Legal and Compliance Data Domain

Legal and Compliance data includes information related to an institution's legal and regulatory obligations, as well as records of compliance activities to ensure adherence to relevant laws and regulations, mitigate legal risks, and support strategic decision-making.

The Legal and Compliance Data Domain is divided into Subdomains providing information on a more granular level.

Data Trustee: TBD

Data classification is a practice that helps us understand the value of our data and identify more sensitive data.  The more sensitive the data, the more cautious you must be about accessing and sharing it with others and the more protections it needs to safeguard it from mishandling or misuse.

Vanderbilt University has a Data Classification Policy that has categorized VU data into the 4 levels listed below. Data classification for transactional row level data are assigned at the Subdomain level.  However the same data may be classified differently dependent on the format of the data.  
*See the next tab for some domain specific data classification guidelines and examples.

Level 1 - Public Level 2 - Institutional OnlyLevel 3 - RestrictedLevel 4 - Critical
Intended for public release or distribution.Private to VU and should not be available to non-VU individuals without permission.Confidential by law or contract, or should not be shared with unauthorized persons.Confidential by law or contract and requires bespoke security requirements.

Visit the VUIT Cybersecurity website for more information and guidance on Data Classification. 

Subdomains

  • Conflict of Interest (COI)

    Conflict of Interest data encompasses information related to the identification, management, and mitigation of situations where an individual's personal interests or relationships may compromise their ability to act impartially or in the best interest of an organization. This may include data on disclosures, reviews, approvals, and monitoring activities.

    Data Steward: TBD

    Regulatory Compliance Requirements: N/A

    Data Classification:  TBD

    Major Data Systems & Applications

    System NameWarehouseData Classification
    TBD  
  • Audit

    Audit data is a crucial component of governance, risk management, and compliance (GRC) frameworks, providing valuable insights into organizational practices and enhancing overall security and accountability. It serves multiple purposes, including compliance monitoring and security analysis.

    Data Steward:  TBD

    Regulatory Compliance Requirements:  N/A

    Data Classification:  TBD

    Major Data Systems & Applications

    System NameWarehouseData Classification
       
  • ERM (Risk Management)

    ERM (Enterprise Risk Management) risk management data refers to the information and metrics collected and analyzed to identify, assess, monitor, and mitigate risks at Vanderbilt University, enabling proactive management, and ensuring that risk-taking aligns with the organization’s strategic objectives.

    Data Steward:  TBD

    Regulatory Compliance Requirements:  N/A

    Data Classification:  TBD

    Major Data Systems & Applications

    System NameWarehouseData Classification
    TBD  
  • Litigation

    Litigation data refers to the information and records associated with legal disputes and proceedings.

    Data Steward:  TBD

    Regulatory Compliance Requirements:  N/A

    Data Classification:  TBD

    Major Data Systems & Applications

    System NameWarehouseData Classification
    TBD  

Minimum Training & Requirements to Request Access to Legal & Compliance Data

  • Departmental Approval Required.

test

Not sure how to start?

Reach out if you don’t know where to begin. The Office of Data and Strategic Analytics Partnering Team collaborate with leaders and serve as trusted advisers.  Partners provide subject matter expertise and are available to assist with your data needs.

Request Help