Data Classification & Handling
Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal
1. Purpose
This policy protects information in proportion to its sensitivity by assigning classification levels and setting clear handling rules for {{COMPANY_LEGAL_NAME}}. It focuses on {{DATA_TYPES}} processed in {{CRITICAL_SYSTEMS}} and stored or retained across {{GEO_SCOPE}}.
2. Scope
This policy applies to all data {{COMPANY_LEGAL_NAME}} creates, receives, processes, or stores, regardless of medium or location. It covers the {{LOCATION}} workforce and any {{DEVICE_TYPES}} used to reach {{CRITICAL_SYSTEMS}}.
3. Policy statements
3.1 Classification scheme
We use four levels: Public, Internal, Confidential, and Restricted. Internal is the default, and a short quick-reference guide gives examples drawn from {{INDUSTRY}} data and {{DATA_TYPES}}. Classification drives access control, encryption, monitoring, and retention across {{CRITICAL_SYSTEMS}} and backups in {{GEO_SCOPE}}.
3.2 Labelling and identification
Documents and data stores are labelled at creation using headers, metadata tags, or clear folder names. Automated tagging is used where supported; otherwise Confidential and Restricted data must be labelled manually. Labels are kept consistent across repositories and preserved through export and replication.
3.3 Access and storage
Access follows least privilege and is aligned to classification level. Confidential and Restricted data is encrypted at rest in {{CRITICAL_SYSTEMS}} and in backups held in {{GEO_SCOPE}}, administrative access to Restricted data is logged, access rights are reviewed on a defined cadence, and encryption keys are protected.
3.4 Transmission and sharing
Confidential and Restricted data moves only over encrypted channels such as TLS or SFTP. Public file-sharing links without access control are prohibited for anything above Internal, and external sharing of Restricted data requires management approval plus an NDA or contract. Insecure protocols are disabled and multi-factor authentication is enforced for privileged transfers.
3.5 Retention and disposal
Retention periods from the data retention policy are applied to each classification, taking {{GEO_SCOPE}} obligations into account. Media holding Confidential or Restricted data is destroyed by secure wipe or certified shredding, destruction is logged, and certificates of destruction are filed where used.
3.6 Compliance measurement
A quarterly sample confirms correct labels, encryption, and access rights against a target of at least 95% accuracy. The sample size scales up for a workforce above {{EMPLOYEE_COUNT}}.
4. Roles and responsibilities
| Role | Responsibility |
|---|---|
| Executive sponsor | Accountable for the program; approves this policy |
| {{POLICY_OWNER_ROLE}} | Maintains this policy and its procedures |
| Managers | Enforce the policy within their teams |
| All personnel | Comply; report issues promptly |
5. Compliance and exceptions
Non-compliance may result in disciplinary action, and mislabelled or mishandled data triggers incident response and mandatory refresher training. Exceptions must document the risk and compensating controls, note any residual risk to {{DATA_TYPES}} and how it is mitigated in {{CRITICAL_SYSTEMS}} or through {{DEVICE_TYPES}} controls, and be approved by {{APPROVER_TITLE}}. They are time-limited and reviewed.
6. Review
This policy is reviewed at least annually and when significant change occurs. Examples and tooling are updated as new {{INDUSTRY}} data types or regulations emerge, including changes affecting {{GEO_SCOPE}}.
Aligned to ISO/IEC 27001:2022. {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by the relevant standards body; full standard text is copyrighted and is not reproduced here.