View Current

Data Classification and Handling Procedure

This is the current version of this document. You can provide feedback on this document to the document author - refer to the Status and Details on the document's navigation bar.

Section 1 - Purpose 

(1) This Procedure:

  1. defines and establishes data classifications to assess the sensitivity of University data; and
  2. outline best practice for handling of University data in accordance with its classification to reduce data related risks.

(2) This Procedure supports and should be read in conjunction with the Data Governance and Management Policy.

Top of Page

Section 2 - Application and Scope

(3) This Procedure applies to:

  1. University staff and affiliates; and
  2. University data.

(4)  This Procedure does not apply to Research data defined in the Research Data Management Policy, with the exception of Section 3 - Data Classifications and Section 4 – Data Labelling Principles.

Top of Page

Section 3 - Data Classifications

(5) Data classification is the activity of categorising data based on potential impact to the University or individuals in the event of a data breach. The impact to the University is measured in line with the Enterprise Risk Management Procedures.

(6) Data must be classified using the classifications detailed in Appendix A: Data Classifications, ranked from the highest to the lowest level of sensitivity:

  1. Official: Sensitive - Legal;
  2. Official: Sensitive - Health;
  3. Official: Sensitive - Personal;
  4. Official: Sensitive;
  5. Official; or
  6. Unofficial.

(7) The default classification for all data, unless specified otherwise, is Official.

(8) Data assets are classified based on the highest classification level of any individual element. Data asset level classifications are recorded in the Data Asset Register.

(9) University classifications are separate from classifications assigned by State and Federal Government entities.

(10) Any data with classifications applied by State and Federal Government entities must be managed in accordance with the relevant security classification guidelines. 

Top of Page

Section 4 - Data Labelling Principles

(11) Data labelling is the activity of tagging or annotating data with labels that indicate the classification of the data.

(12) Institutional Data should be labelled within University storage platforms and business systems where such functionality is available. For detailed labelling instructions, refer to the platform or system labelling documentation.

(13) The process of selecting the appropriate label is outlined in Appendix B: Label Selection Assessment.

(14) A label should be applied where the labelling functionality is supported when:

  1. data is created (e.g., new document, email, or report); and
  2. data is received from an external source (e.g., email from a prospective student; external data set).

(15) As data sensitivity can change over time, relabelling may be required.

Top of Page

Section 5 - Data Handling Principles

(16) Data should be handled in accordance with the requirements of its classification, as outlined in Appendix C: Data Handling Requirements Matrix.

(17) Data received from an external party must also be managed in accordance with the relevant legislation, contracts, obligations, or other restrictions imposed by the relevant jurisdiction.

(18) Unofficial data should not be stored on University storage and should be disposed of as part of a normal administrative practice, as defined in the Records Management Policy, as soon as reasonably practicable.

Top of Page

Section 6 - Roles and responsibilities

(19) Data users are responsible for: 

  1. using data on approved platforms, including AI, in accordance with the classification and access requirements;
  2. completing necessary data training in a timely manner; and
  3. appropriate retention and disposal of data in accordance with the University’s Records Management Policy.

(20) The Data and Analytics Division are responsible for: 

  1. providing training and assisting University staff in the implementation of this procedure; and
  2. collaborating with business system and storage platform owners to implement labelling capabilities.

(21) IMTS Service Delivery are responsible for:

  1. keeping access audit logs for the necessary retention period and protecting these logs from accidental or deliberate modification;
  2. providing data storage and sharing platforms suitable for all data classifications;
  3. ensuring that data within storage platforms and applications is stored within the approved jurisdiction;
  4. providing cybersecurity training;
  5. ensuring encryption of data at rest and in transit where necessary;
  6. providing controls (e.g., VPN, MFA) to securely access enterprise storage and applications where necessary; and
  7. documenting data classifications for University business systems.

(22) The Information Compliance Unit are responsible for:

  1. providing privacy and recordkeeping advice and training; and
  2. advising data users and data guardians on information compliance requirements in accordance with legislative and business requirements.

(23) Data Guardians are responsible for:

  1. approving access for data users;
  2. ensuring their business systems can support data handling requirements based on classification; and
  3. appropriate retention and disposal of data within their business systems and organisational unit storage.
Top of Page

Section 7 - Definitions

Word/Term Definition (with examples if required)
(University) Data
All information created, received, stored, or managed by the university in any format and required for the University to perform its functions.
Data Asset Register (DAR)
A structured, logical grouping of key University data assets, mapped to the Enterprise Data Model, detailing their ownership, classification, and other attributes to support effective data governance, management, and compliance.
Data Breach
Data (whether held in digital or hard copy) is subject to unauthorised access, unauthorised disclosure or is lost in circumstances where the loss is likely to result in unauthorised access or unauthorised disclosure. A data breach may occur as the result of malicious action, systems failure, or human error. Examples are outlined in section 4 of the University’s Data Breach Policy.
Data Guardian
Member of senior leadership, usually a divisional director, faculty executive manager, or similar level, responsible for making strategic and tactical decisions about data within their division or faculty.
Data Handling
Broader set of activities related to the management of data, including creation, collection, storage, usage, disposal, and others.
Data User
Authorised staff member, contractor of affiliate, who is allowed to access and use data to fulfil their duties or contractual obligations.
Health Information
Refers to health information defined in the Health Records and Information Privacy Act 2002 as personal information that is information or an opinion about:
• the physical or mental health or a disability (at any time) of an individual; or
• an individual’s express wishes about the future provision of health services to him or her; or
• a health service provided, or to be provided, to an individual; or
other personal information collected to provide, or in providing, a health service; or
other personal information about an individual collected in connection with the donation, or intended donation, of an individual’s body parts, organs or body substances; or
other personal information that is genetic information about an individual arising from a health service provided to the individual in a form that is or could be predictive of the health (at any time) of the individual or of any sibling, relative or descendant of the individual, or
healthcare identifiers.
Normal Administrative Practice (NAP)
An instrument that allows destruction of certain types of low-value and short-term records in the normal course of business.
Personal Information
Refers to personal information defined in the Privacy and Personal Information Protection Act 1998 as information or an opinion (including information or an opinion forming part of a database and whether or not recorded in a material form) about an individual whose identity is apparent or can reasonably be ascertained from the information or opinion.
Top of Page

Section 8 - Appendices

Appendix A Data Classifications

Appendix B Label Selection Assessment

Appendix C Data Handling Requirements Matrix