Data classification policy
**Document control**
| Field | Value | |---|---| | Organization | [COMPANY NAME] | | Owner | [OWNER NAME / ROLE] | | Approver | [APPROVER NAME / ROLE] | | Version | [VERSION] | | Effective date | [YYYY-MM-DD] | | Next review | [YYYY-MM-DD] |
**Mapped controls:** ISO/IEC 27001:2022 A.5.9, A.5.12, A.5.13, A.5.14; SOC 2 CC6.1, C1.1 (educational mapping).
1. Purpose and scope [COMPANY NAME] classifies information so handling safeguards match business, contractual, privacy, and security risk. This policy applies to information in any format and systems that store, process, or transmit it.
2. Classification levels - **Public:** Approved for public release. - **Internal:** Routine business information not intended for public release. - **Confidential:** Customer, employee, commercial, or security information whose unauthorized disclosure could cause material harm. - **Restricted:** Highest-impact information, including [COMPANY NAME]-defined regulated data, credentials, cryptographic keys, and production secrets.
Data owners classify information based on sensitivity, legal duties, customer commitments, and impact. When mixed, the highest applicable classification governs.
3. Handling requirements 1. Confidential and Restricted information is inventoried, assigned an owner, and accessible only by approved business need. 2. Approved encrypted channels are used for external transmission of Confidential or Restricted data. 3. Restricted data is not placed in development, analytics, collaboration, or AI systems unless expressly approved with required safeguards. 4. Labels are applied where supported and remain with exports or transfers. 5. Retention follows the records schedule; disposal uses approved deletion or destruction methods. 6. Third parties receive only the minimum required information under approved contractual and security terms. 7. Suspected misclassification or unauthorized disclosure is reported through [REPORTING CHANNEL].
4. Review and exceptions System and data inventories are reviewed at least annually and after material change. Exceptions require owner and security approval, compensating measures, and an expiry date.
---
**Disclaimer:** Educational template only — not legal advice, an audit opinion, or a guarantee of compliance. Adapt with qualified counsel and your auditor or assessor. ComplianceBase is vendor-neutral and independent.