Guidelines on Information Classification

For the purposes of this guideline, University information is defined as all information content related to the business of Eastern Illinois University that exists in electronic, digital or hard copy format. University information includes but is not limited to text, spreadsheets, databases, audio, video, photographs and graphics. University information does not include scholarly works and other intellectual property for which the author owns the copyright; in these cases, the author is responsible for determining the level of security and privacy required for the work.

University Information

Different sets of University information require different levels of controls and not all data require the same level of protections. Treating all information in the same manner can introduce risk (i.e. treating Confidential information in the same manner as Public information) or can waste University resources (i.e. treating Public information in the same manner as Confidential information). The controls in place around University information and information resources must be in line with the sensitivity level of the information itself to help ensure adequate protection from unwanted events as well as maintain responsible use of University resources.

University information can be broken down into three different classifications, based on the sensitivity of the information and the level of harm to the individual and the University should this information be exposed. The following guidelines are intended to help the University community identify and classify data into the proper categories to help determine the levels of protection needed.

Public

Any information that is either generally available to the public through other sources, or information for which the disclosure to any party does not pose a threat to the University or an individual, is considered "Public" information. Public information requires the least amount of security controls, but still requires some restrictions to protect against unauthorized and/or unwanted modifications. Examples of Public information include press releases, the public areas of the EIU web site, brochures, flyers, handouts, and newsletters.

Public Information
Information designated by EIU for public distribution. Requires protection against unauthorized modifications. Examples of Public Information include: Press releases, Brochures, Flyers, Handouts, Newsletters, Public areas of the EIU web site

Internal

Any information that is generated during normal University business that does not contain sensitive information about an individual, is not covered by local State or Federal laws and is not covered by any contractual obligation for security or privacy is considered "Internal" information. Internal information requires a moderate amount of security controls to ensure that the information remains internal to the university, remains always available per need and State records requirements, and is protected against unauthorized and/or unwanted modifications. Examples of Internal information include memos, e-mails and other correspondence discussing University business, reports, and meeting agendas. Internal information is the broadest category of information and covers the majority of the information produced by the University.

Internal Information
Information created during EIU operation not covered by laws or regulations requires protection against unauthorized access, deletions, and modifications. Examples of Internal Information include: memos, e-mails, faxes, reports, and meeting agendas. Default classification for University Information. Internal Information should only be stored on authorized systems, including cloud storage, online collaboration software, AI platforms, or service providers.

Confidential

Any information that would, if released to the public, cause serious harm to the University and/or an individual, that is covered by State or Federal laws or is covered by any contractual obligation for security or privacy is considered "Confidential" information. Confidential information requires a significant amount of security controls to ensure that the information remains tightly controlled as required by State and Federal laws, contractual obligations or industry best practice. In general, access to Confidential information is based upon documented need, such as explicit job duties. Confidential information includes information covered by one or more State or Federal regulations such as FERPA, HIPAA, GLBA, and PIPA, information covered by security contractual obligations such as PCI DSS, Employee and Student records, information regarding sensitive University business and legal matters. To help control confidential information contained in the Banner system, several Data Custodians have been identified. The following Data Custodians determine how the information under their control is to be used and who may access this information from within Banner. To locate the appropriate Data Custodian, please visit the ITS Banner Page.

Confidential Information
Information relating to sensitive University business, confidential information on students, faculty or staff, and/or information covered by law or regulation requires significant protection to meet legal requirements and avoid unauthorized access, deletions, and modifications. Examples of Confidential Information include: employee records, student records, credit card and payment information, and legal business. Confidential Information should only be stored on authorized systems, including cloud storage, online collaboration software, AI platforms, or service providers.

Default Classification

By default, any information that does not fall into the Confidential category and has not been designated Public should be considered as Internal.

Examples of Common Documents and Their Classification

The table below shows how documents and information commonly produced at the University are classified. It is illustrative and not exhaustive. Classification follows the content of a document rather than its title or format, and a document that combines information at more than one level takes the highest classification it contains. If a document is not listed, or its classification is unclear, treat it as Internal and contact ITS at support@eiu.edu.

Public

Document or Information Type

Classification

Notes and Common Exceptions

Press releases, news items, and public announcements after release

Public

Drafts and embargoed announcements are Internal until the University releases them.

