(1) This Procedure: (2) This Procedure supports and should be read in conjunction with the Data Governance and Management Policy. (3) This Procedure applies to: (4) This Procedure does not apply to Research data defined in the Research Data Management Policy, with the exception of Section 3 - Data Classifications and Section 4 – Data Labelling Principles. (5) Data classification is the activity of categorising data based on potential impact to the University or individuals in the event of a data breach. The impact to the University is measured in line with the Enterprise Risk Management Procedures. (6) Data must be classified using the classifications detailed in Appendix A: Data Classifications, ranked from the highest to the lowest level of sensitivity: (7) The default classification for all data, unless specified otherwise, is Official. (8) Data assets are classified based on the highest classification level of any individual element. Data asset level classifications are recorded in the Data Asset Register. (9) University classifications are separate from classifications assigned by State and Federal Government entities. (10) Any data with classifications applied by State and Federal Government entities must be managed in accordance with the relevant security classification guidelines. (11) Data labelling is the activity of tagging or annotating data with labels that indicate the classification of the data. (12) Institutional Data should be labelled within University storage platforms and business systems where such functionality is available. For detailed labelling instructions, refer to the platform or system labelling documentation. (13) The process of selecting the appropriate label is outlined in Appendix B: Label Selection Assessment. (14) A label should be applied where the labelling functionality is supported when: (15) As data sensitivity can change over time, relabelling may be required. (16) Data should be handled in accordance with the requirements of its classification, as outlined in Appendix C: Data Handling Requirements Matrix. (17) Data received from an external party must also be managed in accordance with the relevant legislation, contracts, obligations, or other restrictions imposed by the relevant jurisdiction. (18) Unofficial data should not be stored on University storage and should be disposed of as part of a normal administrative practice, as defined in the Records Management Policy, as soon as reasonably practicable. (19) Data users are responsible for: (20) The Data and Analytics Division are responsible for: (21) IMTS Service Delivery are responsible for: (22) The Information Compliance Unit are responsible for: (23) Data Guardians are responsible for:Data Classification and Handling Procedure
Section 1 - Purpose
Section 2 - Application and Scope
Section 3 - Data Classifications
Section 4 - Data Labelling Principles
Section 5 - Data Handling Principles
Section 6 - Roles and responsibilities
Top of PageSection 7 - Definitions
Top of Page
Word/Term
Definition (with examples if required)
healthcare identifiers.
Section 8 - Appendices
Appendix A Data Classifications
Appendix B Label Selection Assessment
Appendix C Data Handling Requirements Matrix
View Current
This is the current version of this document. You can provide feedback on this document to the document author - refer to the Status and Details on the document's navigation bar.
(University) Data
All information created, received, stored, or managed by the university in any format and required for the University to perform its functions.
Data Asset Register (DAR)
A structured, logical grouping of key University data assets, mapped to the Enterprise Data Model, detailing their ownership, classification, and other attributes to support effective data governance, management, and compliance.
Data Breach
Data (whether held in digital or hard copy) is subject to unauthorised access, unauthorised disclosure or is lost in circumstances where the loss is likely to result in unauthorised access or unauthorised disclosure. A data breach may occur as the result of malicious action, systems failure, or human error. Examples are outlined in section 4 of the University’s Data Breach Policy.
Data Guardian
Member of senior leadership, usually a divisional director, faculty executive manager, or similar level, responsible for making strategic and tactical decisions about data within their division or faculty.
Data Handling
Broader set of activities related to the management of data, including creation, collection, storage, usage, disposal, and others.
Data User
Authorised staff member, contractor of affiliate, who is allowed to access and use data to fulfil their duties or contractual obligations.
Health Information
Refers to health information defined in the Health Records and Information Privacy Act 2002 as personal information that is information or an opinion about:
• the physical or mental health or a disability (at any time) of an individual; or
• an individual’s express wishes about the future provision of health services to him or her; or
• a health service provided, or to be provided, to an individual; or
other personal information collected to provide, or in providing, a health service; or
other personal information about an individual collected in connection with the donation, or intended donation, of an individual’s body parts, organs or body substances; or
other personal information that is genetic information about an individual arising from a health service provided to the individual in a form that is or could be predictive of the health (at any time) of the individual or of any sibling, relative or descendant of the individual, or
Normal Administrative Practice (NAP)
An instrument that allows destruction of certain types of low-value and short-term records in the normal course of business.
Personal Information
Refers to personal information defined in the Privacy and Personal Information Protection Act 1998 as information or an opinion (including information or an opinion forming part of a database and whether or not recorded in a material form) about an individual whose identity is apparent or can reasonably be ascertained from the information or opinion.