DPDP NavigatorAct 2023 · Rules 2025
All templates
PoliciesSection 8

Data Classification Policy Template

A policy establishing data sensitivity tiers and corresponding handling controls to support DPDP security safeguard obligations.

Template
DATA CLASSIFICATION POLICY

[Organization Name]
Effective Date: [Effective Date] | Policy Owner: [CISO / DPO]

1. PURPOSE
This Policy establishes a classification scheme for all data handled by [Organization Name], enabling proportionate security safeguards for personal data as required under Section 8(5) of the DPDP Act, 2023, which mandates reasonable technical and organisational measures to prevent personal data breaches.

2. SCOPE
Applies to all data — digital and physical — created, received, or processed by [Organization Name], including personal data of employees, customers, vendors, and other Data Principals.

3. CLASSIFICATION TIERS

   Tier 1 — Public: Data intended for unrestricted public disclosure (e.g., marketing brochures, published pricing). No special handling required.

   Tier 2 — Internal: Non-sensitive business data not intended for public release (e.g., internal memos, non-personal operational reports). Access restricted to employees; no external sharing without approval.

   Tier 3 — Confidential Personal Data: Personal data such as name, contact details, order history, and employment records that identify a Data Principal. Requires access controls, encryption in transit, and logging of access.

   Tier 4 — Sensitive Personal Data: Personal data carrying heightened risk of harm if compromised — financial account details, government ID numbers, health records, biometric data, and children's data. Requires encryption at rest and in transit, multi-factor access controls, masking/tokenisation where feasible, and enhanced audit logging retained per the DPDP Rules, 2025 baseline (minimum one year for access logs, or longer as prescribed).

4. HANDLING MATRIX (illustrative)
   | Control                     | Tier 2 | Tier 3 | Tier 4 |
   |------------------------------|--------|--------|--------|
   | Access restricted to need-to-know | Recommended | Required | Required |
   | Encryption in transit         | Optional | Required | Required |
   | Encryption at rest            | Optional | Recommended | Required |
   | Access logging                | Optional | Required | Required |
   | External sharing requires DPA | No     | Yes    | Yes    |
   | Masking/tokenisation in non-prod environments | N/A | Recommended | Required |

5. LABELLING
All systems, folders, and documents containing Tier 3 or Tier 4 data must be labelled accordingly in [document management system/database schema] to support automated policy enforcement.

6. DATA INVENTORY LINKAGE
Each classified dataset must be recorded in the organisation's Record of Processing Activities, noting classification tier, purpose, legal basis (consent or Section 7 legitimate use), and retention period per the Data Retention Policy.

7. THIRD-PARTY SHARING
Tier 3 and Tier 4 data may only be shared with processors or partners under a Data Processing Agreement that mirrors the security obligations in this Policy, consistent with Section 8(2) of the DPDP Act.

8. SIGNIFICANT DATA FIDUCIARY CONSIDERATIONS
Where [Organization Name] is notified as a Significant Data Fiduciary under Section 10, Tier 4 datasets shall be included within the scope of the mandatory Data Protection Impact Assessment and periodic independent audit.

9. INCIDENT LINKAGE
Any suspected compromise of Tier 3 or Tier 4 data must be reported immediately under the Data Breach Response Policy.

10. TRAINING AND ENFORCEMENT
All employees handling Tier 3/4 data must complete classification-handling training at induction and annually. Non-compliance is subject to disciplinary action under [HR Policy reference].

11. REVIEW
This Policy is reviewed [annually] and updated to reflect changes in the DPDP Rules, 2025 baseline requirements or business data footprint.

Approved by: [Name, Designation] Date: [Date]

This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.