NCSBN Privacy Statement
The following privacy and security policies are applicable to NCSBN Websites. See also: Terms of Use (including the use of Trademarks).
Introduction
National Council of State Boards of Nursing, Inc. (“NCSBN”, “us” or “we”) is committed to protecting your privacy when you provide data to us through NCSBN websites, affiliates, and applications (each hereinafter, a “Site” unless otherwise specifically identified). The NCSBN Privacy Statement (“Privacy Statement” or “Statement”) sets out the privacy practices for NCSBN with respect to information, including Personal Data (which means any information relating to an identified or identifiable natural person), we obtain from and about you.
Please read the information below to learn about the Personal Data collected about you and how it is collected, used and disclosed. The information we are collecting now will be treated consistently with this Statement. We may make changes to this Privacy Statement in the future, so please review the Statement regularly. If we make changes, we will post the revised Statement on the Site and include the date this Privacy Statement was last revised at the end of the Statement. We may also notify you of changes through a notice on the Site home page and/or any by other legal means.
Personal Data Collected
Sources of Personal Data
Personal Data is collected directly from you when you:
- Complete a User profile on an applicable Site.
- Complete search fields on various NCSBN websites.
- Voluntarily share content through applicable Site features, including message boards, testimonials, user ratings, videos and photos (collectively referred to a "Community Features").
- When you visit our Site via passive technologies such as standard server logs and cookies.
Your personal data may also be received from your nursing regulatory body (NRB). It is your responsibility to provide us with accurate data and to provide us with updated Personal Data when it changes.
Categories of Personal Data
The Personal Data we collect depends upon how you interact with us. The Personal Data collected by NCSBN may include:
Identifiers:
- First, middle and last name
- Alias
- Postal address
- Billing address
- Username/password
- Email address
- Telephone number
- IP address
- Social Security number
- Last four digits of Social Security number
- Driver’s license number
- Mother’s maiden name
NCSBN collects Identifiers for the purposes of creating user profiles and granting access to Sites.
By submitting email contact information, NCSBN members consent to receiving email communications from NCSBN, including marketing materials and group and committee information. You can opt out of receiving these communications at any time.
NCSBN collects and uses Personal Data for the purposes of facilitating access to Sites; populating relevant information into various NCSBN databases; maintaining NCSBN’s internal and external membership database; providing relevant information from various NCSBN databases regarding licensure, discipline, or other information; obtaining licensure endorsement; confirming the identity of candidates who wish to take the NCLEX® examination; administering online courses or other services on the Sites; and for email delivery of NCSBN communications.
Characteristics of protected classifications:
- Date of birth
- Gender
- Ethnicity
We collect and use this information in aggregate from E-Notify for Nurses registrants for the NCSBN workforce survey. This aggregate information is for research purposes only.
Biometric information:
-
Palm vein scanning
We collect and use this information to confirm the identity of candidates who wish to take the NCLEX® examination. See the NCSBN Biometric Data Policy for more information.
Internet or other electronic network activity information:
- IP address
- Browser type
- System type
- “Referring URL” (i.e., the page from which you navigated to our Site)
- The pages or areas you navigate to on Site and from which you leave the Site, as well as the time you spend using the Site
We use passively collected information to administer, operate, and improve our Sites, and to provide services and content that are tailored to meet User interests and needs. If we link or associate any information gathered through passive means with Personal Data, we treat the combined information as Personal Data under this Statement. Otherwise, we use information collected by passive means in aggregate only. This usage data is used to assist NCSBN in understanding usage of the Site and what technology can be supported. Also, please be aware that third parties may set cookies on your hard drive or use other means of passively collecting information about your use of their services or content. We do not have access to, or control over, these third-party means of passive data collection.
Information detected by the senses:
- Audio/video testimonials
- Electronic postings and ratings
- Photo image
On an applicable Site, NCSBN will collect content provided by Users and identifying Personal Data submitted on Community Features, such as discussion boards, product ratings and audio and/or video testimonials. NCSBN may use content posted by Users of Community Features in promotional collateral to promote the Site. For example, we may reproduce a User rating and comment about a course offering and may also display the name of the individual who posted that rating and comment. Please be aware that any information that is publicly posted throughout an applicable Site can be accessed by every visitor of the Site.
