Data Classifications
Data Classifications
1. Overview
To align with modern data loss prevention (DLP) frameworks, the University uses a three-tier data classification model to ensure information is protected in accordance with its sensitivity, regulatory requirements, and institutional risk. The classifications are Confidential, Internal, and Public. All University data must be classified into one of these categories and handled in accordance with applicable policies, standards, and legal requirements.
2. Confidential Data
Confidential Data is information that, if accessed, disclosed, altered, or destroyed without authorization, could result in significant harm to the University, its community, or individuals. This harm may be legal, regulatory, financial, reputational, or operational in nature.
Confidential Data includes, but is not limited to:
- Information protected by law or regulation (e.g., HIPAA, IL PIPA, PCI DSS)
- Student education records protected under FERPA
- Payroll, personnel, benefits, and detailed financial records
- Research data, intellectual property, or contractual information subject to confidentiality or non-disclosure obligations
- Authentication credentials, security keys, or system access information
3. Internal Data
Internal Data is information intended for use within the University community that is not approved for public release, but which would generally cause limited or moderate harm if disclosed without authorization. Examples include internal communications, administrative documents, internal policies, procedures, reports, and directory or contact information when not combined with other sensitive or identifying data elements.
4. Public Data
Public Data is information approved for public access and distribution. Unauthorized disclosure or modification of Public Data is not expected to cause harm to the University or individuals when used as intended. Examples include public websites, publications, press releases, marketing materials, course catalogs, event information, and standalone directory information.
5. Personally Identifiable Information (PII) and Social Security Numbers (SSN)
Personally Identifiable Information (PII) refers to information about an individual that can be used to identify, contact, or locate that person, either directly or indirectly. PII must be treated as at least Internal Data and is classified as Confidential when its disclosure, misuse, or compromise could result in harm to an individual or create legal, regulatory, or contractual risk to the University. This classification does not supersede obligations under FERPA, HIPAA, or other applicable laws.
Social Security Numbers (SSNs) are highly sensitive information and are always classified as Confidential Data. In accordance with the University of Illinois Social Security Number (SSN) Policy, the University collects and uses SSNs only when legally required or necessary for approved business purposes, and their use is minimized in favor of University Identification Numbers (UINs).
- SSNs must never be shared via email or stored in unapproved systems and may only be accessed by trained personnel with a documented and authorized business need. Any collection, use, or system storage of SSNs must be reviewed and authorized by the University’s SSN Coordinators.
- Approved secure methods must be used, access must be limited, and SSNs must be removed or securely destroyed when no longer required. Guidance and authorization support are available through the UIC SSN Coordinator service at go.uic.edu/ssn.
6. Data Classification Decision Tree
Use the following questions to determine the appropriate classification:
- Is the information approved for public release?
- Yes → Public Data
- No → Continue
- Does the information include personal data, regulated data, or data requiring restricted access?
- Yes → Continue
- No → Internal Data
- Would unauthorized disclosure cause significant harm to individuals or the University, or violate law or contract?
- Yes → Continue
- No → Internal Data
7. Data Classification Crosswalk
The following table provides guidance for transitioning from legacy classifications to the new model:
- High Risk, Sensitive, Sensitive Data Collection → Confidential
- Internal → Internal
- Public → Public
- PII → Internal or Confidential (based on sensitivity and regulatory context)
8. Responsibility
All faculty, staff, students, contractors, subcontractors, and affiliates are responsible for correctly classifying data they create, access, or manage; handling data in accordance with its classification; and reporting and responding to suspected misuse, loss, or unauthorized disclosure of data.