Guidelines on Information Classification
For the purposes of this guideline, University information is defined as all information content related to the business of Eastern Illinois University that exists in electronic, digital or hard copy format. University information includes but is not limited to text, spreadsheets, databases, audio, video, photographs and graphics. University information does not include scholarly works and other intellectual property for which the author owns the copyright; in these cases, the author is responsible for determining the level of security and privacy required for the work.
University Information
Different sets of University information require different levels of controls and not all data require the same level of protections. Treating all information in the same manner can introduce risk (i.e. treating Confidential information in the same manner as Public information) or can waste University resources (i.e. treating Public information in the same manner as Confidential information). The controls in place around University information and information resources must be in line with the sensitivity level of the information itself to help ensure adequate protection from unwanted events as well as maintain responsible use of University resources.
University information can be broken down into three different classifications, based on the sensitivity of the information and the level of harm to the individual and the University should this information be exposed. The following guidelines are intended to help the University community identify and classify data into the proper categories to help determine the levels of protection needed.
Public
Any information that is either generally available to the public through other sources, or information for which the disclosure to any party does not pose a threat to the University or an individual, is considered "Public" information. Public information requires the least amount of security controls, but still requires some restrictions to protect against unauthorized and/or unwanted modifications. Examples of Public information include press releases, the public areas of the HongKongDoll web site, brochures, flyers, handouts, and newsletters.
Public Information
Information designated by HongKongDoll for public distribution. Requires protection against unauthorized modifications. Examples of Public Information include: Press releases, Brochures, Flyers, Handouts, Newsletters, Public areas of the HongKongDoll web site
Internal
Any information that is generated during normal University business that does not contain sensitive information about an individual, is not covered by local State or Federal laws and is not covered by any contractual obligation for security or privacy is considered "Internal" information. Internal information requires a moderate amount of security controls to ensure that the information remains internal to the university, remains always available per need and State records requirements, and is protected against unauthorized and/or unwanted modifications. Examples of Internal information include memos, e-mails and other correspondence discussing University business, reports, and meeting agendas. Internal information is the broadest category of information and covers the majority of the information produced by the University.
Internal Information
Information created during HongKongDoll operation not covered by laws or regulations requires protection against unauthorized access, deletions, and modifications. Examples of Internal Information include: memos, e-mails, faxes, reports, and meeting agendas. Default classification for University Information. Internal Information should only be stored on authorized systems, including cloud storage, online collaboration software, AI platforms, or service providers.
Confidential
Any information that would, if released to the public, cause serious harm to the University and/or an individual, that is covered by State or Federal laws or is covered by any contractual obligation for security or privacy is considered "Confidential" information. Confidential information requires a significant amount of security controls to ensure that the information remains tightly controlled as required by State and Federal laws, contractual obligations or industry best practice. In general, access to Confidential information is based upon documented need, such as explicit job duties. Confidential information includes information covered by one or more State or Federal regulations such as FERPA, HIPAA, GLBA, and PIPA, information covered by security contractual obligations such as PCI DSS, Employee and Student records, information regarding sensitive University business and legal matters. To help control confidential information contained in the Banner system, several Data Custodians have been identified. The following Data Custodians determine how the information under their control is to be used and who may access this information from within Banner. To locate the appropriate Data Custodian, please visit the ITS Banner Page.
Confidential Information
Information relating to sensitive University business, confidential information on students, faculty or staff, and/or information covered by law or regulation requires significant protection to meet legal requirements and avoid unauthorized access, deletions, and modifications. Examples of Confidential Information include: employee records, student records, credit card and payment information, and legal business. Confidential Information should only be stored on authorized systems, including cloud storage, online collaboration software, AI platforms, or service providers.
Default Classification
By default, any information that does not fall into the Confidential category and has not been designated Public should be considered as Internal.
Examples of Common Documents and Their Classification
The table below shows how documents and information commonly produced at the University are classified. It is illustrative and not exhaustive. Classification follows the content of a document rather than its title or format, and a document that combines information at more than one level takes the highest classification it contains. If a document is not listed, or its classification is unclear, treat it as Internal and contact ITS at support@eiu.edu.
