UMB Data Classification Policy
X-99.06(A) | Information Technology | Approved April 13, 2015 | Last Reviewed July 21, 2026
Responsible VP/AVP: Peter J. Murray, PhD, CAS, MS
Applies to: Faculty, Staff
Revision History
Approved April 13, 2015.
Policy Statement
Data and information are important assets of the University and must be protected from loss of integrity, confidentiality, or availability in compliance with University policy and guidelines, Board of Regents policy, and state and federal laws and regulations.
Policy
All University Data must be classified according to the UMB Classification Schema and protected according to UMB Data Security Standards. This policy applies to data in all formats or media.
Data Classification Schema
Data and information assets are classified according to the risks associated with data being stored or processed. Data with the highest risk need the greatest level of protection to prevent compromise; data with lower risk require proportionately less protection. Three levels of data classification will be used to classify University Data based on how the data are used, its sensitivity to unauthorized disclosure, and requirements imposed by external agencies.
Data are typically stored in aggregate form in databases, tables, or files. In most data collections, highly sensitive data elements are not segregated from less sensitive data elements. For example, a student information system will contain a student's directory information as well as their social security number. Consequently, the classification of the most sensitive element in a data collection will determine the data classification of the entire collection.
UMB Data Classifications:
Level 0 – Public - Information approved for public release. Sharing this data does not create institutional risk because it is already intended to be openly accessible.
Examples:
- University website content
- Public directory information (name, title, department)
- Published research or reports
- Marketing materials, brochures, event schedules
- Campus maps and publicly distributed announcements
- Institutional statistics approved for public release (e.g., enrollment totals, graduation rates)
Level 1 – Internal - Information intended for internal University use. This data is not public, but it does not contain sensitive or regulated elements. Unauthorized disclosure would be undesirable, but not seriously harmful.
Examples:
- Internal emails, memos, meeting notes
- Draft documents not yet approved for publication
- Course materials and instructional content
- Non-sensitive research data
- Department procedures, operational documentation
- Most system configuration details
- Internal reports, metrics, and dashboards
Level 2 – Confidential - Sensitive or regulated information that requires the highest level of protection. If exposed, it could cause harm to individuals or the University. Includes data protected by federal, state, national laws or contractual obligations.
Examples:
- Personal Information (PII): SSNs, driver’s license numbers, passport numbers, DOB + identifiers
- Education Records (FERPA): grades, transcripts, advising notes, student ID numbers
- Health Data (HIPAA): medical records, diagnoses, test results, counseling information
- Financial Data: bank account numbers, credit card numbers, payroll, tax documents, financial aid records
- Authentication Data: usernames paired with passwords, passwords, MFA codes, API keys
- Research Data: human subject data, restricted or proprietary research, sponsor-restricted datasets
Aggregated/De-identified Data Sets:
De-identified or aggregated data is Confidential if any of the following may apply; small sample sizes, unique populations, use of quasi-identifiers, IRB rules, contractual obligations, or realistic re-identification risks apply.