All compliance pages

Data Classification Policy

Last reviewed: Updated 2025

Policy defining levels of sensitivity, storage guidelines, and access rights for corporate data.

DATA CLASSIFICATION POLICY

Policy Overview

Document Control
Reference No.DJTMPL/IT/POL/DCP
Document NameData Classification Policy
Policy OwnerChief Operation Officer
Policy Approving AuthorityBoard Of Directors
Version No.2.0
Document StatusDefinitive
Review Date01-04-2026
Next Review Period01-04-2027
Security ClassificationInternal Use Only
DistributionDJTMPL

Document Revision History

VersionRelease DateChange Description
1.001-06-2024First version
2.001-04-2026Enhanced with additional roles, impact level guidelines, audit & review framework, violation reporting mechanism, and expanded data examples

Table of Contents

S.NoParticulars
1Overview
2Purpose
3Scope
4Definitions
5Data Classification
6Roles and Responsibilities
7Guidelines for Determination of Impact Levels
8Data Classification Workflow
9Requirements
10Exceptions/Waivers
11Policy Compliance
12Reporting Violations
Annexure I
Annexure II

1.0 Overview

Data classification is the process of organizing data into categories for its most effective and efficient use. A well-planned data classification system makes essential data easy to find and retrieve. This is of critical importance for risk management, legal discovery, and regulatory compliance.

Data classifications help DJTMPL meet common compliance standards, including:

    • GDPR — Upholding data subject rights and satisfying access requests
    • HIPAA — Implementing security controls for health record protection
    • ISO 27001 — Preventing unauthorized disclosure or modification based on value and sensitivity
    • NIST SP 800-53 — Proper architecture and management of IT systems
    • PCI DSS — Identifying and securing consumer financial information in payment processing

2.0 Purpose

The purpose of this Policy is to establish a framework for classifying organizational data based on its level of sensitivity, value, and criticality to DJTMPL, as required by DJTMPL Information Security Policy. Classification of data will aid in determining baseline security controls for the protection of data.

Benefits of data classification for DJTMPL include:

    • Prioritizing security measures and adjusting controls based on data sensitivity
    • Clearly defining who can access, modify, or delete data
    • Assessing risks, including the business impact of a breach, ransomware attack, or other threat
    • Assigning specific responsibilities to information owners, custodians, and users
    • Establishing consistent and appropriate controls across all functions of the organization

3.0 Scope

This policy applies to any form of data, including paper documents and digital data stored on any type of media. It applies to all DJTMPL employees, as well as to third-party agents authorized to access the data.

Specifically, this policy covers:

    • All information assets within DJTMPL Asset Management Policy and Information Asset Register
    • All critical information — whether stored or transmitted — in the possession of or under control of DJTMPL
    • Confidential information entrusted to DJTMPL by customers, suppliers, business partners, and others
    • Third-party information, which must be protected with the same care as DJTMPL own data

Note: No distinction is made between the terms 'data,' 'information,' and 'knowledge,' or between 'classification' and 'categorization' in this policy.

4.0 Definitions

TermDefinition
ConfidentialityPrivate or confidential information should not be disclosed to unauthorized individuals.
IntegrityInformation or systems should be protected from intentional, unauthorized, or accidental changes.
AvailabilitySystems, functions, and data must be available on-demand according to agreed-upon parameters.
PII (Personally Identifiable Information)Information that, on its own or combined, can be used to identify, locate, or contact an individual.
PHI (Protected Health Information)Information that can be used to identify an individual AND relates to their past, present, or future physical or mental health care or health care payments.
Data OwnerSenior management member ultimately responsible for the data collected and maintained by their department.
Data CustodianIT or functional team member responsible for technical management, security, and integrity of data.
Data StewardPerson responsible for data quality, definitions, standards, and ensuring data supports all business and regulatory requirements.
Data UserAny employee or contractor who accesses DJTMPL data assets to fulfil their authorized responsibilities.

