The Art of CTO Data Classification tool builds an inventory of an organisation's data assets, assigning each a sensitivity level from public to restricted with the handling requirements that level implies, and tagging which regulations apply to it — GDPR, HIPAA, PCI DSS, CCPA, SOX, FERPA or GLBA. The inventory exports to Excel. It does not map controls to specific regulatory clauses.
What data do we actually hold, and how sensitive is it?
A classified inventory of your data assets by sensitivity and applicable regulation, exportable to Excel.
About 20 min · Generator · Pro
About this toolWhy it matters, common mistakes, FAQ
Do You Know What Data You Are Holding?
Every privacy obligation you have — retention, access requests, breach notification, cross-border transfer — presumes you can say what data exists and how sensitive it is. Without that inventory, each obligation becomes a manual investigation under time pressure.
Classification is done once, as a spreadsheet, and is stale within a quarter. What keeps it honest is tying it to the systems that create data, so a new service or a new field shows up as a classification decision rather than a surprise.
Questions CTOs ask
- What are the standard data classification levels?
- Most organisations use four levels: Public (no harm if disclosed), Internal (routine business data), Confidential (would cause material harm if disclosed, such as customer records or financial data), and Restricted (regulated or highly sensitive data such as health records, payment card data, or credentials). Each level maps to specific encryption, access control, retention, and disposal requirements.
- Why does data classification matter for compliance?
- Nearly every major regulation assumes you know where your sensitive data is. GDPR requires data mapping for Article 30 records and DPIAs, HIPAA requires identifying protected health information, and PCI DSS requires scoping the cardholder data environment. Without classification you cannot demonstrate scope, which means you either over-control everything at great cost or under-control something and fail the audit.
- How often should data classification be reviewed?
- Review classification annually as a baseline, and immediately whenever you add a new data source, enter a new market with different regulations, or change a system that processes regulated data. Classification drifts quickly in fast-moving engineering orgs, so tying a review step to your architecture decision process is more reliable than a calendar reminder.
Related Reading
PCI DSS compliance checklist for startups: a companion guide to the PCI DSS Checker
PCI DSS compliance checklist for startups: a companion guide to the PCI DSS Checker
insightsThe New AI Stack Is a Context Layer: Governance, Semantics, and Routing Are Becoming the Real Differentiators
AI agent deployments are shifting from prompt-centric prototypes to context-engineered, governed, and cost-managed production systems—where the differentiator is the enterprise “context layer” (data...
insightsMid Week Summary: Agentic Governance, Real-Time Data Platforms, and Macro Risk (Energy, Inflation, and Fraud)
The pattern this week: “agents” are easy—operating them safely is the hard part