Campus Technology
Data Governance & Classification
Not every campus record needs the same level of protection — a three-tier classification system decides who can see what, and how it has to be stored.
Three tiers
| Tier | Examples | Handling rule |
|---|---|---|
| Public | Course catalog, published research, directory listings a person has not opted out of | No restriction |
| Internal | Internal budget documents, unpublished meeting minutes, staff-only procedures | Porter accounts only; not for external sharing |
| Restricted | Grades, financial aid records, health records, Social Security numbers, most HR files | Access limited to a documented need; encryption required in storage and transit |
Who decides the classification
A data owner — usually the office that originally collects a given kind of record, like the registrar for grades or human resources for personnel files — assigns its classification and approves who gets ongoing access. The technology office does not set classification on its own; it enforces the controls the data owner requires.
What this means day to day
Restricted data cannot go into a personal cloud drive, a personal email account, or an unencrypted USB drive, full stop — including by well-meaning staff trying to work from home over the weekend. Approved systems (the student information system, the HR platform, an approved shared drive) meet the encryption and access-logging requirements already; the rule mostly changes behavior around exporting data out of them.
Reporting a possible exposure
A misdirected email with restricted data attached, a lost laptop with local student records, or a phished account with access to restricted systems all get reported immediately to the technology office through the help desk phishing and incident channel — the same day, not after trying to fix it quietly first.