5.0 Data Classification

Data classification, in the context of information security, is the classification of data based on its level of sensitivity and the impact to the organization should that data be disclosed, altered or destroyed without authorization. All DJTMPL data must be classified into one of four sensitivity levels:

ClassificationAlso Known AsDescriptionImpact Level
PublicPublicFreely available information with no authentication or authorization requirementsLow
PrivateInternalInformation that, if disclosed, altered or destroyed, could result in moderate risk. Default classification for all unclassified data.Medium
ConfidentialConfidentialSensitive data that, if compromised, could negatively impact operations, harm the company, customers, partners or employees.High
RestrictedRestricted / SecretHighest sensitivity. Unauthorized disclosure could cause significant risk to the company or its affiliates. Requires strongest security controls.Critical

5.1 Public Data

Information with no authentication or authorization requirements, freely available to the general public. While little or no controls are required to protect confidentiality, some level of control is required to prevent unauthorized modification or destruction.

Examples include:

    • Press releases and publicly posted job announcements
    • Product information and price lists
    • Publicly available manuals and marketing brochures
    • Information provided on DJTMPL public website

5.2 Private Data (Internal)

Information restricted based on job responsibility or to a group of employees or authorized third-party users. By default, all company data that is not explicitly classified as Restricted or Public should be treated as Private. Its unauthorized disclosure may harm the organization, its customers, associates, or business partners.

Examples for DJTMPL (Company):

    • Minutes of meetings
    • Vendor contracts and technical documentation for data transfers
    • Internal communications such as HR circulars
    • Information security awareness communications
    • Vendor employees working with/at DJTMPL

Examples for Customers/Business Customers:

    • Home/business telephone numbers and cellular numbers
    • Mailing address, billing address, or address of record

Examples for Associates:

    • Home telephone number and mailing address
    • Associate performance appraisals
    • Time and expense data

5.3 Confidential Data

Sensitive data that, if compromised, could negatively impact DJTMPL operations, including harming the company, its customers, partners, or employees. Strict limitations are placed on internal access and external disclosure.

Examples include:

    • Non-disclosure agreements with clients/vendors
    • Employee reviews and salaries
    • Customer information (detailed financial records)
    • Departmental financial records
    • Corporate-level strategic plans
    • Engineering drawings and proprietary business data

5.4 Restricted Data

The highest level of classification. Unauthorized disclosure, alteration, or destruction could cause significant risk to DJTMPL or its affiliates. Highest level of security controls must be applied.

Examples include:

    • Customer and client Personally Identifiable Information (PII)
    • Credit card and financial payment information
    • Medical or health information (PHI)
    • Bank account numbers and financial institution details
    • Data protected by DJTMPL privacy regulations and confidentiality agreements

6.0 Roles and Responsibilities

The roles and responsibilities associated with data classification at DJTMPL are defined below. Departments shall designate individuals responsible for carrying out the duties of each role. All users must classify their work products to enable adequate safeguards, in compliance with the Information and Cyber Security Policy.

6.1 Data Owner (Business / Functional Heads)

The person who is ultimately responsible for the data and information being collected and maintained by their department. Usually a member of senior management. Data Owners must make decisions about who will be permitted to gain access to information and the uses to which it will be put.

Key responsibilities:

    • Review and categorize data collected by the department
    • Assign data classification labels based on defined impact levels
    • Ensure data compiled from multiple sources is classified at the most secure level of any component
    • Ensure consistent classification and protection of data shared between departments
    • Develop data access guidelines for each classification label
    • Ensure compliance with applicable regulatory and legal requirements for high/moderate impact data

6.2 Data Custodian

Data custodians are responsible for the everyday control of data including security, scalability, configuration management, availability, accuracy, consistency, audit trail, backup and restore, technical standards, policies and business rule implementation.

Key responsibilities:

    • Ensure proper access controls are implemented, monitored, and audited per classification labels
    • Submit annual reports to data owners on availability, integrity, and confidentiality of classified data
    • Perform regular data backups and periodic integrity validation
    • Restore data from backup media as needed
    • Encrypt sensitive data at rest; audit storage activity and review access logs periodically
    • Monitor and record data activity, including who accessed what data
    • Ensure Confidential and Internal/Private data is secured per DJTMPL IT security policies
    • Maintain version history and change management for master data

6.3 Data Steward

Data Stewards are responsible for the quality of data, including business controls, data content, and metadata management. They work with stakeholders to develop definitions, standards, and data controls, and ensure data supports all business needs and regulatory requirements.