Professional or employment-related information:
- Employment
- Employment history
We collect and use this information in aggregate for the NCSBN workforce survey for research purposes.
Education information:
- Schools
- Degrees
- Graduation dates
We collect and use this information in aggregate for the NCSBN workforce survey for research purposes.
Customer experience chat communications:
We may monitor or record chat communications for quality assurance purposes.
Sensitive Personal Data
Some of the data that we collect is considered Sensitive Personal Data under certain state data privacy statutes. Sensitive Personal Data includes gender, race, ethnicity, and biometric information. We will obtain your consent before processing Sensitive Personal Data.
With Whom We Share Personal Data
NCSBN does not sell any of your Personal Data, nor do we share it with any third parties, except as necessary to provide products or services requested, to facilitate communications with you, when we have your permission, or as otherwise described in this Privacy Statement.
We provide Personal Data to third parties who work on behalf of or with NCSBN under confidentiality agreements. These third parties will not use your Personal Data for any purposes other than for which we disclose it to them, including to communicate with you about offers from the service providers themselves, except that Nursing Regulatory Bodies (NRBs) may use your Personal Data to contact you or to contact employers.
Personal Data entered by Users of various NCSBN websites and systems shall be maintained in confidence by NCSBN and will not be disclosed or shared with other organizations, except as provided in this Statement. NCSBN may identify registered organizations as recipients of services in presentations, promotional materials and press releases.
Under limited circumstances, your Personal Data may be disclosed to third parties as permitted by, or to comply with, applicable laws and regulations or as required by law enforcement officials; for instance, when responding to a subpoena, court order or similar legal process, to protect against fraud and unauthorized transactions, in situations involving the physical safety of any person, to investigate violations of and enforce NCSBN Terms of Use, and to otherwise cooperate with law enforcement or regulatory authorities.
Retention of Data
NCSBN will keep your Personal Data only for as long as reasonably necessary to fulfill the purposes for which Personal Data is collected as stated herein; for as long as is necessary for the performance of the contract between you and us, if any, between NCSBN and nursing regulatory bodies; and to comply with legal and statutory obligations, such as in tax, trade and corporate laws. When we no longer need your Personal Data for our purposes, we will destroy, delete or erase that Personal Data or convert it into an anonymous form.
Security of Data
NCSBN takes reasonable steps to protect your Personal Data in our possession from loss, misuse, unauthorized access, disclosure, copying, alteration, and destruction. NCSBN has implemented various measures to protect against the misuse and alteration of any information under NCSBN's control. Sensitive Personal Data provided to NCSBN is encrypted to protect the integrity of the data as it travels the Internet, provided your browser supports this. Such security is not impenetrable, and therefore NCSBN cannot guarantee that no loss, misuse, or alteration of information on the Site will occur. NCSBN and its third-party licensors are not responsible for any damage incurred by any such security failures. We limit access to Personal Data to employees and third parties who we reasonably believe need access to that information to provide products or services to Users or to do their jobs.
NCSBN’s Information Security Management Program is aligned with the Security and Privacy Controls for Federal Information Systems and Organizations. NCSBN uses the National Institute of Standards and Technologies (NIST) 800-53, moderate-impact security controls framework for its information security to protect the confidentiality, integrity and availability of information that is processed, stored and transmitted by NCSBN’s information systems. Please visit the NIST website for additional information on the NIST 800-53 framework. Applicable systems are also PCI compliant as designated by Trustwave.
A credit card processing company is used to process credit cards. Credit card information provided by Site Users will be used only for billing purposes and will not be provided to any third party.
NCSBN has corporate security policies, procedures and contractual security requirements that promote the protection of intellectual property, employee and customer Personal Data, proper data security and data handling procedures, and data transmissions. NCSBN also performs assessments, audits, penetration tests, and vulnerability scans to help assure NIST 800-53, moderate-impact security control compliance and PCI compliance.
