Note: data may be represented in any format including digital records, audio or video recordings, and printed material.
Table of Contents – Data Type
- Accessible Education Center (AEC) disability information
- Architectural diagrams for the physical spaces where critical systems or functions exist
- Attorney-Client Privileged and/or Attorney Work-Product Information
- Common Composite High Risk Data
- Controlled Unclassified Information (CUI) – Research
- Customer Card Data (PCI DSS)
- Disability-Related Medical Information
- Disaster recovery/business continuity plans
- Electrical, Steam, Chiller Utility data
- Human Resource Search Files
- Identifiable Human Subject Data – Research
- Information System Configuration
- Internal Audit Working Papers
- Items Covered by Contractual Non-Disclosure or Data Use Agreement
- Law Enforcement Information (LEI)
- Library Transactional Data
- Non-sensitive Course or Program Information
- Non-sensitive Research Information
- Personally Identifiable Information (PII)
- Personnel Files
- Private Personal Information (PPI)
- Protected Health Information (PHI)
- Sensitive Alumni, Donor or Constituent Information
- Sensitive Intellectual Property - Research
- Sensitive Security Data
- Student Financial Aid Data (GLBA)
- Student Records (directory information)
- Student Records (non-directory)
- University Financial Records
- Workers Compensation
Accessible Education Center (AEC) disability information
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
III.05 ADMINISTRATION OF STUDENT AFFAIRS/Student Records | Accessible Education Center (AEC) disability information | The confidentiality requirements of the Americans with Disabilities Act (ADA) apply to any medical or mental health information a student discloses or provides for the purposes of determining or modifying accommodations to disability. AEC may have records including, psychoeducational evaluations, hospital discharge summaries, psychological evaluations, letters from licensed health care practitioners, health care case notes, neuropsychological evaluations, etc. AEC interactions with students are noted in case notes and will commonly contain detailed medical or mental health information, including symptoms, medications, treatments, determined accommodations, etc.
| High Risk (Red)
| Provost Office – Accessible Education Center (AEC) | Assistant Vice Provost for Accessibility |
|
Architectural diagrams for the physical spaces where critical systems or functions exist
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian | |||||
IV.05. FINANCE/Public safety and Risk Services IV.06. FINANCE/Information technology IV.07. FINANCE/Property, facilities and planning; sustainability IV.09. FINANCE/Purchasing and contracting | Architectural diagrams for the physical spaces where critical systems or functions exist. | Information resides in multiple systems (GIS, CPFM Asset Management) and includes location and in some cases what specific equipment is in them. Examples of sensitive locations include:
| High Risk (Red) |
|
Attorney-Client Privileged and/or Attorney Work-Product Information
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
I.02. GOVERNANCE/Legal affairs
| Attorney-Client Privileged and/or Attorney Work-Product Information | Office of General Counsel’s notes, communications and other records maintained related to client and an attorney. Examples of this type of record include:
| High Risk (Red) | Office of General Counsel
| Vice President & General Counsel | Lead IT service provider for Office of Record |
Common Composite High Risk Data
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
All | Common Composite High Risk Data | Combination of data elements classified as High Risk although the security classifications of each individual data element are classified as Medium or Low Risk. Examples of this type of information include combination of:
| High Risk (Red)
| All | All | University IT |
Controlled Unclassified Information (CUI) – Research
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
II.06. ACADEMICS/Research, general | Controlled Unclassified Information (CUI) - Research | Unclassified federal information (received or created) that requires safeguarding or dissemination controls. Examples of this type of information include: DoD Controlled Technical Information (CTI) Controlled Defense Information (CDI) Export Controlled Information or material is any information or material that cannot be released to foreign nationals or representatives of a foreign entity, without obtaining approval of license from the Department of State for items controlled by the International Traffic in Arms Regulation (ITAR). Federal laws require that this type of data be stored in the US and must only be assessed by authorized U.S. persons. Examples of this type of information are detailed on the UO Export Controlled Items List at: https://exportcontrols.uoregon.edu/export-controlled-items
Please refer to the National Archives’ CUI Registry for further examples and details. | High Risk (Red)
| Head of Office, Institute, Department or Lab that Received the Data
| Head of Office, Institute, Department or Lab that Received the Data, Principal Investigators or Principal Researchers (including student researchers) | Lead IT service provider for Office of Record which may also include the data stewards themselves |
Customer Card Data (PCI DSS)
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
IV.04. FINANCE/Business affairs
| Customer Card Data (PCI DSS) | Credit card, debit card or other payment card information, governed by the Payment Card Industry Data Security Standards (PCI DSS). Examples of this type of information include: At a minimum, the full PAN (Primary Account Number) Full PAN plus any of the following: cardholder name, card expiration date and/or service code | High Risk (Red)
| Business Affairs Office (BAO)
| Associate Vice President, Business Affairs/Controller
| Lead IT service provider for Office of Record |
Disability-Related Medical Information
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian | ||||||
V.01. HR/Affirmative Action and Equal Opportunity V.02. HR/Benefits V.03. HR/Compensation and payroll V.04. HR/Workplace V.05. HR/Performance Management V.06. HR/Recruitment and selection V.07. HR/Separation V.08. HR/Time-off and leave V.09. HR/Employee Records V.10. HR/Human resources, other | Disability-Related Medical Information | The confidentiality requirements of the Americans with Disabilities Act (ADA) apply to any medical information an employee voluntarily discloses or that the university obtains through lawful disability-related inquiries or employment-related medical examinations.
