How to classify your data
The University defines 4 levels for classifying data based on the impact of a data compromise.
Each explanation includes possible examples of data at each level of classification, but it is only a guide. We recommend that you check the impact level of your data by completing an Information Security Risk Assessment (ISRA). Alternatively, you can find the appropriate impact rating and classification level from our impact tables.
If you have research data and you're confident that your data is lower-risk and doesn't contain any confidential personal data or commercially sensitive data, you can complete a 3-minute Research Data Impact Assessment.
Additional steps for personal data
If your dataset includes personal data – including, special category personal data you should also consider performing a Data Protection Impact Assessment (DPIA). This will help you understand the impact on the data subject, whereas the ISRA focuses on the impact on you and the University.
Who should classify data
The data owner or the data custodian - the person responsible for the data on behalf of the University - decides the data security classification. For research data, this is usually the Principal Investigator (PI).
Data classifications
Negligible Impact (Level 0)
All data that would have negligible impact to the University if it is disclosed, modified, lost or destroyed.
Examples of negligible impact data
- Publicly accessible data, such as data sources downloaded from the internet
- General working files, that don't contain personal data or anything listed in the below
You should consider deleting this data, or at least archiving it where possible.
See the recommended storage options for negligible impact level 0 data
Low Impact (Level 1)
Data that is necessary but low-impact if disclosed, modified, lost, or destroyed.
This is usually everyday working data that is not quite 'public'. This includes some personal data required for people to do their work at the University.
Examples of low impact data
- A photoboard of personnel in a building, with their job titles
- A telephone list of staff in a department
- A lecture list, with lecturer names and rooms for students in a certain tripos.
- Some minutes of meetings, some memoranda, some site-licensed software
- Some publications and websites prior to publication
- Teaching materials recorded for student use
- Anonymised data and pseudonymised personal data separated from its 'key' (that would enable the re-identification of the individuals). Unpublished research results, which could result in valuable intellectual property, would be an exception.
See the recommended storage options for low impact, level 1 data
Medium Impact (Level 2)
Data where restricted access is required, but it is acceptable for systems administrators and super users to also have access.
Examples of medium impact data
- Personal data (not defined as subject category data) under UK General Data Protection Regulation (GDPR). This includes keys to pseudonymised datasets.
- Most unreserved business meeting notes, minutes, documents, and papers. These are non-confidential documents open to all committee members.
- Non-personal information held for University business. This includes contract negotiations, unpublished research results, and some teaching materials, even if recorded for students.
- Information relating to activities subject to the provisions of the Animals (Scientific Procedures) Act 1986 other than under section 24 of that Act
See the recommended storage options for medium impact, level 2 data
High Impact (Level 2 or Level 3)
Data where there is:
- a requirement to restrict access to it
- a need to explicitly define who can access it
- a need to ensure there are people who can't access it by the nature of their jobs – for example, HR or systems administrators
Examples of high impact data
- Special category data under UK GDPR. You can read the full definition on the Information Commissioner's Office website. It is defined as:
- personal data revealing racial or ethnic origin
- personal data revealing political opinions
- personal data revealing religious or philosophical beliefs
- personal data revealing trade union membership
- genetic data
- biometric data (where used for identification purposes)
- data concerning health
- data concerning a person’s sex life
- data concerning a person’s sexual orientation
- Confidential personal data not captured within the legal definition of special category data. For example, disciplinary or grievance data, copies of passports, payroll data, and information related to the Prevent duty.
- Confidential and highly sensitive information that is not personal and is held for University business. This includes commercially sensitive data, most financial information, grant costing forms, and unpublished research data that could be commercialised.
- Examination questions and unpublished examination marks
- Legally privileged information
- Most reserved business meeting notes, minutes, documents and papers
See the recommended storage options for high impact, level 2 or level 3 data
Very High Impact (Level 3)
Data that either:
- requires storage on an ISO 27001 platform because of:
- a data sharing agreement or contract
- an external requirement
- a regulatory requirement
- requires equivalent security to NHS data
- or other uses that require an additional level of security
Examples of very high impact data
- Data requires equivalent security to NHS data
- Data under contract or restrictions given by the Ministry of Defence
- Highly restricted unpublished research data
- Unpublished research with highly valuable intellectual property
See the recommended storage options for very high impact, level 3 data