Protected research data
Security classification of research data
When you request a research data folder, you will need to assign a security classification to your data. This means that you need to select one of four security levels based on the severity of the consequences for the individual, society or university if your research data is disclosed, corrupted or made inaccessible.
- Data disclosure means that unauthorised persons gain access to information they should not have.
- Data corruption means that data is altered or manipulated so that it is no longer accurate or reliable. For example, the results of a research study are changed.
- Making data inaccessible means that it can no longer be accessed by those who need it. For example, research data is lost due to a system failure.
Selecting the proper security level
When selecting security level for your research data, it is important to always consider the specific context. The same dataset can have different security levels depending on the context in which it is used. Geographical coordinates may be completely harmless in a study on bird migration, but sensitive in a study on protected species, where the coordinates may reveal specific locations of endangered species.
The highest security level is for data where a leak could result in very serious harm or catastrophic consequences, such as direct danger to life and safety.
Examples of level 4 data
certain sensitive personal data, depending on the context, for example:
information that could pose a risk of harm to an individual or group, such as information on the whereabouts of a person who is under threat.
information concerning an individual’s religious or political affiliation, where disclosure of such information could have a very significant impact on that individual’s life, health and/or rights.
information about a patient which, if disclosed, could have a very significant impact on an individual’s life, health and/or rights (e.g. detailed medical records from a psychologist).
information relating to personal matters which, if disclosed, could have a very significant impact on an individual’s life, health and/or rights.
- pseudonymisation key/encryption key for sensitive personal data which, if disclosed, could have a very significant impact on an individual’s life, health and/or rights.
particularly sensitive information relating to critical infrastructure or defence, such as:
security-sensitive information concerning critical infrastructure such as water and sewerage systems (e.g. pipe networks) and energy supply (e.g. power grids).
security-sensitive information relating to nuclear power stations.
Large volumes of data (compilations), each of which has been classified solely at level 3 (see below), must be protected at level 4.
In-depth example
A researcher is working with a dataset containing names, addresses and social security numbers of individuals with protected identities. A leak could expose these individuals to serious danger or threat, and cause great anxiety and psychological stress to the individuals concerned. The university risks legal consequences and a serious loss of trust. The researcher therefore classifies the data as Level 4.
A is a researcher researching dual-use products, i.e. those that can be used for both civilian and military purposes. The researcher has data on advanced chemical processes that can be used for medical purposes, but also to create biological weapons, which could have catastrophic consequences. Therefore the researcher classifies the data as Level 4.
Here, a leak may result in significant or serious harm to single individuals, the society or Lund University.
Examples of level 3 data
certain sensitive personal data, depending on the context, for example:
information about a patient which, if disclosed, could have a significant impact on an individual’s life, health and/or rights. information concerning an individual’s religious or political affiliation where disclosure of such information could have a significant impact on that individual’s life, health and/or rights.
information concerning minors or other vulnerable groups where the information can be traced back to specific individuals and which, if disclosed, could have a significant impact on an individual’s life, health and/or rights.
information relating to personal matters which, if disclosed, could have a significant impact on an individual’s life, health and/or rights.- records of academic results where the falsification of data could cause significant or serious harm to Lund University, another public authority, or individual natural or legal persons.
- certain sensitive information relating to infrastructure.
In-depth example
A researcher is developing a new medical treatment based on patient data from clinical trials, where the material contains sensitive health data and results with commercial value. For the individual, this can mean invasion of privacy, stigmatisation and impact on life situation. For society, there is a risk of reduced trust in research and care, which may affect participation in future studies. For the university, it can lead to damaged trust, legal consequences and financial losses. Therefore, the researcher classifies their dataset at level 3.
Here the risk of harm from leaking is moderate. For example, disclosure of data from a survey on eating habits may lead to some concern among participants, especially if the data may be combined with other information that allows for indirect identification of participants. Lund University risks some reputational damage and reduced participation in future studies.
Examples of level 2 data
- personal data the disclosure of which is unlikely to cause significant harm but may nevertheless have a moderate impact on an individual’s life, health and rights.
- certain information regarding infrastructure.
- copyright-protected working materials and research findings that have not yet been published.
In-depth example
A researcher collects air and soil samples in the vicinity of a large industrial area to analyse heavy metal levels and other environmental toxins. Although no personal data is involved, dissemination of the results before they are scientifically validated may lead to erroneous conclusions in the media or public concern in society. It may also affect industry's relations with the environment or give rise to speculation about environmental impacts. The researcher therefore classifies the data as Level 2.
This applies to information where the risk is non-existent or negligible. A researcher publishes datasets in open repositories where the information is of public interest and fully anonymised. The risk of disclosure is minimal, as the data is already intended for public access and use.
Examples of Level 1 data
- a presentation of Lund University as an educational institution or similar.
- published datasets in open repositories, such as research data that is described and made openly available via data repositories.
- data taken from published scientific articles.
- public sector bodies’ public materials.
In-depth example
A researcher publishes datasets from climate research in open repositories, which include fully anonymised and harmless measurement data from weather stations. As the data is already intended for public access, the risk of negative consequences is non-existent. The researcher therefore classifies the data as Level 1.
Processing research data
If your data classifies as level three or four, you currently need to rely on one of the secure systems offered by Lund University; LUSEC Desktop or COSMOS-SENS. However, work is ongoing to develop a simple and uniform solution. Meanwhile, the cost of using LUSEC Desktop and COSMOS-SENS has been taken over by central functions and there will be no charges to researchers.
If sensitive data cannot be processed within the university’s secure environments
In certain situations, it may not be possible to process data in LUSEC Desktop or COSMOS-SENS. If you need help determining how to handle the data securely in such cases, please contact support. Some important basic rules are:
- Data should, as far as possible, be processed on computers managed by LU. If you decide that it is necessary to work with sensitive data using hardware or software – such as a computer – that is not managed by LU, this decision must be approved by the relevant managers and documented.
- Where possible, data should be stored on storage spaces that are synchronised with the university’s servers.
- Data must not be transferred to platforms that are not owned by LU or for which LU has not entered into appropriate agreements; no public cloud services may be used.
- When working outside the LU network, you must use Lund University’s official VPN where possible.
- The user must ensure that unauthorised persons cannot access the data.
- The use of administrator rights on computers intended to handle sensitive data must be strictly restricted.
Questions about how to classify your data?
Contact the Information Security Department at Lund University.
Anonymised or pseudonymised personal data?
Anonymised personal data is data from which all identifying information has been removed and which cannot be traced back to individuals in any way. Pseudonymised personal data means that identifying information has been removed, but it is still possible to trace the information back to an individual, for example through a code key or through other variables.
Want to learn more about personal data in research?
In the Competence Portal you can take the Personal data in Research course. The course is online and takes about 30 minutes to complete.
Information & IT security on business trips
Find out more about the handling of sensitive research data
For more information on the handling of sensitive Research data, please visit Swedish National Data Service at researchdata.se