How to Classify Research Data
Appropriately protecting research data is a fundamental obligation rooted in our commitments to:
- The providers and sources of the data.
- The integrity and efficacy of the campus' research mission.
- The prevention of financial or reputational damages to UC Berkeley.
To secure data effectively, researchers must understand their security responsibilities. The first step is identifying the correct Data Classification, which determines the security controls required to protect the information.
Why classify research data?
Researchers must securely protect research data when:
- Participants are at risk: Data elements could expose identities or include sensitive information (e.g., medical, financial, or notice triggering information).
- Contractual obligations exist: A Data Usage Agreement (DUA) from the data provider (e.g. NIH, CPHS, HCAI, CDPH, CDSS) or a research sponsor (federal agencies, private companies, non-profits) stipulates specific security requirements.
- Campus Policy applies: Add data receives protection corresponding to its classification, regardless of whether contractual oblications exist. Minimum Security Standards for Network Devices or Minimum Security Standards for Electronic Information applies to the data collected, retained, and used in the research based on its protection level in the Data and IT Resource Classification Standard.
Rea-World Example: A relevant example of this last point occurred recently on campus. Ransomware infected a researcher's workstation and spread to the department's network file-share drive, encrypting files containing over 20 years of research project data, with little hope of retrieving the encryption key except by paying the ransom.
This disaster was averted by restoring the files from a recent backup, a good example of security preparedness. Proper security logging also helped to rule out any incidents of illicit access to personally identifiable information. Without such logging, the department may have been responsible for costly notification regarding potential identity fraud to research subjects. Additional security safeguards based upon campus policies, when implemented appropriately, could have prevented this incident or stopped it from spreading.
How is research data classified?
The UC Berkeley Data Classification Standard is a framework for assessing data sensitivity based on the “adverse impact” a breach would have on the campus.implemented.
| Data Class | Impact | Data Examples |
| Protection Level: UC P4 | High (Extremely sensitive individually identifiable information) | Data requiring HIPAA compliance; genomic data; GDPR special categories data; genetic data as defined by California AB-825; Federal Controlled Unclassified Information (CUI); high risk export controlled data or technology; and data requiring notification to subjects if breached. |
| Protection Level: UC P3 | Moderate (Moderately sensitive individually identifiable information) | |
| Protection Level: UC P2 | Low (Non-public, non-sensitive information and de-identified information) | Fully de-identified research information (caution: de-identification is difficult); non-public research using publicly available data; and public directory information.ectory information |
| Protection Level: UC P1 | Minimal (Public information) | Published research, press releases, or information the subject consents to make public. |
Steps for classifying research data
The following steps provide a guideline for the considerations necessary to determine the data classification protection level for research data. Answer the following questions:
| Step 1 | Start by identifying the purpose and nature of the research and the data to be classified. |
|
| Step 2 | Identify the specific data elements. | For example:
|
| Step 3 | Identify any laws, regulations, or data usage agreements that govern the data. |
|
| Step 4 | Estimate the number of sensitive records stored. |
|
| Step 5 | Understand what notification requirements may exist in the event of a breach and the potential impact of those requirements. |
|
| Step 6 | Estimate the impact to the research project if the data is lost. |
|
Protection Level Requirements
Based on the data protection levels defined in the Data Classification Standard, the Minimum Security Standard for Electronic Information (MSSEI) policy identifies the security protections required to safeguard the data.
The MSSEI requirements include the Minimum Security Standard for Networked Devices (MSSND), which is a mandatory set of protections for all endpoint devices that utilize campus network services and is required for all protection level data classes.
These basic requirements, such as keeping the operating system and productivity software programs up-to-date, and running current malware detection tools, go a long way towards protecting the campus from security incidents such as the ransomware example cited above.
Following is an overview of the basic requirements for each of the protection level data classes:
| Data Class | Security Requirements |
| UC P1 | All MSSND requirements |
| UC P2/3 | MSSND + MSSEI requirements for UC P2/3 data + other relevant requirements (e.g., DUA) |
| UC P4 | MSSND + MSSEI requirements for UC P4 data + other relevant requirements (e.g., DUA, HIPAA, etc.) |
For the classification of UC P2/3 or UC P4 data, please contact the Research Data Management Program and/or the Information Security Office (ISO)
for assistance with how to apply the MSSEI requirements to research data, and for help with planning the implementation of the requirements.