Skip to main content

The Art of CTO Data Classification tool categorises an organisation's data assets by sensitivity level, mapping each class to the handling, retention, and access controls required by GDPR, HIPAA, PCI DSS, and similar regulations.

Frequently Asked Questions

What are the standard data classification levels?

Most organisations use four levels: Public (no harm if disclosed), Internal (routine business data), Confidential (would cause material harm if disclosed, such as customer records or financial data), and Restricted (regulated or highly sensitive data such as health records, payment card data, or credentials). Each level maps to specific encryption, access control, retention, and disposal requirements.

Why does data classification matter for compliance?

Nearly every major regulation assumes you know where your sensitive data is. GDPR requires data mapping for Article 30 records and DPIAs, HIPAA requires identifying protected health information, and PCI DSS requires scoping the cardholder data environment. Without classification you cannot demonstrate scope, which means you either over-control everything at great cost or under-control something and fail the audit.

How often should data classification be reviewed?

Review classification annually as a baseline, and immediately whenever you add a new data source, enter a new market with different regulations, or change a system that processes regulated data. Classification drifts quickly in fast-moving engineering orgs, so tying a review step to your architecture decision process is more reliable than a calendar reminder.