Data Classification Standard
Purpose
This standard explains how to classify University data and apply baseline handling expectations. It helps people decide when data may be shared, when extra protection is needed, and when to consult the responsible office or Data Owner. This standard implements the requirements of the Information Security Policy (Adopted Policy 5.3) by establishing a framework for classifying and handling University data.
Responsible Owners
Information Technology Services, Division for Finance and Administration
Standards History
Version: | 2.0 |
Effective Date: | July, 2011 |
Last Revised: | July 16, 2026 |
Standards Statement
This standard applies to data created, received, maintained, transmitted, processed, or shared by the University or on its behalf. It uses four classification tiers. Information Technology Services (ITS) maintains the framework; the responsible Data Owner determines the classification and handling expectations for specific data.
Persons Affected
This standard applies to all University faculty, staff, students, affiliates, contractors, volunteers, and other individuals who create, access, use, store, transmit, share, or manage University data.
Definitions
University: University at Albany, State University of New York.
University data means data created, received, maintained, transmitted, processed, or shared by the University or on its behalf, including institutional data and data used for administration, operations, compliance, research, teaching and learning, services, and other University activities.
Institutional Operations and Compliance Data is University data used to operate, administer, support, document, govern, or comply with University programs, services, and business processes.
Research Activity Data is University data used to plan, conduct, analyze, document, or share research, scholarship, sponsored programs, or other scholarly inquiry. Sponsored programs include externally supported projects such as grants, contracts, and cooperative agreements.
Instructional Materials Data is University data created or used to design, deliver, or improve teaching and learning activities, such as course content, exercises, assessments, rubrics, and instructional resources.
Data Owner means the University official, office, principal investigator, or other authorized person responsible for a data set, system, process, course material, or research activity. The Data Owner decides how the data may be used, who may access it, when it may be shared, and what classification applies.
Data Steward means the University official or office that helps manage data on behalf of the Data Owner or within a functional area. The Data Steward helps interpret requirements, apply classifications, support access decisions, and communicate handling expectations so the data is used and protected appropriately.
Third Party means an external person, organization, service, system, or provider that is not acting as part of the University workforce or within a University-managed system. Examples include collaborators, partner institutions, sponsors, vendors, contractors, publishers, cloud services, software platforms, and AI-enabled services.
External Processing means access, storage, transmission, analysis, transformation, hosting, or other handling of University data by a non-University system, service, platform, or provider, including cloud services, software-as-a-service platforms, and AI-enabled tools.
DUA means Data Use Agreement.
EAR means Export Administration Regulations.
FERPA means Family Educational Rights and Privacy Act.
FOIL means Freedom of Information Law.
GLBA means Gramm-Leach-Bliley Act.
HIPAA means Health Insurance Portability and Accountability Act.
IRB means Institutional Review Board.
ITAR means International Traffic in Arms Regulations.
NDA means Non-Disclosure Agreement.
ORRC means Office of Regulatory and Research Compliance.
PCI means Payment Card Industry.
Standards
The University classifies data using four risk tiers. Data type describes context; classification tier describes the level of protection required. A single data type may appear in different classification tiers depending on content, context, and governing requirements. Use the first table to understand the four tiers. Use the second table to match the data’s context (operations/compliance, research, or instruction) to examples and consult contacts.
Risk Tier Summary
Risk Tier | When to Use | General Handling Direction |
Restricted | Data requiring the highest level of protection because of legal, regulatory, contractual, or significant institutional requirements, or because unauthorized access, use, or disclosure could cause substantial harm. | Use approved high-protection tools and controls. Consult the responsible Data Owner or Data Steward before sharing, external processing, publication, or use in new systems or AI-enabled services. |
Sensitive | Non-public data requiring heightened care because unauthorized access, use, or disclosure could create meaningful risk or harm to individuals or the University. | Limit access to authorized University purposes. Use approved tools and consult the Data Owner or Data Steward before external sharing or use in vendor, hosted, or AI-enabled services. |
Internal | Data used primarily for instructional materials or research activity where unauthorized disclosure is not expected to cause more than minimal harm. | Share only with appropriate University audiences or authorized partners. Apply context-specific handling expectations. |
Public | Data approved for open sharing with minimal adverse impact if disclosed. | If public status is unclear, check with the publication authority or responsible Data Owner. |
Data Context Classification Guide
Classification Tier | Institutional Operations and Compliance | Research Activity (see ORRC Research Data Management) | Instructional Materials |
Restricted | Consult:
Examples:
| Consult:
Examples:
| Consult:
Examples:
|
Sensitive | Consult:
Examples:
| Consult:
Examples:
| Consult:
Examples:
|
Internal | Consult:
Examples:
| Consult:
Examples:
| Consult:
Examples:
|
Public | Consult (if status unclear):
Examples:
| Consult (if status unclear):
Examples:
| Consult (if status unclear):
Examples:
|
Baseline Handling Expectations.
Classify data before storing, sharing, publishing, or using it in a new system, tool, vendor platform, or AI-enabled service.
Apply the highest applicable requirement when legal, regulatory, contractual, sponsor, accreditation, privacy, academic, research, or institutional requirements overlap.
Limit access, use, disclosure, retention, and transmission to individuals, systems, and services with an authorized University purpose and a need for the data.
Use approved University storage, collaboration, transmission, and processing tools appropriate for the data’s classification and functional context.
Do not place Sensitive or Restricted data in an external tool, vendor platform, or AI-enabled service unless the required University review and approval have been completed. Contact ITS if University review is needed.
Depending on the context, the responsible Data Owner may be supported by an applicable Data Steward or offices with authority over the data or process, such as ITS, the Registrar, ORRC, Enterprise Risk Management & Compliance, or academic leadership.
Contact ITS with questions or when guidance is needed regarding data classification, handling expectations, or appropriate use of University data.
Third-Party Access, Disclosure, and Processing. University data may be shared with or processed by a third party only for an authorized University purpose and when allowed by applicable law, policy, contract, award terms, or other requirements. External platforms, vendors, hosted tools, and AI-enabled services may require additional review. Convenience does not lower the data’s classification.
Institutional Operations and Compliance Data may be shared with service providers, contractors, consultants, and business partners when required procurement, privacy, security, and contract reviews are complete.
Research Activity Data may be shared with sponsors, collaborators, external investigators, laboratories, repositories, and publishers when consistent with award terms, research agreements, NDAs, DUAs, IRB requirements, export control, and other research controls.
Instructional Materials Data may be shared with instructional tool providers, publishers, proctoring services, placement or internship systems, tutoring platforms, and similar educational service providers when the content is not regulated student information.
Use with AI-Enabled Capabilities. Data classification applies whether data is handled by traditional software, automated tools, or AI-enabled services. AI use does not change the classification. Separate University standards and procedures may add AI-specific requirements.
Review and Maintenance. This standard will be reviewed and maintained through the ITS standards governance process.
These standards are effective immediately upon approval.
Related Documents