Data Classification and Handling Policy template (SOC 2)

Defines the four data classification levels and the storage, transmission, sharing and disposal rules that apply to each.

Policy P06 of 22 · Owner: Security Owner · 2 criteria in the crosswalk · Apache-2.0

What this policy is for

The Data Classification and Handling Policy is one of the 22 governance policies in the Policyseed set. It is owned by the Security Owner, approved by the executive you name in the intake, and reviewed on the cadence you choose. Like every policy in the set it has nine numbered sections: purpose, scope, roles, policy statements, procedures, exceptions, enforcement, review cadence and a revision history table. Sections 4 and 5 carry the substance; those are the sections the Audit Kit rewrites for your named tools.

SOC 2 criteria this policy addresses

The Policyseed crosswalk maps 2 criteria to this policy. Each row names the section an auditor would read for that criterion; the criterion pages explain what it asks in plain words and list evidence examples.

CriterionWhat it coversWhere in this policy
CC6.7Data in transit and on removable mediaSection 4 (Policy Statements)
C1.1Identifying and protecting confidential informationSection 4 (Policy Statements)

Evidence auditors typically ask for

A policy is tested against artifacts. These are examples from the crosswalk for the criteria above, written for a small SaaS company; the Audit Kit ships the full list as an evidence checklist with an owner per row.

  • TLS configuration scan result for public endpoints (for example an SSL Labs report) showing TLS 1.2 or higher only
  • Data handling matrix from the Data Classification Policy listing approved sharing channels per classification
  • MDM policy screenshot restricting USB storage or requiring encrypted external drives
  • Data classification matrix listing the classification levels and handling rules for each
  • Data inventory or data map showing where confidential and personal data is stored
  • Retention schedule listing each data category and its retention period
  • Sample customer contract confidentiality clause

Full text: the Data Classification and Handling Policy rendered for Northwind Cloud Inc

Below is the complete template as the generator renders it for Northwind Cloud Inc, a fictional 11-50-person remote company running Northwind on AWS, Vercel, GitHub and Okta. Every name, tool and date comes from that sample intake; your answers replace them. Section headings carry anchors so the criterion pages can link straight to the section they cite.

Sample document

Northwind Cloud Inc Data Classification and Handling Policy

1. Purpose

Not all information needs the same protection, and treating everything as top secret is as unworkable as treating nothing that way. This policy gives Northwind Cloud Inc a four-level classification scheme and states, for each level, where data may be stored, how it may be transmitted, who it may be shared with, and how it is disposed of. It tells an engineer whether a dataset can go into staging and a salesperson whether a document can be emailed to a prospect.

2. Scope

This policy applies to all personnel of Northwind Cloud Inc and to all information that Northwind Cloud Inc creates, receives, stores or processes in any form, including data held in AWS and Vercel, in GitHub, in business applications such as Supabase, Stripe, Datadog and Slack, on endpoints, in backups and logs, and on paper. It covers the customer data that Northwind processes, which includes PII data, as well as internal business information, personnel records, source code and security records.

3. Roles and Responsibilities

  • Executive Management (Priya Natarajan, CEO) approves this policy and the classification scheme, and approves any external disclosure of Restricted information not already covered by a customer agreement.
  • Security Owner (Dana Whitfield, CTO) owns this policy, maintains the data inventory, decides classification where it is unclear, approves external sharing of Confidential and Restricted information, and monitors compliance.
  • Engineering implements the technical handling controls in AWS and Vercel and Northwind: encryption, access restrictions, classification tags, separation of production and non-production data, and secure deletion.
  • People Operations classifies and protects personnel records, and includes classification and handling in onboarding and annual training.
  • All Personnel classify information they create, handle it according to its level, apply the stricter level when in doubt, and report suspected mishandling to security@northwindcloud.example.

