Data
Classification.
How Cyber Compliance Pro classifies information by sensitivity and risk, and the handling controls that apply at each level — so the right data gets the right protection.
1 Purpose of This Data Classification Policy
This data classification policy defines a consistent approach for classifying and handling information based on sensitivity, risk and regulatory requirements. As a result, classification enables the organisation to apply proportionate protection and access controls — strong enough to safeguard sensitive information, without imposing unnecessary friction on lower-risk work.
2 Scope
This data classification policy applies to all data created, received, stored, processed or transmitted by employees, contractors and third parties across the organisation — regardless of format (electronic or physical) or the system or device on which it resides.
3 Data Classification Policy Levels
This data classification policy sets four classification levels. Specifically, every information asset must be assigned to one of these tiers.
Information approved for public release. Minimal risk if disclosed — e.g. marketing content, published policies, general company information.
Non-sensitive information limited to authorised personnel within the organisation — e.g. internal procedures, org charts, non-sensitive project material.
Sensitive business or personal information requiring strong protection — e.g. customer records, contracts, commercial pricing, staff records.
Highly sensitive information that could cause significant harm if disclosed — e.g. personal data, financial data, system credentials, encryption keys.
4 Handling Guidelines
Overall, the controls below apply as minimums for each level. Higher levels inherit all controls of the levels below them.
| Level | Access | Encryption | Access Logging | Sharing |
|---|---|---|---|---|
| Public | Unrestricted | Not required | Not required | May be shared without restriction |
| Internal | Authorised staff, business need | Recommended in transit | Not required | Internal only; external sharing on approval |
| Confidential | Named individuals, least privilege | Required in transit and at rest | Recommended | NDA or contract required for external sharing |
| Restricted | Strict role-based, MFA-protected | Required in transit and at rest | Required — all access events logged | External sharing prohibited without executive approval |
5 Labelling Requirements
Specifically, all documents and digital files must be labelled with the appropriate classification level using headers, footers or metadata tags. Labels should be clearly visible on the first page of documents and included in email subject lines or footers where practical.
When in doubt, classify up. If you’re unsure which level applies, treat the information as one level higher and consult the Data Owner or Information Security Officer.
6 Roles & Responsibilities
Classify and periodically review information assets under their responsibility, and approve access requests.
Implement and enforce the access, encryption, logging and protection mechanisms required by each classification level.
Handle and label information in accordance with this policy and report any misclassification or suspected mishandling.
7 Review & Reclassification
Under this data classification policy, data must be reviewed periodically and reclassified as business context or risk changes. Data Owners review the classification of their assets at least annually and whenever a material change occurs — new regulation, changed system, changed sharing arrangement or an incident that alters the risk profile.
8 Data Classification Policy Compliance
Ultimately, non-compliance with this policy may lead to disciplinary action and increased risk exposure for the organisation and its customers. Suspected non-compliance should be reported to the Information Security Officer.
Report an issue. If you believe data has been misclassified, mishandled or exposed, contact the Information Security Officer immediately at security@cybercompliancepro.com.
9 Contact Details
For questions about this policy or classification decisions, please contact: