How to purchase software


Overview


Follow the steps below to ensure that any new software purchase or renewal complies with UC San Diego  IT Procurement policies and receives the required security and privacy approvals before a requisition is submitted

Critical Concepts


Steps to Take


Preparation 

Before initiating a software purchase or renewal request, complete the following actions: 

  1. Check the UCOP Technology Agreement Page to see if the software is already covered by a UC systemwide contract. These agreements often include pre-negotiated pricing, terms, and data protection provisions.
  2. Gather key information about the software’s purpose, the type of data it will process, and any new features or integrations.
  3. Identify whether this is a new purchase or a renewal (especially one older than 3–5 years or with expanded functionality).

Determine if an ITS Security Review Is Required

Ask yourself: 

  1. Is this a new software purchase?
  2. Is this a renewal that’s 3–5 years old or one with major scope or functionality changes (such as new features, integrations, or expanded use)?

If you said yes to any of these questions, an ITS Security Review is required. Complete and submit the Vendor Security Review Request Form to begin the review process.

If you said no to all, no ITS review is needed.

Determine if a Privacy Review Is Required

Ask yourself: 

  1. Does the software process P3 or P4 data?
  2. Does the software include or rely on AI technology?

If you said yes to either question, a Privacy Review is required. Complete a Privacy Risk Intake Form with the Campus Privacy Office.

If you said no to both, no privacy review is needed.

Attach Approvals and Submit Your Requisition

Once all required reviews are complete:

  1. Collect approval notifications from both the ITS Security Review and the Privacy Review (if applicable).
  2. Attach these approvals to your final requisition in Oracle.
  3. Submit the requisition only after all reviews are complete.

 

Helpful Contacts & Resources


 

Topic

Contact / Resource

Data Security ReviewsEmail oia-rc@ucsd.edu to check the status of an ITS security review.
Campus Privacy OfficeEmail ucsdprivacy@ucsd.edu for privacy-related inquiries
UCSD Health Sciences Privacy MattersEmail hscomply@health.ucsd.edu for all privacy matters related to UCSD Health Sciences, including medical research.
Additional ResourcesVisit the Software Acquisition Blink Page for comprehensive IT procurement guidance.

 

If you still have questions or need additional assistance, please submit a ticket.