Key responsibilities:

    • Develop data definitions, standards, and business data controls
    • Sponsor data quality, data acquisition, and data entry initiatives
    • Ensure data quality issue resolution in partnership with Data Custodians
    • Support the Data Classification Workflow process

6.4 Data User

Employees and contractors may be assigned roles and provided access to data assets to fulfil their responsibilities. Any person, organization, or entity that interacts with, accesses, uses, or updates DJTMPL data for the purpose of performing an authorized task must:

    • Use permissions in a manner consistent with the intended purpose
    • Comply with this policy and all applicable data use policies
    • Immediately report any suspected misuse, unauthorized access, or policy violations to the IT team

7.0 Guidelines for Determination of Impact Levels

The following table is used to ascertain impact levels based on the Confidentiality, Integrity, and Availability of data (CIA Triad). As the total potential impact to DJTMPL increases from Low to High, the classification of data should become more restrictive, moving from Public to Restricted.

Security ObjectiveLowModerateHigh
Confidentiality (Restrict unauthorized access & disclosure)Unauthorized disclosure expected to have limited adverse effect on operations, assets, or individuals.Unauthorized disclosure expected to have a serious adverse effect on operations, assets, or individuals.Unauthorized disclosure expected to have a severe or catastrophic adverse effect on operations, assets, or individuals.
Integrity (Guard against improper modification or destruction)Unauthorized modification or destruction expected to have a limited adverse effect on operations, assets, or individuals.Unauthorized modification or destruction expected to have a serious adverse effect on operations, assets, or individuals.Unauthorized modification or destruction expected to have a severe or catastrophic adverse effect on operations, assets, or individuals.
Availability (Ensure timely & reliable access)Disruption of access expected to have a limited adverse effect on operations, assets, or individuals.Disruption of access expected to have a serious adverse effect on operations, assets, or individuals.Disruption of access expected to have a severe or catastrophic adverse effect on operations, assets, or individuals.

8.0 Data Classification Workflow

The following steps guide employees in determining the appropriate classification for data:

    • Step 1: Confirm you are the Data Steward for the data in question. If not, consult the designated Data Steward.
    • Step 2: Determine if the data is governed by any law or regulation. If yes, classify as Restricted.
    • Step 3: Determine if the data is governed by a Data Use Agreement or Confidentiality Agreement. If yes, classify as Restricted.
    • Step 4: Assess if there are significant consequences to DJTMPL if the data is exposed, altered, or destroyed. If yes, classify as Restricted; if unsure, use the Data Classification Guidelines.
    • Step 5: Assess if there are moderate consequences to DJTMPL. If yes, classify as Private. If no, classify as Public.

9.0 Requirements

All information must be classified. Assigning a classification to information is the responsibility of the data owner. Classification must be based on:

    • Applicable legal and contractual requirements
    • Risks and threats to the data, including sensitivity and criticality to DJTMPL

Classification levels must be reviewed periodically and any changes communicated to the data owner, custodian, and user. The information owner is responsible for maintaining data classification documentation and providing oversight of proper data handling.

10.0 Exceptions / Waivers

Waivers to this policy must be formally submitted for approval to the Group IT Head at DJTMPL, along with a detailed justification including benefits attributed to the waiver. The following conditions apply:

    • Waivers are permitted only in exceptional situations for a specific case or defined period
    • After the specified period, the need for the waiver will be reassessed and re-approved by the Group IT Head
    • The DJTMPL IT team will monitor the waiver to ensure compliance with the specified period and exception
    • Exceptions must be approved and signed by appropriate officials as decided by Top Management
    • If exceptions may circumvent internal controls, Mitigating or Compensating Controls must be implemented
    • The Information Systems Security Committee must be involved when internal security controls are bypassed

11.0 Policy Compliance

11.1 Compliance Measurement

The Infosec team will verify compliance to this policy through various methods, including but not limited to business tool reports, internal and external audits, and feedback to the policy owner.

