Sensitivity Levels
Sensitivity levels are labels that rank data according to how much protection it needs, so that more damaging information receives stronger controls than routine information. Organizations commonly use a small set of tiers, such as Public, Internal, Confidential, and Restricted, to guide how data should be stored, shared, and secured. The right number and names of tiers vary by organization and are a matter of internal policy rather than a single universal standard.
A sensitivity level is a classification value assigned to a data asset (for example a project, table, file store, or document) that expresses the degree of protection warranted, generally framed in terms of the potential impact on confidentiality, integrity, and availability if the data were exposed or compromised. In practice, schemes typically use a small ordered set of tiers, such as Public, Internal/General, Confidential, and Restricted/Highly Confidential, that map to differentiated handling, access, and security controls. Sensitivity classification is primarily a data governance construct that supports control selection; it should not be conflated with information security controls themselves, which enforce the protections that a given level implies. It is also distinct from regulatory categories: a high sensitivity level does not automatically equate to 'personal data' or 'special category / sensitive data' under a specific legal regime such as the EU GDPR or UK GDPR, and applicable classification of regulated data must be determined against the relevant instrument. This entry defines the concept only; it does not specify a mandated taxonomy, retention rules, cross-border transfer treatment, or the specific technical controls required at each tier, all of which depend on jurisdiction, sector, and implementation. Accountability under governance frameworks generally requires that assigned levels and their handling rules be documented and demonstrable, not merely stated.
Why it matters
Sensitivity levels are the connective tissue between an organization's data governance policy and the protective controls it actually applies. Without a consistent way to rank data by the degree of protection it warrants, organizations tend to over-protect routine information (adding friction and cost) while under-protecting the data whose exposure would be most damaging. A workable tiered scheme, such as Public, Internal, Confidential, and Restricted, lets teams make repeatable decisions about how data should be stored, shared, and secured, and gives auditors a reference point against which handling can be checked.
The practical value depends on the labels being applied consistently and on the handling rules being documented rather than merely assumed. Sensitivity classification is a governance construct that guides which controls to select; it does not itself enforce anything. A high sensitivity level tells you data warrants strong protection, but the confidentiality, integrity, and availability controls that deliver that protection are a separate matter of information security implementation. Organizations that treat the label as the safeguard, rather than as a trigger for safeguards, leave a gap between stated policy and actual protection.
Who it's relevant to
Inside Sensitivity Levels
Common questions
Answers to the questions practitioners most commonly ask about Sensitivity Levels.