The process of categorizing data by sensitivity, type, or regulatory requirement to determine how it should be handled, protected, and shared.

Data classification creates a structured framework for managing data risk. Common classification levels include: public (freely shareable), internal (for organizational use), confidential (restricted access), and restricted or secret (highest protection). Each level has associated handling rules — who can access it, how it must be stored, and how it may be shared.

Classification is the foundation of data governance. You cannot apply appropriate controls to data you have not categorized. It also supports compliance with privacy laws, which impose different obligations depending on the sensitivity of the data.

Example: A municipal government classifies its data into four levels: Open (published on the open data portal), Internal (for staff use only), Confidential (personal information requiring restricted access), and Protected (sensitive personal information requiring the highest security controls). Each dataset in the organization's inventory is assigned a classification level that determines how it is stored, who can access it, and whether it can be shared externally.

Related Terms

Learn More

← Back to Glossary Français →