| Level | Boundary question | Illustrative information | Handling direction |
|---|---|---|---|
| Public | Approved for public release? | Marketing brochure, published report | Integrity and version control may still apply |
| Internal | Limited harm if disclosed? | Process documentation, staff directory | Restrict to organisation; basic access control |
| Confidential | Material harm or duty breach? | Client contracts, financial data | Narrow access; encryption; approval for sharing |
| Restricted | Severe harm or stringent consequences? | Credentials, vulnerability details, board strategy | Strictest access; need-to-know; enhanced monitoring |
What are data classification levels?
A classification level is an organisation-defined category within a scheme. A classification decision assigns information to one of those categories; a label or metadata records the assignment; and linked controls govern handling. None of these is, by itself, a legal category, technical safeguard or security certification.
The UK Government Security Classifications Policy uses three tiers: OFFICIAL, SECRET and TOP SECRET. Each tier connects the likely impact of compromise to proportionate behaviours and controls. It applies to government and partners, so it is not a statutory business taxonomy. For a business, the useful principle is to define levels by likely impact and context, rather than document type or storage location.
A level should tell someone how carefully to handle information and why. You set the triggers around your own risks and duties.
How many classification levels should you use?
Use as few levels as people need to make consistent decisions. Three are easier to teach and operate. A fourth can separate the most tightly controlled material; five or more allow finer distinctions but add boundaries to learn. One broad "sensitive" bucket can be too blunt when different information needs different handling. Organisation size alone does not decide the model.
Test each boundary against real work before rollout. Ask what changes between two adjacent levels: who approves access, where the information can be stored, how it can be shared and whether extra monitoring applies. If nobody can name a meaningful handling change, the levels may be doing the same job. If one level contains both routine meeting notes and high-impact client records, it may be too broad. Pilot the scheme with documents from several teams, record where people disagree and rewrite the boundary tests.
The Cabinet Office Working at OFFICIAL guidance treats OFFICIAL-SENSITIVE as a marking within OFFICIAL, not a fourth tier. A marking can flag extra handling needs, but it cannot protect the file. The same applies in business: a "sensitive" flag on an Internal document is a marking, not a new level.
An illustrative four-level model
The following model is a practical synthesis for small and medium organisations. It is not prescribed by any standard, regulator or law. Adapt the boundary tests and examples to your context.
Public
Information that is approved for public release. This includes published reports, marketing materials, press releases and content on your public website.
Even Public information may need integrity and availability protection. A published price list that is accidentally altered could cause commercial harm. A public-facing document that is unavailable during a critical period could affect operations. Version control and copyright remain relevant.
Internal
Use Internal for routine non-public information where unauthorised disclosure is unlikely to cause material harm. This includes internal process documentation, meeting notes that do not contain client or personal data, staff directories, internal announcements and draft documents that have not yet been approved for external release. If disclosure could breach a legal or contractual duty or create a material competitive disadvantage, a higher level may be appropriate under this model.
Confidential
Information whose disclosure, alteration or loss could cause material harm to the organisation, its clients, its people or its partners, or could breach a legal or contractual duty. This includes client contracts, unpublished financial data, employee personal data, business plans, supplier pricing and internal security documentation.
In this illustrative model, the boundary test is: could disclosure, alteration or loss cause material harm or breach an applicable duty? The adopting organisation should replace that wording with examples and tests its users can apply consistently.
Restricted
The organisation's most tightly controlled information, where compromise could cause severe harm or trigger stringent legal, contractual or operational consequences. This includes security credentials, vulnerability details before patching, board strategy before announcement, merger or acquisition details, and information subject to a specific legal privilege or regulatory restriction.
Restricted is not "top secret" in a government sense. It is the level where the organisation has decided that the consequences of compromise are so severe that access must be strictly limited to named individuals with a demonstrated need.
How other classification schemes differ
These schemes solve different problems. They can inform your method, but none is a ready-made tier model for a UK business:
UK government. The Cabinet Office uses OFFICIAL, SECRET and TOP SECRET. OFFICIAL is the baseline for most government information; SECRET and TOP SECRET are reserved for information where compromise would damage national security. OFFICIAL-SENSITIVE is a marking within OFFICIAL, not a separate tier. The scheme is designed for a specific threat landscape and is not a business taxonomy.
US federal. FIPS 199 defines low, moderate and high potential impact separately for confidentiality, integrity and availability. A system can be, for example, high confidentiality but low availability. This is a security-categorisation method for federal information systems under FISMA, not a corporate sensitivity tier.