Examples of potential sources of confidential medical information include:
Examples of information that does not constitute medical information includes, but is not limited to, the following:
| High Risk (Red)
|
|
Disaster recovery/business continuity plans
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
IV.05. FINANCE/Public safety and Risk Services | Disaster recovery/business continuity plans | Data relating to continuity plans, which may include moderately sensitive information relating to systems or business processes. | Moderate Risk (Amber) | Safety and Risk Services (SRS) | Director of Operations
| Lead IT service provider(s) for Office of Record |
Electrical, Steam, Chiller Utility data
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
IV.07 FINANCE, ADMINISTRATION AND INFRASTRUCTURE/Property, Facilities and Planning; Sustainability | Electrical, Steam, Chiller Utility data.
| Data relating to temperature, pressures, voltage, fluid flows throughout Campus Utility Production and Distribution. Includes real-time and historic information. | Moderate Risk (Amber) | Campus Planning & Facility Management (CPFM)
| Associate Vice President for Campus Planning and Facilities Management | Lead IT service provider(s) for Office of Record |
Human Resource Search Files
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
V.07 HUMAN RESOURCES/Recruitment and Selection | Human Resource Search Files | Search files including but not limited to evaluation of qualifications, interview questions and notes, search process documentation, reference checks.
| Moderate Risk (Amber) | Units conducting the search are holders of these aspects of search files. | Chief HR Officer | Unit IT Lead |
Identifiable Human Subject Data – Research
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
II.06. ACADEMICS/Research, general | Identifiable Human Subject Data - Research | Individually identifiable research data containing sensitive information about human subjects. A human subject is a living individual about whom an investigator (whether professional or student) obtains: 1) information or biospecimens through intervention or interaction with the individual, and uses, studies, or analyzes the information or biospecimens; or 2) obtains, uses, studies, analyzes, or generates identifiable private information or identifiable biospecimens. This data type is governed by the Federal Policy for the Protection of Human Subjects (also called the “Common Rule”) and must comply with UO IRB regulations. Examples of this type of information are listed on the UO Research Compliance website at: http://rcs.uoregon.edu/sites/infosec2.uoregon.edu/files/HSR%20definitions.pdf | High Risk (Red)
| Head of Office, Institute, Department or Lab that Received the Data
| Head of Office, Institute, Department or Lab that Received the Data, Principal Investigators or Principal Researchers (including student researchers) | Lead IT service provider for Office of Record which may also include the data stewards themselves |
Information System Configuration
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
IV.05. FINANCE/Public safety and Risk Services IV.06. FINANCE/Information technology IV.07. FINANCE/Property, facilities and planning; sustainability IV.09. FINANCE/Purchasing and contracting | Information System Configuration | Information system and configuration data, where modification (maliciously or accidentally) could compromise the confidentiality, integrity or availability of UO information systems and data. Examples of this type of record include:
| High Risk (Red)
| Information Services
| Vice Provost and Chief Information Officer | ACIOs, CTO, CISO |
Internal Audit Working Papers
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
IV.02. FINANCE/Audits | Internal Audit Working Papers | Evidence obtained by Internal Audit or their delegates during audit, consulting or investigative activities, used to support final opinions or recommendations during an engagement. Examples of this type of record include:
| High Risk (Red)
| Audit | Chief Auditor | Lead IT service provider for Office of Record
|
Items Covered by Contractual Non-Disclosure or Data Use Agreement
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
IV.09. FINANCE/Purchasing and contracting
| Items Covered by Contractual Non-Disclosure or Data Use Agreement | Items including information, equipment, materials, or data deemed confidential or sensitive by contract executed by University representatives with third parties. Example:
| High Risk (Red) | Office, Department or Lab that Received the Data | Head of Office, Department or Lab that Received the Data
| Lead IT Support for Office of Record
|
Law Enforcement Information (LEI)
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
IV.05 FINANCE, ADMINISTRATION AND INFRASTRUCTURE/Public Safety and Risk Services | Law Enforcement Information (LEI) | Non-public law enforcement records generated or maintained by the University of Oregon Police Department (UOPD) and Regional Partners (City of Eugene PD, City of Springfield PD, Junction City PD). Examples of this type of information include:
| High Risk (Red)
| UOPD
| UO Police Chief | Lead IT service provider for Office of Record |
Library Transactional Data
