Policy

A data classification standard is necessary to provide a framework for securing data from risks including, but not limited to, unauthorized destruction, modification, disclosure, access, use, and removal.

Purpose

This standard outlines how Renton Technical College classifies its data to align with WA State law, the greater WA State Agencies’ standards (WaTech & OCIO), and IT Cybersecurity standards.

Scope

This policy applies to all RTC data and to all user-developed data sets and systems that may access this data, regardless of the environment where the data reside (including cloud systems, servers, personal computers, mobile devices, etc.). The standard applies regardless of the media on which data reside (including electronic, microfiche, printouts, CD, etc.) or the form they may take (text, graphics, video, voice, etc.).

Nothing in this policy is intended to override FERPA regulations nor the Washington State Public Records Law (42.56). In a case where FERPA is more restrictive than this Standard, FERPA must still be followed.

Standard

Data is classified into four categories based on the sensitivity of the data. These categories are in line with the Washington State data classification categories as defined in WaTech standard SEC- 08-01-S (Previously OCIO 141.10 (4.1)).

Category 1 – Public Information

Public information is information that can be or currently is released to the public. It does not need protection from unauthorized disclosure but does need integrity and availability protection controls.

Examples:

  • Employee Directory data
  • FERPA compliant Directory data
  • Board Meeting minutes

Category 2 – Sensitive Information

Sensitive information may not be specifically protected from disclosure by law and is for official use only. Sensitive information is generally not released to the public unless specifically requested.

FERPA “directory information” such as Student Name, Dates of Attendance, Degrees received, College Code, etc. would be considered Category 2 data; additionally, course and program information that is not directly associated with a student such as course titles, intent, program codes would be Category 2 data.

Examples:

  • Student information that is not considered FERPA “directory information” such as Student Name with college name or code, dates of attendance, degrees.
  • Course and Program information not associated with a particular student such as Department and Course numbers, titles, intent codes, etc.

Category 3 – Confidential Information – DO NOT DISCLOSE

Confidential information is information that is specifically protected from disclosure by law. It may include but is not limited to:

  • Personal information about individuals, regardless of how that information is (Personal Information is defined in RCW 42.56.590 and RCW 19.255.010)
  • Information concerning employee personnel (RCW 42.56.250)
  • Information regarding IT infrastructure and security of computer and telecommunications systems. (RCW 42.56.420)

Confidential information must not be disclosed without prior written approval and a data sharing agreement in place where applicable.

Examples:

  • Student ID numbers, grades, scores, demographics,
  • Personnel data

Category 4 – Confidential Information Requiring Special Handling – DO NOT DISCLOSE

Confidential information requiring special handling is information that is specifically protected from disclosure by law and for which:

  • Especially strict handling requirements are dictated, such as by statutes, regulations, or
  • Serious consequences could arise from unauthorized disclosure, such as threats to health and safety, or legal sanctions.

Category 4 data must not be disclosed without prior written approval and a data sharing agreement in place where applicable.

Examples:

  • SSN
  • Name plus last 4 of SSN
  • Name plus full date of birth
  • Credit Card, Drivers License, or Tax ID information
  • Health Information
  • E-Signatures

Combined or Aggregated Data

RTC employees must consider how aggregating or combining data both before and after sharing may increase the sensitivity and therefore Category of the data. Prior written exemption must be obtained if aggregate data rises to the level of Category 3 or 4.

Compliance

CTS will periodically verify compliance to this standard through various methods. Methodologies may include but are not limited to monitoring, reporting, logging, internal and external audits.

CTS may also use tools and automated systems to identify and/or protect Category 3 & 4 data from being shared without written approval. Examples of this technology include but are not limited to: sensitivity labeling, encryption of data on laptops or servers, automatic identification of category 3 & 4 data in order to apply encryption to outgoing email, limitations on OneDrive downloading or sharing, and Darktrace monitoring for data exfiltration.

A.  Compliance Exceptions:

Any exception to the standard must be approved in writing by the Executive Director of College Technology Services. Any exceptions to this standard when shared with external vendors/companies will be accompanied by a Data Sharing Agreement signed by the Executive Director of College Technology Services.

B.  Non-Compliance:

An employee found to have violated this standard may be subject to disciplinary action, which may include termination of employment in accordance with any collective bargaining agreement (if applicable).

HISTORY

  • Adopted: 6/2025