Free policy template ISO 27001

Data Classification & Handling Policy

Classification tiers and how each is labeled, stored, shared, and disposed of across its lifecycle.

Download the Markdown

Free and ungated, no email required. The full template is below and in the download. Authored in Keel's own words and mapped to ISO 27001 by clause; replace the {{PLACEHOLDER}} tokens with your details.

How to use it

  1. Download the template. Grab the Markdown file, or copy the full text from this page.
  2. Fill in the placeholders. Replace every {{PLACEHOLDER}} token (company name, owner, approver, dates, version) with your details.
  3. Tailor it to how you operate. Adjust the statements so they describe what your organization actually does. A policy you do not follow is worse than none.
  4. Approve and publish. Have an accountable owner approve it, set an effective date and a review date, and share it where staff can find it.
  5. Keep it current. Review on the schedule you set (or when things change), and keep evidence that it is followed. In Keel this is tracked for you.

Related

Data Classification & Handling

Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal


1. Purpose

This policy protects information in proportion to its sensitivity by assigning classification levels and setting clear handling rules for {{COMPANY_LEGAL_NAME}}. It focuses on {{DATA_TYPES}} processed in {{CRITICAL_SYSTEMS}} and stored or retained across {{GEO_SCOPE}}.

2. Scope

This policy applies to all data {{COMPANY_LEGAL_NAME}} creates, receives, processes, or stores, regardless of medium or location. It covers the {{LOCATION}} workforce and any {{DEVICE_TYPES}} used to reach {{CRITICAL_SYSTEMS}}.

3. Policy statements

3.1 Classification scheme

We use four levels: Public, Internal, Confidential, and Restricted. Internal is the default, and a short quick-reference guide gives examples drawn from {{INDUSTRY}} data and {{DATA_TYPES}}. Classification drives access control, encryption, monitoring, and retention across {{CRITICAL_SYSTEMS}} and backups in {{GEO_SCOPE}}.

3.2 Labelling and identification

Documents and data stores are labelled at creation using headers, metadata tags, or clear folder names. Automated tagging is used where supported; otherwise Confidential and Restricted data must be labelled manually. Labels are kept consistent across repositories and preserved through export and replication.

3.3 Access and storage

Access follows least privilege and is aligned to classification level. Confidential and Restricted data is encrypted at rest in {{CRITICAL_SYSTEMS}} and in backups held in {{GEO_SCOPE}}, administrative access to Restricted data is logged, access rights are reviewed on a defined cadence, and encryption keys are protected.

3.4 Transmission and sharing

Confidential and Restricted data moves only over encrypted channels such as TLS or SFTP. Public file-sharing links without access control are prohibited for anything above Internal, and external sharing of Restricted data requires management approval plus an NDA or contract. Insecure protocols are disabled and multi-factor authentication is enforced for privileged transfers.

3.5 Retention and disposal

Retention periods from the data retention policy are applied to each classification, taking {{GEO_SCOPE}} obligations into account. Media holding Confidential or Restricted data is destroyed by secure wipe or certified shredding, destruction is logged, and certificates of destruction are filed where used.

3.6 Compliance measurement

A quarterly sample confirms correct labels, encryption, and access rights against a target of at least 95% accuracy. The sample size scales up for a workforce above {{EMPLOYEE_COUNT}}.

4. Roles and responsibilities

Role Responsibility
Executive sponsor Accountable for the program; approves this policy
{{POLICY_OWNER_ROLE}} Maintains this policy and its procedures
Managers Enforce the policy within their teams
All personnel Comply; report issues promptly

5. Compliance and exceptions

Non-compliance may result in disciplinary action, and mislabelled or mishandled data triggers incident response and mandatory refresher training. Exceptions must document the risk and compensating controls, note any residual risk to {{DATA_TYPES}} and how it is mitigated in {{CRITICAL_SYSTEMS}} or through {{DEVICE_TYPES}} controls, and be approved by {{APPROVER_TITLE}}. They are time-limited and reviewed.

6. Review

This policy is reviewed at least annually and when significant change occurs. Examples and tooling are updated as new {{INDUSTRY}} data types or regulations emerge, including changes affecting {{GEO_SCOPE}}.


Aligned to ISO/IEC 27001:2022. {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by the relevant standards body; full standard text is copyrighted and is not reproduced here.

This template is authored by Keel in its own words. Clause references to ISO 27001 are factual identifiers; Keel is not affiliated with or endorsed by the standards bodies named. It is a starting point, not legal advice, review and adapt it for your organization.

Manage this policy in Keel

Keel ships this template in-product, fills the placeholders, maps it to your controls, and tracks approvals and reviews, so the policy stays live evidence, not a file in a drive. Start free.

Start free Browse all templates