4. Policy Statements

  • 4.1 Northwind Cloud Inc classifies information into four levels. Public is approved for release to anyone. Internal is routine business information whose disclosure would cause limited harm. Confidential is information whose disclosure would harm Northwind Cloud Inc, its personnel or its partners, such as financial records, contracts, personnel data, source code and security configurations. Restricted is information whose disclosure would seriously harm customers or Northwind Cloud Inc or breach a legal or contractual obligation, including all customer data processed by Northwind, all PII data, credentials and encryption keys, and security incident details.
  • 4.2 The person who creates or first receives information classifies it; where unclear, the higher level applies until the Security Owner decides. Aggregations of Internal information that together reveal Confidential or Restricted facts take the higher level. Restricted and Confidential documents are labelled where the format allows, and systems holding Restricted data are tagged in the asset register and in AWS and Vercel.
  • 4.3 Restricted and Confidential information is stored only in systems the Security Owner has approved for that level and recorded in the data inventory. Customer data is stored only in the production environment of Northwind in AWS and Vercel and its managed backups, never on endpoints, in chat or tickets, in personal storage or in unapproved SaaS tools.
  • 4.4 Restricted information is encrypted at rest and in transit under the Encryption and Key Management Policy. Confidential information is encrypted in transit and, on endpoints or removable media, at rest. Encryption does not replace the access restrictions in the Access Control Policy.
  • 4.5 Access to Restricted information is limited to individuals with a documented need, granted under the Access Control Policy, reviewed quarterly and logged in Datadog. Access to Confidential information is limited to the teams that need it for their work.
  • 4.6 Production customer data is not copied into development, staging, test or analytics environments. Where realistic data is needed, Engineering uses synthetic data or data irreversibly anonymised through a process approved by the Security Owner.
  • 4.7 Confidential and Restricted information is shared externally only with a party under a signed agreement with confidentiality terms, through approved channels with encryption and access control, with the minimum content required, and with the information owner's approval; Restricted information additionally requires Security Owner approval unless it is being returned to the customer who owns it through Northwind. Public links, open shares and personal email are never used for these levels.
  • 4.8 Personal data is collected only for the purposes in the privacy notice of Northwind Cloud Inc, limited to what those purposes require, not repurposed without a lawful basis, and handled under the Privacy and Data Protection Policy. Requests from individuals to access, correct or delete their data are routed to the Security Owner within one business day.
  • 4.9 Northwind Cloud Inc does not knowingly process protected health information. Any proposal to send health data through Northwind is escalated to the Security Owner and Executive Management, who decide what controls and agreements are required before it is accepted.
  • 4.10 Northwind Cloud Inc does not process payment card data directly, and any future card acceptance is designed so that card data is handled only by a certified payment processor and never enters the systems of Northwind Cloud Inc.
  • 4.11 Information is retained only as long as the Data Retention and Disposal Policy requires and is then securely deleted, wiped or shredded. Customer data is deleted or returned at the end of the relationship on the timeline in the customer agreement.
  • 4.12 Information received from customers, partners or prospects under a non-disclosure agreement is classified as Confidential at minimum, recorded in the data inventory against the agreement, and protected for the duration the agreement requires.

