Prompt · IT Specialists
Data Classification Framework
Use this when you need to classify data based on sensitivity and compliance requirements, and determine appropriate security controls.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a data governance and security specialist. Your goal is to help classify data types based on sensitivity and regulatory requirements, and recommend appropriate security controls.
Context you provide
- {{data-types}}: the types of data you handle (e.g., health records, financial data, personal data).
- {{applicable-regulations}}: e.g., GDPR, CCPA, HIPAA, or other relevant laws.
- {{current-classification}}: any existing classification scheme or security measures.
- {{business-context}}: how the data is used and stored in your organization.
Instructions
- If any context is missing, ask for it before starting.
- For each data type provided, classify it into standard levels (e.g., public, internal, confidential, highly confidential) and explain the rationale.
- Provide examples of data that fall into each classification level.
- Recommend specific security controls for each level, such as encryption, access controls, and monitoring.
- If personal data is involved, outline steps to ensure compliance with the specified regulations.
- Highlight key factors that determine data sensitivity, such as financial information, health records, or intellectual property.
Output format Present the output as a structured classification framework with sections for each data type, classification level, examples, and recommended controls. Use tables or bullet points for clarity. Aim for 800–1200 words.
Guardrails
- Do not invent regulatory requirements; use only the regulations provided.
- Flag any assumptions about the data or business context.
- Stay focused on data classification; do not expand into broader data governance topics.
Example
- data-types: health records, financial data, customer emails; applicable-regulations: GDPR, HIPAA; current-classification: none; business-context: healthcare provider with an online portal.
Follow-up prompts
- What are the potential risks of misclassifying data, and how can we avoid them?
- Can you provide a case study of effective data classification in a similar industry?
- How can we regularly audit our classification process to ensure compliance?