Legal & compliance centre

HLD Group

Data classification policy

Classification levels and handling requirements for information assets.

Last updated: 24 July 2026

Version 1.3 · Review cycle: 365 days · View all frameworks

1. Purpose

This policy establishes how HLD Group classifies information according to its sensitivity and the impact of its unauthorised disclosure, alteration, or loss, and how information of each classification must be handled. Consistent classification is the mechanism by which every other data-protection control — access, encryption, retention, and disposal — is applied proportionately.

2. Scope

This policy applies to all information created, received, stored, processed, or transmitted by HLD Group in any form or medium, and to all personnel, contractors, and systems that handle it, including customer data held under our management.

3. Classification levels

Public

Information approved for public release, whose disclosure causes no harm. Examples: published marketing, public documentation.

Internal

Information intended for internal use whose disclosure would cause limited harm. Examples: internal procedures, non-sensitive project material.

Confidential

Sensitive information whose disclosure could cause significant harm to HLD Group, customers, or individuals. Examples: customer data, contracts, source code, personal information.

Restricted

The most sensitive information, whose disclosure could cause severe harm or legal consequences. Examples: secrets and keys, regulated personal data, controlled or classified material, security-critical configuration.

4. Handling requirements by classification

  • Access — granted on least-privilege and need-to-know, with stricter controls at higher classifications
  • Encryption — Confidential and Restricted data encrypted at rest and in transit; Restricted may require additional controls such as field-level encryption
  • Storage — data stored only in approved locations appropriate to its classification
  • Transmission — Confidential and Restricted data sent only over encrypted channels and to authorised recipients
  • Labelling — information and systems labelled or tagged with their classification where practicable
  • Disposal — sanitised or destroyed under the Asset Management Policy commensurate with classification

5. Special categories of data

Certain data attracts additional legal obligations regardless of its general classification and is handled under the relevant specialised policy.

  • Personal information and sensitive information under the Privacy Act 1988 (Cth) and equivalent laws — see the Data Processing and Privacy arrangements
  • Special category data under the GDPR
  • Protected health information — see the HIPAA Safeguards Policy
  • Controlled unclassified and export-controlled information — see the CUI Handling Policy
  • Cardholder data under PCI DSS

6. Ownership and responsibilities

Every information asset has an owner responsible for assigning and reviewing its classification. Personnel are responsible for handling information according to its classification and for seeking guidance when unsure. When in doubt, information is treated at the higher classification until confirmed.

7. Framework alignment

  • ISO/IEC 27001:2022 Annex A controls 5.12 (classification of information) and 5.13 (labelling of information)
  • NIST SP 800-53 Rev. 5 control RA-2 (security categorization) and MP (Media Protection)
  • SOC 2 Trust Services Criteria CC6.1 and the confidentiality category (C1.1)

8. Exceptions and review

Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually.

Related frameworks

For contractual attestations or audit packs, contact [email protected].