Data Classification Review Checklist Template

Most organisations wrote a classification policy once, chose four labels and moved on. A few years later half the files carry no label, the rest say Internal because that was the default, and nobody can say for certain where the restricted data lives.

A classification scheme is only useful if people apply it and the controls downstream respect it. Data loss prevention rules, encryption, sharing settings and access reviews all key off the level a piece of information carries. When the labels are wrong or missing, those controls protect the wrong things. This free data classification review checklist is for information security managers, data protection officers and information governance leads who run the periodic check of the scheme and how well it is applied: once a year as a baseline, and again after a merger, a new core system or a change in the law. Seven phases cover the scheme itself, the data inventory and its owners, sample checks of labelled and unlabelled content, label coverage and auto-labelling, handling rules and regulated data, alignment with DLP, access and training, and the exceptions and sign-off that close the cycle.

Use This Template Free See Live Example
No Credit Card Required

Classification Asks How Sensitive. Retention Asks How Long.

Classification ranks information by the harm its loss or misuse would cause, then attaches handling rules to each rank. ISO/IEC 27001:2022 Annex A 5.12 asks for information to be classified by its confidentiality, integrity and availability needs and the requirements of interested parties, and 5.13 asks for labelling procedures that follow the scheme. Commercial schemes usually settle on four levels, often called Public, Internal, Confidential and Restricted, though the names vary. Government schemes differ. The UK Government Security Classifications Policy, updated in June 2023, has three tiers (OFFICIAL, SECRET and TOP SECRET), with -SENSITIVE as an additional marking on OFFICIAL information rather than a fourth tier. US federal agencies categorise information and systems as low, moderate or high impact under FIPS 199. If you hold government or defence contracts, your scheme has to map to theirs.

Schemes drift for predictable reasons. New kinds of data arrive that nobody placed in a level. A default label of Internal quietly becomes the label for everything. Staff over-classify to be safe, and when everything is Confidential the word stops meaning anything. Under-classification is worse, because it lets restricted data travel through channels built for internal memos. A review finds these patterns while they are still small. It is a different exercise from a retention review, which asks how long each record class is kept and how it is destroyed. The two can share an inventory, but they answer different questions.

Classification scheme

The rule

Holds: the levels, a definition and examples for each, and the handling rules that go with them.

Owner: the information security manager or CISO, approved by senior management.

Changes: when the business, the law or a customer contract changes what counts as sensitive.

Classification review

This checklist

Asks: does the scheme still fit, is it applied correctly, and do the controls follow the labels?

Cadence: yearly, plus after a merger, a new core system, a new regulation or a data incident.

Produces: sample results, an updated handling matrix, an exceptions register and signed approval.

Retention review

A separate cycle

Asks: what has passed its retention period, what is on legal hold, and what can be destroyed.

Cadence: yearly, or quarterly for high-volume systems.

Produces: a disposal log and deletion evidence.

Run both from the same data inventory. The retention cycle lives in the Data Retention & Disposal Review Checklist; this page stays on sensitivity, labels and handling.

What the Data Classification Review Checklist Covers

Seven phases take one review cycle from the scheme to signed approval. The auto-labelling and regulated data steps appear only when Phase 1 says they apply.

Phase 1

Phase 1: Trigger, Scope & Scheme Fit

Owned by the information security manager or DPO. The Phase 1 answers on labelling tools and regulated data decide which tasks appear in Phases 4 and 5.

  • Record why this review is running and what is in scope — annual cycle, merger or acquisition, new core system, new regulation or a data incident; list the business units and systems covered
  • Record whether a labelling tool is deployed and whether regulated data is held — yes or no for each: special category personal data, cardholder data, protected health information, government-marked material
  • Close out last cycle’s exceptions and actions — confirm each one is resolved, renewed with a new expiry date or escalated
  • Confirm each level still has a clear definition, examples and an impact statement — test it by asking two data owners to classify the same five documents and comparing the answers
  • Check the scheme against new obligations — customer contracts, government or defence marking rules, and regulations that took effect since the last review
  • Confirm the policy has a named owner, a current version and an approval date — and that no older copy is still circulating on the intranet
Phase 2

Phase 2: Data Inventory & Owners

  • List every data store in scope with a named data owner — business applications, SaaS tools, file shares, collaboration sites, databases, data warehouses, email and backups
  • Record the highest classification each store holds — a store holding even one Restricted data set is handled as Restricted unless that data is segregated
  • Reconcile the inventory with the asset register and the GDPR Article 30 records of processing — categories of personal data in the records should appear in a store on this list
  • Add stores created since the last review — new SaaS subscriptions, shared drives and team sites are the usual gaps; check purchasing and the identity provider’s app list
  • Log stores with no owner or no assigned level as exceptions — ownerless data is the first thing to go wrong in an incident
Phase 3

Phase 3: Sample Labelled & Unlabelled Content

Sample sizes are risk-based: larger for stores holding Confidential or Restricted data. Results go in a table inside the task.

