Data Classification Policy
Information Handling Standards
Data Governance Committee
January 17, 2026
Abstract
To ensure the effective protection of information assets, data must be classified accord-
ing to its sensitivity and the impact of its potential disclosure. This policy outlines the four
classification levels used by the organization.
1 Classification Levels
1.1 Level 1: Public
Information that is intended for public use or has been approved for release to the general
public.
- Examples: Marketing materials, press releases, job postings.
- Controls: No special protection required.
1.2 Level 2: Internal Use Only
Information that is proprietary but not highly sensitive. Unauthorized disclosure would cause
minimal harm.
- Examples: Organizational charts, internal memos, policies.
- Controls: Access limited to employees; standard encryption on laptops.
1.3 Level 3: Confidential
Sensitive information where unauthorized disclosure could cause financial loss, reputational
damage, or legal issues.
- Examples: Customer PII (Personally Identifiable Information), contracts, payroll data.
- Controls: Multi-Factor Authentication (MFA) required for access; encryption at rest and in
transit.
1.4 Level 4: Restricted
Highly sensitive trade secrets or data subject to strict regulatory compliance (e.g., HIPAA, GDPR).
Disclosure could cause catastrophic damage.
- Examples: Source code, encryption keys, merger and acquisition strategies.
- Controls: Strict ”Need to Know” access; auditing of all access logs; data cannot be stored
on portable drives.
1
2 Labeling and Handling
All documents and emails containing Level 3 or Level 4 data must be clearly labeled in the header
or footer. External transmission of Restricted data requires approval from a Data Owner.