Data Handling & Classification

MODULE 04 / INTERMEDIATE11 min / Includes knowledge checks and quiz

Data Handling & Classification

Not all data is created equal. Learn to classify data, handle it appropriately, avoid shadow IT risks, and prevent the most common data exposure mistakes.

Organized filing cabinets with color-coded labels in a bright office storage room, a person neatly organizing documents into labeled folders

What You Will Learn

Not all data is created equal. Patient records, client files, and financial data need more protection than a public newsletter. This module teaches you how to classify data, handle it appropriately, and avoid the most common data exposure mistakes.

  • Data classification: public, internal, confidential, and restricted
  • Handling rules: how to store, share, and dispose of each data type
  • Shadow IT: the hidden risk of unapproved tools and apps
  • Email mistakes: how to prevent the most common data exposure errors
  • Industry examples: HIPAA, attorney-client privilege, grant data, and student records

Why Data Classification Matters

Data classification is the foundation of data privacy. When you know what type of data you are handling, you know how to protect it. Most data breaches in small organizations are not the result of sophisticated hacking. They are the result of someone sending the wrong file to the wrong person, storing sensitive data in the wrong place, or using an unapproved tool.

Quick Check

You need to send a patient intake form to a colleague. How should you send it?

A) Attach it to a regular email and send it
B) Use your organization’s approved secure file sharing method
C) Upload it to your personal Google Drive and share the link
D) Text a photo of it to your colleague

The Four Data Classifications

Data Classification Levels

  • Public: Information that is already available to the public. Examples: your website content, published brochures, press releases. No special handling required.
  • Internal: Information meant for staff but not sensitive. Examples: staff directories, internal newsletters, meeting notes without sensitive topics. Share within the organization but not externally.
  • Confidential: Sensitive information that could harm individuals or the organization if exposed. Examples: financial reports, contracts, vendor pricing, donor lists. Requires encryption, access controls, and secure sharing.
  • Restricted: The most sensitive data. Exposure has legal, regulatory, or severe business consequences. Examples: patient records (PHI), attorney-client communications, student records, Social Security numbers, bank account details. Requires encryption, strict access controls, audit logging, and secure disposal.

Quick Check

A vendor asks you to email them a spreadsheet containing your organization’s bank account numbers and routing numbers for setting up payments. What classification is this data and how should you share it?

A) Internal – email it freely
B) Confidential – email it but mark it as confidential
C) Restricted – use encrypted email or a secure file sharing platform, not regular email
D) Public – it is just bank details

Handling Rules for Each Classification

  • Public data: Store anywhere, share freely, no special disposal required.
  • Internal data: Store on organization systems, share with staff only, standard disposal.
  • Confidential data: Store with access controls, share through approved methods, shred or securely delete.
  • Restricted data: Store encrypted with strict access controls, share only through approved encrypted channels, shred with cross-cut shredder or use certified data destruction.

Shadow IT: The Hidden Risk

Shadow IT is any software, app, or cloud service that staff use for work without IT approval. It is one of the biggest data exposure risks in small organizations. Common examples include personal Google Drive, Dropbox, personal email, and free online tools.

The risk is simple: when staff upload work files to personal cloud accounts, those files are outside your organization’s control. There is no encryption, no access logging, no IT oversight, and no way to recover or delete the data if the person leaves.

Quick Check

Your team needs a project management tool. A colleague signs up for a free Trello account using their personal email and starts uploading client documents. What is the risk?

A) No risk – Trello is a legitimate tool
B) This is shadow IT. Client documents are now stored outside organization control with no IT oversight, encryption, or access logging.
C) The risk is that Trello might shut down
D) The risk is that the colleague might forget their password

Common Email Mistakes

Top Email Data Exposure Risks

  • Wrong recipient: Autocomplete fills in the wrong person with a similar name. Always verify the recipient before sending sensitive data.
  • Reply-all with sensitive data: Someone replies all to a large email chain with confidential information attached. Check who is on the thread before replying.
  • Unencrypted attachments: Sending restricted data as a regular email attachment. Use encrypted email or secure file sharing instead.
  • Forwarding without permission: Forwarding confidential emails to people who should not have access. When in doubt, ask before forwarding.

How This Looks in Your Industry

Healthcare Practices

PHI (Protected Health Information) is restricted data under HIPAA. This includes patient names, addresses, birth dates, Social Security numbers, diagnoses, and treatment information. PHI must be encrypted, access-controlled, and shared only through approved channels. Emailing PHI to the wrong person is a reportable HIPAA breach.

Legal Firms

Attorney-client communications are restricted. Exposing them can waive privilege and compromise cases. All case files, client communications, and settlement details should be classified as restricted and handled with encryption and access controls.

Nonprofits

Donor information, grant reports, and financial data are confidential or restricted. Grant agreements may specify how data must be handled. Donor trust depends on keeping their information private. Use approved tools for all grant and donor data.

Daycares and Schools

Student records, parent contact information, and photos of children are restricted under FERPA and COPPA. Staff photos on personal phones, student data in personal cloud accounts, and parent information in unapproved apps all create compliance risks.

Key Takeaways

  • Data classification is the foundation of data privacy. Know what type of data you are handling.
  • Four levels: Public, Internal, Confidential, Restricted. Each has different handling rules.
  • Shadow IT (unapproved tools) is a major data exposure risk. Request tools through IT.
  • Always verify email recipients before sending sensitive data. Autocomplete mistakes are common.
  • Restricted data (PHI, client files, financial data) requires encryption, access controls, and secure disposal.

Module Quiz

Select an answer for each question to reveal the correct response and explanation.

1. Which data classification level applies to patient medical records?

A) Public
B) Internal
C) Confidential
D) Restricted

2. You want to use a free online PDF converter to merge two confidential client documents. What should you do?

A) Use it – free tools are fine for quick tasks
B) Upload the documents since you will delete them afterward
C) Do not use it. Uploading confidential documents to an unapproved online tool exposes them to a third party.
D) Use it but only for the merge, not for viewing

3. You accidentally email a spreadsheet with donor names and donation amounts to your entire mailing list instead of just the board. What should you do?

A) Nothing – it was an honest mistake
B) Recall the email if possible, notify your supervisor and IT immediately, and document the incident
C) Send a follow-up email asking people to delete it and move on
D) Wait to see if anyone complains

4. What is shadow IT?

A) IT equipment that is no longer in use
B) Software or cloud services used for work without IT approval
C) IT staff who work at night
D) Backup IT systems

5. How should restricted data be disposed of?

A) Throw it in the recycling bin
B) Delete the file and empty the trash
C) Use a cross-cut shredder for paper and certified data destruction for digital files
D) Store it in a box and deal with it later

Module 04 of 10 – Cybersecurity Essentials Training

Previous ModuleBack to ResourcesNext Module