This clause sorts your data into categories based on how sensitive it is (for example: "public," "internal," "confidential," "highly confidential"), and sets different protection rules for each level. It matters because not all data needs the same level of security—protecting a public website differently than customer credit card numbers would be wasteful, but protecting credit card numbers like public data would be negligent. The clause should clearly define what goes in each category and what security rules apply (for example, "highly confidential data must be encrypted, logged, and accessed only by named people"). UK GDPR requires you to assess data risks, and US laws like HIPAA (for health data) and PCI-DSS (for payment data) mandate stricter rules for sensitive information.
Make sure your most sensitive data (customer names, payment details, health information) is labeled "highly confidential" and gets the strongest protections—encryption, limited access, and regular audits. Insist on a written classification policy you can review, and require the company to tell you immediately if they reclassify your data to a lower security level. If they refuse to classify data or won't explain why certain data gets certain protection, they probably don't have a real security plan.
Frequently Asked Questions
What does this clause mean in simple terms?
This clause sorts your data into categories based on how sensitive it is (for example: "public," "internal," "confidential," "highly confidential"), and sets different protection rules for each level.
Why should I care about this clause?
It matters because not all data needs the same level of security—protecting a public website differently than customer credit card numbers would be wasteful, but protecting credit card numbers like public data would be negligent.
What are my options?
The clause should clearly define what goes in each category and what security rules apply (for example, "highly confidential data must be encrypted, logged, and accessed only by named people").
How does this affect small businesses?
UK GDPR requires you to assess data risks, and US laws like HIPAA (for health data) and PCI-DSS (for payment data) mandate stricter rules for sensitive information.
