Data Classification and Sensitivity Labels

Summary

Learn how Restricted, Internal, and Public sensitivity labels help protect institutional data. This article explains each classification, provides common examples, and outlines how to handle labeled documents, emails, and Teams meetings.

Body

Issue/Question

What are data sensitivity labels, and how should Restricted, Internal, and Public information be classified and handled?

Overview

To reduce the risk of unauthorized data exposure or exfiltration, ITS has implemented sensitivity labels for documents, emails, and Teams meetings.

These labels identify how information should be accessed, shared, and protected. The three data classifications are:

Restricted Internal Public
Environment
  • Documents
  • Email
  • Microsoft Teams meetings and meeting invitations
  • Students, faculty, and staff who access or manage institutional information
Resolution

Using Sensitivity Labels

Sensitivity labels may appear at the top of a document, email, or meeting invitation. When a label is present, handle the information according to its classification and established institutional procedures.

  • Students can view the sensitivity label applied to content.
  • Faculty and staff may update a sensitivity label when appropriate and may be required to provide justification when lowering the classification.
  • Do not remove or lower a label solely to bypass access or sharing restrictions.

Use the following descriptions and examples to determine which classification applies.

Restricted Data

Restricted Data is highly sensitive information that should only be accessible to authorized individuals approved by the information owner.

Examples include:

  • Educational, health, and financial records protected by FERPA, HIPAA, GLBA, or similar requirements
  • Data protected by state, federal, or international law
  • Research data subject to Institutional Review Board or other privacy requirements
  • Confidential, sponsor-restricted, unpublished sensitive, or export-controlled research data
  • Social Security numbers, taxpayer identification numbers, and driver's license information
  • Passwords, email addresses, dates of birth, demographic information, and government-issued identification numbers
  • Trade secrets, intellectual property, internal software, databases, performance reviews, and promotion deliberations

Internal Data

Internal Data is information intended for organizational use that must be protected from unauthorized disclosure outside the institution.

Examples include:

  • Unpublished, non-sensitive research data and analyses
  • Internal plans, policy drafts, and operational documents
  • Non-public institutional reports
  • Non-restricted technical documentation
  • Pre-release data shared under institutional agreements

Public Data

Public Data is information that is explicitly or implicitly approved for public distribution.

Examples include:

  • Student directory information not subject to privacy restrictions
  • Published research data, code, and documentation
  • Public academic materials, catalogs, and schedules
  • Public reports, statistics, and institutional information
  • Research metadata and information stored in public repositories

Support

For assistance with sensitivity labels or questions about classifying information, contact the ITS Support Desk.

Details

Details

Article ID: 148733
Created
Wed 8/5/26 9:47 AM
Modified
Wed 8/5/26 12:52 PM
Review & Maintenance
Annually