This guide is part of Stockholm University’s work on information security.

The purpose is to support users in choosing the appropriate workspace for digital information, based on the content and sensitivity of the information. The table below shows the workspaces that are approved for use when Stockholm University is the information owner.

Information classification

Information classification means assessing an organisation’s information in a consistent way based on the potential consequences of insufficient protection (Swedish Civil Defence and Resilience Agency, MCF). The choice of storage location must be based on an information classification. A confidentiality value (K‑value) is assigned to each type of information. This value is determined during the information classification process.

The table below shows the workspaces that are approved for use when Stockholm University is the information owner.

Digital workspaces tableZoom image

This category covers information that does not contain sensitive personal data or classified information. It may also include data that is harmless or publicly available, such as names, job titles, and work‑related contact details.

K1

Documents or materials that are openly shared through the university’s public channels, such as su.se, social media, information screens, and notice boards.

K2 - Internal

Internal working documents and drafts that are shared within the organization, including financial, administrative, and communication‑related materials, as well as internal governing documents, process descriptions, and work routines.

Non-sensitive personal data refers to:

  • Name
  • Address
  • Telephone number
  • Job title
  • Email address
  • Photographs (portrait photos, work‑related photos)
  • Electronic identifiers (e.g., IP address)

Examples of approved storage and sharing platforms for this type of information:

  • Internal workspaces within the university
  • Cloud‑based Microsoft services, e.g. OneDrive and Teams
  • Email via Outlook (part of the university’s Microsoft environment)
  • Box

K3

This refers to sensitive information and special categories of particularly sensitive personal data*. This type of information requires special handling and must not be stored or shared freely. It should only be accessible to individuals who need the information to perform their work tasks.

Sensitive information (K3) includes:

  • Information related to risk assessments, legal processes, or information that is confidential under contractual terms
  • Technical vulnerabilities

Particularly protected personal data (K3) includes:

  • Personal identity numbers
  • Salary information
  • Classified information
  • Criminal offences
  • Social circumstances
  • Information close to the private sphere
  • Evaluative information (e.g. performance reviews, personality tests, personality profiles)
  • Personal data about children (up to 16 years old)

K4

This refers to sensitive information and sensitive personal data*. This type of information requires special handling and must not be stored or shared freely. It should only be accessible to individuals who need the information to perform their work tasks.

Highly sensitive information (K4) includes:

  • Information covered by the Patient Data Act or the Act on Control of
  • Dual‑Use Products
  • Login credentials such as passwords and PIN codes
  • Technical security configurations and vulnerabilities with severe impact

Sensitive personal data includes:

  • Ethnic origin
  • Political opinions
  • Religion
  • Trade union membership
  • Health
  • Sexual life or sexual orientation
  • Genetic data
  • Biometric data

*GDPR

Examples of approved storage and sharing platforms for this type of information:

  • Internal workspaces within the university, X: in access‑controlled folders
  • Sunet Drive (for research data only)
  • Email (with encryption)

Handling when sharing K4 information via email*

Information may be sent by email only if the encryption feature is used.

Link to knowledge article on encryption: Secure electronic transfer of sensitive information – Serviceportalen

Please note that the email tool is not suitable for storing K3–K4 information. If you receive or handle such information, you should save the email in an appropriate location, preferably in an access‑controlled folder on the shared server (e.g. X:\common), and then delete the email from your Outlook mailbox.

Handling when storing information containing K4**

Files containing K4 information must be stored in access‑controlled folders, and access should only be granted to employees who require the information to perform their work tasks.

Survey & Report – Special Handling for Collecting Sensitive Data (K3–K4) in Surveys***

If you are creating a survey and collecting sensitive information, such as research data, there are specific measures that help ensure you provide as little visibility into the survey data as possible.

Read the knowledge article: Settings for collecting sensitive data in surveys – Serviceportalen

Additional knowledge articles for Survey & Report: Survey & Report (survey tool) – Serviceportalen

For questions regarding the handling and storage of research data, contact the Research Data Team at opendata@su.se

More information about research data

The main principle is that Stockholm University’s official documents should be managed in the document and case management system W3D3 or in other operational systems specifically designed for the relevant type of document. Information that is not managed in operational systems must be stored in a secure location designated by the university. The goal is to carry out centralised archival exports from operational systems containing information that should be preserved. Archival exports will also need to be carried out for local systems that handle official documents.

The Information management plan specifies how documents should be handled—whether they should be registered, preserved, or disposed of, and the applicable retention periods.

More information about archiving and registration

Information Suspected to Be Subject to Protective Security

Information that is subject to Protective security act may cause harm to Sweden’s national security if disclosed. If you suspect, or need to determine, whether such information exists within your area of operations, you must contact the Security function at the Property management department.

Verify whether the information is already covered by any form of confidentiality and inform the Security function accordingly. Until it has been determined whether the information is subject to protective security, it must not be shared or distributed and must be handled as securely as possible.

The Security function can be contacted at: sakerhet@su.se

More information about protective security

To avoid the risk of losing your files and documents in the event of a hard drive crash or if your computer is stolen, it is recommended that you save your files on SU’s shared server (X:, H:) or an equivalent shared server in your local IT environment, rather than only storing files locally on your own computer (for example, on the desktop).

You should not use USB drives, external hard drives, or similar devices as your primary workspace without backup. IT Services’ ability to recover files from this type of storage is very limited.

Take the time to review how you save and store your files but remember to look at the table above to see which services you can use depending on the type of information you want to manage.

Kontakt

Last updated: 2026-06-23

Source: IT Services