New York Labor Law §203-d / en Data Classification and Protection Policy /policy/data-classification-and-protection-policy <span class="field field--name-title field--type-string field--label-hidden">Data Classification and Protection Policy</span> <span class="field field--name-uid field--type-entity-reference field--label-hidden"><span>hoverholt</span></span> <span class="field field--name-created field--type-created field--label-hidden"><time datetime="2024-09-13T15:52:39-04:00" title="Friday, September 13, 2024 - 15:52" class="datetime">Fri, 09/13/2024 - 15:52</time> </span> <div class="field field--name-field-policy-image-media field--type-entity-reference field--label-hidden field__item"><div class="media media--type-image media--view-mode-policy-image"> <div class="field field--name-field-media-image field--type-image field--label-visually_hidden"> <div class="field__label visually-hidden">Image</div> <div class="field__item"> <img loading="lazy" src="/sites/default/files/styles/policy_page_logo/public/images/geneseo-and-suny-logo_0.png?itok=JceXUryZ" width="300" height="100" alt class="img-fluid image-style-policy-page-logo"> </div> </div> </div> </div> <div class="field field--name-field-policy-number field--type-string field--label-hidden field__item">1-005</div> <div class="field field--name-field-policy-approved-by field--type-string field--label-hidden field__item">Cabinet</div> <div class="field field--name-field-policy-effective-date field--type-datetime field--label-hidden field__item">01-05-2009</div> <div class="field field--name-field-policy-date-last-revised field--type-datetime field--label-hidden field__item">10-21-2025</div> <div> <div>Category</div> <div>General College</div> </div> <div class="field field--name-field-policy-responsible-office field--type-string field--label-hidden field__item">Chief Information Officer</div> <div class="field field--name-field-responsible-office-number field--type-telephone field--label-hidden field__item"><a href="tel:585-245-5577">585-245-5577</a></div> <div class="clearfix text-formatted field field--name-field-policy-scope field--type-text-long field--label-hidden field__item"><p>This policy applies to all SUNY Geneseo employees, contractors, and systems that create, access, store, or transmit institutional data.</p> </div> <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item"><p>This policy establishes a framework for classifying and protecting institutional data at SUNY Geneseo. It supports compliance with applicable laws and regulations, including the New York SHIELD Act, FERPA, HIPAA, and NY Labor Law §203-d, and promotes responsible data stewardship across the college.</p> </div> <div class="field field--name-field-policy-definitions field--type-entity-reference field--label-hidden field__items"> <div class="field__item"><a href="/taxonomy/term/3455" hreflang="en">Data Classification</a></div> <div class="field__item"><a href="/taxonomy/term/3456" hreflang="en">Data Steward</a></div> <div class="field__item"><a href="/taxonomy/term/3457" hreflang="en">New York SHIELD Act</a></div> <div class="field__item"><a href="/taxonomy/term/3458" hreflang="en">Private Information (per NY SHIELD Act)</a></div> <div class="field__item"><a href="/taxonomy/term/3459" hreflang="en">New York Labor Law §203-d</a></div> </div> <div class="clearfix text-formatted field field--name-field-policy field--type-text-long field--label-hidden field__item"><p><meta charset="utf-8"></p> <h3>Data Classification Levels</h3> <table style="border-collapse:collapse;border-style:none;" border="1" cellspacing="0" cellpadding="0"> <tbody> <tr> <td style="border-color:windowtext;border-width:1.0pt;padding:0in 5.4pt;vertical-align:top;width:121.25pt;" width="162"> <p style="line-height:normal;margin-bottom:0in;"><strong>Classification Level</strong></p> </td> <td style="border-bottom-style:solid;border-color:windowtext;border-left-style:none;border-right-style:solid;border-top-style:solid;border-width:1.0pt;padding:0in 5.4pt;vertical-align:top;width:166.45pt;" width="222"> <p style="line-height:normal;margin-bottom:0in;"><strong>Definition</strong></p> </td> <td style="border-bottom-style:solid;border-color:windowtext;border-left-style:none;border-right-style:solid;border-top-style:solid;border-width:1.0pt;padding:0in 5.4pt;vertical-align:top;width:143.8pt;" width="192"> <p style="line-height:normal;margin-bottom:0in;"><strong>Examples</strong></p> </td> </tr> <tr> <td style="border-bottom-style:solid;border-color:windowtext;border-left-style:solid;border-right-style:solid;border-top-style:none;border-width:1.0pt;padding:0in 5.4pt;vertical-align:top;width:121.25pt;" width="162"> <p style="line-height:normal;margin-bottom:0in;">Confidential</p> </td> <td style="border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0in 5.4pt;vertical-align:top;width:166.45pt;" width="222"> <p style="line-height:normal;margin-bottom:0in;">Regulated data requiring strict controls. Unauthorized disclosure could result in legal or financial penalties.</p> </td> <td style="border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0in 5.4pt;vertical-align:top;width:143.8pt;" width="192"> <p style="line-height:normal;margin-bottom:0in;">Private information such as SSNs, bank account numbers, health records, driver’s license numbers, disciplinary records</p> </td> </tr> <tr> <td style="border-bottom-style:solid;border-color:windowtext;border-left-style:solid;border-right-style:solid;border-top-style:none;border-width:1.0pt;padding:0in 5.4pt;vertical-align:top;width:121.25pt;" width="162"> <p style="line-height:normal;margin-bottom:0in;">Sensitive</p> </td> <td style="border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0in 5.4pt;vertical-align:top;width:166.45pt;" width="222"> <p style="line-height:normal;margin-bottom:0in;">Internal data with reputational or operational risk.