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
II.08 ACADEMICS, INSTRUCTION AND RESEARCH/Museums and Libraries | Library Transactional Data | Library circulation data that are exempt from Public Records Request under Oregon Public Records law. Specifically, E.4.e.(23) Library Records ORS 192.502(23) exempts the records of a library, including:
| Moderate Risk (Amber) | University Libraries | Dean of Libraries | Lead IT service provider(s) for Office of Record |
Non-sensitive Course or Program Information
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
II.01 ACADEMICS, INSTRUCTION AND RESEARCH/Curriculum and Instruction | Non-sensitive Course or Program Information
| Majority of data generated or received as part of conducting course work, that has not been identified by the University as sensitive and subject to another classification in this table. Examples of this type of data include:
| Low Risk (Green) | Head of Office, Institute, Department or Lab that Received the Data
| Course instructors, students for their work products | Lead IT service provider for Office of Record which may also include the data stewards themselves |
Non-sensitive Research Information
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
II.06. ACADEMICS/Research, general
II.08. ACADEMICS/Museums and Libraries | Non-sensitive Research Information
| Majority of data generated or received as part of conducting research, testing or other sponsored activity, that has not been identified by funders/sponsors, or by the University as sensitive and subject to another classification in this table. | Low Risk (Green) | Head of Office, Institute, Department or Lab that Received the Data
| Head of Office, Institute, Department or Lab that Received the Data, Principal Investigators or Principal Researchers (including student researchers) | Lead IT service provider for Office of Record which may also include the data stewards themselves |
Personally Identifiable Information (PII)
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian | |||||||||||||||||||
II.06. ACADEMICS/Research, general
II.08. ACADEMICS/Museums and Libraries
III.01. STUDENTS/Conduct and Student Activities III.02. STUDENTS/Housing and residence life III.03. STUDENTS/Tuition and student fees III.04. STUDENTS/Student health services III.05. STUDENTS/Student records III.06. STUDENTS/Scholarships and financial aid III.07. STUDENTS/Intercollegiate athletics III.08. STUDENTS/Admissions, Oregon residency
IV.04. FINANCE/Business affairs IV.05. FINANCE/Public safety and Risk Services IV.06. FINANCE/Information technology
IV.08. FINANCE/Parking and vehicles IV.09. FINANCE/Purchasing and contracting
IV.11. FINANCE/Fundraising and Development
V.01. HR/Affirmative Action and Equal Opportunity V.02. HR/Benefits V.03. HR/Compensation and payroll V.04. HR/Workplace V.05. HR/Performance Management V.06. HR/Recruitment and selection V.07. HR/Separation V.08. HR/Time-off and leave V.09. HR/Employee Records V.10. HR/Human resources, other | Personally Identifiable Information (PII) | Personally Identifiable Information (PII) is defined as any data element or combination of data elements that would be sufficient to be used to fraudulently assume the identity of an individual, consistent with the Oregon Consumer Identify Theft Protection Act (OCITPA). Examples of this type data include a person’s name in combination with one or more of the following:
| High Risk (Red)
|
|
Personnel Files
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
V.09. HR/Employee Records | Personnel Files | Faculty or staff personnel records. Examples of this include:
This information can be in a variety of formats, systems, and locations such as, MyTrack, and personnel files held in the department, Provost Office and/or Human Resources in paper and electronic file drives. Some of this information can be obtained via a public record request. | Moderate Risk (Amber) | Human Resource Office
| Chief Human Resource Officer (CHRO) | Sr. Associate Director of HR Operations |
Private Personal Information (PPI)
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian | |||||||||||||||||
Spans many series | Private Personal Information (PPI) | Faculty, staff, students and others as applicable:
| High Risk (Red)
|
|
Protected Health Information (PHI)
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian | |||||||||||||||||||||||||||||||||||
III.04. STUDENTS/Student health services
III.07. STUDENTS/Intercollegiate athletics
V.01. HR/Affirmative Action and Equal Opportunity
V.07. HR/Separation V.08. HR/Time-off and leave V.09. HR/Employee Records V.10. HR/Human resources, other | Protected Health Information (PHI) | Protected Health Information (PHI) as defined by the Health Insurance Portability and Accountability Act (HIPAA) refers to “all individually identifiable health information” in any form that is related to the provision of past, present, or future physical or mental health care to the individual, or the payment of health care. It is also defined as health and demographic information with respect to which there is a reasonable basis to believe the information can be used to identify the individual. Note: similar data used in HIPAA Hybrid Covered Entities are classified similar to PHI used in HIPAA Covered Components. Health information combined with unique identifiers of the individual or of relatives, employers, or household members of the individual, will result in the information being categorized as Protected Health Information (PHI):