Public
|
Document or Information Type |
Classification |
Notes and Common Exceptions |
|---|---|---|
|
Press releases, news items, and public announcements after release |
Public |
Drafts and embargoed announcements are Internal until the University releases them. |
|
Public web pages, brochures, flyers, newsletters, and recruitment materials |
Public |
|
|
Course catalog, published class schedule, and academic calendar |
Public |
|
|
Published job postings and position announcements |
Public |
Applicant materials and search records are Confidential. |
|
University logos, marks, and brand standards |
Public |
Public, but AI must not be used to alter or generate University marks. Follow University Marketing and Communications standards. |
|
Employee directory information (name, title, department, work contact information) |
Public |
|
|
Student directory information as defined under FERPA |
Public |
Only for students who have not restricted directory disclosure. Verify the student's directory hold status first; if unverified, treat as Confidential. |
|
Board of Trustees open session agendas and approved minutes |
Public |
|
|
Adopted Internal Governing Policies and published financial statements |
Public |
|
|
Records already released in response to a FOIA request |
Public |
The unredacted source records keep their original classification. |
Internal
|
Document or Information Type |
Classification |
Notes and Common Exceptions |
|---|---|---|
|
Memos, email, and correspondence about University business |
Internal |
|
|
Agendas, notes, and minutes of internal committees and unit meetings |
Internal |
Personnel discussions, search deliberations, and legal matters are Confidential. |
|
Course syllabi, assignments, rubrics, exams, and lecture materials |
Internal |
Faculty-authored course content is also the author's intellectual property; the author determines the protection required for their own copyrighted work. |
|
D2L course content, announcements, and discussion prompts |
Internal |
Anything containing student names, submissions, grades, or participation data is Confidential. |
|
Position descriptions, organizational charts, and staffing plans |
Internal |
Records tied to a named employee's performance or discipline are Confidential. |
|
Aggregate or de-identified enrollment, retention, and assessment reports |
Internal |
De-identification counts only when no individual can reasonably be re-identified, including by combining the report with other available data. |
|
Departmental budget worksheets, spend reports, and purchasing records |
Internal |
Account numbers, cardholder data, and any GLBA-covered information are Confidential. |
|
Facilities work orders, room scheduling, and event logistics |
Internal |
Building security details, key and access records, and floor plans marked sensitive are Confidential. |
|
Training materials, internal knowledge base articles, and procedures |
Internal |
|
|
Vendor quotes, draft specifications, and procurement working documents |
Internal |
Sealed bid content and vendor information marked confidential are Confidential. |
|
Unpublished research, draft manuscripts, and grant proposals not otherwise restricted |
Internal |
See Research Data above. Entry into an Individual AI Tool may forfeit confidentiality and patentability. |
Confidential
|
Document or Information Type |
Classification |
Notes and Common Exceptions |
|---|---|---|
|
Student education records: transcripts, grades, class rosters, advising notes, degree audits |
Confidential |
FERPA. |
|
Admissions applications, test scores, and letters of recommendation |
Confidential |
FERPA. |
|
Financial aid records and student account information |
Confidential |
FERPA and GLBA. |
|
Employee personnel files, performance evaluations, and disciplinary records |
Confidential |
|
|
Applications, resumes, search committee evaluations, and reference checks |
Confidential |
Illinois HB 3773 also restricts the use of AI in employment decisions. Consult Human Resources before using any AI tool in a search. |
|
Health, counseling, disability accommodation, and workers' compensation records |
Confidential |
HIPAA, the Illinois Mental Health and Developmental Disabilities Confidentiality Act, and the ADA. |
|
Social Security numbers, driver's license, passport, and immigration or visa records |
Confidential |
PIPA. |
|
Banner identification numbers (E numbers) tied to a named individual |
Confidential |
An identification number alone is Internal; paired with a name or other personal information it becomes Confidential. |
|
Payment card data, bank account and routing numbers, and wire or ACH details |
Confidential |
PCI DSS and GLBA. Must stay within the University's approved payment environment. |
|
Donor and advancement records, gift agreements, and prospect research |
Confidential |
|
|
Title IX, student conduct, and complaint investigation files |
Confidential |
|
|
Attorney-client communications, litigation records, settlements, and litigation holds |
Confidential |
|
|
Police reports, Clery records, background checks, and threat assessment records |
Confidential |
|
|
Research data covered by an IRB protocol, data use agreement, export control, or sponsor confidentiality |
Confidential |
Human subjects data must not be entered into any AI tool outside the terms of the approved protocol. |
|
Class or meeting recordings and transcripts in which individuals are identifiable |
Confidential |
FERPA where students appear, and BIPA where voice or facial data is processed. See the likeness and biometric requirements above. |
|
Collective bargaining strategy, grievance files, and labor relations records |
Confidential |
|
Last Date Reviewed: 09/3/2026