Data Classification Guidance
This page explains the data classification levels used in the Approved Software Directory. In this directory, the "Approved for" label indicates the highest university data classification a software product is currently approved to handle.
How to read "Approved for" in the directory
The classification shown on a software profile is not just a descriptive label. It is a data allowance boundary. For example, if a tool is marked Approved for: Internal, that means the tool should not be used for Confidential or Regulated data unless a separate review and approval says otherwise.
Public
Information approved for public release with no expectation of confidentiality. Unauthorized disclosure poses no risk to the university, its operations, or individuals. Public data may be shared freely without restriction.
Typical examples
- Public websites
- University regulations
- Course catalog
- ASU System directory information
- Public research
What this means in the directory
If a tool is approved for Public data, it should only be relied on for information already intended for public release. Public approval should not be interpreted as permission to use Internal, Confidential, or Regulated data in that tool.
Internal
Information intended for internal university use only. Unauthorized disclosure could cause minor operational, reputational, or administrative impact. Access is limited to authorized university personnel and affiliates with a legitimate business need.
Typical examples
- Internal memos or procedures
- System security plans
- Unpublished research results
- Exams, question banks, and answer keys
What this means in the directory
If a tool is approved for Internal data, it may be appropriate for normal internal university work, but it should not automatically be used for Confidential or Regulated data. Additional review would still be needed for higher-risk data.
Confidential
Sensitive information that requires protection to prevent significant risk to the university or individuals. Unauthorized disclosure could result in financial loss, legal exposure, reputational harm, or disruption of university operations.
Typical examples
- Student records
- Class schedules
- Transcripts
- Personally identifiable information
- Employee data
- FERPA-protected records
What this means in the directory
If a tool is approved for Confidential data, it may be considered for more sensitive university information, but that does not automatically make it appropriate for legally regulated data such as HIPAA, PCI, CJIS, or GLBA-covered information.
Regulated
Information subject to legal, regulatory, or contractual requirements. Unauthorized disclosure could result in severe financial loss, legal exposure, reputational harm, or major disruption of university operations. This is the highest classification level in the current draft policy.
Typical examples
- Export-controlled data
- Credit card cardholder data
- Social Security numbers
- Donor financial records
- Identifiable patient health records
- HIPAA, PCI, CJIS, and GLBA-related data
What this means in the directory
If a tool is approved for Regulated data, it would need to meet the strongest legal, contractual, and security expectations. This level should be interpreted carefully, because regulated data carries the highest institutional risk.
AI and Data Handling Note
The current draft policy states that data classified as Confidential or Regulated is not permitted for entry into AI tools unless explicitly authorized. It also states that Internal data is permitted only on university-maintained and approved AI platforms.