Data Classification

How to classify data and enforce boundaries across systems, teams, and vendors.
Published:
Admin User
Updated:
published

Data Classification

Data classification defines how data must be handled, stored, shared, and protected.

It’s foundational for security posture, vendor risk, and LLM governance.

See also

Security & Trust Reference Model Vendor Risk Management Audit Readiness LLM Data Boundaries PII Redaction

FAQ

What is data classification?
A system for labeling data by sensitivity and defining handling rules for each class.

How does classification affect security controls?
Controls (access, encryption, logging) become stricter as sensitivity increases.

How does this relate to vendor risk?
Vendors must adhere to the handling rules for any data classes they touch.

How does this relate to LLM usage?
Classification defines what may be used in prompts/retrieval and what must be redacted.

What’s the fastest starting point?
Define 3–4 classes (public/internal/confidential/restricted) and map handling rules.