### Purpose

This policy defines how company information should be stored, accessed, used, transferred, shared, and disposed of.

The goal is to make sure sensitive information is available to people who need it without being unnecessarily exposed.

### Scope

This policy applies to company, customer, employee, financial, contractual, technical, and other business information handled by employees, contractors, vendors, or company systems.

### Data Classification

The company should use a simple classification model.

- **Public:** Information approved for public release.

- **Internal:** Normal business information intended for company use.

- **Confidential:** Information that could cause business, customer, employee, financial, legal, or reputational harm if exposed.

- **Highly Sensitive:** Particularly important information requiring tighter access, such as credentials, financial information, payroll data, privileged technical information, regulated data, or critical business secrets.

The company does not need a complicated classification program. Employees should at minimum understand which information requires additional protection.

### Access

Access should follow business need and least privilege.

**Sensitive information should:**

- Be accessible only to authorized users.
- Have a business or data owner where practical.
- Be reviewed periodically.
- Not remain accessible to former employees, contractors, or vendors.

### Approved Storage

Company information should be stored in approved company-managed systems.

**Employees should avoid storing business information in:**

- Personal email
- Personal cloud storage
- Unapproved SaaS services
- Personal messaging applications
- Unmanaged USB devices
- Unapproved AI services
- Local device folders where approved central storage should be used

### Sharing

Before sharing sensitive information:

- Confirm the recipient.
- Confirm the recipient actually needs the information.
- Use an approved sharing method.
- Apply appropriate permissions.
- Avoid public links unless specifically required.
- Set expiry dates where available.
- Remove access when no longer needed.

### Email

Sensitive information should not be sent casually by email.

**Before sending:**

- Check recipients carefully.
- Consider whether a secure sharing link is safer than an attachment.
- Avoid unnecessary distribution lists.
- Do not send sensitive company information to personal email accounts.

### External Sharing

External access should be deliberate.

**Where practical:**

- Use named recipients.
- Avoid “anyone with the link” sharing.
- Set expiry dates.
- Restrict downloading where appropriate.
- Record important external access.
- Remove access when the business need ends.

### Removable Media

USB drives and other removable storage should be restricted where practical.

**If used for sensitive information:**

- Use company-approved devices.
- Encrypt the storage.
- Do not leave media unattended.
- Remove information when no longer required.

### AI and Online Services

Sensitive company information should not be entered into public or unapproved AI, translation, file-conversion, transcription, or other online services.

Employees should use approved services and follow company rules regarding confidential information.

### Accidental Disclosure

If information is sent to the wrong person, shared publicly, uploaded to an unauthorized service, or otherwise exposed:

1. Report it immediately.
2. Do not attempt to hide the mistake.
3. Remove or restrict access where possible.
4. Preserve relevant information about what happened.

### Data Disposal

Information should be deleted or securely disposed of when no longer required, subject to legal, contractual, operational, and retention requirements.

### Practical Rule

Store company information in approved systems, share it only with people who need it, and report mistakes quickly.
