Data Classification Guideline


Not sure if AI use is appropriate?

When in doubt, ask before you enter University data into an AI tool. ITS is here to help you make the right call.

Data Classification Guideline

The University of North Carolina Asheville is committed to protecting the privacy of its users. To meet that commitment, the University has developed these guidelines used to categorize University data as it relates to its acceptable use and required security controls for related systems and applications.


Definitions

Any individual granted access to university computing resources, including faculty, staff, students, contractors, non-agency personnel, volunteers, vendors, interns, alumni, emeriti, and guests.

Data is developed and intended for public consumption.

Data is not generally readily available to the public. A breach surrounding this data could have minimal adverse consequences on UNCA’s mission, safety, finances, or reputation. This data is used in the daily operation of UNCA.

This information is sensitive and is to be protected. A breach surrounding this data could have an adverse effect on UNCA’s mission, safety, finances, or reputation.

This information is highly sensitive and is to be protected by law. A breach surrounding this data could have significant adverse effects on UNCA’s mission, safety, finances, or reputation. UNCA is subject to penalties and notification mandates in the event of unauthorized access or disclosure.


Example Data Elements

While this list is comprehensive it is not exhaustive, its general spirit should be used when it comes to data classification. If questions arise around a particular data element that is not listed below, please contact ITS.

Public

  • Employee & Student Directory Information
  • Press Releases
  • Job Postings
  • Catalogs and Bulletins
  • Public Websites
  • Published Policy, Procedure, and Guidelines

Internal Use

  • Internal policies, procedures, and memos intended for internal use
  • Most UNCA emails
  • Training material
  • Day-to-day internal documents, spreadsheets, and presentations that do not include Confidential or Restricted data
  • Meeting agendas
  • Assignments, assessments, and rubrics

Confidential

  • FERPA protected data
  • Birth dates, addresses, and other forms of PII
  • Attorney-client privileged information
  • Data protected by contractual agreements
  • Research findings
  • Intellectual property
  • Employee evaluations
  • Security and network documentation

Restricted

  • Federal tax data received or derived from the IRS
  • Financial information subject to the Gramm-Leach-Bliley Act (financial aid)
  • Social Security, passport, and visa numbers
  • Debit and/or credit card numbers
  • Bank account information
  • Authentication secrets: passwords and biometrics

Not sure if AI use is appropriate?

When in doubt, ask before you enter University data into an AI tool. ITS is here to help you make the right call.