Data Classification and Protection Policy
Title:
Data Classification and Protection Policy
Effective Date:
2010
Responsible Office:
Information Technology, Provost
Last Revision Date:
July 17, 2026
Purpose
This document defines the William & Mary system and data classification scheme and establishes procedures for protecting critical IT systems and sensitive and protected university data processed, received, sent or maintained by or on behalf of the university.
Scope
This policy applies to all data owned or leased by William & Mary.
Definitions
Sensitive Data
Sensitive and personally identifiable information is highly confidential or personal information protected by statutes, regulations, university policies or contractual language which, if exposed or breached, could result in legal damages, fines/penalties, identify theft and/or financial fraud.
Sensitive and personally identifiable information includes any data that can be used to distinguish or trace an individual's identity, either alone or when combined with other information. Examples include a name, home address, email address, social security number, driver's license number, bank account number, passport number, date of birth, biometrics such as fingerprints, or information that is linked or linkable to an individual such as medical, educational, financial, and employment information.
Information such as gender, race, religion, and marital status are typically not considered PII alone. However, this information should still be treated as sensitive because it could identify an individual when combined with other data.
Specific examples of sensitive and personally identifiable information include:
Personally Identifiable Information (PII) - (Protected under laws like GDPR, CCPA, etc.)
- Full name
- Social Security number (or any national ID number)
- Passport number
- Driver’s license number
- Birthdate
- Place of birth
- Gender
- Biometric identifiers (fingerprints, retina scans, facial recognition)
- IP address (in some jurisdictions)
- Device identifiers / MAC address
- Home address
- Email address
- Phone number
- Login credentials (usernames and passwords)
- Security questions and answers
- Photograph (when used for identification)
Protected Health Information (PHI) - (Protected under HIPAA and equivalent international laws)
- Medical record numbers
- Health insurance information
- Lab test results
- Medical diagnoses
- Treatment and care plans
- Prescription information
- Doctor's notes
- Genetic information
- Mental health data
- Health-related biometric data
- Appointment schedules and reminders
Student Information - (Protected under FERPA and related laws)
- Student ID numbers
- Grades and transcripts
- Enrollment status
- Class schedules
- Disciplinary records
- Learning disabilities or accommodations
- Educational test results
- Advising notes
- Financial aid information
Employee/HR Information - (Protected under various labor and privacy laws)
- Employment history
- Background check results
- Performance evaluations
- Disciplinary actions
- Payroll records
- Benefit selections (e.g., health, retirement)
- Work visa or immigration data
- Internal HR communications
- Time and attendance logs
- Union membership
Payment Card Information (PCI) - (Protected under PCI DSS)
- Primary Account Number (PAN)
- Cardholder name
- Expiration date
- CVV/CVC codes
- Bank account numbers
Financial Data - (Protected under GLBA, SOX, and more)
- Bank account numbers
- Investment details
- Credit/debit card numbers
- Credit scores
- Loan details
- Income and salary
- Tax information (e.g., W-2, 1099 forms)
- Financial transaction records
- Cryptocurrency wallet keys
- Mortgage information
- Billing records
System & Network Information - (Protected under cybersecurity standards like NIST, ISO/IEC 27001)
- Authentication credentials (passwords, tokens, biometrics)
- Security logs
- Network diagrams
- Encryption keys / certificates
- API keys and access tokens
- Configuration files
- Cloud storage credentials
- Backup data
- Vulnerability scan reports
- Incident response documentation
Legal and Compliance-Related Data
- Litigation documents
- Regulatory filings
- Internal compliance audit results
- Whistleblower reports
- Law enforcement communications
- Subpoenas and legal holds
- Legal opinions
Research Data - (Especially in academic, medical, or defense contexts)
- Clinical trial results
- Research participant data
- Unpublished manuscripts or papers
- Proprietary algorithms or formulas
- Patent applications (pre-filing)
Sensitive Content Under Ethics or Human Rights Protections
- Sexual orientation
- Racial or ethnic origin
- Religious or philosophical beliefs
- Political opinions or affiliations
- Gender identity
- Disability status
- Criminal history
- Refugee or asylum status
Sensitive data does not include information in the William & Mary directory or data that is made public by the university. Furthermore, the university has no obligation to protect an individual’s personal information if the personal information is provided to a third-party by another supplier without the involvement of the university.
