Skip to main content

dataVersion 1SOC2ISO27001NIST800-171GDPR

Data Classification & Handling Policy

How data is classified and what handling rules apply to each level.

Download PDFSHA-256 02674318a7417c1e…

Data Classification & Handling Policy

1. Purpose

Establishes the classification scheme Rex Black uses to decide how every piece of data must be stored, transmitted, shared, and destroyed.

2. Classification scheme

Level Definition Examples
Public Approved for public release. Website marketing content, published policies, open-source code.
Internal Non-sensitive business data; disclosure is undesirable but not harmful. Internal wikis, PRs, project plans.
Confidential Sensitive business or client data; disclosure causes material harm. Executed SOWs, client project data, internal finances, source code.
Restricted Legally protected data; disclosure triggers regulatory duties. PII, PHI, payment card data, authentication secrets, CUI, export-controlled.

3. Handling requirements by level

Control Public Internal Confidential Restricted
Encryption at rest , Required Required Required + FIPS
Encryption in transit , Required Required Required (TLS 1.2+)
Access controls , Authn RBAC least-priv RBAC + MFA + tamper-evident audit
External sharing allowed Yes With care NDA required Written approval + encrypted channel
Generative-AI processing Yes Yes Approved SaaS only Prohibited unless SaaS is explicitly listed for Restricted
Backup required Best-effort Yes Yes Yes + cross-region + Object Lock
Retention default As needed 3 years 7 years Per legal / contractual minimum
Deletion method Soft Soft Soft + crypto-erase backups Crypto-erase + audit log

4. Policy statements

  1. Every data store is labeled with a classification on creation. Unlabeled stores default to Confidential.
  2. Data inherits the highest classification of its source. Derived data from Restricted source is Restricted.
  3. Personnel handling Restricted data complete annual targeted training (HIPAA, PCI, CUI awareness, whichever applies).
  4. Printing of Confidential or Restricted data is prohibited unless explicitly authorized and the printed copy is logged and destroyed.
  5. No Rex Black or client data above Public may be copied to personal devices or personal accounts. Work-BYOD devices that are MDM-enrolled and disk-encrypted are permitted.

5. Client data

  1. Every client engagement is scoped to a classification in the SOW and reflected on the client's ClientOrg record.
  2. Client data is tenant-isolated by orgId in all data stores. No cross-tenant query is permitted outside of approved, time-boxed engineering maintenance with an audit-logged elevation.

6. Roles & responsibilities

Role Responsibility
Privacy Officer Owns the classification scheme; resolves disputes.
Data owner Classifies data at creation; re-classifies on change.
All personnel Handle data according to its classification.

7. Enforcement & exceptions

Mis-classification or mis-handling of Restricted data is a security incident. Exceptions require Privacy Officer approval.

8. References

  • 010-data-retention-and-disposal-policy.md
  • 011-encryption-standard.md
  • 026-ai-acceptable-use-policy.md
  • 028-data-subject-rights-policy.md

9. Revision history

Version Date Author Approver Change
1.0 2026-04-17 P.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center