A practical, risk-based approach to classifying data and connecting classification to ownership, access, sharing, retention, security, lineage and AI-use decisions.
Classification lifecycle
IdentifyAsset / purpose
owner / source
owner / source
Assess ImpactDisclosure / integrity
availability / misuse
availability / misuse
ClassifyPublic / Internal
Confidential / Restricted
Confidential / Restricted
Apply ControlsAccess / sharing
retention / monitoring
retention / monitoring
PropagateFollow downstream
copies and consumers
copies and consumers
ReviewChange / AI / third party
migration / incident
migration / incident
Start with impact, not the label
- Consider confidentiality, integrity, availability, privacy and misuse impact.
- Include legal, contractual and regulatory obligations.
- Consider business criticality, external distribution and analytics or AI use.
Classification establishes a minimum control baseline
The label should influence access, sharing, storage, encryption, retention, disposal, monitoring, third-party use and AI review. Context may require stronger controls than the baseline.
Classification inheritance
Downstream data should normally inherit the source classification unless there is a documented and approved basis to change it, such as verified aggregation, masking, tokenisation or de-identification.
Key relationship
Classification tells us the control requirement. Lineage tells us everywhere that requirement has to follow.