# Information classification and handling policy

Source: https://aestech.com.au/policy-templates/#information-classification-and-handling-policy
Markdown URL: https://aestech.com.au/policy-templates/information-classification-and-handling-policy.md

Use for ISO 27001 A.5.12, A.5.13, A.5.14, privacy, SOC 2 Confidentiality, and data handling controls.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how information is classified, labelled, stored, transferred, retained and disposed of.

2. Classification levels
- Public: approved for public release.
- Internal: business information for employees and contractors.
- Confidential: customer, employee, financial, security or commercial information.
- Restricted: highly sensitive data such as credentials, production secrets, regulated data or security evidence.

3. Handling rules
- Confidential and Restricted data must be stored only in approved systems.
- External transfer requires approved channels and encryption where appropriate.
- Restricted data must not be used in test, demo or AI tools unless approved and masked.
- Records must be retained according to the retention schedule.
- Data past its retention period must be deleted or anonymised.

4. Evidence
Keep data inventories, transfer approvals, DLP alerts, retention schedules, deletion records, data processing records and exceptions.

Owner: [role]
Review cadence: annually and after material data-flow changes.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md