All Guides
Data and Governance

Data Classification for SMBs

Most classification projects fail because they are designed for a 50,000-person bank. This guide is different. A four-tier scheme, plain-English handling rules, and the Microsoft 365 tools to enforce them without drowning the business in stickers and labels.

Last updated April 202610 min read

Start With the Question

Data classification is the discipline of labelling information by sensitivity so you can protect it appropriately. Public marketing collateral does not need the same controls as client financial records. Everyone nods. Most businesses still treat every file the same way.

The goal is not perfect coverage. The goal is that the highest-risk data is labelled, encrypted, and DLP-enforced, and staff know the difference between a board pack and a team lunch menu.

Why Bother

  • Australian Privacy Act obligations require reasonable steps to protect personal information. Classification is one of those steps.
  • Cyber insurance applications increasingly ask about classification and DLP.
  • Data breach severity correlates directly with how well the affected data was protected.
  • Essential Eight progression at ML2 and ML3 assumes classification exists.
  • Customer, industry, and contractual obligations often require it (financial, health, government, education).

A Simple Four-Tier Scheme

Public

Intended for external publication. Marketing material, press releases, job ads. No controls needed.

Internal

Default for day-to-day business information. Internal memos, team documents, meeting notes. Accessible to all staff, not for external sharing without thought.

Confidential

Sensitive business information. Financials, contracts, pricing, strategy, HR records. Access limited to those who need it. External sharing requires encryption.

Restricted

Highest sensitivity. Personal information at scale, regulated data, trade secrets, credentials. Strict access control, encryption at rest and in transit, audit logging, no external sharing without sign-off.

Four tiers is the sweet spot. Two tiers is too blunt. Six tiers is where staff stop paying attention.

Handling Rules

Storage

Public and Internal live in SharePoint or OneDrive. Confidential and Restricted live in SharePoint sites with explicit permissions and label-based encryption.

Email

Confidential email encrypted by default (Microsoft Purview Message Encryption). Restricted email may be forbidden, or limited to approved recipients only.

External sharing

Public: free. Internal: allowed with a warning. Confidential: blocked by default, enabled per request with expiry. Restricted: blocked, escalation required.

Printing and download

Restricted: printing blocked, download only to compliant devices. Confidential: watermarked printing only.

Retention

Each classification gets a retention period. Restricted financial records: 7 years. Confidential contracts: life of contract plus 7 years. Internal: 3 years. Public: as needed.

Disposal

Restricted and Confidential data destroyed securely at end of retention. Internal data purged on schedule.

Tools That Help

  • Microsoft Purview Sensitivity Labels: four labels mapped to the four tiers. Apply manually, via policy, or auto-apply based on content detection.
  • Auto-labelling policies: scan documents and emails for patterns (TFN, credit card, Medicare, passport, SWIFT) and apply the right label automatically.
  • Data Loss Prevention (DLP): block Confidential and Restricted data from leaving via email, Teams, SharePoint, or OneDrive.
  • Rights Management (label-based encryption): encryption follows the document even after it leaves your tenant. Revokable access.
  • Defender for Cloud Apps: extends classification and DLP to third-party SaaS (Dropbox, Google, Salesforce, Slack).
  • Retention labels: enforce the disposal rules automatically.

Realistic Rollout Plan

  1. Agree the four-tier scheme with leadership and document it in a one-page policy.
  2. Build the sensitivity labels in Microsoft Purview. Encryption and content marking on Confidential and Restricted.
  3. Default every new document to Internal so nothing sits unlabelled.
  4. Train staff with 10 minutes and one example of each tier. Keep it simple.
  5. Enable auto-labelling for obvious patterns (TFN, credit card, Medicare). Let the platform do the heavy lifting.
  6. Layer DLP in audit mode first, then switch to block once false positives are tuned out.
  7. Review quarterly. Adjust rules, add patterns, refine training.

Common Mistakes

Too many tiers

Six or seven tiers makes staff freeze. Four is the sweet spot. Stop fiddling.

Expecting staff to label everything manually

They will not. Auto-labelling and sensible defaults do the work.

Switching on blocking DLP on day one

You will get a flood of false positives and a revolt. Audit first, tune, then block.

Ignoring legacy data

The SharePoint site from 2018 with 40,000 unlabelled documents does not classify itself. Plan for bulk auto-labelling or explicit remediation.

Policy without tooling

A classification policy without Purview labels and DLP is a PDF nobody reads. Tools and policy roll out together.

No review cadence

Data changes, staff change, regulations change. Review at least annually.

Get Classification Off the Ground

We deploy Microsoft Purview sensitivity labels, DLP, and auto-labelling for Australian SMBs. Practical rollout, not a six-month policy project.