data-classification

Define sensitivity levels and handling requirements for organizational data assets.

2|Updated Jan 15, 2026
One-click install
npx skills add https://github.com/DTMC-marketplace/governance --skill data-classification-dtmc-marketplace
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: data-classification
Source: https://github.com/DTMC-marketplace/governance/tree/main/skills/data-classification
Command: npx skills add https://github.com/DTMC-marketplace/governance --skill data-classification-dtmc-marketplace

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides a comprehensive framework for classifying data based on sensitivity, defining handling requirements, and managing the data lifecycle to ensure compliance and security.

Core Features & Use Cases

  • Define Sensitivity Levels: Establish clear categories like Public, Internal, Confidential, Restricted, and Top Secret.
  • Handling Requirements: Create a matrix detailing access control, encryption, sharing, and retention policies for each level.
  • Data Lifecycle Management: Implement procedures for data creation, storage, usage, archiving, and destruction.
  • Use Case: A financial institution can use this Skill to define that customer PII is 'Restricted' and requires encryption at rest and in transit, along with strict access controls and a 7-year retention policy.

Quick Start

Use the data-classification skill to define handling requirements for 'Confidential' data.

Frequently Asked Questions about data-classification

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I define data sensitivity levels for GDPR and CCPA compliance?▼

To define data sensitivity levels for GDPR and CCPA compliance, establish clear categories like Public, Internal, Confidential, Restricted, and Top Secret. This classification framework ensures appropriate handling requirements and lifecycle management for organizational data assets.

What is the best way to create a data handling requirements matrix for access control and encryption?▼

The best way to create a data handling requirements matrix is to map each sensitivity level to specific access controls, encryption standards, sharing rules, and retention policies. This structured approach ensures data assets receive protection proportional to their classification.

How do I implement data lifecycle management procedures for retention and disposal?▼

To implement data lifecycle management procedures, establish structured processes for data creation, storage, usage, archiving, and destruction. This framework defines clear retention and disposal procedures to maintain compliance and secure data assets throughout their lifecycle.

Can I use this data classification framework for a financial institution's PII encryption policies?▼

Yes, you can use this data classification framework for a financial institution by defining customer PII as Restricted. This establishes requirements for encryption at rest and in transit, strict access controls, and specific retention policies like a 7-year retention mandate.

Does data governance policy require data discovery and inventory processes?▼

Data governance policy requires data discovery and inventory processes to accurately classify and manage organizational data assets. Implementing these procedures ensures comprehensive visibility and supports sensitivity labeling and lifecycle management across the entire data ecosystem.