Public
Meant for anyone: website content, published marketing. Minimal protection.
Not all data needs the same protection. Classifying it by sensitivity means the most valuable information gets the strongest safeguards, without locking down everything else.
Client records and payment details need far stricter protection than a staff rota or a published brochure. Data classification is the process of sorting your information into categories by sensitivity, so you can apply the right level of security to each.
It also answers the questions UK GDPR expects you to answer: what personal data you hold, why you hold it, where it is, who can reach it, and how it is protected.
Meant for anyone: website content, published marketing. Minimal protection.
Everyday business information, such as staff contact lists and meeting notes. Standard access controls.
HR files, internal financial reports, client contracts. Authorised staff only.
Personal client data, medical records, payment details. Encryption, two-factor sign-in and strict access.

If your business holds client names (personal data) and product stock lists (not personal data), GDPR expects stronger protection for the first. Without classification, it is easy to apply the wrong level of security, or to overlook personal data altogether.
Classification makes it possible to identify the personal data you process, justify why you hold it, and protect it in proportion to the risk.
We help you list the kinds of data you hold, agree a level for each, and set up Microsoft 365, SharePoint and your file storage so the protections follow the label. Classification then feeds directly into access control.
Four (public, internal, confidential and restricted) works for most small businesses. Fewer levels are easier for staff to apply consistently.
We put these controls in place for small and medium businesses, and keep them there. Tell us how your business works.
See also
What UK GDPR and the Data Protection Act 2018 require of a small business, what the fines are, and the practical steps that protect client d
Role-based access control for small businesses: staff see only the data their job needs. Meets UK GDPR and Cyber Essentials access control r
Secure business laptops, phones and tablets: encryption, two-factor sign-in, password managers and device management, for UK GDPR and Cyber