How to Classify Research Data

Appropriately protecting research data is a fundamental obligation rooted in our commitments to:

  • The providers and sources of the data.
  • The integrity and efficacy of the campus' research mission.
  • The prevention of financial or reputational damages to UC Berkeley.

To secure data effectively, researchers must understand their security responsibilities. The first step is identifying the correct Data Classification, which determines the security controls required to protect the information.

Why classify research data?

Researchers must securely protect research data when:

  • Participants are at risk: Data elements could expose identities or include sensitive information (e.g., medical, financial, or notice triggering information).
  • Contractual obligations exist: A Data Usage Agreement (DUA) from the data provider (e.g. NIH, CPHS, HCAI, CDPH, CDSS) or a research sponsor (federal agencies, private companies, non-profits) stipulates specific security requirements. 
  • Campus Policy applies: Add data receives protection corresponding to its classification, regardless of whether contractual oblications exist. Minimum Security Standards for Network Devices or Minimum Security Standards for Electronic Information applies to the data collected, retained, and used in the research based on its protection level in the Data and IT Resource Classification Standard.

Rea-World Example: A relevant example of this last point occurred recently on campus. Ransomware infected a researcher's workstation and spread to the department's network file-share drive, encrypting files containing over 20 years of research project data, with little hope of retrieving the encryption key except by paying the ransom.

This disaster was averted by restoring the files from a recent backup, a good example of security preparedness. Proper security logging also helped to rule out any incidents of illicit access to personally identifiable information. Without such logging, the department may have been responsible for costly notification regarding potential identity fraud to research subjects. Additional security safeguards based upon campus policies, when implemented appropriately, could have prevented this incident or stopped it from spreading.

How is research data classified?

The UC Berkeley Data Classification Standard is a framework for assessing data sensitivity based on the “adverse impact” a breach would have on the campus.implemented.

Data ClassImpactData Examples
Protection Level:
UC P4

High

(Extremely sensitive individually identifiable information)

Data requiring HIPAA compliance; genomic data; GDPR special categories data; genetic data as defined by California AB-825; Federal Controlled Unclassified Information (CUI); high risk export controlled data or technology; and data requiring notification to subjects if breached.
Protection Level:
UC P3

Moderate

(Moderately sensitive individually identifiable information)

 
Protection Level:
UC P2

Low

(Non-public, non-sensitive information and de-identified information)

Fully de-identified research information (caution: de-identification is difficult); non-public research using publicly available data; and public directory information.ectory information
Protection Level:
UC P1

Minimal

(Public information)

Published research, press releases, or information the subject consents to make public.

Steps for classifying research data

The following steps provide a guideline for the considerations necessary to determine the data classification protection level for research data. Answer the following questions:

Step 1Start by identifying the purpose and nature of the research and the data to be classified.
  • Does the research involve human subjects?
  • Is the data intended for public (no sharing restriction) or private (only those with a need-to-know can access) use?
Step 2Identify the specific data elements.

For example:

  • Health-related information
  • Personally Identifiable Information (PII)
  • Data collected about human research subjects
Step 3Identify any laws, regulations, or data usage agreements that govern the data.
  • Is there a DUA (Data Usage Agreement) between the research unit and the data-provider?
  • Does the data fall under the category of CA State "notice-triggering" information? (e.g., social security number, driver's license number)
  • Does the data include health information protected by HIPAA?
Step 4Estimate the number of sensitive records stored.
  • Use this number to help determine the potential impact of a breach (see Step 5)
  • For data elements covered by CA State Law, does the number of records exceed the minimum limit (500) for "notice-triggering" requirements?
Step 5Understand what notification requirements may exist in the event of a breach and the potential impact of those requirements.
  • Does the DUA specify requirements for an incident response plan?
  • Who will need to be contacted when a security incident is reported?
  • Estimate the cost of notification in the event of a breach (approx. $200 per person)
  • Include potential DUA penalties or fees, and possible litigation costs
Step 6Estimate the impact to the research project if the data is lost.
  • Will the research project be able to continue unimpeded if the data is lost? Is there a backup plan?
  • How will the project be affected if lost work and delays impact the research?
  • Will the validity of the research outcome be in question because of a security event?
  • How will the reputation of the research unit (and the University) be affected by a breach, especially in terms of future projects and funding?

Protection Level Requirements

Based on the data protection levels defined in the Data Classification Standard, the Minimum Security Standard for Electronic Information (MSSEI) policy identifies the security protections required to safeguard the data.

The MSSEI requirements include the Minimum Security Standard for Networked Devices (MSSND), which is a mandatory set of protections for all endpoint devices that utilize campus network services and is required for all protection level data classes.

These basic requirements, such as keeping the operating system and productivity software programs up-to-date, and running current malware detection tools, go a long way towards protecting the campus from security incidents such as the ransomware example cited above.

Following is an overview of the basic requirements for each of the protection level data classes:

Data ClassSecurity Requirements
UC P1All MSSND requirements
UC P2/3MSSND + MSSEI requirements for UC P2/3 data + other relevant requirements (e.g., DUA)
UC P4MSSND + MSSEI requirements for UC P4 data + other relevant requirements (e.g., DUA, HIPAA, etc.)

For the classification of UC P2/3 or UC P4 data, please contact the Research Data Management Program and/or the Information Security Office (ISO)

for assistance with how to apply the MSSEI requirements to research data, and for help with planning the implementation of the requirements.

Support and ResourcesFor assistance with classification, contact the Committee for Protection of Human Subjects or Campus Privacy Office. Contact the Export Control Office for export controlled data or technology.