received an exception under Section II.3, the organizational unit must adhere to the following standards:
    1. Privacy
      1. Only eCommunications related to the university鈥檚 official business may be sent without an unsubscribe link (transactional communication, as defined by CAN-SPAM legislation).听
      2. FERPA privacy flags are respected above all 鈥 students with these flags only receive messages related to educational business.听听
    2. Use of text messaging
      1. Shall only be used to relay time-sensitive and actionable information that immediately benefits the audience receiving the information.听
      2. Shall not be used by university personnel solely for promotional communications.听
      3. Shall not be used as the sole means of communication.听听听
    3. Accessiblity and Brand
      1. Communications respect accessibility best practices and meet听Accessibility of Information and Communication Technology听policy stipulations.听
      2. Communications follow University of baby直播app Boulder brand identity standards.听
    4. Building Audiences
      1. Do Not Email and Do Not Contact flags (as set by university Advancement offices) are respected in audience definitions for external communications.听听
      2. Preferences, as kept in communications preference centers or other systems of record, are honored in audience definitions.听
      3. Communicators are supported with platforms to communicate with audiences defined by their organizational function, also known as a constituent audience.听听
      4. Technology platforms will provide functionality for audiences to indicate preferences.听
      5. Audience definitions can include audience members outside of an organizational unit when the audience members have indicated it as a preference.听
      6. When audience definitions contain recipients beyond an organizational unit (e.g., cross-campus program promotions), they will be assessed and approved or denied by Strategic Relations and Communications.听
    5. Technology Enforced Controls
      1. Only organizational units with privileges to access constituent audiences may view constituent data and send eCommunications.听
      2. Preferences for communications must be maintained and honored as appropriate to the communication.