Data Classification Standard

Data Classification Standard

Purpose

This standard explains how to classify University data and apply baseline handling expectations. It helps people decide when data may be shared, when extra protection is needed, and when to consult the responsible office or Data Owner. This standard implements the requirements of the Information Security Policy (Adopted Policy 5.3) by establishing a framework for classifying and handling University data.

Responsible Owners

Information Technology Services, Division for Finance and Administration

Standards History

Version:

2.0

Effective Date:

July, 2011

Last Revised:

July 16, 2026

Standards Statement

This standard applies to data created, received, maintained, transmitted, processed, or shared by the University or on its behalf. It uses four classification tiers. Information Technology Services (ITS) maintains the framework; the responsible Data Owner determines the classification and handling expectations for specific data.

Persons Affected

This standard applies to all University faculty, staff, students, affiliates, contractors, volunteers, and other individuals who create, access, use, store, transmit, share, or manage University data.

Definitions

University: University at Albany, State University of New York.

University data means data created, received, maintained, transmitted, processed, or shared by the University or on its behalf, including institutional data and data used for administration, operations, compliance, research, teaching and learning, services, and other University activities.

Institutional Operations and Compliance Data is University data used to operate, administer, support, document, govern, or comply with University programs, services, and business processes.

Research Activity Data is University data used to plan, conduct, analyze, document, or share research, scholarship, sponsored programs, or other scholarly inquiry. Sponsored programs include externally supported projects such as grants, contracts, and cooperative agreements.

Instructional Materials Data is University data created or used to design, deliver, or improve teaching and learning activities, such as course content, exercises, assessments, rubrics, and instructional resources.

Data Owner means the University official, office, principal investigator, or other authorized person responsible for a data set, system, process, course material, or research activity. The Data Owner decides how the data may be used, who may access it, when it may be shared, and what classification applies.

Data Steward means the University official or office that helps manage data on behalf of the Data Owner or within a functional area. The Data Steward helps interpret requirements, apply classifications, support access decisions, and communicate handling expectations so the data is used and protected appropriately.

Third Party means an external person, organization, service, system, or provider that is not acting as part of the University workforce or within a University-managed system. Examples include collaborators, partner institutions, sponsors, vendors, contractors, publishers, cloud services, software platforms, and AI-enabled services.

External Processing means access, storage, transmission, analysis, transformation, hosting, or other handling of University data by a non-University system, service, platform, or provider, including cloud services, software-as-a-service platforms, and AI-enabled tools.

DUA means Data Use Agreement.
EAR means Export Administration Regulations.
FERPA means Family Educational Rights and Privacy Act.
FOIL means Freedom of Information Law.
GLBA means Gramm-Leach-Bliley Act.
HIPAA means Health Insurance Portability and Accountability Act.
IRB means Institutional Review Board.
ITAR means International Traffic in Arms Regulations.
NDA means Non-Disclosure Agreement.
ORRC means Office of Regulatory and Research Compliance.
PCI means Payment Card Industry.

Standards

  1. The University classifies data using four risk tiers. Data type describes context; classification tier describes the level of protection required. A single data type may appear in different classification tiers depending on content, context, and governing requirements. Use the first table to understand the four tiers. Use the second table to match the data’s context (operations/compliance, research, or instruction) to examples and consult contacts.

 

Risk Tier Summary

Risk Tier

When to Use

General Handling Direction

Restricted

Data requiring the highest level of protection because of legal, regulatory, contractual, or significant institutional requirements, or because unauthorized access, use, or disclosure could cause substantial harm.

Use approved high-protection tools and controls. Consult the responsible Data Owner or Data Steward before sharing, external processing, publication, or use in new systems or AI-enabled services.

Sensitive

Non-public data requiring heightened care because unauthorized access, use, or disclosure could create meaningful risk or harm to individuals or the University.

Limit access to authorized University purposes. Use approved tools and consult the Data Owner or Data Steward before external sharing or use in vendor, hosted, or AI-enabled services.

Internal

Data used primarily for instructional materials or research activity where unauthorized disclosure is not expected to cause more than minimal harm.

Share only with appropriate University audiences or authorized partners. Apply context-specific handling expectations.

Public

Data approved for open sharing with minimal adverse impact if disclosed.

If public status is unclear, check with the publication authority or responsible Data Owner.

Data Context Classification Guide

Classification Tier

Institutional Operations and Compliance

Research Activity (see ORRC Research Data Management)

Instructional Materials

Restricted

Consult:

  • ITS

  • Responsible Data Owner or applicable Data Steward

  • Enterprise Risk Management & Compliance

Examples:

  • Social Security numbers

  • Government ID numbers

  • Banking, financial account, credit/debit card, and PCI data

  • FERPA-protected student records

  • GLBA-covered data

  • HIPAA electronic protected health information

  • Employee medical or accommodation records

  • Electronic credentials

  • Attorney-client privileged documents

  • Restricted administrative records supporting research or instruction

Consult:

  • Principal investigator or research lead

  • ORRC

  • Sponsor guidance or agreement terms

  • IRB, export control, or other applicable research authority

Examples:

  • Federal-contracted applied research data

  • Controlled Unclassified Information (CUI)

  • Export-controlled research data

  • Identifiable human subjects research data, including direct or indirect identifiers, sensitive participant information, or protected health information

  • Research data requiring the highest level of protection under sponsor, collaborator, agreement, IRB, DUA, ORRC, export control, regulatory, or other binding research requirements

Consult:

  • Academic leadership

  • Instructional support

  • Registrar

  • Responsible academic office, as applicable

Examples:

  • Instructional materials subject to a specific legal, contractual, or institutional restriction

  • Regulated student records used in instructional contexts.

