Thursday, July 30, 2026
The Data Governor
← All templates

Data Classification Policy

A complete, editable classification policy: four sensitivity tiers with real examples, a control-by-control handling matrix, assignment and inheritance rules, labeling standards, and an exception process. Replace the brackets, walk it past Security, and approve.

Download Word doc (.docx) Updated 2026-07-29

What's in the policy

  • Four classification tiers — Public, Internal, Confidential, Restricted — each with a definition and concrete examples, color-coded in the brand palette.
  • Handling-requirements matrix — eight controls (access, storage, transmission, external sharing, labeling, printing, retention, incident reporting) with the minimum standard per tier.
  • Roles — owner, steward, custodian, users, and council responsibilities in one table.
  • Process rules that prevent chaos — Internal-by-default, inheritance for derived data, aggregation raising the tier, and annual owner review.
  • Exceptions & downgrades — time-bound, logged, owner-approved; Restricted declassification needs Legal.
  • Approval page — revision history and signature block.

Three tiers or four?

The template ships with the classic four tiers because regulated industries need the Restricted/Confidential split (PCI, PHI, MNPI). If you're a smaller organization, collapse to three by merging Confidential and Restricted — three tiers people actually use beat four they ignore. The case for that trade-off is in Data Classification in Practice: A Sustainable 3-Tier System.

How to adapt it (about 3 hours)

  1. Pick your tier count (see above) and adjust the tier table's examples to data your teams recognize.
  2. Replace every [bracketed] value — policy owner, approval body, incident-reporting windows, exception durations.
  3. Walk the handling matrix with Security and IT. Every cell must be enforceable on your actual systems; delete rows you cannot enforce rather than shipping aspirational controls.
  4. Wire it into tooling. Record tiers in your data catalog, map them to sensitivity labels (e.g., Microsoft Purview), and key DLP rules off them.
  5. Approve and version. Route through the governance council and start the annual review clock.

What this policy doesn't replace

Classification tells you how sensitive data is — not how long to keep it (that's the retention policy & schedule) or who decides (that's the RACI matrix and council charter). For the broader guide to classification programs, see the data classification guide.

Download the classification policy (Word)

10 sections · 4 color-coded tiers · 8-control handling matrix · Fully editable DOCX · No registration required