
Data Classification & Handling Standard Client‑Safe
Labels, controls and handling rules • Effective 28 Sep 2025
Classification Levels
- Public — intended for public release.
- Internal — routine business information; limited distribution.
- Sensitive — could cause harm if disclosed; strong access control; encryption required.
- Confidential — significant harm risk; strict need‑to‑know; heightened monitoring.
- Restricted — critical or high‑impact; explicit owner approval; additional safeguards.
Minimum Handling Requirements
- Encrypt Sensitive+ at rest and in transit; approved repositories only
- Apply MFA and least‑privilege; review access quarterly
- No unapproved removable media; prevent shadow IT; DLP enforced
- Residency: NZ primary; AU optional for DR if elected
- Retention by policy; secure disposal with records
Labelling & Sharing
- Apply labels in docs/repositories; default to Internal when unsure
- External sharing requires owner approval for Sensitive+
- Third‑party processors must be contracted and risk‑assessed