Qualtrics Acceptable Use and Data Security

The Qualtrics license grants the University of Minnesota permission to use the software solely for University of Minnesota purposes, and expressly prohibits use by third parties. If users do not adhere to the Qualtrics acceptable use terms outlined below, they may be subject to liability. 

Qualtrics Acceptable Use Terms

The Qualtrics acceptable use terms are as follows: 

  • Users must not distribute a survey if the survey project is unrelated to a University academic, employment, or business need. Qualtrics should be used solely for University purposes.
     
  • Users must follow the University's Internal Mass Email requirements when using the Qualtrics email distributions. 
     
  • Users must avoid excessive use of Qualtrics email distributions. Excessive use is defined as use that is disproportionate to that of other users, is unrelated to academic or employment-related needs, or interferes with other authorized uses.
     
  • Users should use appropriate survey templates based on their relationship to the University. All Qualtrics surveys conducted by faculty and staff should use an official University of Minnesota Basic template. Students should not use any of the official University of Minnesota branded templates and should instead use the Qualtrics branded templates. Templates can be found in the Look & Feel section of the Qualtrics survey builder. See more information about survey branding guidelines.
     

For questions about whether or not your survey project meets acceptable use for the University’s Qualtrics license, please contact the UMN Qualtrics Brand Administrators at [email protected]. 

Qualtrics Privacy and Data Security

Qualtrics is the preferred online survey tool of the University of Minnesota because it meets stringent information security requirements not found in most free online survey tools.

Data Ownership

The University of Minnesota, not Qualtrics, are the owners of the data in the University’s instance of Qualtrics. 

Data Access

In the best interest of protecting data privacy, there will be a limited number of UMN Qualtrics Brand Administrators who have access to UMN Qualtrics data. If you are a researcher and need to include the number of people who have access to the data in your documentation to IRB or granting agencies, contact [email protected].

FERPA

Staff and faculty must take additional care with student information, most of which is protected by the Family Educational Rights and Privacy Act (FERPA). Because Qualtrics is a licensed tool, it is permissible to use with FERPA-protected data. This only applies when logged into Qualtrics with your University of Minnesota account.

Qualtrics data containing FERPA-protected information can only be shared with school officials who have a legitimate educational interest in the information. For more information on FERPA, review the FERPA resources or take the FERPA training (SR0071) available in the Training Hub. For FERPA questions, contact [email protected].

HIPAA

Staff, faculty, and people within the Healthcare Component (HCC) must take additional care in handling Health Information. Health Information includes, but is not limited to, Individually Identifiable Health Information (IIHI) and Protected Health Information (PHI).

Qualtrics has acknowledged that its offerings are HIPAA compliant by entering into a Business Associate Agreement (BAA) with the University of Minnesota. This means that if your survey involves Protected Health Information (PHI), Qualtrics will handle the PHI in a manner that is in compliance with the law.

Qualtrics may be used for Health Information in IRB-approved studies, but any use of Qualtrics with Health Information, and how it is used, must be outlined in the study protocol.

Any data that is considered PHI must be maintained in alignment with the University’s policy. PHI is classified at the highest level of data security for the University, Private Highly Restricted, in accordance with Administrative Policy: Data Security Classification and related data classification. PHI must be handled in accordance with the highest security level identified in the appendices of Administrative Policy: Information Security, and such other policies, procedures, standards and guidelines as may be developed for the handling of PHI by the University.

De-identified data standards must align with HIPCO guidance regarding De-identified Data sets.

For other questions about Health Information, please contact the Health Information Privacy & Compliance Office (HIPCO) at [email protected].

General Data Protection Regulation (GDPR)

The University of Minnesota’s Qualtrics platform is GDPR compliant from a base data security perspective, but it is up to individual users to ensure that they are managing Qualtrics projects in a manner that adheres to GDPR standards. 

Qualtrics Data Security Resources

Use of Third-Party Survey Software

The text below has been approved by the Office of General Counsel (OGC) regarding reasons University faculty, staff, and students should not purchase or use other third-party survey software (such as Survey Monkey or Zoomerang).

A click-through agreement is a contract, and the University can be liable under the contract. The “click-through” license agreements that users must “accept” before using a software program are subject to the same principles as contracts that are formed in any other way, meaning these click-through agreements are legally binding contracts. When a University employee enters into such an agreement, they are doing so on behalf of the University. Therefore, the University as a whole (not just the employee) may be bound by this employee’s agreement, and may also be liable under it. These click-through agreements can also violate University policy and practices regarding contract review, and uncapped liability, and jurisdiction over what state’s laws govern. Under University policy, the OGC must review any contract not in the University’s standard Contracts Library.

Click-through agreements can also grant ownership of your (and therefore, the University’s) data to the software company. Most third-party hosted sites claim to own the content on their site. Not only would this mean loss of valuable intellectual property for individuals and the University, it could also violate the Minnesota Government Data Practices Act or the federal Family Educational Rights and Privacy Act.

Use of third-party survey software could violate privacy laws. State and federal laws prohibit disclosure of certain information about students, and require specific security measures to prevent unauthorized access to this information. Without official contracts verified by OGC to ensure the safety of this data, the third-party survey software vendor may have no legal responsibility to uphold these standards.