Email Communications Choice/Opt-Out
When NCSBN members provide us with email contact information, they consent to receiving email communications from NCSBN, including marketing materials and group and committee information. All subscription-based NCSBN email communications provide users with a link to unsubscribe to the service. Users can also request via email (communications@ncsbn.org) the removal of their information from subscription-based NCSBN email communications to not receive future communications.
Regarding Children Under 13
The Site is not marketed to children under the age of 13 and we do not intentionally gather Personal Data about visitors who are under the age of 13. NCSBN is committed to protecting the privacy of children and if NCSBN becomes aware that such Personal Data was collected, it will treat that Personal Data as sensitive.
Your Data Subject Rights
Depending on the state where you reside, the following rights may be available to you.
Right to Access
You may have the right to request that we disclose the categories of Personal Data collected by NCSBN, the categories of sources from which Personal Data is collected, the business or commercial purpose for collection, the categories of third parties with which we share Personal Data, and the specific pieces of Personal Data that we have about you. You also may have the right to request that we provide your Personal Data to you in a readily useable format. NCSBN is contractually unable to share some Personal Data about you that is provided by NCSBN NRBs.
Right to Request Deletion
You may have the right to request that we delete Personal Data that we collected from you. Note, however, that certain requests to delete Personal Data may be denied if we are required to retain the information as a matter of law, the information is necessary for detecting security incidents, exercising free speech, protecting or defending against legal claims, or for internal uses reasonably aligned with consumer expectations.
Right to Non-Discrimination
You have the right not to receive discriminatory treatment by us for exercise of these privacy rights. We do not offer financial incentives related to the provision of data.
Authorized Agent
You may have the right to designate an authorized agent to make these requests on your behalf. To exercise any of these rights, please contact us at privacy@ncsbn.org. We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it.
Canadian Privacy Rights and Provisions
If you are a resident of Canada, the following rights and provisions apply to you.
Transfers
NCSBN may process, store and transfer your Personal Data in and to countries other than Canada, including the United States, whose privacy or data protection laws may or may not be equivalent to Canadian law. In these circumstances, the governments, courts, law enforcement and/or regulatory agencies of that country may be able to obtain access to your Personal Data through the laws of that country. If your Personal Data is transferred to a service provider in a country outside of Canada, we will take reasonable measures to protect your Personal Data with appropriate contract clauses.
Withdraw Consent
Subject to certain legal and contractual restrictions and reasonable notice, you may refuse or withdraw your consent to the collection, use or disclosure of your Personal Data at any time by contacting us as described below (see “Contact Information”). Please note that if you withdraw your consent we may not be able to provide you with a particular product or service. We will explain the implications to you at the time to help you with your decision.
Right to Access
Upon request, subject to limited exceptions under applicable law, we will provide you with access to the Personal Data we hold about you and provide you with an account of the use of that Personal Data and third parties to whom it has or may have been disclosed. You may challenge the accuracy and completeness of that information and, if you demonstrate that your Personal Data is inaccurate or incomplete, we will make reasonable efforts to amend that information as required and, where appropriate, transmit the amended information to third parties having access to the information in question. We may request specific information from you to help us confirm your identity and your right to access the Personal Data that we hold about you or to make your requested changes. If we are unable to provide you with access to some or all of your Personal Data, we will inform you of the reasons why, subject to any legal or regulatory restrictions. If you would like to request access to or correction of your Personal Data, please contact us as described below (see “Contact Information”).
You may also review and update your Personal Data by logging into your User profile on the applicable Site.
Contact Information
Unless otherwise stated, NCSBN is a data controller for Personal Data processed subject to this Statement. If you have any questions about this Statement or if you believe that your Personal Data has been processed or disclosed in violation of this Statement, please contact us by sending an email to privacy@ncsbn.org or a letter to:
NCSBN
Attn: Director, Information Security Assurance
111 E. Wacker Dr., Ste. 2900
Chicago, IL 60601-4277
Last Updated: 2/20/2024