Start with the records that could cause harm
List the information you hold, where it sits, who can reach it and who owns the business decision about it. Start with payroll, customer records, contracts and other information whose exposure, alteration or loss would matter.
APP 11 requires covered entities to take reasonable technical and organisational steps to protect personal information. Classification can support that work, but a classification policy does not prove Privacy Act compliance. It is not an extra strategy in the Essential Eight or a substitute for implementing its controls.
Four example levels, not a mandatory standard
Use names that staff can explain and test them against real work. These four levels are an illustrative business scheme, not an Australian Government classification or a guaranteed mapping to the Industry Data Classification Framework.
Public
Example: an approved brochure. Publish the approved version, but still protect editing rights, integrity and any unpublished drafts.
Internal
Example: a routine team procedure. Limit it to the relevant staff; do not assume every internal record belongs in an all-staff folder.
Confidential
Example: a client contract or payroll report. Give named roles access, control external sharing and consider encryption for the workflow.
Restricted
Example: sensitive health records or commercially critical designs. Require an accountable owner, tightly scoped access and review of any proposed disclosure.
Write the handling rule beside the label
Storage and access
Name the approved repository and the roles that need the information. Check existing permissions before assuming a label fixes them.
Email and external sharing
Specify approved recipients, the approval owner, secure delivery and link expiry where supported. Test a genuine external-recipient workflow.
Download and print
Set restrictions where the application and protection method support them. Screenshots and copies outside the controlled workflow still need staff rules.
Retention
Set periods by record type, business need, law and contract. A sensitivity level does not automatically mean a seven-year retention period.
Disposal
Specify how records and copies are destroyed or de-identified when no longer needed, subject to legal holds and other retention requirements.
Ownership and exceptions
Name who approves a change, reviews access and handles an exception. Train staff with an example from their own work.
Microsoft Purview labels are one part of the control
Microsoft documents that sensitivity labels can identify content and, when configured, apply protection such as encryption and markings. A label can also be applied without protection settings. Check the actual policy, supported application and user licence rather than treating the label name as proof of encryption.
Features such as automatic labelling, endpoint controls and Teams DLP have separate licensing and support conditions. There is no blanket promise that every Microsoft 365 plan includes every Purview capability.
| Control | What it does | What to verify |
|---|---|---|
| Sensitivity label | Identifies sensitivity and can apply configured protection. | Published policy, encryption settings, application support and licences. |
| Permissions | Determines who can reach a site, folder or record. | Named roles, guest access and inherited permissions. |
| DLP policy | Detects relevant content and can warn or restrict configured activities. | Covered locations, rule behaviour, exceptions and licensing. |
| Retention rule | Controls record retention or deletion under a configured policy. | Legal requirements, record type, holds and service support. |
Different controls do different work
- Control
- Sensitivity label
- What it does
- Identifies sensitivity and can apply configured protection.
- What to verify
- Published policy, encryption settings, application support and licences.
- Control
- Permissions
- What it does
- Determines who can reach a site, folder or record.
- What to verify
- Named roles, guest access and inherited permissions.
- Control
- DLP policy
- What it does
- Detects relevant content and can warn or restrict configured activities.
- What to verify
- Covered locations, rule behaviour, exceptions and licensing.
- Control
- Retention rule
- What it does
- Controls record retention or deletion under a configured policy.
- What to verify
- Legal requirements, record type, holds and service support.
Pilot the scheme before enforcing it everywhere
- Step 1
Discuss the information in the first call
We review the repositories, work patterns and current licences. You nominate data owners and explain which records or obligations need attention.
- Step 2
Agree the rules and responsibilities
We turn the chosen levels into practical access, sharing and disposal rules. You approve the owners, exceptions and recordkeeping requirements.
- Step 3
Test a representative pilot
We configure the agreed labels and available controls, using simulation or audit options where supported. Your staff test real tasks before wider enforcement.
- Step 4
Review a month into the pilot
We review rule matches, incorrect blocks and adoption. You confirm what works, approve changes and assign an ongoing review owner.
Check the gaps that a label will not fix
Too many unexplained levels
Keep the scheme small enough for staff to choose a level using a real example. Four is an option, not a universal optimum.
Unreviewed legacy records
Inventory existing shared folders and exports. New-document defaults do not repair historical permissions or classify every old copy.
Blocking without a pilot
Review matches and legitimate work before broad restrictions. Check the available test mode for each product and location.
No accountable review
Assign an owner and review after incidents, new systems or changed obligations, as well as on your agreed schedule.
We will not prescribe retention periods without your recordkeeping requirements, promise perfect detection or call a labelled environment compliant without checking the controls.
A new Australian framework to consider
CSIRO and the Department of Home Affairs announced the voluntary Industry Data Classification Framework on 2 September 2026. It provides a shared approach to understanding data value and risk, rather than requiring every business to use the four example labels in this guide.
Use the framework when you need a more detailed assessment or a shared language with another organisation. Do not rename local labels as official data security levels without doing that assessment.
Common questions
How many data classification levels do we need?
There is no single required number for every business. Start with a small scheme staff can apply to real records. The four levels here are examples; your contracts or regulatory setting may call for different names or detail.
Does a sensitivity label encrypt every file?
No. Microsoft labels can be applied without protection settings. Encryption depends on the label configuration, supported file and application, and the relevant licences.
Is automatic labelling included in every Microsoft 365 plan?
No. Licensing differs between manual labelling, automatic labelling, DLP locations and other controls. Check Microsoft's current service description for the features and users in your rollout.
Does classification make us Privacy Act or Essential Eight compliant?
No. Classification supports decisions about protection, but compliance depends on the applicable duties and implemented controls. It is not a separate Essential Eight strategy or a certification.
How long should we retain confidential information?
Retention depends on the record, its purpose, law and contract, not the sensitivity label alone. Agree a recordkeeping schedule and account for legal holds before configuring deletion.
How does this relate to the Industry Data Classification Framework?
The IDCF is a voluntary Australian framework announced in September 2026 for assessing data value and risk. The example business labels in this guide are not an automatic mapping to its data security levels.
Start with one data set and its owner
Tell us which records need tighter handling and where they live. We can scope a pilot against your current licences and work patterns before recommending wider controls.

Remote Support