Data Classification Policy
Contact
Information Technology Services (ITS)Humanities 316
651-696-6525
helpdesk@macalester.edu
Hours
Data Categories
This policy provides definitions and examples of Macalester College’s three data categories: Public, Regulated, and Confidential. Macalester Sensitive Information (MSI) by definition includes Confidential and Regulated information. Public information, as described below, is not considered sensitive provided it was not inappropriately accessed or altered in any way. This classification applies to all Macalester information regardless of the storage medium (e.g., hard copy vs. digital/electronic).
Public Data
Public Data: Definition
Information that can be shared with anyone without damage to Macalester College
Public Data: Risk
Minimal but possible
Public Data: Examples
- Official statements and press releases
- Campus maps
- Public directory data (e.g., contact information)
- Email address
- Dates of attendance
Regulated Data
Regulated Data: Definition
Information that is subject to regulatory compliance
Regulated Data: Risk
High
Regulated Data: Examples
- Student record information
- Prospective students
- Employee info
- Financial records
- Contracts
- Physical plant details
- Credit card numbers
- Health records
Confidential Data
Confidential Data: Definition
Information integral to the business operations of the college
Confidential Data: Risk
Medium to High
Confidential Data: Examples
- Information maintained by the Office of the Provost
- Alumni/Advancement info (unless permission for release is granted)
- Donor/prospect info
- Research data
- Performance reviews
- Donor profiles
Sharing and Handling
Email should at all times be assumed to be transported in the clear; there should be no expectation of privacy or confidentiality. Email messages and attachments, therefore, should never contain Macalester Sensitive Information.
The Family Educational Rights and Privacy Act (FERPA) is a federal law that protects the privacy of student education records which are defined as records “directly related to a student” that are “maintained” by an educational institution. Email accounts of students in the domain (macalester.edu) have never been considered “education records” within the meaning of FERPA because they are not “maintained” either by or on behalf of Macalester College. Instead the college merely provides a server to facilitate such exchanges. Macalester College does accord FERPA protection to emails that directly relate to a student when those emails are in the accounts of a Macalester employee.
Sharing Macalester Sensitive Information externally through file sharing platforms (Google Drive, Dropbox, SFTP, etc.) is prohibited unless there is a defined and approved business reason to do so. Using file sharing platforms that are not maintained and managed by Macalester College are prohibited.
Intellectual Property
Except where explicitly addressed in the Employee Handbook (Sec 12.13, Ownership of Copyrights in Works (Revised 09/18/06)) or in the Macalester College Copyright Policy, the development of any aspect of Intellectual Property (i.e., material or products suitable for copyright or patent) that occurs within the scope of employment at Macalester College shall be deemed an asset of the college and shall not be disclosed outside of the ordinary channels of communication within the institution.
Macalester Sensitive Information
The data specified in the next five sections are representative examples of Macalester Sensitive Information (MSI). This listing is not comprehensive. Please contact your department or division director for a current, comprehensive listing for your unit.
Student Information
- Grades
- Student conduct records
- Student Identification Number
- Marital status
- Religious affiliation
- Social Security Number
- Ethnic backgrounds
- Wire transfers
- Student schedules
- Home address
- Payment history
- Financial aid/grants
- Student bills
Employee Information
- Social Security Number (includes partials, such as last four digits)
- Performance reviews and related documents
- Date of birth
- Home address or personal contact information
Information on Alumni and Friends of the College
- Name
- Date of birth
- Graduating class and degree(s)
- Social Security Number
- Giving history
- Donor/prospect information
- Addresses
- Telephone/fax numbers
- Email addresses
- Employment information
- Family information (spouse(s)/children/grandchildren)
Financial Information – Individual
- Credit card numbers
- Bank account numbers
- Student financial information
- Salary
Financial Information – Institutional
- Accounts Payable/Accounts Receivable
- Spending Balances
- Vendor SSN
- Vendor Business ID
Protected Health Information (PHI)
Electronic transmission of student and employee health information is governed by the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Business Associate agreements compliant with HIPAA protecting such information are in place between Macalester College and health-related vendors.
The Macalester College Health Plan, a covered entity for purposes of HIPAA, has developed this HIPAA Privacy Policy in order to comply with the requirements under the HIPAA privacy regulations and guidelines. The Health Plan is a fully-insured health plan sponsored by Macalester College (Plan Sponsor).
Protected Health Information (PHI) means individually identifiable information relating to the past, present or future physical or mental health or condition of an individual, provision of health care to an individual, or the past, present or future payment for health care provided to an individual.
Neither the Health Plan nor the Plan Sponsor (or any member of the Plan Sponsor’s workforce) shall create or receive protected health information (PHI) other than specifically described below.
The Health Plan Does Not Create, Maintain or Receive PHI Except For:
- Enrollment/disenrollment information
- Summary health information
- Periodic review of status
Summary health information may be used by the Plan Sponsor for two limited purposes: (1) obtaining premium bids for providing health insurance coverage under the Health Plan, and also for (2) modifying, amending or terminating the Health Plan. Violations of this policy will be subject to discipline.
Public Directory Information
Student Public/Directory Information
Under FERPA and Macalester policy the following student data are considered directory and therefore public information which may ordinarily be released by the College without student consent unless the student designates otherwise. The U.S. Department of Education has more information.
- Name
- Date and place of birth
- Local phone number
- Email address
- Local address
- Participation in officially recognized activities and sports
- Weight and height of members of athletic teams
- Dates of attendance
- Degree(s) awarded and date(s)
- Major field of study
- Degrees and awards received
- Institution attended immediately prior to Macalester
- ID card photographs
Employee Public/Directory Information
- Name
- Job title
- Department
- Campus address
- Campus phone
- Date of hire
- Date of termination