Privacy & Data Protection
Data Sensitivity Classifier
Quickly determine the sensitivity level and handling requirements for any data asset.
Inconsistent data labeling is a major source of security breaches. This classifier uses a risk-based framework to categorize data into four standard tiers: Public, Internal, Confidential, and Restricted. By evaluating the impact of unauthorized disclosure and the presence of PII/PHI/PCI, it provides clear handling, storage, and disposal requirements to ensure your organization stays compliant with global privacy laws.
Classification Result
Configure parameters to determine the data sensitivity level.
Handling Specifications
Requirement Breakdown
| Action | Requirement |
|---|---|
| Internal Sharing | - |
| External Email | - |
| Cloud Storage | - |
| Printing | - |
Risk Weighting
Handling Guidelines
- Labeling: Ensure the file name or document header clearly states the sensitivity level.
- Least Privilege: Only grant access to users who have a specific business "need to know."
- Clean Desk: For high-sensitivity data, do not leave printed copies unattended.
- Shadow IT: Never upload Confidential or Restricted data to unauthorized personal cloud accounts.
- Reporting: Immediately report any suspected exposure or loss of Restricted data to the SOC.
Policy Disclaimer
This classifier is an educational tool based on general best practices (NIST/ISO). Your organization's specific data classification policy may vary and should be the primary authority for actual labeling.
Classification Disclaimer
Classifications are derived from typical NIST 800-60 and FIPS 199 mapping logic.
- Legal definitions of PII/PHI vary by jurisdiction (GDPR vs. HIPAA vs. PIPL).
- In case of doubt, always apply the higher (more restrictive) classification level.
- Consult your Data Protection Officer (DPO) for high-volume regulated datasets.
Search topics covered
- data sensitivity classifier
- information classification levels
- PII data sensitivity assessment
- restricted data handling guidelines
- confidential data storage rules
- NIST data classification framework
- ISO 27001 information labeling
- public vs private data sensitivity
- intellectual property protection levels
- data privacy impact quantification
- GDPR data sensitivity tiers
- handling PHI and PCI data
- data classification matrix tool
- information asset risk assessment
- data sensitivity scoring engine
How to use this classifier
Select Data Elements
Identify the most sensitive piece of information in the asset. If a spreadsheet contains 90% public data but 10% Social Security Numbers, the entire asset must be classified based on the SSNs. Our tool analyzes these elements to set the baseline protection tier.
Evaluate Disclosure Impact
Consider the "worst-case scenario" if this data were leaked. Would it cause brand damage, lead to a regulatory fine, or allow an attacker to breach other systems? Higher impact scores automatically trigger more restrictive handling requirements.
Identify Availability Context
How broadly is the data currently available within the firm? Data that is already widely available to all staff is often (though not always) less sensitive than data that is currently siloed or restricted to specific executive roles.
Account for Volume
The "Aggregation Risk" principle states that a large collection of non-sensitive data can become sensitive when viewed as a whole. A list of 1 million customer names is far more sensitive than a single customer name. Adjust the volume to reflect the scale of the dataset.
Review Requirements
Once classified, the tool provides specific rules for encryption, storage, and sharing. These rules are designed to align with ISO 27001 and NIST standards, providing a professional roadmap for your IT and security teams.
Implement and Label
Use the output to apply digital labels or watermarks to your documents. Export the classification report to PDF as evidence for your data inventory or compliance audits, ensuring a clear "paper trail" for your security decisions.
Advantages of this classifier
Standardizes Labeling
Removes the guesswork from data labeling. By using a consistent logic, different departments will classify the same types of data the same way, creating a unified security language across the organization.
Reduces Over-Classification
Labeling everything as "Top Secret" leads to "Security Fatigue" and slows down business operations. Our tool helps find the "just right" level of protection, ensuring high security where it matters without blocking low-risk work.
Simplifies Compliance Audits
Auditors look for a defined classification methodology. Using this tool provides a repeatable, risk-based approach that can be easily explained and defended during external security or privacy audits.
Optimizes Security Spend
By knowing exactly which data is "Restricted," you can focus your most expensive security controls (like hardware security modules or dedicated air-gapped servers) on the assets that actually need them.
Improves Incident Response
When a breach occurs, the first question is "what was lost?" Having pre-classified data allows the incident response team to immediately determine the severity and reporting requirements for the affected assets.
Enhances Data Awareness
The clear handling guidelines educate employees on the importance of data protection in their daily workflows, turning classification into a proactive cultural habit rather than a reactive IT chore.
Governing bodies & standards
Q&A
What is 'Restricted' data?
This is your most sensitive data, such as SSNs, passwords, or critical IP. Loss of this data would cause severe damage to the organization or individuals.
Can Public data become Confidential?
Yes, through aggregation. A list of public addresses is public, but a list of addresses of all your high-value clients might be Confidential.
Does this tool store my data?
No. This tool operates entirely in your browser. No data elements or classification results are ever sent to our servers.
What is the difference between PII and PHI?
PII is Personally Identifiable Information (General). PHI is Protected Health Information (Medical), which often carries higher legal penalties (HIPAA).
How often should we re-classify?
Review classifications annually or whenever the "context" of the data changes significantly (e.g., merging with a public dataset).