GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

DAT-001 Data Classification Scheme

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A documented data classification scheme exists that categorises all information by sensitivity level (e.g. Public, Internal, Confidential, Restricted). All information assets are classified at creation or ingestion, and handling controls are proportionate to the assigned classification.

Rationale

Classification is the prerequisite for all other data protection controls. Without it, encryption strength, access scoping, retention periods and transfer rules cannot be applied proportionately.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (18)

DCS-06Assets Classificationfull
DSP-01Security and Privacy Policy and Procedurespartial
DSP-04Data Classificationfull
IAM-16Knowledge Access Control - Need to Knowinformative
DCS-06Assets Classificationfull
DSP-01Security and Privacy Policy and Procedurespartial
DSP-04Data Classificationfull
GDPR-Art.5.1cData Minimisationinformative
HIPAA-164.308.a.4.iInformation Access Managementinformative
5.12Classification of informationfull
5.13Labelling of informationinformative
AML.M0000Limit Public Release of Informationinformative
NIS2-CIR-12.1Asset Classificationpartial
NIS2-CIR-9Cryptographyinformative
AC-22Publicly Accessible Contentpartial
RA-2Security Categorizationfull
GV-6.1-001Third-Party AI Risk Policies | GV-6.1-001informative
C1.1Confidential Information Identification and Maintenancefull

Evidence (2)

policydocumentmanual

Data classification policy defining sensitivity tiers, their criteria, and handling requirements for each tier across storage, transmission, sharing and disposal.

Example: Data Classification Policy v2.1 (Confluence / Google Drive), approved by DPO and CISO, defining Public / Internal / Confidential / Restricted tiers with explicit handling rules per tier

Test: Request the data classification policy. Verify: (1) defines at least 3 distinct sensitivity tiers with unambiguous criteria for each, (2) specifies handling requirements for storage, transmission, sharing and disposal per tier, (3) document is approved by a named owner and dated within the last 12 months, (4) policy is accessible to all staff.

reportdocumentmanual

Data inventory or asset register showing each data asset classified against the published sensitivity tiers.

Example: Data Asset Register (Notion / spreadsheet), listing data stores, classification tier assigned, date last reviewed, and responsible data owner, exported at audit date

Test: Request the data asset register and the list of data stores held in the system component inventory. Verify: (1) every data store or data category in the register carries a classification drawn from the published scheme, (2) every data store holding personal data carries a classification, (3) every entry carries a last-reviewed date within the defined interval, (4) every data store present in the component inventory appears in the register, (5) every classification used in the register is one the scheme defines.

Questions (3)

boolean

Does your organisation maintain a documented data classification scheme?

The policy should define at least three tiers (e.g. Public / Internal / Confidential / Restricted) and specify handling rules for storage, transmission, sharing and disposal at each tier. It must be approved by a named owner and reviewed within the last 12 months.

select

How are data assets assigned a classification tier?

Automated classification tooling (e.g. DLP, sensitivity labels)Manual classification by data owners at creationClassification applied during periodic data inventory reviewsClassification is not consistently applied

Automated tooling provides the most reliable coverage at scale. Manual classification by data owners is acceptable for smaller or less dynamic data sets, provided a data inventory confirms consistent application.

multi

For which of the following does the classification scheme define handling controls at each sensitivity level?

StorageTransmissionSharing with third partiesDisposal and destructionLabellingNone of the above

A scheme that names sensitivity levels without saying what changes between them gives an asset owner nothing to apply. Answer against the scheme as written, not against what the organisation does in practice.