The Skeleton
Policy scaffold

Data Protection and Classification Policy

Decides what the organisation's data is worth, who may see each kind, and what handling each kind requires.

What it has to decide

  1. A classification scheme with no more than four levels

    Four is the practical ceiling. Beyond that, people cannot remember the difference and default to the middle, which defeats the scheme.

  2. Handling rules per level, per state

    At rest, in transit, in use, and on disposal. A scheme that classifies data and never says what follows from the classification has done nothing.

  3. Who classifies, and when

    Classification at creation by the creator is the only version that works. Retrospective classification programs run for years and finish never.

  4. Retention and disposal, with periods

    State the period, the trigger that starts it, and the disposal method. Data kept past its retention period is pure liability with no offsetting value.

  5. Location and sovereignty

    Where data may reside and where it may not, including backups and support access from other jurisdictions. Offshore support access is the clause most often missed.

  6. Personal information, handled explicitly

    Australian entities should reference their Privacy Act obligations here rather than in a separate document nobody links to.

How it is usually got wrong

  • The scheme has five or six levels and everything in practice is labelled Internal.
  • Classification labels exist and no handling rule differs between them, so the labels carry no consequence.
  • Retention periods are stated and no deletion has ever been executed, so the organisation holds twelve years of data against a seven year policy.
  • Backups are out of scope for sovereignty, and the backups sit in another jurisdiction.
  • Support engineers offshore hold standing access to production data, unaddressed by the policy.

Worked extract

What a decision looks like once it has been madeData is classified at the point of creation by the person creating it, into one of four levels: Public, Internal, Confidential, Restricted. Confidential and Restricted data is encrypted at rest and in transit, and may not be transmitted to an external party except through an approved channel. Restricted data may not be stored outside Australia, including in backups and including in any support tooling, and may not be accessed from outside Australia without an approved and time-limited exception. Confidential data is retained for seven years from the end of the customer relationship and is then destroyed. Destruction is evidenced by a certificate retained for three years. Where a support arrangement requires access from another jurisdiction, that access is brokered, recorded and time-limited, and standing access is not granted.