This page summarizes. The official policies linked here are the authority. Where this page and a policy differ, the policy wins.
Data protection levels
The University of California classifies information by the harm that could come from its disclosure, from P1 (minimal) to P4 (high). The level decides where data may be stored and processed, and what controls are required. Read the UC classification standard for the definitions and examples.
In practice:
- P1 and P2 (public and internal) data can generally use the campus services on this site, as each service page indicates.
- P3 and P4 data, and data covered by a contract, data use agreement or regulation, need a review before you choose where to keep it. Often they also need a data security plan.
- Research Computing does not support US classified data.
If you are not sure of your data's level, ask before you store it. That is far easier than moving it later.
Data security plans
A data security plan (DSP) documents the roles, controls and processes that protect a project's data. Agreements and regulations often require one. Research Computing works with researchers and the campus Information Security Office to prepare DSPs. See UCR data security plans for the process and template.
Regulated and contract-controlled data
Some grants and agreements require specific controls. Examples are Department of Defense work (NIST SP 800-171, CMMC Level 2), controlled-access NIH data such as dbGaP, and health data. For NIST SP 800-171 and CMMC Level 2 work, the campus offers a secure research enclave, after review, an approved DSP and training. Health data (HIPAA) follows a different path; see KB006. Contact us before you sign an agreement or submit a proposal that carries such requirements.
AI tools and research data
The campus guidance on approved AI tools, and the terms that apply to each, is maintained by ITS at AI at UCR. Check it, and your data's protection level, before using any AI tool with research data.
Policies that apply
- UC IS-3, Electronic Information Security: the UC information security policy.
- UC classification standard: P1 to P4.
- UC Research Data Policy: ownership and stewardship of research data.
- Records retention: how long research records must be kept.
- UCR campus policies and UCR research policies.
- Each service's own acceptable-use policies, linked from its page.