Skip to content
Fundamentals6 min read

Public, internal, confidential: how classification decides what to mask

Public, internal, confidential, restricted: what each classification level means, and exactly what to mask before a document reaches a wider audience.

By Alexis de ONYRI

Public, internal, confidential, restricted: many companies stamp a document with one of these words before anyone reads it. The label tells the reader who may see the file. It also tells you, in a few words, what still needs to be hidden before that document leaves its usual circle.

What do classification levels mean?

Classification is a simple idea. Sort documents by the harm it would cause if the wrong person read them. A holiday schedule causes no harm if a stranger sees it. A merger plan can cause real damage. Most organizations settle on three or four levels. They name them differently, but the logic repeats everywhere. The UK government, for instance, uses OFFICIAL, SECRET and TOP SECRET. NIST guidance for United States federal systems skips names and sorts information by potential impact instead, from low to high.

  • Public: written to be shared outside the company, on a website or in a press release.
  • Internal: for staff and sometimes contractors. It would embarrass or confuse outsiders, but not harm the company.
  • Confidential: for a named team or role, such as finance, HR or legal. Disclosure could hurt the company or a person.
  • Restricted: for a short, named list of people. Disclosure could cause serious legal, financial or safety harm.

Why are there two different reasons to classify a document?

Two separate worries sit behind the same four words. The first is personal data: a name, an address, a salary. European data protection law asks companies to limit who sees that kind of information to what each person's job actually requires.

The second worry is business secrets: pricing, a client list, a product design. Directive (EU) 2016/943 protects information as a trade secret only when its holder has taken reasonable steps to keep it secret. Article 2 of the directive sets that condition in exact terms. A document left open on a shared drive, with no restriction at all, is harder to defend as a secret later.

How do you decide a classification level?

Three questions usually settle the level. First, does a law require a certain handling, such as GDPR for personal data? Second, how much harm would disclosure cause, and to whom? Third, who genuinely needs to read the document to do their job? Answer those three, and the level almost picks itself.

What should you mask before sharing more widely?

LevelTypical audienceWhat to mask before a wider audience
PublicAnyone, including outside the organizationNothing extra. The document was written to be shared.
InternalAll staff, sometimes contractorsNames of external partners not meant to see it, draft figures, internal code names.
ConfidentialA named team or role, such as finance, HR or legalSalaries, client identifiers, ID numbers, anything the wider company should not see.
RestrictedA short, named list of peoplePersonal data, trade secrets, security details. Mask it unless the reader is on that list.
A common four-level scheme, and what each step up usually hides.

ONYRI Sanitize can help once you know a document needs to travel further than its label allows. Its detection profiles group custom rules by project or client. A recurring internal term, like a code name or a client reference, gets masked every time you drop in a new file. The limit: ONYRI does not read a document's classification label or decide its level. That choice stays yours.

Classification also needs to be visible, not just decided. Many organizations write the level in a document's header or footer, in a fixed spot readers learn to check. The same level can go in the file's own properties too. That is the metadata a reader sees in a word processor's document panel. A search or a mail filter can catch it there as well.

Who decides when a document can be downgraded?

Turning a confidential file into something safe for a wider audience, through redaction, is a downgrade. It needs an owner. Good practice puts that decision with the person or team who set the original level. That is often a manager, a data protection lead or legal counsel. It is not whoever happens to be sending the email that day. Jane Example, a project lead, cannot decide alone to strip a client's data from a confidential report and forward it to a supplier. That call belongs to whoever owns the classification.

  1. 1Check the label before you share, not after.
  2. 2Ask who genuinely needs to read this version.
  3. 3Mask what the new, wider audience should not see.
  4. 4Get the downgrade approved by whoever owns the classification.
  5. 5Recheck the label in the header, footer and file properties.

Frequently asked questions

What is the difference between internal and confidential documents?
Internal documents are for staff and sometimes contractors. Reading them by mistake would not seriously harm the company. Confidential documents are for a named team, such as finance or HR, and disclosure could cause real damage. They need stricter handling and, often, masking before they leave that group.
Can one document carry two classification levels?
Not at the same time for the whole file, but a document can change level as it travels. A confidential internal report can become a public one once the sensitive figures are masked and a manager approves the change. Track that change with a new label, not by editing the old one quietly.
Does a classification label make a document GDPR-compliant?
No. A label only tells a reader how to handle the file. It does not remove personal data, and it does not make the document compliant by itself. The document still needs the right legal basis and a limited set of readers. For wider sharing, it also needs masking of names, numbers and other personal details it contains.
Who decides when a confidential document can be shared outside the company?
Usually whoever owns the classification: the manager, project lead or data protection contact who set the level in the first place. A single employee forwarding a confidential file on their own judgment is exactly the scenario classification rules exist to prevent.
What happens if a document has no classification label at all?
Treat it as confidential until someone who knows its content says otherwise. An unlabeled document is not automatically safe to share. It usually means nobody has reviewed it yet, not that it is low risk.

Sources & references

Mask a document without uploading it

ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.

Read next