  • Choose a sample from each store — recent documents, emails and records, weighted towards the stores that hold the most sensitive data
  • Check labelled items carry the right level — record each as correct, over-classified or under-classified, with the reason
  • Check a sample of unlabelled items — what level they should carry, and whether sensitive content is sitting unlabelled in a general-purpose store
  • Check sharing on Confidential and Restricted items — links open to anyone, external guests and copies in personal storage
  • Record the results per store and look for patterns — one team over-labelling everything, or one document type always missed, points to a training or tooling fix
Phase 4

Phase 4: Label Coverage & Auto-Labelling

Appears only when Phase 1 records that a labelling tool is deployed. Assigned to the administrator of that tool, with the information security manager reviewing.

  • Report label coverage by location — the share of items labelled in each site, mailbox or repository, compared with the last review
  • Review default label settings — a default of Internal is reasonable for documents and email, but confirm it is not hiding content that should be higher
  • Review automatic labelling rules and their results — in Microsoft Purview, for example, run service-side auto-labelling policies in simulation first and check a sample of matches before enforcing
  • Check that each label’s protection still matches the handling rules — encryption, headers, footers and watermarks applied by the label, and who can open encrypted content
  • Review label downgrades and removals since the last cycle — where users must give a justification, read a sample of the reasons
Phase 5

Phase 5: Handling Rules & Regulated Data

The regulated data tasks appear only for the categories Phase 1 records as held. Legal or the DPO confirms the legal mapping.

  • Review the handling matrix for each level — where it may be stored, who it may be shared with, encryption at rest and in transit, printing, removable media and disposal
  • Test the matrix against reality — pick one Restricted data set and confirm it is encrypted, stored where the matrix says and disposed of as it says
  • Map special category data and criminal offence data to your highest practical level — GDPR Articles 9 and 10 data needs a lawful condition and extra safeguards
  • Confirm cardholder data and the media holding it are classified — PCI DSS v4.0.1 requirement 9.4.2 asks for media with cardholder data to be classified by sensitivity
  • Confirm protected health information and government-marked material carry the level and markings their rules require — HIPAA, contract clauses or the government scheme
Phase 6

Phase 6: DLP, Access & Training Alignment

  • Confirm DLP rules key off the current labels and sensitive data types — rules written for a retired label or level protect nothing
  • Review DLP alerts and user overrides since the last cycle — repeated overrides on one data type suggest the rule, the label or the training is wrong
  • Check access to Restricted stores matches need to know — take the result from the latest user access review rather than repeating it
  • Confirm staff completed classification and handling training — including joiners since the last cycle, with completion records attached
  • Collect acceptable use and handling attestations — from staff and from contractors and suppliers who handle Confidential data, backed by confidentiality terms
Phase 7

Phase 7: Exceptions, Updates & Sign-off

Sign-off is an approval task for the CISO or senior information risk owner. The checklist does not close until it is approved.

  • Log every exception with an owner, a compensating control and an expiry date — stores that cannot be labelled, legacy systems without encryption, and unowned data
  • Update the scheme and handling matrix and issue a new version — with a change log so staff can see what moved
  • Tell staff what changed — a short note with examples does more than reissuing the full policy
  • Report the cycle to management — sample accuracy, label coverage, exceptions open and decisions needed
  • Approve the review and schedule the next one — yearly as a baseline, and on the triggers recorded in Phase 1

Where a Classification Review Shows Up in Frameworks and Law

Few frameworks say how often to review a classification scheme. CIS Controls v8.1 is the exception: safeguard 3.7 asks for the scheme to be reviewed and updated annually or when significant enterprise changes occur, and 3.2 asks for the data inventory to be reviewed at least annually, prioritising sensitive data. The table maps the requirements this review most often has to meet to the phase that produces the evidence.

