The definition of protection classes is the core of every data classification. They are based on protection requirements and legal/regulatory obligations.
🔒
Typical protection classes:
•
Public: Data that can be published without risk (e.g., marketing materials).
•
Internal: Data intended only for employees (e.g., internal policies).
•
Confidential: Data with elevated protection requirements (e.g., customer lists, internal reports).
•
Strictly confidential: Critical data whose loss or disclosure would have serious consequences (e.g., personal data, financial data, trade secrets).
📝
Classification criteria:
•
Legal requirements (GDPR, BDSG, etc.)
•
Internal company policies
•
Risk and damage potential in case of loss or disclosure
•
Confidentiality, integrity, availability
💡
Expert tip:
Protection classes should be clearly defined, easy to understand, and simple for all employees to apply. Automated tools can support classification based on metadata, content, or context.