Purpose

The Data Protection Categorization indicates the minimum level of protections required for Organizational Data and Information Systems based on Cyber Security’s Data Protection Safeguards and Protected Data Practices. Additional protection requirements above this minimum may be required if the Organizational Data or Information System is also regulated (see Data Regulation Categorization)

 

Go to Procedures
Go to Resources

Definitions

Capitalized terms not otherwise defined herein shall have the same meaning as set forth in the Data Governance and Management Policy

Audience

Responsible

Associate Data Trustee

Data Steward

System Owner

AccountableData Governance Committee
Support

Associate Data Steward

Technical Manager

ConsultedData Governance Team
Informed

Data Domain & Technology Subcommittees

Data Administrator

Data User

Procedures

Assigning a "Data Protection Categorization"

  • A Data Steward must assign a “Data Protection Categorization” to a Data Element.
  • A Data Steward must assign a “Data Protection Categorization” to a Data Sub-Domain, which may be derived by choosing the highest risk categorization from Data Elements within the Data Sub-Domain.
  • An Associate Data Trustee must assign a “Data Protection Categorization” to a Data Domain, which may be derived by choosing the highest risk categorization from its Data Sub-Domains.
  • A System Owner must assign a “Data Protection Categorization” to an Information System, which may be derived by choosing the highest risk categorization from the Organizational Data within the Information System.
  • A report or a data set that contains Organizational Data may indicate the “Data Protection Categorization” in order to communicate to its intended audience the type of risk the report or data set contains.

The “Data Protection Categorization” indicates the minimum level of protections required for Organizational Data and Information Systems based on Cyber Security’s Data Protection Safeguards and Protected Data Practices. When Organizational Data may fall into more than one categorization, it should be categorized in the highest applicable risk categorization. The following categorizations are available:

ProtectedInformation is not generally available to parties outside of the Georgia Tech community. This is the default "Data Protection Categorization" for Organizational Data. A categorization of Protected does not always mean that the data contained therein is confidential or non-disclosable and such data may be subject to disclosure under the Georgia Open Records Act or other applicable laws and regulations.
PublicInformation is targeted for public use. Examples include website content for general viewing and published press releases.

Modifications to the approved “Data Protection Categorization” choices

  1. An individual must submit a request to add a new categorization, change the name and/or definition of an existing categorization, or deprecate the use of an existing categorization to the Data Governance Committee. The request must include:
    1. Name of the categorization (proposed name if new or changing)
    2. Definition of the categorization (proposed definition if new or changing)
    3. Reason the modification is requested
  2. The Data Governance Committee will review the request and determine if further discussion is required with the requestor or others involved with the request.
  3. If approved, the Data Governance Committee will notify the requestor and publish the change to the official list of approved “Data Protection Categorization” choices on the website. Inventories that rely upon “Data Protection Categorization” (e.g., Data Element Dictionary) will be updated.
  4. If not approved, the Data Governance Committee will articulate the rejection and send it back to the requestor.

Resources

Does this “Data Protection Categorization” replace the existing data categorizations in the Georgia Tech Data Access Policy?

Yes. Existing data categories I through IV are replaced with Data Protection Categorizations of “Protected” or “Public”.

What data protections are required for “Protected” Organizational Data?

Please see Cyber Security’s Data Protection Safeguards and Protected Data Practices

What data protections are required for “Public” Organizational Data?

Please see Cyber Security’s Data Protection Safeguards and Protected Data Practices
 

What if I am unsure of the appropriate Data Protection Categorization for Organizational Data?

You should categorize the Organizational Data as “Protected,” as this is the default “Data Protection Categorization.”

What if Organizational Data is also regulated?

All Organizational Data will have a Data Regulation Categorization which informs which regulations (if any) apply to the data. Please see Cyber Security’s Data Protection Safeguards and Protected Data Practices for more information.

 


 

Is FERPA directory information categorized as “Protected?”

Yes. Student information is not targeted for public use. Protected data, including FERPA directory information, may be subject to disclosure under FERPA, the Georgia Open Records Act, or other applicable laws and regulations.

Examples of various types of Organizational Data and their “Data Protection Categorization”

Faculty/Staff Information 
Georgia Tech Email AddressPublic
Georgia Tech Phone NumberPublic
Georgia Tech Work AddressPublic

Personal and Emergency Contact Information

(without permission to publish)

Protected
Social Security NumberProtected
Employee ID Number (GT ID and PeopleSoft ID)Protected
BuzzCard NumberProtected
Compensation InformationProtected
Performance EvaluationsProtected
Benefits ElectionsProtected
Health InformationProtected
Georgia Tech Account PasswordProtected
Student Information 
FERPA Directory InformationProtected
Social Security NumberProtected
Student ID Number (GT ID)Protected
BuzzCard NumberProtected
Admission InformationProtected
Student InformationProtected
Financial Aid and Scholarship InformationProtected
Housing InformationProtected
Health InformationProtected
Georgia Tech Account PasswordProtected
Research Information 
Published Research DataProtected
Sponsored Project Contracts, Grants, and Associate ProtocolsProtected
Non-Sponsored Research InformationProtected
Technology Licensing and Invention Disclosure InformationProtected
Unpublished Research DataProtected
Proprietary Information Obtained by Georgia Tech under Nondisclosure AgreementProtected
Intellectual Property Owned by Georgia TechProtected
General Business Information 
Public Websites (e.g., http://www.gatech.edu)Public
Organizational ChartsPublic
Public Relations Brochures (containing General Georgia Tech Information)Public
Annual ReportsPublic
EmailProtected
Chat LogsProtected
Internal WebsitesProtected
Customer Personal ChecksProtected
Purchasing ReceiptsProtected
Network DiagramsProtected
Georgia Tech Financial Account NumberProtected
Purchasing and Receiving ReportsProtected
Travel Reimbursement FormsProtected
Purchasing Card (P-Card) NumbersProtected
Credit Card NumbersProtected
Library Records Information 
Library Catalogue InformationPublic
Active Interlibrary Loan RecordsProtected
Library DatabasesProtected
Active Circulation RecordsProtected
Security Camera RecordingsProtected
Environmental and Physical Information 
Georgia Tech Building BlueprintsProtected
Chematix Chemical Tracking SystemProtected
Building HVAC Monitoring/Control DataProtected
BuzzCard SystemProtected
Continuum SystemProtected
Building Safety PlansProtected
Revision DateAuthorDescription
2022-10-28Zachary Hayes, Data GovernanceExpanded examples of public and protected data
2021-07-27Zachary Hayes, Data GovernanceNew