Skip to main content

The Art of CTO Data Classification tool builds an inventory of an organisation's data assets, assigning each a sensitivity level from public to restricted with the handling requirements that level implies, and tagging which regulations apply to it — GDPR, HIPAA, PCI DSS, CCPA, SOX, FERPA or GLBA. The inventory exports to Excel. It does not map controls to specific regulatory clauses.

What data do we actually hold, and how sensitive is it?

A classified inventory of your data assets by sensitivity and applicable regulation, exportable to Excel.

About 20 min · Generator · Pro

About this toolWhy it matters, common mistakes, FAQ

Do You Know What Data You Are Holding?

Every privacy obligation you have — retention, access requests, breach notification, cross-border transfer — presumes you can say what data exists and how sensitive it is. Without that inventory, each obligation becomes a manual investigation under time pressure.

Classification is done once, as a spreadsheet, and is stale within a quarter. What keeps it honest is tying it to the systems that create data, so a new service or a new field shows up as a classification decision rather than a surprise.

Questions CTOs ask

What are the standard data classification levels?
Most organisations use four levels: Public (no harm if disclosed), Internal (routine business data), Confidential (would cause material harm if disclosed, such as customer records or financial data), and Restricted (regulated or highly sensitive data such as health records, payment card data, or credentials). Each level maps to specific encryption, access control, retention, and disposal requirements.
Why does data classification matter for compliance?
Nearly every major regulation assumes you know where your sensitive data is. GDPR requires data mapping for Article 30 records and DPIAs, HIPAA requires identifying protected health information, and PCI DSS requires scoping the cardholder data environment. Without classification you cannot demonstrate scope, which means you either over-control everything at great cost or under-control something and fail the audit.
How often should data classification be reviewed?
Review classification annually as a baseline, and immediately whenever you add a new data source, enter a new market with different regulations, or change a system that processes regulated data. Classification drifts quickly in fast-moving engineering orgs, so tying a review step to your architecture decision process is more reliable than a calendar reminder.

Related Reading