| High Risk (Red)
|
|
Sensitive Alumni, Donor or Constituent Information
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian | |||||||||
Spans many series | Sensitive Alumni, Donor or Constituent Information | Sensitive information of alumni and donors including:
| High Risk (Red)
|
|
Sensitive Intellectual Property - Research
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
II.06. ACADEMICS/Research, general | Sensitive Intellectual Property - Research | Information about intellectual property created by University employees in connection with their work, or information provided to UO employees that represents intellectual property to the owner. Examples of this type of information include:
| High Risk (Red)
| Head of Office, Institute, Department or Lab that Received the Data
| Head of Office, Institute, Department or Lab that Received the Data, Principal Investigators or Principal Researchers (including student researchers) | Lead IT service provider for Office of Record which may also include the data stewards themselves |
Sensitive Security Data
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
IV.05. FINANCE/Public safety and Risk Services | Sensitive Security Data | Information that can be used to assist an attacker in compromising the confidentiality, integrity or availability of UO information systems and data. Examples of this type of record include:
Authentication data, e.g.,
| High Risk (Red) | Information Security Office | Chief Information Security Officer | Director of Information Security Services and Assurance |
Student Financial Aid Data (GLBA)
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian | ||||||
III.06. STUDENTS/Scholarships and financial aid III.07. STUDENTS/Intercollegiate athletics
IV.04. FINANCE/Business affairs
V.03. HR/Compensation and payroll
V.09. HR/Employee Records | Student Financial Aid Data (GLBA) | The Gramm-Leach-Bliley Act (GLBA) requires that financial institutions act to ensure the confidentiality and security of customers’ “nonpublic personal information,” or NPI. This law also covers Financial Aid Data stored and processed by Universities. Examples of this type of information include nonpublic personal information such as:
| High Risk (Red)
|
|
Student Records (directory information)
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian | ||||||
III.01 ADMINISTRATION OF STUDENT AFFAIRS/Conduct and Student Activities III.02 ADMINISTRATION OF STUDENT AFFAIRS/Housing and Residence Life III.04 ADMINISTRATION OF STUDENT AFFAIRS/Student Health Services III.05 ADMINISTRATION OF STUDENT AFFAIRS/Student Records III.06 ADMINISTRATION OF STUDENT AFFAIRS/Scholarships and Financial Aid III.07 ADMINISTRATION OF STUDENT AFFAIRS/Intercollegiate Athletics
| Student Records (directory information) | Student educational records designated as “directory information” by the University Registrar’s Office; by default these records can be released without student approval. Students can request nondisclosure by filing a Directory Information Restriction via the Registrar’s Office. Examples of this type of information are listed on the Registrar’s website at: https://registrar.uoregon.edu/records-privacy | Low Risk (Green) |
|
Student Records (non-directory)
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian | |||||
All series under “Student Records” | Student Records (non-directory) | Student educational records designated as “nondirectory information” by the University Registrar’s Office. The Family Educational Rights and Privacy Act (FERPA) governs release of, and access to, student education records. Examples of this type of information are listed on the Registrar’s website at: https://registrar.uoregon.edu/records-privacy | Moderate Risk (Amber) |
|
University Financial Records
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian | |||||
II.06 ACADEMICS, INSTRUCTION AND RESEARCH/Research, General III.03 ADMINISTRATION OF STUDENT AFFAIRS/Tuition and Student Fees III.06 ADMINISTRATION OF STUDENT AFFAIRS/Scholarships and Financial Aid IV.01 FINANCE, ADMINISTRATION AND INFRASTRUCTURE/Budget IV.04 FINANCE, ADMINISTRATION AND INFRASTRUCTURE/Business Affairs IV.09 FINANCE, ADMINISTRATION AND INFRASTRUCTURE/Purchasing and Contracting IV.11 FINANCE, ADMINISTRATION AND INFRASTRUCTURE/Fundraising and Development V.03 HUMAN RESOURCES/Compensation and Payroll
| University Financial Records | UO internal financial records subject to public records law but not yet vetted for release. Examples of this type of information include:
| Moderate Risk (Amber) |
|
Workers Compensation
Functional Classification/Corresponding Retention Schedule Series | Data Type | Description & Examples | Security Classification | Office of Record | Data Steward | Data Custodian |
IV.05. FINANCE/Public safety and Risk Services | Workers Compensation | Data relating to workers compensation injuries, which could contain medical information. | High Risk (Red)
| Safety and Risk Services (SRS) | Occupational Health & Safety Manager | Lead IT service provider(s) for Office of Record |