11.2 Review and Audit

Data classification and applied security controls may be evaluated at any time in accordance with DJTMPL Information Technology Policy. The following apply:

    • This policy will be reviewed annually, or earlier if there are significant changes in DJTMPL business or regulatory environment
    • Any identified deficiencies or control weaknesses will be documented and reported to relevant department heads
    • Depending on severity, audit findings may be treated as a security incident and handled per the Manage Problems and Incidents Procedure

12.0 Reporting Violations

All individuals with access to DJTMPL resources are required to immediately report any of the following to the IT team:

    • Unauthorized access, disclosure, modification, or deletion of DJTMPL data
    • Insufficient controls or identified weaknesses in data protection
    • Improper risk classifications or mislabelled data

12.1 Non-Compliance Consequences

Non-compliance with this policy may result in disciplinary action, including but not limited to:

    • Suspension
    • Termination of employment or contract
    • Other disciplinary action
    • Civil and/or criminal prosecution

ANNEXURE I

Data Security Standards

Employee Personally Identifiable Information (PII)

The following data elements constitute Employee PII and must be handled with appropriate controls:

    • Aadhaar number
    • Bank account information
    • Home address
    • Personal telephone / mobile number
    • Personal email address
    • Family members' details

Client Personally Identifiable Information (PII)

The following data elements constitute Client PII:

    • Full name
    • Aadhaar number / Passport / Driver's License / PAN number
    • Bank account information
    • Home address
    • Personal telephone / mobile number / email address
    • IP address

Client Confidential Data — Handling Standards

The following rules apply to all Client Confidential Data:

    • Must be protected from disclosure by law, regulation, or contract
    • Can only be viewed on designated systems/reports
    • Can be stored in the form of databases, documents, and images
    • Client PII and PHI must be encrypted at all times
    • More than one Client PII/PHI record must not be stored on any personal system or device
    • More than one Client PII/PHI record must not be sent via email
    • More than one Client PII/PHI record must not be exported to any external document (xls, csv, doc, pdf, etc.)
    • More than one Client PII/PHI record must not be printed in a single document
    • Client confidential data must be permanently removed when no longer required, as per the data retention policy

ANNEXURE II

Summary of Changes: v1.0 vs v2.0

The table below summarizes key changes made in Version 2.0 of this policy compared to Version 1.0, incorporating enhancements where relevant and applicable to DJTMPL.

SectionOld Policy (v1.0)New Policy (v2.0) — Changes Made
Classification Levels
    • 3 levels: Restricted, Confidential, Private, Public
    • 4 levels retained (Public/Internal/Confidential)
    • Added 'Also Known As' column for cross-reference clarity
Roles & Responsibilities
    • Data Owner, Data Custodian, Data Steward only
    • Added Data User role
    • Expanded Data Owner duties: label assignment, cross-dept coordination, data compilation rules
    • Expanded Data Custodian duties: secure storage, encryption, access logging, restoration
Impact Level Guidelines
    • Basic Low/Moderate/High impact table for Confidentiality only
    • Full CIA triad table added (Confidentiality + Integrity + Availability)
    • Detailed descriptors for each impact level per security objective
Data Examples
    • Limited examples under each classification
    • Extended examples covering: Company, Customers, Business Customers, Associates, Third Parties
    • Added PII/PHI definitions with India-specific identifiers (Aadhaar, PAN)
Exceptions / Waivers
    • Exceptions approved by Top Management; mitigating controls required
    • Approval authority clarified as Group IT Head
    • Added periodic reassessment and re-approval requirement
    • IT team monitoring of waiver compliance added
Review & Audit
    • Compliance verification via audits & reports only
    • Annual policy review cycle formalized
    • Audit findings may be escalated as security incidents
    • Triggers for earlier review: major business or regulatory changes
Violation Reporting
    • Non-compliance can lead to suspension, termination, or prosecution
    • Added mandatory immediate reporting obligation for all users
    • Covers: unauthorized access, disclosure, modification, deletion, insufficient controls, and improper risk classifications
Data Security Standards
    • Annexure I with basic PII/PHI handling rules
    • Retained and enhanced with encryption, storage, and transmission controls
    • Added data retention and secure deletion requirements