Skip to main content
Category: Data Classification

Information Types

Also known as: Information Type, Sensitive Information Types
Simply put

An information type is a specific category of information, such as medical, financial, privacy-related, or proprietary information, that an organization identifies so it can be handled and protected appropriately. Grouping data into these categories helps organizations decide what controls and policies should apply to each kind of information. The concept is about labeling and organizing information by its nature, not about any single specific data value.

Formal definition

In NIST usage, an information type is a specific category of information (for example privacy, medical, proprietary, financial, investigative, contractor sensitive, or security management information) defined by an organization or, in some cases, by law, executive order, directive, policy, or regulation. Under the SP 800-60 methodology, information types serve as the unit for mapping information to security categorization and, in proposed updates, for addressing privacy considerations during that process. Related but distinct is the vendor concept of 'sensitive information types' used in data loss prevention and classification tooling (for example in Microsoft Purview), which denotes machine-detectable patterns rather than the NIST categorization construct; these should not be conflated. This entry covers the categorization concept only and does not address impact-level assignment, control selection, retention rules, cross-border transfer, or how any given regime (such as the EU GDPR, UK GDPR, or HIPAA) defines special category or protected data, which are governed separately and differ by jurisdiction. Classifying data as a particular information type does not by itself determine its legal status as personal, special category, or non-personal data.

Why it matters

Information types provide the organizing foundation that lets an organization apply consistent, defensible handling rules to its data. Without a shared vocabulary of categories such as privacy, medical, financial, proprietary, or security management information, controls tend to be applied inconsistently, and it becomes difficult to demonstrate the deliberate, evidence-based decision-making that governance and accountability frameworks expect. Treating information type as an explicit unit of categorization allows security categorization, policy assignment, and stewardship responsibilities to be tied to something concrete rather than to ad hoc judgments about individual records.

The concept also matters because it is frequently conflated with things it is not. In NIST usage, an information type is a categorization construct defined by an organization or, in some cases, by law, executive order, directive, policy, or regulation. That is distinct from the vendor notion of 'sensitive information types' found in data loss prevention and classification tooling such as Microsoft Purview, which refers to machine-detectable patterns. Confusing the two can lead teams to assume that a detection rule in a DLP product is equivalent to a formal categorization decision, when in practice they operate at different levels and serve different purposes.

Equally important is what categorization does not do. Labeling data as a particular information type does not, by itself, determine its legal status as personal, special category, or non-personal data, and it does not resolve retention, cross-border transfer, or control-selection questions. Those determinations are governed separately and, in the case of legal status, differ by jurisdiction and by the specific regime in question. Organizations that treat an information type label as a legal conclusion risk misapplying obligations under regimes such as the EU GDPR, the UK GDPR, or HIPAA, each of which defines protected or special category data on its own terms.

Who it's relevant to

Information governance and data stewardship leads
Those responsible for ownership, classification, and policy assignment use information types as the unit around which stewardship and handling rules are organized. A clear, documented set of categories supports the demonstrable, evidence-based accountability that governance frameworks expect, rather than relying on stated intent alone.
Security categorization and risk practitioners
Practitioners applying the NIST SP 800-60 methodology treat information types as the input to security categorization. This entry addresses the categorization construct itself and not impact-level assignment or control selection, which are governed separately within the broader process.
Privacy and data protection officers
Privacy professionals should note that classifying data as a given information type does not by itself determine its legal status as personal, special category, or non-personal data. NIST has proposed updates to the categorization methodology to better account for privacy considerations, but legal determinations under regimes such as the EU GDPR, UK GDPR, or HIPAA differ by jurisdiction and must be assessed on their own terms.
Data loss prevention and tooling administrators
Administrators working with classification and DLP platforms, such as Microsoft Purview, should distinguish the vendor concept of machine-detectable 'sensitive information types' from the NIST categorization construct. The two operate at different levels and should not be treated as equivalent.

Inside Information Types

Personal Data
Information relating to an identified or identifiable natural person. This is the baseline category under regimes such as the EU GDPR and UK GDPR, and remains personal data even after pseudonymization or encryption where re-identification is reasonably possible.
Special Category / Sensitive Data
A distinct subset of personal data (for example, data revealing health, racial or ethnic origin, or biometric data used for identification under the EU/UK GDPR) that generally attracts heightened protections and additional conditions for processing. Note that the CCPA/CPRA uses its own concept of sensitive personal information, which is scoped differently and should not be treated as identical.
Pseudonymized Data
Data processed so it can no longer be attributed to a specific individual without additional information kept separately. It remains personal data because re-identification is reversible, and it stays within the scope of most data protection regimes.
Anonymized Data
Data rendered irreversibly non-identifiable such that individuals cannot be re-identified. Where anonymization is genuinely achieved, the data generally falls outside the scope of most data protection regulation. The threshold is high, and claims of anonymization should be tested against reasonable re-identification risk.
Non-Personal / Other Business Data
Information that does not relate to an identifiable individual, such as aggregated statistics or purely operational and technical data. Classification here should be evidenced rather than assumed, since mixed datasets can contain personal data.
Classification Basis and Governance Context
The criteria and ownership used to assign information types, spanning data governance concerns (stewardship, cataloging, lineage, data quality) and their intersection with information security controls (confidentiality, integrity, availability). Governance and security overlap here but remain distinct disciplines.