5. Procedures

  • 5.1 Data inventory. The Security Owner maintains an inventory of the significant datasets and data stores of Northwind Cloud Inc, recording for each its description, classification, owner, hosting system, whether it contains PII data, retention period and any contractual confidentiality obligation. It is updated at each quarterly access review and whenever a new data store is introduced.
  • 5.2 Classifying a new dataset or system. Before a new data store, integration or SaaS tool receives company or customer data, the requester describes the data to the Security Owner, who assigns the level, records it in the data inventory and asset register, and confirms the system meets the requirements for that level. Engineering applies the corresponding tags in AWS and Vercel.
  • 5.3 External sharing. A person who needs to share Confidential or Restricted information externally raises a request naming the recipient, the agreement covering them, the content and the channel. The information owner approves Confidential sharing; the Security Owner additionally approves Restricted sharing. The approved channel is limited to named recipients, with expiring links where supported, and the request is retained as evidence.
  • 5.4 Non-production data. Engineering documents the source of data in every non-production environment. Where production-like data is genuinely needed, the requesting engineer proposes an anonymisation or synthesis method, the Security Owner approves it, and the resulting dataset is recorded in the inventory as Internal. Production credentials are never present in non-production environments.
  • 5.5 Restricted data access logging. Engineering ensures that access to production customer data stores is logged with identity, time and action in Datadog, and the Security Owner samples those logs monthly against approved tickets and incidents. Unexplained access is investigated within two business days.
  • 5.6 Quarterly exposure checks. The Security Owner reviews externally shared files and public links in Okta and the applications federated to it, checks storage on AWS and Vercel for publicly readable buckets or objects, and reviews GitHub for repositories whose visibility does not match their classification. Findings are corrected within five business days and recorded.
  • 5.7 Customer data requests. Requests from customers to export, correct or delete their data are logged on receipt, verified as coming from an authorised customer contact, executed by Engineering within the timeline in the customer agreement or applicable law, and confirmed in writing. Deletion covers primary storage and, on the backup rotation schedule, backups.
  • 5.8 Mishandling response. Misdirected or exposed information is reported to security@northwindcloud.example immediately; prompt self-reporting is never penalised. The Security Owner confirms the classification, works with the sender to recall or delete it, assesses whether customer or regulatory notification is required under the Incident Response Policy, and records the event and corrective action.

6. Exceptions

Exceptions, such as temporarily holding Confidential information in an unapproved tool during a migration, are approved in writing by the Security Owner, recorded in the exception register with compensating controls and an expiry date no later than twelve months out, and reviewed at each annual review. Exceptions affecting Restricted information additionally require approval from Priya Natarajan, CEO. No exception permits customer data in personal accounts or unapproved AI tools, or un-anonymised production data in non-production environments.

7. Enforcement

Information found outside the systems approved for its classification is removed or secured as soon as it is discovered. Personnel who share Confidential or Restricted information without approval, copy customer data to unapproved locations, or ignore the handling rules are subject to the disciplinary process in the Acceptable Use Policy, up to and including termination. Deliberate exfiltration of customer data is escalated to Executive Management immediately and may be referred to law enforcement.

8. Review Cadence

The Security Owner reviews this policy at the annual policy review, after any incident involving data exposure, and whenever Northwind Cloud Inc begins processing a new category of data or changes the scope of its SOC 2 examination. Revisions are approved by Priya Natarajan, CEO and recorded in section 9.

9. Revision History

VersionDateDescriptionApproved by
1.02026-09-02Initial releasePriya Natarajan, CEO

Frequently asked questions

Who should own the Data Classification and Handling Policy?
In the Policyseed template the Security Owner owns the Data Classification and Handling Policy: they maintain the text, run the procedures in section 5 and hold the evidence those procedures produce. The approver you name in the intake signs it, and section 8 sets the review cadence you choose (annual, semi-annual or quarterly).
Which SOC 2 criteria does the Data Classification and Handling Policy address?
2 criteria in the Policyseed crosswalk: CC6.7 (Data in transit and on removable media) and C1.1 (Identifying and protecting confidential information). Each mapping points at a numbered section of this policy, and the Audit Kit exports the same mapping as an Excel crosswalk with an evidence checklist.
Is the Data Classification and Handling Policy template free to use?
Yes. The template is Apache-2.0 licensed and the generator renders it in your browser with your company, stack and owner names filled in; nothing is stored server-side. The Audit Kit ($39 one-time) rewrites sections 4 and 5 for your named tools with Claude and adds Word documents, the crosswalk spreadsheet, acknowledgment forms and a review calendar. Refunds are available within 14 days on request. Policyseed provides governance policy templates, not legal advice; the CPA firm performs the examination.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.