Data Classifica... What?
Data Classifica... What?
Four data types at AAU
More than one data type
If you find that the information you are working with contains more than one data type, always follow the instructions for the highest level of your information.
Level 0: Public Information
Level 0 on the data classification model characterises information that is available to the public and where publication will not harm AAU. Therefore, if you work with this type of data, there are no labelling, access, storage and shipping requirements for documents, emails and websites with public information.
Level 1: Internal Information
Level 1 refers to the information you work with that only other users with a work-related need can and may access, and where a breach of confidentiality can have a low impact on AAU, private individuals or business partner(s).
Especially for internal information:
- Internal information must be labelled
- Electronic access to internal information must be password protected
- Electronic storage can be on AAU network drives, AAUs ESDH-system or other AAU-approved solutions.
- Physically, internal information must be stored behind a lock.
- It is recommended that internal information is encrypted when sent.
- Internal information may be sent internally by internal mail or externally as regular mail.
Level 2: Confidential Information
Level 2 among the data types is about the information that only users with a work-related need may, and can, access, and where a breach of confidentiality can have a medium damaging effect on AAU, private individuals or business partner(s).
Especially for confidential information:
- Confidential information must be labelled
- Electronic access to confidential information must be password protected with AAU account information
- Electronic storage of confidential information can be on network drives, AAUs ESDH-system or other AAU-approved solutions
- Physically, confidential information must be stored behind a lock
- Use 'Follow-You' printing when printing confidential documents
- Confidential information may only be sent or disclosed to business partners if there is a legal basis, e.g. in the form of a data processing agreement
Level 3: Sensitive Information
Level 3 applies to information that only users with a work-related need may, and can, access, and where a breach of confidentiality can have a major damaging effect on AAU, private individuals or business partner(s).
This is information that, by virtue of its personal, technical, business or competitive nature and sensitivity, must be protected against unauthorised access and disclosure.
Especially for sensitive information:
- Sensitive information must be labelled
- Electronic access must be password protected with AAU account information and 2-factor validation outside the AAU network
- Be aware that others must not be able to see the information (screen/papers)
- Use 'Follow-You' printing when printing sensitive documents
- Sensitive information may only be sent/disclosed to business partners on a legal basis, e.g. in the form of a data processing agreement