Protected Data
Protected Data is information that is protected by statutes, regulations, university policies or contractual language but which does not carry the same level of risk as Sensitive and Personally Identifiable Information. By way of illustration only, some examples of Protected Data include:
- Student educational records protected by the Family Educational Rights and Privacy Act (FERPA). Under FERPA, education records are any documents, files, and/or other materials that contain information directly related to a student, are personally identifiable to that student, and are maintained by the university or a university agent. These records include but are not limited to grades, transcripts, class lists, student course schedules, contact and family information, student health records, student financial information (at the postsecondary level), and student discipline files. The information may be recorded in any way, including, but not limited to, handwriting, print, computer media, videotape, audiotape, film, microfilm, microfiche, and e-mail.
- FERPA designates several types of records that are exceptions to this definition, including law enforcement records and medical and treatment records.
For more detailed information contact the University Registrar at ferpa@wm.edu or visit the webpage Student Records Privacy Policy and Notification of Rights under FERPA
- Personal information or giving history collected from a donor, alumnus, or another individual
- Employment or non-identifiable personnel data
- Banner 93 numbers
- Performance evaluations
Non-Sensitive Internal Use Data
Non-Sensitive internal use data is information that is intended for use by active William & Mary staff and students during the normal course of business operations. While not subject to privacy or protection laws, this information should be kept internal to the William & Mary network. By way of illustration only, some examples of Non-Sensitive data include:
- Business email
- Meeting agendas or notes
- Internally shared files or collaborative chats
Non-Sensitive Public Data
Non-Sensitive data is information that may or must be open to the general public. It is defined as information with no existing local, national or international legal restrictions on access or usage. By way of illustration only, some examples of Non-Sensitive data include:
- Publicly posted press releases
- Publicly posted schedules of classes.
- Publicly posted interactive university maps, newsletters, newspapers, and magazines.
- Public announcements, advertisements, directory information, and other freely available data on university websites.
Policy
IT System Classification
Systems at William & Mary are classified as either critical or non-critical. Using the university business impact analysis as a primary input, the university has identified systems that are critical based on their role in supporting the university Mission Essential Functions (MEFs). Additionally, any system identified as essential during an emergency event is also classified as critical. Critical IT systems require a higher degree of protection and may, therefore, be subject to stricter controls for access management, logging and monitoring, and disaster recovery planning.
Data Classification
Data processed, received, sent, or maintained by the university is classified into the following three categories:
- Sensitive
- Protected
- Non-Sensitive
Collecting Sensitive Data
There are laws governing university collection of sensitive data. The legal restrictions most commonly impacting the university are summarized below. For additional information, contact the Information Security Office.
- Sensitive data may only be collected, maintained, used, or disseminated as necessary to accomplish a proper academic or business purpose of the university or as required by law.
- Units requesting or collecting sensitive data must communicate why the data is being collected, how it will be used, and, if applicable, any consequences of not providing it.
Sending or Receiving Sensitive Data in Electronic or Physical Form
The following restrictions apply both to internal data transmissions (such as sharing files with another university employee) as well as transmissions to outside parties.
- Sensitive data sent or received electronically must be secured using encryption technology, a secure web transfer, or the Secure File Transfer Protocol. Other acceptable methods include transferring files between network drives on the university's internal network or using the university's secure cloud file system. The university's email system is not designed to support the transmission of sensitive data securely.
- For any other release of sensitive data by the university to a third-party the sender must ensure that the third-party is aware of the confidentiality obligations applicable.
- Sensitive data sent in physical form, such as through the post office or interdepartmental mail, must be secured in a sealed envelope or similar method with a clear marking indicating confidentiality of the contents.
- Routine exchange of sensitive data with a vendor or application hosting provider requires that the vendor or hosting provider undergo a security review, including a third-party assessment of the vendor’s security controls. The sender must also ensure that there are contractual requirements describing which party is responsible for securing sensitive data in transit, how the data will be secured, and any specific confidentiality obligations.
Storing Sensitive Data
Sensitive data should only be stored on university-administered servers or the university’s approved cloud storage systems. If sensitive data must be stored on personal or college-owned devices, including but not limited to laptops, personal computers, CDs, flash or thumb drives, cell phones, or personal computing devices (i.e. smartphones, tablets, etc...), the data must be encrypted according to the university’s Data Encryption Standard and the device must be password protected.
