Am I a Proprietor?

This short questionnaire helps UC community members decide whether they are acting as an Institutional Information Proprietor under UC’s IS‑3 policy, and what to do next.

What “Proprietor” means (plain language)

Under UC IS‑3, a Proprietor is the person (or designated role/group) responsible for specific UC Institutional Information or IT Resources and their supporting processes. They set classification (Protection & Availability Levels), define access and use rules, communicate requirements, and approve releases/transfers of the information. (Example: the Registrar is the proprietor of student data.)

Many roles can become proprietors when they create or collect UC Institutional Information or acquire/use a system that stores/handles it (common in academic settings for faculty, researchers, and PIs).

Institutional Information is defined as "A term that broadly describes all data and information created, received and/or collected by UC."
https://security.ucop.edu/files/documents/policies/it-policy-glossary.pdf (See page 21)

What this tool is (and isn’t)

This tool offers policy‑aligned guidance; it doesn’t assign roles, provide legal advice, or replace local procedures. Always confirm outcomes with your Unit Information Security Lead (UISL) or CISO.

Sources

Quick questionnaire

Answer “Yes / No / Not sure”. Your result updates instantly.

1) Do you decide who can access a dataset or system (approve/grant/remove access)?
Proprietors establish and document access rules for their information.
2) Do you create or collect UC Institutional Information (e.g., research, student/employee, financial, operational data)?
Creating/collecting Institutional Information can make you a Proprietor; in academics this includes faculty, researchers, and PIs.
3) Have you acquired/configured a system or application that stores/processes UC data for your unit/project?
If a Unit procures/installs such a system, it creates an IT Resource and must assign a Proprietor.
4) Are you a PI/faculty/researcher who created a dataset or oversees a system for a UC project?
In academic settings, PIs/faculty/researchers often act as Proprietors for their data/systems.
5) Do you review or approve transfers of UC Institutional Information to external parties/suppliers?
Proprietors approve information transfers and communicate protection levels and requirements.
6) Are you responsible for determining classification — Protection Levels (P1–P4) and/or Availability Levels (A1–A4)?
Proprietors determine PL/AL with support from (Unit Information Security Leads (UISLs)/Subject Matter Experts (SMEs); use the UC classification resources.
7) Do you set/approve rules for use, access, alternate use, or reuse of UC data in your area?
Proprietors set rules for use, access, and removal of access in their area of responsibility.
8) Do you document or approve retention, sanitization, or disposal plans for the information?
Proprietors observe records retention and approve sanitization plans.
9) Are you a Unit Head (e.g., Dean, Chair, Director, AVC) without directly overseeing a dataset/system?
Unit Heads must ensure effective cyber‑risk management and that a Proprietor is assigned when needed.
10) Are you only an end user (you use data/systems) with no decision‑making rights on access, classification, or transfer?
End users who don’t set rules/approvals are generally not proprietors. Confirm your responsibilities with your UISL.