Institutional Data Classification Framework

The Institutional Data Classification Standard defines the following framework for categorizing institutional data according to its sensitivity and the potential adverse impact of loss or unauthorized access, use, or alteration.

This information is intended for data protection only—do not use for data disclosure. Data protection is the implementation of administrative, technical, or physical measure to guard against unauthorized data access. Refer to the Standard and User Guide for details on minimum data protection requirements and the roles and responsibilities associated with data classification at WSU. 

Classification Categories and Examples

Public (Green): Unauthorized access, use, disclosure, or loss is likely to have low or no risk. Data that is intended for public availability or has been explicitly approved for publication. There are no restrictions on access, but controls should be in place to prevent unauthorized modification or destruction.

Internal (Yellow): Unauthorized access, use, disclosure, or loss is likely to have moderate but not significant adverse impact. Non-sensitive data used in the daily operations of the University. While the data may not be explicitly protected by law, it is not intended for public release. The impact of disclosure is generally limited to operational disruption or minor reputational harm.

Private (Orange): Unauthorized access, use, disclosure, or loss is likely to have significant and serious adverse effects. Data that must be protected due to ethical, legal, or privacy considerations, even if not subject to the same strict regulatory requirements as Restricted data. The unauthorized disclosure could cause social, psychological, reputational, financial, or legal harm to individuals or the University.

Restricted (Red): Access and use is strictly controlled and restricted by laws, regulations, or contracts. Data where unauthorized access, use, disclosure, or loss will have severe legal consequences, including civil and criminal penalties, loss of funding, inability to continue current research, and inability to obtain future funding or partnerships. This data requires the highest level of protection.

Category Examples
Public (Green)
  • Press releases

  • Public-facing website content

  • Course catalogs and schedules

  • Campus maps

  • Institutional policies

  • University employee directory

  • Published budgets, financial reports, and audits

Internal (Yellow)
  • FERPA Student Directory Information (where not restricted by a Confidentiality Block)

  • Internal memos, correspondence, and emails not containing otherwise Private or Restricted information

  • Operational manuals

Private (Orange)
  • Personally Identifiable Information (PII)

  • Student education records protected by FERPA (grades, transcripts, class schedules, etc.)

  • Personnel files and performance evaluations

  • Donor information (except where disclosure is required by law)

  • Intellectual property supporting inventions

Restricted (Red)
  • Social Security Numbers

  • Payment Card Industry (PCI) data (credit card numbers)

  • Protected Health Information (HIPAA)

  • Authentication verifiers (passwords, private keys)

  • Criminal justice records

Questions? We're Here to Help.

Protecting university assets is a shared responsibility. Depending on your needs, please reach out to the appropriate team:

  • Data Classification: For questions about who classifies data or determining which classification level applies to a specific data asset, contact the Data Governance Program at datagovernance@weber.edu.
  • Data Security: For guidance on how to securely store, share, or manage data or establish appropriate security controls based on classification level, contact the Information Security Office at security@weber.edu.