Skip to main content
Search

Processing especially confidential information

Highly confidential information refers to information classes 1R and 2A in the information classification scheme (see the instructions on the page Data classification and handling). The secure processing of such information requires special measures at different stages. First, you must store the information in a way that safeguards its confidentiality so that it cannot fall into unauthorised hands. The second significant stage is sharing information with collaborators. The third stage is processing the information, which you must do using approved tools and methods.

Objectives of information protection

Protect all your files against unauthorised access by external parties. This is your obligation under data protection regulations and, more generally, to protect confidential information from external parties. You can find additional guidance on the pages Data protection at Tampere Universities and Information security and IT policies.

Protect all your files against harmful use by artificial intelligence. AI tools can read all files stored in Teams and OneDrive to which you have access. If an AI tool can access a file containing information that is too confidential, that confidential content may end up in AI-generated responses. As a result, you may unintentionally cause a personal data breach or other harm. If an AI tool can access a file containing outdated or otherwise inaccurate information, that information may also appear in AI-generated responses. As a result, you may unintentionally distribute outdated or incorrect information. For more information, see the pages AI and copyright and Artificial intelligence.

Methods for protecting information

Review all your files and determine the information classification of each one according to the instructions on the page Data classification and handling.

Share and process information using secure working methods. Guidance is provided later on this page.

Follow the instructions on this page both for files that you create and process yourself and for files created and processed in projects and other collaborative initiatives. In research projects, responsibility for all information processing lies not only with each user but also with the principal investigator (PI).

Information classification in Office applications

Set the information classification of all files created with Office applications (Word, PowerPoint, Excel and others) to the correct level using the Sensitivity menu. The default classification is “3Y Confidential”, but this may well be incorrect. Applying an information classification to a file restricts its sharing and AI access to its content. However, information classification does not save the file in encrypted form. Therefore, you must encrypt all 1R files and preferably also 2A files with a separate encryption program. The protection measures associated with information classification work when the file is stored in OneDrive or Teams.

File encryption

Encrypt files with a separate encryption program whenever you want to ensure that only specific people, and no one or nothing else, can access them. Encrypt at least all 1R files and preferably also 2A files using a separate encryption program. Use one of our recommended encryption programs and a long passphrase. Instructions are available on the File encryption page. Files that require editing are best encrypted with VeraCrypt or Cryptomator. Other files are easiest to encrypt with 7-Zip. You can create an encrypted vault or volume with an encryption program in any storage location and copy it anywhere while maintaining the same level of security (USB devices require additional protection; see the instructions on the above-mentioned page).

Exceptions

If you can carry out your research project work in CSC’s SD Desktop or CSC’s ePouta, files stored there are protected sufficiently through other measures and do not require Office information classification or encryption with a separate program. You can find more information about both services on the CSC page Services for sensitive data. You can obtain further information and help with implementation from the IT Helpdesk.

Tampere University is implementing its own secure data processing system, which will be completed during spring 2027. We will announce its completion on the intranet. 

File sharing

After storing highly confidential files securely, you often also need to share them within Tampere Universities and with external partners, please find instructions for that on the page Sharing files with partners.

Secure working methods

In addition to the protection measures described above, processing highly confidential information requires special working methods. The following instructions cover some common processing activities. If you cannot find the information you need, please contact the IT Helpdesk for assistance.

  1. Guidance on collecting research data is available on the page Collecting research data.
  2. Guidance on secure video meetings is available on the page Information security guidelines for setting up remote meetings and interviews using Teams or Zoom.
  3. Guidance on transcription is available on the page Interview data.
  4. Unfortunately, no computer-based tools are currently available for translating 1R-classified material. The only secure option is to order translation as a service according to the instructions on the page Translation and language services. If you send material by email, encrypt the message according to the instructions on the page Email encryption.

 

IT Helpdesk
0294 520 500
it-helpdesk [at] tuni.fi (it-helpdesk[at]tuni[dot]fi)
helpdesk.tuni.fi

Published: 25.8.2026
Updated: 5.10.2026