The category or label should drive practical handling rules such as who may access the data, where it may be stored, how it may be shared, and when it should be deleted.
A workable classification scheme is understandable to the people and systems that use it. Organizations commonly combine owner-applied labels, contextual rules, content discovery, and inherited metadata. Automated tools can assist, but accountable owners must define meaning and resolve ambiguity.
Key points
Possible criteriaConfidentiality impact, business criticality, personal data, regulated content, intellectual property, contractual limits, and safety relevance.
Policy outputsAccess, encryption, sharing, retention, monitoring, backup, disposal, and incident-handling requirements.
Good designUse a small number of distinct categories, clear examples, default handling, and a process for relabeling data as context changes.
Important limitationA label does not protect data by itself, and inaccurate or stale labels can drive both unsafe sharing and unnecessary restriction.