Common questions

Answers to the questions practitioners most commonly ask about Information Types.

Does classifying data by information type tell me whether it is personal data under the GDPR?
Not on its own. An information type taxonomy organizes data by category, sensitivity, or business purpose, but it is a governance construct rather than a legal determination. Whether a given element constitutes personal data under the EU GDPR or UK GDPR depends on whether it relates to an identified or identifiable natural person in context, and whether it falls into special category data is a separate legal test again. Two organizations may map the same field to different information types depending on their scheme, so the classification should inform, but not substitute for, a legal assessment of personal data status. This entry does not cover how those legal tests are conducted.
If an information type is labeled encrypted or tokenized, is it no longer personal data?
Generally no. Applying encryption or tokenization is a security control that reduces risk, but it does not by itself remove data from the scope of data protection regimes such as the EU GDPR or UK GDPR. Where the transformation is reversible, or where a party can restore identifiability using keys or mapping tables, the data typically remains personal data and, depending on regime, may be treated as pseudonymized rather than anonymized. An information type scheme may flag the protection state of data, but that label describes a control, not a legal reclassification. This entry does not address the technical mechanics of specific protection methods.
How granular should information types be when we build the scheme?
Granularity is typically driven by the decisions the scheme needs to support, such as access control, retention, and handling requirements. Categories that are too broad can obscure meaningful differences in sensitivity or obligation, while categories that are too fine can become unmaintainable and inconsistently applied. In most implementations, teams balance the number of types against the ability of data stewards to apply them reliably. This entry does not prescribe a specific number of tiers, as appropriate granularity depends on organizational context and the governance and security uses the scheme must serve.
Who is accountable for assigning and maintaining information types?
Accountability generally sits with data governance roles such as data owners and data stewards, who define the scheme and apply classifications to the data they are responsible for, often with input from privacy and security functions. Under governance frameworks, this accountability requires demonstrable evidence, meaning documented ownership, applied labels, and review records rather than a stated intention to classify. Note that governance ownership of the scheme is distinct from any legal role such as controller or processor, which is determined separately. This entry does not address how those legal roles are allocated.
How do information types relate to a records of processing activities obligation?
Information types can help structure and populate records that describe what data is processed, but the two are not the same thing. A records of processing activities obligation, where it applies under a regime such as the EU GDPR, has specific content requirements and is not satisfied merely by maintaining a classification scheme or a data inventory tool. Information types may feed such records and support consistency, yet the obligation must be met on its own terms. This entry does not detail the content or applicability conditions of records of processing activities requirements.
Can we use information types to drive retention and access controls automatically?
In many implementations, information types serve as a bridge between governance policy and operational controls, so that a classification can be mapped to handling rules for access, retention, and security. This supports both governance objectives such as data quality and lineage and security objectives such as confidentiality controls, without collapsing the distinction between them. Automation typically depends on classifications being applied accurately and consistently, which is why steward accountability matters. This entry does not specify retention periods or particular technical control configurations, as those depend on jurisdiction and implementation.

Common misconceptions

Encrypting, tokenizing, or pseudonymizing data removes it from the scope of data protection law.
These techniques are security or risk-reduction measures, not a change of legal status. Because they are generally reversible or dependent on separately held information, the data typically remains personal data under regimes such as the EU and UK GDPR. Only genuine, irreversible anonymization generally takes data out of scope, and that threshold is difficult to meet.
Special category or sensitive data is just personal data that happens to be more important.
It is a legally defined subset that generally requires additional conditions for lawful processing beyond those for ordinary personal data. Moreover, the definition differs by regime: the EU/UK GDPR special categories are not the same set as the CCPA/CPRA concept of sensitive personal information, so classification must be scoped to the applicable law.
Assigning an information type is a purely technical exercise handled by security tooling.
Classification is a governance activity involving ownership, stewardship, and documented criteria, and it interacts with but is not the same as information security controls. Accountability requires demonstrable evidence of how types were determined, not merely the output of a scanning tool.

Best practices

Define classification criteria explicitly and map each information type to the applicable regime (for example, EU GDPR, UK GDPR, CCPA/CPRA), since categories such as sensitive data are scoped differently across regimes rather than universally.
Treat pseudonymized, encrypted, or tokenized data as personal data by default, and reserve the anonymized classification only where irreversible non-identifiability can be evidenced against reasonable re-identification risk.
Assign clear ownership and stewardship for classification decisions, keeping governance responsibilities distinct from the security controls applied, while documenting where the two overlap.
Maintain demonstrable evidence of how information types were determined, recognizing that accountability under governance frameworks requires documented justification rather than stated intent.
Re-examine classification for mixed datasets, since aggregated or operational data can still contain personal data and should not be assumed non-personal without review.
Coordinate with legal and privacy functions before relying on a classification to draw scope conclusions, as this determination alone does not address lawful basis, cross-border transfer mechanics, retention, or enforcement, which are out of scope for classification itself.