Data classification and sensitivity tags
The classification says who may see an asset at all. The sensitivity tags say why it is sensitive, and so which checks apply.
For: Everyone · 1 min read
The three classifications
| Classification | What it covers | How access works |
|---|---|---|
| Internal | Open to all staff. Aggregates, policy text, public series and synthetic data. | Self-service: subscribe and use, logged for chargeback. |
| Confidential | Business-sensitive. Models and data products scoped to named business units. | Entitlement per business unit, approved by the owner; conditions attach. |
| Strictly Confidential | Customer-level data under banking secrecy and PDPA, and models that decide on customers. | Named-user entitlement with the data owner's consent and a stated purpose; reviewed on expiry. |
The rules behind them
Customer information is protected by Banking secrecy under the Financial Services Act 2013 and by the Personal Data Protection Act 2010 (PDPA). Classification and tags are how the platform applies those rules without every member of staff having to interpret them.
If you think an asset is classified wrongly, raise it with the data owner. Classification changes are decided by the Data Governance Committee, not on the platform.
Read next
Was this helpful?