Local government. Lincolnshire County Council's information classification policy operates within one government classification (OFFICIAL) while adding context-dependent additional safeguards based on sensitivity and harm. This shows that an organisation can use a single external tier and still differentiate handling internally.
US federal information types. NIST SP 800-60 Volume I maps information types to security categories and provisional impact levels, considering confidentiality, integrity and availability separately. It is a US-federal catalogue; the contextual method is useful, but its values are not defaults for a UK business.
Choose tiers your users can apply consistently, with a visible and enforceable handling change at each level.
Criteria for choosing the right level
When classifying a specific piece of information, consider:
- Content: What does the information contain? Personal data, financial data, security material, client information?
- Context: Who created it, for what purpose, and in what relationship? A blank template is different from a completed copy.
- Duties: Are there legal, contractual or professional obligations that apply?
- Aggregation: Does combining this information with other information increase the risk?
- Likely harm: If this information were disclosed, altered or lost, what would the worst realistic outcome be?
- Recipients: Who needs to see it, and who must not?
The Cabinet Office Working at OFFICIAL guidance emphasises that the creator assesses context and that need-to-know is balanced with need-to-share. A business can adopt that principle without copying the government role model: define who makes the initial classification, what evidence they use and who reviews it. One workable option is to let the person who creates or first receives the information make a provisional assignment under the information owner's oversight.
Who assigns, reviews and changes a classification?
Classification is a governed decision. One workable role model is:
- Initial assignment: The person who creates or first receives the information assigns the level, using the organisation's boundary tests.
- Review: The information owner for the relevant data domain reviews classifications periodically or on trigger events.
- Change: A classification can be changed when context, purpose, duties or impact change. The change should be recorded with a reason.
- Dispute: If two people disagree on the level, the escalation route in the policy applies. Typically this is: user to information owner to policy owner.
A classification is not necessarily permanent. A document that is Confidential during a project may be reviewed for a different level after the project ends. A vulnerability detail that is Restricted before a patch is released may be reviewed after the patch is widely deployed. Neither change is automatic.
How levels connect to handling controls
Each level needs a clear set of handling rules:
- Access: Who can see it, and how is that enforced?
- Storage: Where does it live, and what protections apply?
- Sharing: How can it be transmitted, and to whom?
- Retention: How long is it kept, and how is it disposed of?
- Incident: What happens if a handling rule is breached?
Write these rules as actions people can follow. "Share Restricted files only with named recipients through [approved channel]" is clearer than "take extra care". Check that current tools can enforce each rule. Where they cannot, name the required approval or compensating control rather than leaving the gap implicit.
Next, map levels to handling controls so each decision leads to a repeatable action.
Then build the rules into a policy.
Applying a classification before AI use
When a document is proposed for use in an AI workflow, the classification decision comes first. The organisation must determine:
- What level does this document carry?
- Is the proposed AI use permitted for that level under the organisation's policy?
- Does the data need to be minimised or redacted before sharing?
- What provider-specific controls apply?
Once those decisions are made, a document-security checkpoint can examine the exact file version for reported signals. It cannot classify the document or approve its use. You can see what the document check covers.
For less obvious classifications, work through the worked data classification examples.
If the file contains personal or special-category data, start with the criteria for identifying sensitive data.
Frequently asked questions
What are the four levels of data classification?
In this guide: Public, Internal, Confidential and Restricted. This is one illustrative model; choose clear levels that fit your context and trigger distinct handling rules.
Are four levels mandatory?
No. No universal source prescribes four levels. Use the smallest set your people can apply consistently.
Is Confidential higher than Restricted?
No. In the illustrative model, Restricted is the highest level. Confidential is the second-highest. The order from lowest to highest is: Public, Internal, Confidential, Restricted.
Is all personal data Confidential?
Personal data is a legal category, not an organisational level, so it does not automatically map to one tier. Under a locally defined scheme, different personal data may receive different levels according to context, applicable duties and likely harm; every item still remains personal data and must be handled accordingly.
Can a classification change?
Yes. A classification should be reviewed when context, purpose, duties or impact change. A project document or patched-vulnerability report may qualify for a different level after review, but the change is not automatic and should be recorded with its reason.
Where document security fits
Your classification rules inform how a file may be handled. A separate authorised decision determines whether the proposed AI use is permitted. A later document-security check examines the exact version for reported signals; it does not classify the file, authorise its use or replace handling controls.
.mdSiren is a document security workspace for AI. Coming soon, Standard Scan will check the exact document version, route it to Approved, Needs review or Quarantine, and keep eligible Approved versions in a private Library. That result does not assign the file's classification or authorise its use, and it is limited to the reported checks and coverage for that version.