Public web pages, brochures, flyers, newsletters, and recruitment materials

Public

 

Course catalog, published class schedule, and academic calendar

Public

 

Published job postings and position announcements

Public

Applicant materials and search records are Confidential.

University logos, marks, and brand standards

Public

Public, but AI must not be used to alter or generate University marks. Follow University Marketing and Communications standards.

Employee directory information (name, title, department, work contact information)

Public

 

Student directory information as defined under FERPA

Public

Only for students who have not restricted directory disclosure. Verify the student's directory hold status first; if unverified, treat as Confidential.

Board of Trustees open session agendas and approved minutes

Public

 

Adopted Internal Governing Policies and published financial statements

Public

 

Records already released in response to a FOIA request

Public

The unredacted source records keep their original classification.

Internal

Document or Information Type

Classification

Notes and Common Exceptions

Memos, email, and correspondence about University business

Internal

 

Agendas, notes, and minutes of internal committees and unit meetings

Internal

Personnel discussions, search deliberations, and legal matters are Confidential.

Course syllabi, assignments, rubrics, exams, and lecture materials

Internal

Faculty-authored course content is also the author's intellectual property; the author determines the protection required for their own copyrighted work.

D2L course content, announcements, and discussion prompts

Internal

Anything containing student names, submissions, grades, or participation data is Confidential.

Position descriptions, organizational charts, and staffing plans

Internal

Records tied to a named employee's performance or discipline are Confidential.

Aggregate or de-identified enrollment, retention, and assessment reports

Internal

De-identification counts only when no individual can reasonably be re-identified, including by combining the report with other available data.

Departmental budget worksheets, spend reports, and purchasing records

Internal

Account numbers, cardholder data, and any GLBA-covered information are Confidential.

Facilities work orders, room scheduling, and event logistics

Internal

Building security details, key and access records, and floor plans marked sensitive are Confidential.

Training materials, internal knowledge base articles, and procedures

Internal

 

Vendor quotes, draft specifications, and procurement working documents

Internal

Sealed bid content and vendor information marked confidential are Confidential.

Unpublished research, draft manuscripts, and grant proposals not otherwise restricted

Internal

See Research Data above. Entry into an Individual AI Tool may forfeit confidentiality and patentability.

Confidential

Document or Information Type

Classification

Notes and Common Exceptions

Student education records: transcripts, grades, class rosters, advising notes, degree audits

Confidential

FERPA.

Admissions applications, test scores, and letters of recommendation

Confidential

FERPA.

Financial aid records and student account information

Confidential

FERPA and GLBA.

Employee personnel files, performance evaluations, and disciplinary records

Confidential

 

Applications, resumes, search committee evaluations, and reference checks

Confidential

Illinois HB 3773 also restricts the use of AI in employment decisions. Consult Human Resources before using any AI tool in a search.

Health, counseling, disability accommodation, and workers' compensation records

Confidential

HIPAA, the Illinois Mental Health and Developmental Disabilities Confidentiality Act, and the ADA.

Social Security numbers, driver's license, passport, and immigration or visa records

Confidential

PIPA.

Banner identification numbers (E numbers) tied to a named individual

Confidential

An identification number alone is Internal; paired with a name or other personal information it becomes Confidential.

Payment card data, bank account and routing numbers, and wire or ACH details

Confidential

PCI DSS and GLBA. Must stay within the University's approved payment environment.

Donor and advancement records, gift agreements, and prospect research

Confidential

 

Title IX, student conduct, and complaint investigation files

Confidential

 

Attorney-client communications, litigation records, settlements, and litigation holds

Confidential

 

Police reports, Clery records, background checks, and threat assessment records

Confidential

 

Research data covered by an IRB protocol, data use agreement, export control, or sponsor confidentiality

Confidential

Human subjects data must not be entered into any AI tool outside the terms of the approved protocol.

Class or meeting recordings and transcripts in which individuals are identifiable

Confidential

FERPA where students appear, and BIPA where voice or facial data is processed. See the likeness and biometric requirements above.

Collective bargaining strategy, grievance files, and labor relations records

Confidential

 

 

Last Date Reviewed: 09/3/2026