Guidelines for Safeguarding Information
Data Classification
The following chart provides definitions and examples of Brown's three data categories: Public, Regulated, and Brown Confidential. Much information classified as "Public" must also be adequately protected. Such information, if inappropriately accessed and altered in some way, could cause damage to the University.
Public Data |
Regulated Data |
Brown Confidential Data |
|
Definition |
Information that can be shared with anyone without damage to the University. |
Information is subject to regulatory compliance |
Everything else |
Risk |
Minimal but possible |
High |
Medium to High |
Examples |
|
|
|
| Student Information (FERPA): | |
|
|
| The following data may ordinarily be revealed by the University without student consent unless the student designates otherwise (for more information, see the U.S. Department of Education's FERPA web page): | |
|
|
| Employee Information: | |
|
|
With permission from Stanford University for use of their Classification of Data document as a model
* Note: Brown is not subject to HIPAA compliance.
Related Documents
Guidelines for Safeguarding Information
Data Protection Roles
Confidentiality Agreement Template
Administrative Information Systems Confidentiality Agreement
Questions or comments to: ITPolicy@brown.edu
Effective Date: May 17, 2006
