{"entity":"Acme Supplies SRL","version":"2026.1","effective_date":"2026-02-01","next_review":"2027-02-01","classification_levels":[{"level_name":"Public","description":"Information intentionally made available to the general public.","example_data_types":["Public pricing","Press releases","Website content","Product catalogue"],"handling_rules":"No access restrictions. Must be accurate and reviewed before publication.","retention_default":"Indefinite while commercially relevant.","allowed_storage":"Any company-managed location including the public website.","allowed_transmission":"Any channel."},{"level_name":"Internal","description":"Information intended for employees, contractors and business partners under NDA.","example_data_types":["Internal procedures","Non-sensitive training materials","Marketing assets under development","Code repositories (non-credential)"],"handling_rules":"Default-deny external sharing. Share with third parties only under an executed NDA. Visible to all staff via authenticated access.","retention_default":"Active life of the business process + 2 years.","allowed_storage":"Company systems (M365, Confluence, GitHub private repos).","allowed_transmission":"Corporate email, authenticated collaboration tools, NDA-backed external transfer."},{"level_name":"Confidential","description":"Information whose unauthorised disclosure would cause material harm to the business, customers or employees.","example_data_types":["Supplier contracts","Financial records (non-public)","Product specifications not yet released","Customer support tickets","Audit logs"],"handling_rules":"Role-based access. Sharing outside the controlling team requires owner approval. No storage on personal devices outside MDM.","retention_default":"Varies by data type (see registry); minimum 7 years for financial records per BE commercial law.","allowed_storage":"Company systems with MFA enforcement.","allowed_transmission":"Encrypted channels only (TLS 1.2+ or end-to-end)."},{"level_name":"Restricted","description":"Information whose unauthorised disclosure would cause severe harm — regulatory exposure, legal liability, loss of trust, or safety impact.","example_data_types":["Customer PII","Employee HR records","Credentials and secrets","Board minutes","M&A working files"],"handling_rules":"Need-to-know access; logged every access. No transmission to personal email. No storage on personal devices under any circumstance. Any incident is immediately escalated to the CISO/DPO.","retention_default":"Minimum required by statute; purge on schedule. PII: as per data retention schedule. Credentials: never persist in logs.","allowed_storage":"Encrypted-at-rest systems with hardware-backed keys; production databases, Key Vault, 1Password.","allowed_transmission":"End-to-end encrypted channels. No attachments in email; use signed URLs with time-limited access instead."}],"data_registry":[{"data_type":"Customer personal data (contact, order history)","classification_level":"Restricted","business_owner":"Head of Customer Success","systems":["CRM (HubSpot)","ERP (Sage)"],"retention":"7 years after end of customer relationship (BE commercial law).","special_controls":"GDPR SAR procedure applies."},{"data_type":"Employee HR data","classification_level":"Restricted","business_owner":"Head of People","systems":["HRIS","Payroll (Sage)"],"retention":"5 years after end of employment (fiscal); 10 years for pension.","special_controls":"GDPR Art. 9 special-category data where applicable (health)."},{"data_type":"Financial records and invoices","classification_level":"Confidential","business_owner":"Head of Finance","systems":["Accounting software","Archive S3 bucket"],"retention":"7 years from close of fiscal year (BE VAT Code art. 60 §4)."},{"data_type":"Supplier contracts","classification_level":"Confidential","business_owner":"Head of Procurement","systems":["DocuSign","Contract repository"],"retention":"10 years after contract end."},{"data_type":"Product specifications (pre-release)","classification_level":"Confidential","business_owner":"Head of Product","systems":["Confluence","Internal wiki"],"retention":"Active life + 3 years."},{"data_type":"Product specifications (released)","classification_level":"Public","business_owner":"Head of Product","systems":["Website","Product catalogue"],"retention":"While product is sold + 3 years."},{"data_type":"Marketing assets (under development)","classification_level":"Internal","business_owner":"Head of Marketing","systems":["Adobe CC cloud","Notion"],"retention":"Until campaign launch + 1 year."},{"data_type":"Marketing assets (published)","classification_level":"Public","business_owner":"Head of Marketing","systems":["Website","Social media","CDN"],"retention":"Indefinite."},{"data_type":"Public pricing","classification_level":"Public","business_owner":"Head of Sales","systems":["Website","ERP"],"retention":"Indefinite."},{"data_type":"Press releases","classification_level":"Public","business_owner":"Head of Marketing","systems":["Website","Newsroom"],"retention":"Indefinite."},{"data_type":"Internal procedures and SOPs","classification_level":"Internal","business_owner":"Head of Operations","systems":["Confluence"],"retention":"Active + 2 years."},{"data_type":"Customer support tickets","classification_level":"Confidential","business_owner":"Head of Customer Success","systems":["Zendesk"],"retention":"24 months after ticket closure."},{"data_type":"Audit logs (systems, access, admin)","classification_level":"Confidential","business_owner":"Head of Engineering","systems":["Log aggregation","Cloud provider logs"],"retention":"3 years."},{"data_type":"Code repositories","classification_level":"Internal","business_owner":"Head of Engineering","systems":["GitHub (private)"],"retention":"Active life of the project; archived on decommission.","special_controls":"Credentials and secrets MUST NOT be committed — enforced via pre-commit hooks and secret-scanning."},{"data_type":"Credentials, API keys and cryptographic secrets","classification_level":"Restricted","business_owner":"Head of Engineering","systems":["1Password","Cloud Key Vault"],"retention":"Rotated on a documented schedule; destroyed on rotation.","special_controls":"Never logged; never emailed; accessed on-demand only."},{"data_type":"Board and shareholder minutes","classification_level":"Restricted","business_owner":"Managing Director","systems":["Encrypted document vault"],"retention":"Permanent (corporate record)."}],"review_cycle":"Annual, or sooner if a material change in processing, a new regulation, or an incident requires it.","policy_owner":{"name":"Marie Laurent","title":"CISO/DPO"}}