Data classification is the practice of sorting an organization’s information into categories based on how sensitive and valuable it is, and attaching handling rules to each category. A typical scheme separates public information from internal, confidential and restricted data, with rules for who can access it, whether it must be encrypted, where it may be stored and whether it can leave the organization. Classification is the step that lets security controls treat a press release differently from a payroll file.
At a glance
- Classification labels data by sensitivity, often in three to five levels, and ties each level to handling rules.
- Labels can be applied by people, by automated content inspection or by both.
- Tools such as data loss prevention and cloud access security brokers use labels to decide what to block, encrypt or alert on.
- Regulated data types, such as personal, health and payment data, usually map to the higher levels.
- A scheme works best when staff understand it and data owners keep it current.
What problem it solves
Most organizations can’t protect all data equally: maximum protection everywhere is expensive and gets in the way of work, while minimum protection everywhere exposes the data that matters. Without classification, security teams guess, and tools such as data loss prevention (DLP) either block legitimate work or miss real leaks.
Classification answers the basic questions: where is our sensitive data, what kind is it, and what rules apply? That answer drives encryption choices, access decisions, cloud and SaaS approvals, data retention and incident response, and it is often the first thing an auditor or cyber insurer asks about.
How it works
Define the scheme. Set a small number of levels with plain names and examples, and decide the handling rules for each: access, storage locations, sharing, encryption, retention and disposal.
Identify data types. List the regulated and sensitive data you hold, such as personally identifiable information (PII), protected health information (PHI), payment card data, financial records and intellectual property, and map each to a level.
Discover and label. Scan file shares, cloud storage, email and SaaS apps to find where sensitive data lives. Apply labels manually, automatically by content pattern, or by default based on location or system.
Enforce. Connect labels to controls: DLP rules, cloud access security broker (CASB) policies for SaaS, encryption and rights management, and access reviews. Tell staff how to handle each level in your acceptable use policy (AUP) and training.
Maintain. Data owners review classifications when data, systems or regulations change, and the program is checked periodically as part of data governance.
Classification levels
There is no single required scheme; many organizations use four levels like these, adjusted to their data and obligations. Government schemes use their own levels and rules.
| Level | What typically belongs here | Typical handling rules | What a provider may be asked to show |
|---|---|---|---|
| Public | Marketing material, published prices, press releases | No restrictions beyond accuracy and approval to publish | Nothing specific |
| Internal | Policies, internal directories, routine business documents | Staff access only; not shared externally without approval | Access controls, account management |
| Confidential | Customer data, contracts, financial results before release, most personal data | Need-to-know access, encryption in transit and at rest, approved systems only | Independent security reports, encryption details, access logging |
| Restricted | Regulated or highly sensitive data such as health, payment card or authentication data, trade secrets | Strict access, strong encryption and key control, monitoring, limits on location and sharing | Framework-specific evidence (for example a HIPAA BAA or PCI DSS attestation), key management details, data location commitments |
When it matters for buyers
- When moving data into a new SaaS, cloud or backup service. Your classification tells you which provider controls and contract terms you need.
- When buying DLP, CASB or information protection tools. They depend on labels or detection rules to be useful.
- When a regulation or customer contract names specific data types. Classification shows where that data lives.
- When preparing for an audit or cyber insurance renewal. Expect questions about where sensitive data is stored.
Our cloud access security broker and governance, risk and compliance overviews cover tools that discover, label and protect sensitive data.
Questions to ask vendors
- Can your service read and honor our existing sensitivity labels?
- Which built-in detectors do you offer for regulated data, and how do you measure false positives?
- Where will our confidential and restricted data be stored and processed?
- Who controls encryption keys for data at our highest classification level?
- Can we restrict sharing, download or external access based on classification?
- How do you report where sensitive data was found and what happened to it?
How it differs from data loss prevention
Data loss prevention (DLP) is a set of tools and rules that detect sensitive data in motion, in use or at rest and block, warn or log when it moves somewhere it shouldn’t. Data classification is the decision about what is sensitive and how it should be handled. DLP often includes classification features, which is why the two get confused, but DLP enforces a policy that classification defines. Without a classification scheme, DLP rules tend to be guesses; without enforcement, classification labels are only advice.