Sensitive

Consult:

  • ITS

  • Responsible Data Owner or applicable Data Steward

  • Enterprise Risk Management & Compliance

Examples:

  • Non-public business, operational, administrative, planning, meeting, and working records

  • Security, IT infrastructure, licensed software, and technology information

  • Law enforcement, public safety, judicial, and student disciplinary information

  • Non-public HR employment data, including Albany ID / EmplID

  • University financial data

  • Collective bargaining and contract negotiation data

  • Trade secrets, University intellectual property, proprietary data, and NDA-protected data

  • Research administration and instructional support records

  • Inter- or intra-agency records not otherwise Restricted

Consult:

  • Principal investigator or research lead

  • ORRC

  • Sponsor guidance, agreement terms, IRB, export control, or other applicable research authority when requirements are unclear

Examples:

  • Non-public study data

  • Preliminary analyses

  • Sensitive research observations

  • Research instruments

  • Non-public research data requiring heightened care under sponsor, IRB, DUA, ORRC, NDA, collaboration, repository, publication, or other research requirements

Consult:

  • Academic leadership

  • Instructional support

  • Registrar

  • Responsible academic office, as applicable

Examples:

  • Non-public instructional materials

  • Draft assessments

  • Rubrics

  • Answer keys

  • Course activity materials

  • Faculty-created teaching materials designated as sensitive

  • Regulated student records are excluded

Internal

Consult:

  • Applicable Data Owner or Data Steward

Examples:

  • Very limited use in this context.

Consult:

  • Principal investigator

  • Research team lead

  • ORRC or sponsor guidance, as applicable

Examples:

  • Research planning materials

  • Draft manuscripts and collaborator review copies

  • Research notes and preliminary analysis outputs not otherwise Sensitive or Restricted

  • Unpublished research data not otherwise Sensitive or Restricted

Consult:

  • Instructor

  • Academic leadership

  • Instructional support, as applicable

Examples:

  • Draft instructional materials not otherwise Sensitive or Restricted

  • Learning exercises and course activity materials not otherwise Sensitive or Restricted

  • Faculty-created teaching materials not otherwise Sensitive or Restricted

Public

Consult (if status unclear):

  • Responsible Data Owner or publication authority

  • ITS

Examples:

  • Approved web content

  • Public reports

  • Public directories

  • Marketing materials

Consult (if status unclear):

  • Principal investigator, publisher, or repository owner, as applicable

  • ORRC

Examples:

  • Publications

  • Open datasets

  • Open-source research code

  • De-identified research data approved for sharing

Consult (if status unclear):

  • Academic leadership

Examples:

  • Course catalogs

  • Published syllabi

  • Public program descriptions

  • Open educational resources approved for public sharing

  1. Baseline Handling Expectations.

    1. Classify data before storing, sharing, publishing, or using it in a new system, tool, vendor platform, or AI-enabled service.

    2. Apply the highest applicable requirement when legal, regulatory, contractual, sponsor, accreditation, privacy, academic, research, or institutional requirements overlap.

    3. Limit access, use, disclosure, retention, and transmission to individuals, systems, and services with an authorized University purpose and a need for the data.

    4. Use approved University storage, collaboration, transmission, and processing tools appropriate for the data’s classification and functional context.

    5. Do not place Sensitive or Restricted data in an external tool, vendor platform, or AI-enabled service unless the required University review and approval have been completed. Contact ITS if University review is needed.

    6. Depending on the context, the responsible Data Owner may be supported by an applicable Data Steward or offices with authority over the data or process, such as ITS, the Registrar, ORRC, Enterprise Risk Management & Compliance, or academic leadership.

    7. Contact ITS with questions or when guidance is needed regarding data classification, handling expectations, or appropriate use of University data.

  2. Third-Party Access, Disclosure, and Processing. University data may be shared with or processed by a third party only for an authorized University purpose and when allowed by applicable law, policy, contract, award terms, or other requirements. External platforms, vendors, hosted tools, and AI-enabled services may require additional review. Convenience does not lower the data’s classification.

    1. Institutional Operations and Compliance Data may be shared with service providers, contractors, consultants, and business partners when required procurement, privacy, security, and contract reviews are complete.

    2. Research Activity Data may be shared with sponsors, collaborators, external investigators, laboratories, repositories, and publishers when consistent with award terms, research agreements, NDAs, DUAs, IRB requirements, export control, and other research controls.

    3. Instructional Materials Data may be shared with instructional tool providers, publishers, proctoring services, placement or internship systems, tutoring platforms, and similar educational service providers when the content is not regulated student information.

  3. Use with AI-Enabled Capabilities. Data classification applies whether data is handled by traditional software, automated tools, or AI-enabled services. AI use does not change the classification. Separate University standards and procedures may add AI-specific requirements.

  4. Review and Maintenance. This standard will be reviewed and maintained through the ITS standards governance process.

  5. These standards are effective immediately upon approval.

Related Documents

Statutes:

 

Regulations:

 

SUNY Policies:

 

University Policies, Guidelines and Procedures:

 

Other: