Information Types
An information type is a specific category of information, such as medical, financial, privacy-related, or proprietary information, that an organization identifies so it can be handled and protected appropriately. Grouping data into these categories helps organizations decide what controls and policies should apply to each kind of information. The concept is about labeling and organizing information by its nature, not about any single specific data value.
In NIST usage, an information type is a specific category of information (for example privacy, medical, proprietary, financial, investigative, contractor sensitive, or security management information) defined by an organization or, in some cases, by law, executive order, directive, policy, or regulation. Under the SP 800-60 methodology, information types serve as the unit for mapping information to security categorization and, in proposed updates, for addressing privacy considerations during that process. Related but distinct is the vendor concept of 'sensitive information types' used in data loss prevention and classification tooling (for example in Microsoft Purview), which denotes machine-detectable patterns rather than the NIST categorization construct; these should not be conflated. This entry covers the categorization concept only and does not address impact-level assignment, control selection, retention rules, cross-border transfer, or how any given regime (such as the EU GDPR, UK GDPR, or HIPAA) defines special category or protected data, which are governed separately and differ by jurisdiction. Classifying data as a particular information type does not by itself determine its legal status as personal, special category, or non-personal data.
Why it matters
Information types provide the organizing foundation that lets an organization apply consistent, defensible handling rules to its data. Without a shared vocabulary of categories such as privacy, medical, financial, proprietary, or security management information, controls tend to be applied inconsistently, and it becomes difficult to demonstrate the deliberate, evidence-based decision-making that governance and accountability frameworks expect. Treating information type as an explicit unit of categorization allows security categorization, policy assignment, and stewardship responsibilities to be tied to something concrete rather than to ad hoc judgments about individual records.
The concept also matters because it is frequently conflated with things it is not. In NIST usage, an information type is a categorization construct defined by an organization or, in some cases, by law, executive order, directive, policy, or regulation. That is distinct from the vendor notion of 'sensitive information types' found in data loss prevention and classification tooling such as Microsoft Purview, which refers to machine-detectable patterns. Confusing the two can lead teams to assume that a detection rule in a DLP product is equivalent to a formal categorization decision, when in practice they operate at different levels and serve different purposes.
Equally important is what categorization does not do. Labeling data as a particular information type does not, by itself, determine its legal status as personal, special category, or non-personal data, and it does not resolve retention, cross-border transfer, or control-selection questions. Those determinations are governed separately and, in the case of legal status, differ by jurisdiction and by the specific regime in question. Organizations that treat an information type label as a legal conclusion risk misapplying obligations under regimes such as the EU GDPR, the UK GDPR, or HIPAA, each of which defines protected or special category data on its own terms.
Who it's relevant to
Inside Information Types
Common questions
Answers to the questions practitioners most commonly ask about Information Types.