Free data classification policy builder. Create government or commercial schemas with handling rules and compliance mapping for HIPAA, PCI-DSS, GDPR.
Data classification is the process of organizing data into categories based on its sensitivity, value, and regulatory requirements. A classification framework assigns labels (such as Public, Internal, Confidential, Restricted) that determine how data must be handled, stored, transmitted, and disposed of throughout its lifecycle.
Data classification is the foundation of any data protection program. Without knowing what data you have and how sensitive it is, you cannot apply appropriate security controls, meet compliance obligations, or respond effectively to data breaches. Regulations including GDPR, HIPAA, PCI DSS, and CMMC all require organizations to classify and protect data according to its sensitivity.
| Level | Description | Examples | Handling Requirements |
|---|---|---|---|
| Public | No harm if disclosed | Marketing materials, public website content | No restrictions |
| Internal | Low harm if disclosed externally | Internal policies, org charts, meeting notes | Access restricted to employees |
| Confidential | Significant harm if disclosed | Customer data, financial reports, source code | Encryption, access controls, NDA required |
| Restricted | Severe harm if disclosed | PII, PHI, payment card data, trade secrets | Strongest controls, encryption at rest and in transit, strict access |
| Regulation | Data Types | Required Classification |
|---|---|---|
| GDPR | Personal data of EU residents | Must identify and protect all personal data processing |
| HIPAA | Protected Health Information (PHI) | Must classify and safeguard all PHI |
| PCI DSS | Cardholder data | Must identify all locations where cardholder data is stored, processed, or transmitted |
| CMMC | Controlled Unclassified Information (CUI) | Must classify and protect CUI per NIST 800-171 |
| SOX | Financial records | Must classify and protect financial reporting data |
The U.S. government uses four classification levels: Top Secret (exceptionally grave damage to national security), Secret (serious damage), Confidential (damage to national security), and Unclassified (no damage). Each level has specific handling, storage, transmission, and destruction requirements defined by Executive Order 13526.
Common commercial classification schemas include: Restricted (highest sensitivity - trade secrets, PII), Confidential (internal sensitive data - financial records, HR data), Internal (business use only - policies, procedures), and Public (freely shareable - marketing materials, press releases). Some organizations add a fifth "Critical" level.
Higher classification levels require stricter controls: encryption at rest and in transit (Restricted), access controls and audit logging (Confidential), basic access controls (Internal), and no special controls (Public). This tool lets you define specific handling rules for storage, transmission, disposal, and access at each level.
Data classification is foundational to compliance. HIPAA requires identifying PHI, PCI-DSS requires identifying cardholder data, GDPR requires identifying personal data, and CMMC requires identifying CUI. This tool provides compliance overlays that map classification levels to regulatory requirements for each framework.
The data owner (typically a business unit leader or executive) is responsible for classifying data based on its sensitivity and value. The data custodian (typically IT) implements the technical controls required by the classification. Data users must handle information according to its classification level.
Generate customized information security policies for your organization. Create Acceptable Use, Password, Incident Response, Access Control, Remote Work, and Data Classification policies tailored to your industry and compliance requirements.
Map GDPR data processing roles (Controller, Processor, Joint Controller), define data processing activities, calculate retention periods by data type and jurisdiction, select legal bases, assess pseudonymization needs, and generate Article 30 Records of Processing Activities.
Get NIST SP 800-88 aligned recommendations for media sanitization and destruction. Select media type, data sensitivity, and asset disposition to receive detailed procedures, verification methods, regulatory compliance guidance, and certificate of destruction templates.