> For the complete documentation index, see [llms.txt](https://framework.aic.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://framework.aic.io/company-operating-manual/security-compliance-and-data/data-handling-and-classification.md).

# Data Handling and Classification

### Purpose

Data handling rules protect customer information, company information, personal data, and sensitive material.

### Data Classification

Projects should classify data as:

* public
* internal
* confidential
* sensitive
* customer confidential
* personal data
* special category personal data where applicable

### Government Classifications

When work is conduct on HMG projects or HMG aligned projects, we classify our data following GOV.UK guidelines.

* OFFICIAL
* OFFICIAL-SENSITIVE
* SECRET
* TOP SECRET

### Data Handling Rules

Data must be:

* stored only in approved locations
* accessed only by authorised users
* shared only through approved channels
* retained only for the required period
* deleted or returned when required
* encrypted where appropriate
* handled according to customer requirements

### Data Register

Projects handling sensitive or customer data should maintain a data register showing:

* data type
* source
* owner
* storage location
* access permissions
* retention period
* deletion process
