Skip to content
Sections
All notes

All notes · Risk

Data Classification Before Anything Else

Rules about tools cannot work. Rules about information can, and they need a classification simple enough that people apply it.

Risk · Procedure

The durable rule is not "do not use that tool" but "do not put that kind of information anywhere unapproved". That requires people to know what kind of information they are holding.

The controls in “Data Classification Before Anything Else” only remain useful when someone owns the reviews, exceptions and follow-up work. An organisation evaluating project time tracking can attach time and responsibility to those recurring governance tasks, but the platform should support the policy rather than decide whether an AI use case is acceptable.

For an independent benchmark, compare the local approach with ICO artificial-intelligence guidance; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.

Why tool-based rules fail

Tools change monthly and the list is always out of date.

Approved tools gain AI features, so the approval no longer means what it meant.

And the rule gives no guidance for a tool not on either list, which is most of them.

Classification-based rules survive all three, because the categories change slowly and the judgement sits with the person holding the data.

The simplest workable scheme

Three levels, not five.

Public: already published or publishable.

Internal: ordinary business information, embarrassing but not damaging if disclosed.

Confidential: client data, personal data, regulated data, commercially sensitive material.

Most organisations with a five-level scheme find that nobody can distinguish levels two and three, and the scheme is ignored in full.

The rule that follows

Public: any tool.

Internal: approved tools only.

Confidential: approved tools with an enterprise agreement, or not at all.

Three lines. Somebody can remember them and apply them without consulting a document.

Making it usable

Give examples rather than definitions. "A client contract is confidential. A draft internal email is internal. Our published price list is public."

Five examples per level, drawn from your own work, beats a page of criteria.

And handle the common case explicitly: most of what people want to do with AI tools is internal or public, and saying so removes the fear that makes people hide ordinary use.

Where it gets hard

Mixed documents: a mostly-internal report with two confidential figures.

The honest guidance is to treat the document as its highest classification, and to teach people to extract the part they need.

Which is also the fix for the paste problem — selecting the paragraph rather than the file.

The prerequisite nobody wants

This requires that your organisation has a classification scheme people actually use, and many do not.

If yours exists on paper only, this programme will need to revive it, which is a larger piece of work than the AI question itself.

Say that early rather than discovering it in month three.

What to check

Do you have a classification scheme, and can a random colleague state its levels?

Are there examples, or only definitions?

Does your AI policy reference classification or tool names?

And what is the guidance for a mixed document?

The point

Rules about tools are obsolete within a quarter.

Rules about information categories survive, because the categories change on a scale of years.

Underlying all of this

Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.

The recurring pattern

The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.