Start With the Question
Data classification is the discipline of labelling information by sensitivity so you can protect it appropriately. Public marketing collateral does not need the same controls as client financial records. Everyone nods. Most businesses still treat every file the same way.
The goal is not perfect coverage. The goal is that the highest-risk data is labelled, encrypted, and DLP-enforced, and staff know the difference between a board pack and a team lunch menu.
Why Bother
- Australian Privacy Act obligations require reasonable steps to protect personal information. Classification is one of those steps.
- Cyber insurance applications increasingly ask about classification and DLP.
- Data breach severity correlates directly with how well the affected data was protected.
- Essential Eight progression at ML2 and ML3 assumes classification exists.
- Customer, industry, and contractual obligations often require it (financial, health, government, education).
A Simple Four-Tier Scheme
Public
Intended for external publication. Marketing material, press releases, job ads. No controls needed.
Internal
Default for day-to-day business information. Internal memos, team documents, meeting notes. Accessible to all staff, not for external sharing without thought.
Confidential
Sensitive business information. Financials, contracts, pricing, strategy, HR records. Access limited to those who need it. External sharing requires encryption.
Restricted
Highest sensitivity. Personal information at scale, regulated data, trade secrets, credentials. Strict access control, encryption at rest and in transit, audit logging, no external sharing without sign-off.
Four tiers is the sweet spot. Two tiers is too blunt. Six tiers is where staff stop paying attention.
Handling Rules
Storage
Public and Internal live in SharePoint or OneDrive. Confidential and Restricted live in SharePoint sites with explicit permissions and label-based encryption.
Confidential email encrypted by default (Microsoft Purview Message Encryption). Restricted email may be forbidden, or limited to approved recipients only.
External sharing
Public: free. Internal: allowed with a warning. Confidential: blocked by default, enabled per request with expiry. Restricted: blocked, escalation required.
Printing and download
Restricted: printing blocked, download only to compliant devices. Confidential: watermarked printing only.
Retention
Each classification gets a retention period. Restricted financial records: 7 years. Confidential contracts: life of contract plus 7 years. Internal: 3 years. Public: as needed.
Disposal
Restricted and Confidential data destroyed securely at end of retention. Internal data purged on schedule.
Tools That Help
- Microsoft Purview Sensitivity Labels: four labels mapped to the four tiers. Apply manually, via policy, or auto-apply based on content detection.
- Auto-labelling policies: scan documents and emails for patterns (TFN, credit card, Medicare, passport, SWIFT) and apply the right label automatically.
- Data Loss Prevention (DLP): block Confidential and Restricted data from leaving via email, Teams, SharePoint, or OneDrive.
- Rights Management (label-based encryption): encryption follows the document even after it leaves your tenant. Revokable access.
- Defender for Cloud Apps: extends classification and DLP to third-party SaaS (Dropbox, Google, Salesforce, Slack).
- Retention labels: enforce the disposal rules automatically.
Realistic Rollout Plan
- Agree the four-tier scheme with leadership and document it in a one-page policy.
- Build the sensitivity labels in Microsoft Purview. Encryption and content marking on Confidential and Restricted.
- Default every new document to Internal so nothing sits unlabelled.
- Train staff with 10 minutes and one example of each tier. Keep it simple.
- Enable auto-labelling for obvious patterns (TFN, credit card, Medicare). Let the platform do the heavy lifting.
- Layer DLP in audit mode first, then switch to block once false positives are tuned out.
- Review quarterly. Adjust rules, add patterns, refine training.
Common Mistakes
Too many tiers
Six or seven tiers makes staff freeze. Four is the sweet spot. Stop fiddling.
Expecting staff to label everything manually
They will not. Auto-labelling and sensible defaults do the work.
Switching on blocking DLP on day one
You will get a flood of false positives and a revolt. Audit first, tune, then block.
Ignoring legacy data
The SharePoint site from 2018 with 40,000 unlabelled documents does not classify itself. Plan for bulk auto-labelling or explicit remediation.
Policy without tooling
A classification policy without Purview labels and DLP is a PDF nobody reads. Tools and policy roll out together.
No review cadence
Data changes, staff change, regulations change. Review at least annually.
Get Classification Off the Ground
We deploy Microsoft Purview sensitivity labels, DLP, and auto-labelling for Australian SMBs. Practical rollout, not a six-month policy project.

Remote Support