Sensitive data that will be stored by a vendor or application hosting provider must be protected and secured to the same standards applied by the university. Use of third-party vendors or application hosting vendors must adhere to the policy and procedures detailed in the university’s Application Hosting Policy.
- Sensitive data saved in non-electronic form (i.e. paper or a whiteboard) must be protected from unauthorized access when left unattended and destroyed when it is no longer needed. For example, papers with sensitive data cannot be left on an unattended desk but instead must be filed in a locked cabinet or a locked office.
Sending or Receiving Protected Data in Electronic or Physical Form
The following restrictions apply both to internal data transmissions (such as sharing files with another university employee) as well as transmissions to outside parties.
- Transmission of FERPA protected data using the university's electronic communications systems must be restricted to recipients with a legitimate educational interest. Emailing FERPA data to large groups of people is generally a violation of this restriction unless it is verified that each recipient has a legitimate educational interest.
- Protected data sent or received electronically can be transmitted using the university’s email system. In addition, protected data can be transmitted using secure web transfer, or the Secure File Transfer Protocol. Other acceptable methods include transferring files between network drives on the university's internal network or using the university's secure web file system.
- For any other release of protected data by the university to a third-party the sender must ensure that the third-party is aware of the confidentiality obligations applicable.
- Protected data sent in physical form, such as through the post office or interdepartmental mail, must be secured in a sealed envelope or similar method.
- Faxing protected data is permitted provided that the recipient is notified in advance and is available to retrieve the fax immediately following transmission or able to secure it upon receipt (i.e., receiving a fax in an office that is only accessible by the recipient). Individuals receiving faxed documents with protected data are responsible for securing the document after receipt.
- Routine exchange of protected data with a vendor or application hosting provider requires that the vendor or hosting provider undergo a security review and contractual requirements describing which party is responsible for securing protected data in transit and how the data will be secured, and any specific confidentiality obligations.
Storing Protected Data
- Protected data should only be stored on university-administered servers or the university’s approved cloud storage systems. If protected data must be stored on personal or college-owned devices, including but not limited to laptops, personal computers, CDs, flash or thumb drives, cell phones, or personal computing devices (i.e. smartphones, tablets, etc...), the data must be encrypted according to the university’s Data Encryption Standard and the device must be password protected.
- Protected data that will be stored by a vendor or application hosting provider must be protected and secured to the same standards applied by the university.
Destruction of Electronic Media Containing Sensitive or Protected Data
Electronic media including computers, jump or flash drives, CD/DVDs or servers on which sensitive data has been stored must be disposed of according to the university's Standard for the Disposal of Electronic Data.
Key:
N/A = Approved
X = Not Approved
| Storage Platform | Non-Sensitive (Public) | Protected | Sensitive | CUI/FTI* |
|---|---|---|---|---|
| W&M Managed Storage | N/A | N/A | N/A | X |
| Box | N/A | N/A | N/A | X |
| Other MS 360 Apps (Teams/Sharepoint/OneDrive) | N/A | N/A | N/A | X |
| Operational Reporting Platform | N/A | N/A | N/A | X |
| MS Outlook/Exchange | N/A | N/A | X | X |
| W&M Managed Workstation | N/A | X | X | X |
| Portable Storage | N/A | X | X | X |
| Google Suite | N/A | X | X | X |
| DropBox | N/A | X | X | X |
| Any AI/LLM that is not managed by W&M | N/A | X | X | X |
Note: Highly Sensitive is data that is either CUI - Classified Uncontrolled Information or FTI - Federal Tax Information. Any questions or handling Highly Sensitive data, please contact [[ciso]].
Non-Compliance
An employee’s failure to comply with any of the above policy statements may result in being disciplined, in accordance with general university employment policies and procedures that apply to the respective category of employees. The university may also temporarily deny access to university information systems and may refer the case to the appropriate local, state, or federal authority for further disposition.
A student’s failure to comply with any of the above policy statements may result in disciplinary actions in accordance with the Student Handbook. Depending on the nature and severity of the violation, the university may take one or more of the disciplinary actions listed under Administration of Student Code of Conduct, Section VII. The university may also temporarily deny access to university information systems and may refer the case to the appropriate local, state, or federal authority for further disposition.