Data and governance

Data classification for Australian businesses

Data classification groups information by its sensitivity and the harm that misuse could cause. For an Australian business, a useful starting point is a small set of named levels, an owner for each data type and clear rules for access, sharing, retention and disposal. A label alone does not enforce those rules.

Compare the example levels
Updated By Real Bytes

Start with the records that could cause harm

List the information you hold, where it sits, who can reach it and who owns the business decision about it. Start with payroll, customer records, contracts and other information whose exposure, alteration or loss would matter.

APP 11 requires covered entities to take reasonable technical and organisational steps to protect personal information. Classification can support that work, but a classification policy does not prove Privacy Act compliance. It is not an extra strategy in the Essential Eight or a substitute for implementing its controls.

Four example levels, not a mandatory standard

Use names that staff can explain and test them against real work. These four levels are an illustrative business scheme, not an Australian Government classification or a guaranteed mapping to the Industry Data Classification Framework.

  • Public

    Example: an approved brochure. Publish the approved version, but still protect editing rights, integrity and any unpublished drafts.

  • Internal

    Example: a routine team procedure. Limit it to the relevant staff; do not assume every internal record belongs in an all-staff folder.

  • Confidential

    Example: a client contract or payroll report. Give named roles access, control external sharing and consider encryption for the workflow.

  • Restricted

    Example: sensitive health records or commercially critical designs. Require an accountable owner, tightly scoped access and review of any proposed disclosure.

Write the handling rule beside the label

  • Storage and access

    Name the approved repository and the roles that need the information. Check existing permissions before assuming a label fixes them.

  • Email and external sharing

    Specify approved recipients, the approval owner, secure delivery and link expiry where supported. Test a genuine external-recipient workflow.

  • Download and print

    Set restrictions where the application and protection method support them. Screenshots and copies outside the controlled workflow still need staff rules.

  • Retention

    Set periods by record type, business need, law and contract. A sensitivity level does not automatically mean a seven-year retention period.

  • Disposal

    Specify how records and copies are destroyed or de-identified when no longer needed, subject to legal holds and other retention requirements.

  • Ownership and exceptions

    Name who approves a change, reviews access and handles an exception. Train staff with an example from their own work.

Microsoft Purview labels are one part of the control

Microsoft documents that sensitivity labels can identify content and, when configured, apply protection such as encryption and markings. A label can also be applied without protection settings. Check the actual policy, supported application and user licence rather than treating the label name as proof of encryption.

Features such as automatic labelling, endpoint controls and Teams DLP have separate licensing and support conditions. There is no blanket promise that every Microsoft 365 plan includes every Purview capability.

Different controls do different work

Control
Sensitivity label
What it does
Identifies sensitivity and can apply configured protection.
What to verify
Published policy, encryption settings, application support and licences.
Control
Permissions
What it does
Determines who can reach a site, folder or record.
What to verify
Named roles, guest access and inherited permissions.
Control
DLP policy
What it does
Detects relevant content and can warn or restrict configured activities.
What to verify
Covered locations, rule behaviour, exceptions and licensing.
Control
Retention rule
What it does
Controls record retention or deletion under a configured policy.
What to verify
Legal requirements, record type, holds and service support.

Pilot the scheme before enforcing it everywhere

  1. Step 1

    Discuss the information in the first call

    We review the repositories, work patterns and current licences. You nominate data owners and explain which records or obligations need attention.

  2. Step 2

    Agree the rules and responsibilities

    We turn the chosen levels into practical access, sharing and disposal rules. You approve the owners, exceptions and recordkeeping requirements.

  3. Step 3

    Test a representative pilot

    We configure the agreed labels and available controls, using simulation or audit options where supported. Your staff test real tasks before wider enforcement.

  4. Step 4

    Review a month into the pilot

    We review rule matches, incorrect blocks and adoption. You confirm what works, approve changes and assign an ongoing review owner.

Check the gaps that a label will not fix

  • Too many unexplained levels

    Keep the scheme small enough for staff to choose a level using a real example. Four is an option, not a universal optimum.

  • Unreviewed legacy records

    Inventory existing shared folders and exports. New-document defaults do not repair historical permissions or classify every old copy.

  • Blocking without a pilot

    Review matches and legitimate work before broad restrictions. Check the available test mode for each product and location.

  • No accountable review

    Assign an owner and review after incidents, new systems or changed obligations, as well as on your agreed schedule.

We will not prescribe retention periods without your recordkeeping requirements, promise perfect detection or call a labelled environment compliant without checking the controls.

A new Australian framework to consider

CSIRO and the Department of Home Affairs announced the voluntary Industry Data Classification Framework on 2 September 2026. It provides a shared approach to understanding data value and risk, rather than requiring every business to use the four example labels in this guide.

Use the framework when you need a more detailed assessment or a shared language with another organisation. Do not rename local labels as official data security levels without doing that assessment.

Common questions

How many data classification levels do we need?

There is no single required number for every business. Start with a small scheme staff can apply to real records. The four levels here are examples; your contracts or regulatory setting may call for different names or detail.

Does a sensitivity label encrypt every file?

No. Microsoft labels can be applied without protection settings. Encryption depends on the label configuration, supported file and application, and the relevant licences.

Is automatic labelling included in every Microsoft 365 plan?

No. Licensing differs between manual labelling, automatic labelling, DLP locations and other controls. Check Microsoft's current service description for the features and users in your rollout.

Does classification make us Privacy Act or Essential Eight compliant?

No. Classification supports decisions about protection, but compliance depends on the applicable duties and implemented controls. It is not a separate Essential Eight strategy or a certification.

How long should we retain confidential information?

Retention depends on the record, its purpose, law and contract, not the sensitivity label alone. Agree a recordkeeping schedule and account for legal holds before configuring deletion.

How does this relate to the Industry Data Classification Framework?

The IDCF is a voluntary Australian framework announced in September 2026 for assessing data value and risk. The example business labels in this guide are not an automatic mapping to its data security levels.

Start with one data set and its owner

Tell us which records need tighter handling and where they live. We can scope a pilot against your current licences and work patterns before recommending wider controls.