Classify your own data
Sort a sample of your own files into classification levels and write the handling rules for each: where it may be stored, who may see it, and how it's shared and destroyed.
Environment
Your own files (just list them; nothing needs moving) and a spreadsheet.
Before you start
- Read Data Types (p.415), Data Classifications (p.417) and Privacy Data (p.420).
You will
- Apply classification labels
- Write handling rules per label
- Spot personal data
Steps
-
1
Choose four levels, e.g. Public, Internal, Confidential, Restricted.
-
2
List about 15 of your own files or data sets: CV, tax return, holiday photos, passwords export, study notes, and so on.
-
3
Label each one and mark any that contain personal data (PII) or financial data.
-
4
For each level, write the rules: storage location, encryption needed, who may access it, how it may be shared, and retention and destruction.
-
5
Find one file stored more loosely than its label allows and fix it, e.g. move it into an encrypted vault.
-
6
Note any file whose classification would change over time, e.g. data that becomes public after a date.
Check your understanding
- ?Which of your files would be most harmful in a privacy breach, and why?
- ?How do data owner and data custodian roles differ for these files?
- ?Why do handling rules matter more than the labels themselves?