Data Classification Policy Template
A starter template for classifying data as Public, Internal, Confidential, or Restricted with handling, storage, and disposal rules.
Purpose and Scope
This policy establishes a framework for classifying organizational data based on its sensitivity and defining appropriate handling, storage, sharing, and disposal requirements for each classification level. It applies to all employees, contractors, volunteers, and partners who access organizational data.
Data Classification Levels
Level 1: Public
- Definition: Information that is already available to the public or approved for public release.
- Examples: Website content, published brochures, press releases, public event information.
- Handling: No special handling required. Share freely.
- Storage: Store anywhere.
- Disposal: Standard disposal (recycling or trash).
Level 2: Internal
- Definition: Information meant for staff and internal operations but not sensitive if exposed.
- Examples: Staff directories, internal newsletters, meeting notes without sensitive topics, general operational procedures.
- Handling: Share within the organization. Do not share externally without approval.
- Storage: Store on organization systems.
- Disposal: Standard disposal.
Level 3: Confidential
- Definition: Sensitive information that could harm individuals or the organization if exposed.
- Examples: Financial reports, contracts, vendor pricing, donor lists, strategic plans, HR records.
- Handling: Requires encryption and access controls. Share only through approved methods.
- Storage: Store with access controls on approved systems.
- Disposal: Shred with cross-cut shredder or securely delete.
Level 4: Restricted
- Definition: The most sensitive data. Exposure has legal, regulatory, or severe business consequences.
- Examples: Patient records (PHI), attorney-client communications, student records, Social Security numbers, bank account details, credit card numbers.
- Handling: Requires encryption, strict access controls, audit logging, and secure sharing.
- Storage: Store encrypted with strict access controls and audit logging.
- Disposal: Cross-cut shred or certified data destruction. Never dispose of in regular trash.
Handling Rules Summary
Shadow IT Policy
No staff member may use unapproved software, cloud services, or online tools for organizational data. All new tools must be requested through IT for security vetting. This includes free online tools, personal cloud storage, and AI tools.
Email Handling Rules
- Verify recipients before sending sensitive data. Autocomplete mistakes are common.
- Check reply-all before replying to large email chains with sensitive information.
- Use encrypted email or secure file sharing for restricted data. Regular email is not encrypted.
- Do not forward confidential emails without permission.
This template is a supplement to Module 04: Data Handling and Classification. Complete the full module for interactive training and knowledge checks.