University Policies

922 Data Classification

Effective Date: August 31, 2026
Responsible Division: Information Technology
Responsible Office: Information Technology
Responsible Officer: Vice President for Information Technology

I. Purpose & Scope

This policy defines the classifications for data created and maintained by MTSU to ensure appropriate maintenance and use of such data by the University. Nothing in this policy, however, alters or supersedes Middle Tennessee State University’s obligations pursuant to the Public Records Act, Tennessee Code Annotated Section 10-7-501 et seq and MTSU Policy 120, Public Records.

II. Definitions

  1. Operational Reliance: The dependency of university operations on the data being evaluated.
  2. Intended Audience: The intended user(s) of the data being evaluated.
  3. Regulated by federal, state, or industry: An indication of whether data being evaluated is subject to any regulatory requirements by governmental or other authorities.
  4. Institutional harm: The level of harm or damage to MTSU if data has unauthorized access, is lost or stolen.
  5. Assigned Risk: The risk level associated with the data after data evaluation.
  6. Personally Identifiable Information (PII): Any combination of information about an individual that: (a) can be used to distinguish or trace an individual’s identity, such as name, date and place of birth, mother’s maiden name, or biometric records; (b) is linked or linkable to an individual, such as medical, educational, financial, and employment information, which if lost, compromised, or disclosed without authorization, could result in harm to that individual; or (c) is protected by federal, state or local laws and regulation or industry standards.
  7. Protected Health Information (PHI): Any information created, received, maintained, processed, or transmitted by MTSU, including but not limited to, the MTSU Campus Pharmacy, Student Health Services, and/or Counseling Services, that relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, and/or the past, present, or future payment for health care when that information either  identifies the individual or with respect to which there is a reasonable basis to believe that the information can be used to identify the individual. The University’s Office of University Counsel and Office of Compliance and Enterprise Risk Management are responsible for determining whether particular information constitutes PHI.
  8. Payment Card Information (PCI): Data defined by the Payment Card Industry requiring special handling, defined in the Payment Card Information Data Security Standard (PCI-DSS) including primary account numbers (PAN) in addition to cardholder name, expiration date, and/or service code.

III. Classification of Data

Data assets will be classified based on the following risk matrix:

Data assets will be classified based on the following risk matrix
  1. Level I: Public – Any information produced to be made available to the general public, with no legal restrictions on its access or use, or published research.  Users should anticipate that data classified as Level I Public data will be subject to public disclosure, consumption, and analysis,  which may include public/open Gen AI and LLM “consumption” and model training or other technologies that may be developed in the future.
  2. Level II: General – University data not meant specifically for public consumption. This data can be shared within MTSU and external partners as business, operational and research needs require. Users may use MTSU Contracted Gen AI tools. Level II General data SHALL NOT contain PII, PHI, IRB or other restricted or confidential data types.
  3. Level III: Restricted – Any information that is proprietary or produced for use by members of the MTSU community who have a legitimate purpose for accessing such data. Level III Restricted data can be shared within MTSU and external partners as business, operational and research needs require. Users may use MTSU Contracted Gen AI tools. Special handling requirements are required as set forth in Policy 924 Data Security and Handling.
  4. Level IV: Confidential – Any information that is specifically protected by federal, state, or local laws and regulations, or industry standards, such as HIPAA, HITECH, and PCI-DSS. This data can be shared within MTSU and external partners as business, operational and research needs require. Users may use MTSU Contracted Gen AI tools. Special handling requirements are required as set forth in Policy 924 Data Security and Handling.

IV. Policy

  1. The applicable data owner is responsible for evaluating and classifying data for which s/he is responsible according to the classification system described above. Any data created prior to the effective date of Policy 922 will be considered non-classified protected data until such time that the data is accessed and classified per Policy 922.
  2. All data users must follow data security requirements as set forth in Policy 924, Data Security and Handling, applicable to each data classification.
  3. If data of more than one classification level exists in the same system or endpoint, all the data must be protected at the highest level of any of the data contained in the system or endpoint

V. Non-Compliance

Intentional or willful misclassification of data to circumvent technical, procedural, operational, or administrative controls may result in one or more actions, including, but not limited to:

  1. The immediate suspension of network access, access to administrative systems, and access to the internet.
  2. Use of the applicable disciplinary processes and procedures of the University for students, staff, administrators, and faculty.
  3. Referral to appropriate law enforcement agencies, in the case where violation resulted in an attempted or suspected breach of sensitive information.

VI. Policy Development and Maintenance

This policy will be reviewed every three (3) years or earlier whenever circumstances require review, by the Chief Information Security Officer, with recommendations for revision presented to the Vice President for Information Technology and Chief Information Officer.

Forms: None
Revisions:
References: T.C.A. § 49-8-203(a)(1)(E)