&nbsp;</p> </td> <td style="border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0in 5.4pt;vertical-align:top;width:143.8pt;" width="192"> <p style="line-height:normal;margin-bottom:0in;">Grades, G-numbers, performance reviews</p> </td> </tr> <tr> <td style="border-bottom-style:solid;border-color:windowtext;border-left-style:solid;border-right-style:solid;border-top-style:none;border-width:1.0pt;padding:0in 5.4pt;vertical-align:top;width:121.25pt;" width="162"> <p style="line-height:normal;margin-bottom:0in;">General</p> </td> <td style="border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0in 5.4pt;vertical-align:top;width:166.45pt;" width="222"> <p style="line-height:normal;margin-bottom:0in;">Information not intended for public release but not subject to regulatory or contractual confidentiality. May be shared with Geneseo accounts and select external collaborators with a legitimate need.</p> </td> <td style="border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0in 5.4pt;vertical-align:top;width:143.8pt;" width="192"> <p style="line-height:normal;margin-bottom:0in;">Syllabi, meeting agendas, internal procedures</p> </td> </tr> <tr> <td style="border-bottom-style:solid;border-color:windowtext;border-left-style:solid;border-right-style:solid;border-top-style:none;border-width:1.0pt;padding:0in 5.4pt;vertical-align:top;width:121.25pt;" width="162"> <p style="line-height:normal;margin-bottom:0in;">Public</p> </td> <td style="border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0in 5.4pt;vertical-align:top;width:166.45pt;" width="222"> <p style="line-height:normal;margin-bottom:0in;">Information intended for external audiences and unrestricted sharing.</p> </td> <td style="border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0in 5.4pt;vertical-align:top;width:143.8pt;" width="192"> <p style="line-height:normal;margin-bottom:0in;">Press releases, recruitment materials, published research</p> </td> </tr> </tbody> </table> <h3>Safeguards</h3> <p>Safeguards for institutional data are applied based on its classification level and include administrative, technical, and physical controls. These controls are designed to ensure appropriate protection of data across its lifecycle: from creation and access to storage and disposal. Specific requirements for each classification level (Confidential, Sensitive, General, and Public) are detailed in the&nbsp;<a href="https://go.geneseo.edu/DataClassStandard">Data Protection Standard</a>.&nbsp;</p> <h3>Incident Response</h3> <p>Any suspected data breach must be <a href="https://go.geneseo.edu/securityincidentform">reported immediately</a> to CIT. Breaches involving private information as defined by the SHIELD Act will trigger notification procedures in accordance with state law and the College’s cybersecurity incident response plan.</p> <h3>Roles and Responsibilities</h3> <ul style="list-style-type:disc;"> <li><strong>Data Stewards:</strong> Ensure proper classification, access controls, and compliance within their data domain. In most cases the data steward of a department is the director or department head.</li> <li><strong>CIT:</strong> Implement technical safeguards, monitor systems, and respond to incidents.</li> <li><strong>Compliance Office</strong>: Ensure alignment with legal and regulatory requirements.</li> <li><strong>End Users:</strong> Apply appropriate sensitivity labels and follow data handling procedures.</li> </ul> <h3>Compliance</h3> <p>This policy supports compliance with the New York SHIELD Act, FERPA, HIPAA, NY Labor Law §203-d, and other applicable regulations.&nbsp;</p> <p>Inappropriate disclosure of information pertaining to students, faculty, staff and other college constituents may violate applicable law and regulations and is considered a violation of ethics and a breach of trust placed in employees by the College.&nbsp; Upon finding of a violation of this policy by an employee in a collective bargaining unit, the College may initiate disciplinary action pursuant to the applicable collective bargaining agreement, up to and including termination of employment.</p> <p style="margin-bottom:6.0pt;margin-left:0in;margin-right:0in;margin-top:0in;">For employees not covered by a collective bargaining agreement, sanctions may include actions up to and including termination of employment.</p> <p style="margin-bottom:6.0pt;margin-left:0in;margin-right:0in;margin-top:0in;">Student employees who have violated these provisions may be referred to the student disciplinary process.</p> <p style="margin-bottom:6.0pt;margin-left:0in;margin-right:0in;margin-top:0in;">Volunteers who have violated these provisions may have their voluntary appointments terminated.</p> <p>Employees who deal with confidential material on a regular basis will be required to sign a <a href="https://go.geneseo.edu/confidentialityagreement">confidentiality agreement</a>.</p> </div> <div class="clearfix text-formatted field field--name-field-frequency-review-update field--type-text-long field--label-hidden field__item"><p>Every 3 years.&nbsp;</p> </div> <div class="field field--name-field-policy-signed-by field--type-string field--label-hidden field__item">Paul Jackson</div> <div class="field field--name-field-name-title field--type-string field--label-hidden field__item">Chief Information Officer &amp; Director of CIT</div> <div class="field field--name-field-policy-date-signed field--type-datetime field--label-hidden field__item">10-21-2025</div> Fri, 13 Sep 2024 19:52:39 +0000 hoverholt 150652 at