FrameworkReferenceWhat it expectsEvidenced in
ISO/IEC 27001:2022 Annex A5.12, 5.13Information classified by confidentiality, integrity, availability and interested party requirements; labelling procedures that follow the schemePhases 1, 3–4
ISO/IEC 27001:2022 Annex A5.9, 5.10An inventory of information and associated assets with owners; rules for acceptable use and handlingPhases 2, 5–6
CIS Controls v8.13.2, 3.7A data inventory and a classification scheme, each reviewed and updated at least annuallyPhases 1–2
NIST FIPS 199, SP 800-60Security categorisationInformation and systems categorised as low, moderate or high impact for confidentiality, integrity and availability; information types mapped to provisional impact levelsPhases 1–2
GDPR and UK GDPRArts. 9, 10, 30Records of processing that describe categories of personal data; extra conditions for special category and criminal offence dataPhases 2, 5
PCI DSS v4.0.19.4.2All media with cardholder data classified in accordance with the sensitivity of the dataPhase 5
SOC 2 Trust Services CriteriaC1.1Confidential information identified and maintained to meet the entity’s confidentiality objectivesPhases 2, 6

Treat the table as a starting point, not legal or audit advice. Your auditor or certification body decides what counts as sufficient evidence for your scope, and counsel should confirm which data protection rules apply. The GDPR does not use the word classification, but you cannot keep accurate Article 30 records or apply Article 32 security appropriate to the risk without knowing which data is sensitive.

One revision is still in progress. NIST published an initial working draft of SP 800-60 Revision 2 in January 2024 to update the information types and bring privacy into categorisation, and in April 2026 still listed it as an upcoming publication. Volumes 1 and 2 of Revision 1 remain the published guidance, so check the status before citing the draft.

Why Run Your Classification Review in CheckFlow?

1

Every store has a named owner and a task

The inventory phase assigns each data store to its owner with a due date. Owners confirm the level and the sample results themselves, so the review does not depend on one person chasing a spreadsheet.

2

Only the relevant steps appear

Conditional logic driven by the Phase 1 answers adds the auto-labelling tasks only where a labelling tool exists, and the cardholder, health or special category tasks only for data you actually hold. A small organisation gets a short review.

3

Evidence an auditor can follow

Sample tables, coverage reports, DLP summaries and training records are attached to the task they support. The audit trail records who completed each step and when, and the final approval holds the sign-off.

CheckFlow is not a labelling, discovery or DLP tool. It runs the human side of classification around those tools: who owns each store, who checked the sample, what was decided and who approved it. CheckFlow for compliance checklists shows how a yearly review like this sits alongside your other recurring controls, and the ISO 27001 checklist guide explains where classification fits in an ISMS.

Classification feeds other reviews. Pair it with the GDPR Compliance Audit Checklist for records of processing and lawful bases, the Data Retention & Disposal Review Checklist for how long each level is kept, and the User Access Review Checklist to confirm who can reach the Restricted stores.

Frequently Asked Questions

What is a data classification review?

+

It is a scheduled check that your classification scheme still fits the business and that people and systems apply it correctly. The review confirms the levels and handling rules, checks that every data store has an owner and an assigned level, samples labelled and unlabelled content for accuracy, and confirms that controls such as DLP, encryption and access rules follow the labels. It ends with an updated scheme, a list of exceptions and management sign-off.

How often should data classification be reviewed?

+

At least once a year, and again after significant change. CIS Controls v8.1 safeguard 3.7 asks for the classification scheme to be reviewed and updated annually or when significant enterprise changes occur. Typical triggers for an extra review are a merger, a new core system, a new regulation or contract requirement, and an incident involving mislabelled data.

What are the four levels of data classification?

+

Most commercial schemes use four levels, commonly Public, Internal, Confidential and Restricted, though some call the top level Highly Confidential or Secret. Public data can be released freely; Internal is for staff only; Confidential would cause harm if disclosed; Restricted would cause serious harm and gets the tightest controls. Government schemes differ: the UK uses OFFICIAL, SECRET and TOP SECRET, and US federal systems are categorised as low, moderate or high impact under FIPS 199. Fewer levels are easier for staff to apply correctly.

What is the difference between data classification and labelling?

+

Classification is the decision about how sensitive information is. Labelling is how that decision is recorded on the information so people and systems can see it: a header, a watermark, a metadata tag or a sensitivity label applied by a tool such as Microsoft Purview. ISO/IEC 27001:2022 treats them as two controls, 5.12 for classification and 5.13 for labelling. A review checks both, because correct decisions that are never labelled cannot drive DLP or encryption.

Who is responsible for classifying data?

+

The data owner, usually the business manager accountable for a system or data set, decides its level. People who create documents and emails label them in line with the scheme. The information security manager or CISO owns the scheme itself and runs the review, and the DPO advises on personal data. Senior management approves the scheme and accepts the exceptions.

Does GDPR require data classification?

+

Not by name. The GDPR requires records of processing that describe the categories of personal data you hold (Article 30), extra conditions for special category data (Article 9) and security appropriate to the risk (Article 32). In practice those duties are hard to meet without knowing which data is sensitive and where it is, which is what a classification scheme provides. Confirm with counsel how the rules apply to your organisation.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Make Sure Your Labels Still Mean Something

Free trial — no credit card required.