Home / Data Classification Policy
Legal & Compliance

Data
Classification.

How Cyber Compliance Pro classifies information by sensitivity and risk, and the handling controls that apply at each level — so the right data gets the right protection.

Quick answer: Cyber Compliance Pro's Data Classification Policy sets out how information is classified by sensitivity, and the handling requirements that apply at each classification level.
Version 1.0
Effective: 30 July 2026
Classification: Internal
Document Control
Owner Information Security Officer
Approved By Managing Director
Review Annual or upon significant change
Applies To Employees, contractors and third parties
Classification Internal
Version 1.0 — Effective 30 July 2026

1 Purpose of This Data Classification Policy

This data classification policy defines a consistent approach for classifying and handling information based on sensitivity, risk and regulatory requirements. As a result, classification enables the organisation to apply proportionate protection and access controls — strong enough to safeguard sensitive information, without imposing unnecessary friction on lower-risk work.

2 Scope

This data classification policy applies to all data created, received, stored, processed or transmitted by employees, contractors and third parties across the organisation — regardless of format (electronic or physical) or the system or device on which it resides.

3 Data Classification Policy Levels

This data classification policy sets four classification levels. Specifically, every information asset must be assigned to one of these tiers.

Public
Level 1

Information approved for public release. Minimal risk if disclosed — e.g. marketing content, published policies, general company information.

Internal
Level 2

Non-sensitive information limited to authorised personnel within the organisation — e.g. internal procedures, org charts, non-sensitive project material.

Confidential
Level 3

Sensitive business or personal information requiring strong protection — e.g. customer records, contracts, commercial pricing, staff records.

Restricted
Level 4

Highly sensitive information that could cause significant harm if disclosed — e.g. personal data, financial data, system credentials, encryption keys.

4 Handling Guidelines

Overall, the controls below apply as minimums for each level. Higher levels inherit all controls of the levels below them.

Level Access Encryption Access Logging Sharing
Public Unrestricted Not required Not required May be shared without restriction
Internal Authorised staff, business need Recommended in transit Not required Internal only; external sharing on approval
Confidential Named individuals, least privilege Required in transit and at rest Recommended NDA or contract required for external sharing
Restricted Strict role-based, MFA-protected Required in transit and at rest Required — all access events logged External sharing prohibited without executive approval

5 Labelling Requirements

Specifically, all documents and digital files must be labelled with the appropriate classification level using headers, footers or metadata tags. Labels should be clearly visible on the first page of documents and included in email subject lines or footers where practical.

When in doubt, classify up. If you’re unsure which level applies, treat the information as one level higher and consult the Data Owner or Information Security Officer.

6 Roles & Responsibilities

Data Owners

Classify and periodically review information assets under their responsibility, and approve access requests.

IT & Security Teams

Implement and enforce the access, encryption, logging and protection mechanisms required by each classification level.

All Users

Handle and label information in accordance with this policy and report any misclassification or suspected mishandling.

7 Review & Reclassification

Under this data classification policy, data must be reviewed periodically and reclassified as business context or risk changes. Data Owners review the classification of their assets at least annually and whenever a material change occurs — new regulation, changed system, changed sharing arrangement or an incident that alters the risk profile.

8 Data Classification Policy Compliance

Ultimately, non-compliance with this policy may lead to disciplinary action and increased risk exposure for the organisation and its customers. Suspected non-compliance should be reported to the Information Security Officer.

Report an issue. If you believe data has been misclassified, mishandled or exposed, contact the Information Security Officer immediately at security@cybercompliancepro.com.

9 Contact Details

For questions about this policy or classification decisions, please contact:

Cyber Compliance Pro (ABN 86 711 059 645)