Agent skill

Classification Policy

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Develops data classification policies with tiered handling (public, internal, confidential, restricted), labeling requirements, enforcement mechanisms, and procedures per tier.

Apache-2.0Auto-check passedLegal & Compliance

Install Classification Policy

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill classification-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills classification-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/classification-policy .claude/skills/classification-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
classification-policy
GitHub stars
295
Token cost
~3k tokens
SKILL.md length
1,196 words
Files
5 (incl. scripts, references, assets)
Skills in repo
278
Repo updated
First seen
Licence
Apache-2.0

At a glance

Develops data classification policies with tiered handling (public, internal, confidential, restricted), labeling requirements, enforcement mechanisms, and procedures per tier.

  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Classification Tier Structure, Handling Procedures Per Tier and Policy Governance, plus 3 more sections
  • Runs Python scripts from its folder
  • Tasks that involve Data governance

What it does

Classification Policy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Develops data classification policies with tiered handling (public, internal, confidential, restricted), labeling requirements, enforcement mechanisms, and procedures per tier. Covers policy governance, exception handling, and compliance monitoring. Keywords: classification policy, data tiers, handling procedures, labeling, enforcement, data governance, information security.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR, Data governance and Error handling. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Data governance
  • Tasks that involve Error handling

Example prompts

  • “Use the classification-policy skill to develop data classification policies with tiered handling (public, internal, confidential, restricted)…”
  • “/classification-policy”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Classification Policy loads about 3k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 1,196 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,196 words, ~3,033 tokens.

Download SKILL.mdSave it as .claude/skills/classification-policy/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
classification-policy
description
Develops data classification policies with tiered handling (public, internal, confidential, restricted), labeling requirements, enforcement mechanisms, and procedures per tier. Covers policy governance, exception handling, and compliance monitoring. Keywords: classification policy, data tiers, handling procedures, labeling, enforcement, data governance, information security.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-classification
metadata.tags
classification-policy, data-tiers, handling-procedures, labeling, enforcement, governance

Data Classification Policy Development

Overview

A data classification policy establishes the enterprise-wide framework for categorising data by sensitivity level and prescribing handling requirements per tier. The policy translates GDPR classification obligations (personal, special category, criminal) and information security requirements (confidentiality, integrity, availability) into practical, enforceable rules that govern how data is stored, transmitted, accessed, and disposed of throughout its lifecycle. This skill covers the design, implementation, and enforcement of a four-tier classification scheme aligned with GDPR requirements and ISO 27001 Annex A controls.

Classification Tier Structure

Four-Tier Model for Vanguard Financial Services
TierLabelDescriptionGDPR MappingISO 27001 Mapping
Tier 1: PublicPUBLICInformation approved for public release. Disclosure carries no risk to the organisation or individuals.Anonymised data (Recital 26), published reports, public filingsA.8.2 — Unclassified/Public
Tier 2: InternalINTERNALInformation for internal use only. Disclosure would cause minor inconvenience but no significant harm.Pseudonymised aggregate data, internal procedures, organisational chartsA.8.2 — Internal
Tier 3: ConfidentialCONFIDENTIALInformation whose disclosure would cause significant harm to individuals or the organisation.Personal data (Art. 4(1)), financial data, customer records, employee recordsA.8.2 — Confidential
Tier 4: RestrictedRESTRICTEDInformation whose disclosure would cause severe harm, regulatory sanction, or irreversible damage.Art. 9 special category data, Art. 10 criminal data, trade secrets, regulatory investigation dataA.8.2 — Restricted/Secret
Classification Decision Matrix
Data TypeTierRationale
Published annual reportPUBLICApproved for public disclosure
Internal org chartINTERNALNo individual harm from disclosure, but not intended for external distribution
Customer name and emailCONFIDENTIALPersonal data — disclosure would breach GDPR obligations
Customer account number and transactionsCONFIDENTIALPersonal data with financial sensitivity
Employee National Insurance NumberCONFIDENTIAL (borderline RESTRICTED)High-sensitivity direct identifier
Employee health recordsRESTRICTEDArt. 9 special category data
Biometric access templatesRESTRICTEDArt. 9 biometric data
Criminal background check resultsRESTRICTEDArt. 10 criminal data
AML investigation filesRESTRICTEDCriminal data + legal privilege
Board strategic plansRESTRICTEDCommercial sensitivity
Encryption keys and credentialsRESTRICTEDSecurity-critical

Handling Procedures Per Tier

Tier 1: PUBLIC
ControlRequirement
StorageNo restrictions; any approved platform
TransmissionNo restrictions; may be sent via any channel
Access controlNo restrictions; accessible to all
EncryptionNot required (but recommended for integrity)
RetentionPer document retention schedule
DisposalStandard deletion
LabellingLabel: "Public" or no label required
Tier 2: INTERNAL
ControlRequirement
StorageVanguard-managed systems only (no personal devices, no personal cloud)
TransmissionVanguard email or approved collaboration tools; not via personal email
Access controlAll Vanguard employees and approved contractors with valid account
EncryptionRequired in transit (TLS 1.2+); recommended at rest
RetentionPer document retention schedule
DisposalStandard secure deletion (file system delete)
LabellingLabel: "Internal" applied via header/footer or metadata
Tier 3: CONFIDENTIAL
ControlRequirement
StorageVanguard-managed systems with access controls; encrypted at rest (AES-256)
TransmissionEncrypted email (TLS 1.3 or S/MIME); approved SFTP; no unencrypted channels
Access controlRole-based access control (RBAC); business need-to-know; MFA required
EncryptionRequired at rest (AES-256) and in transit (TLS 1.3); field-level encryption for high-sensitivity fields
PrintingPermitted with secure print release; printed copies secured in locked cabinets
External sharingPermitted only with approved third parties under DPA/NDA; DPO approval for new recipients
RetentionPer data-specific retention schedule; automated enforcement
DisposalSecure overwrite (NIST 800-88 Clear); shredding for physical media
LabellingLabel: "Confidential" in document header/footer, email subject tag, and metadata
AuditAccess logged; quarterly review of access permissions
DLPDLP policies active: warn on external sharing, block sharing to personal email
Tier 4: RESTRICTED
ControlRequirement
StorageDesignated restricted-access systems only; encrypted at rest with customer-managed keys; separate network segment or HSM where applicable
TransmissionEnd-to-end encrypted channels only; no email without encryption; approved secure file transfer only
Access controlNamed individual access lists (not role-based); dual-person authorisation for bulk access; MFA required; privileged access management (PAM)
EncryptionAES-256 at rest with customer-managed keys; TLS 1.3 in transit; field-level encryption mandatory
PrintingProhibited unless specifically authorised by DPO; watermarked with user identity
External sharingProhibited unless DPO and Chief Privacy Officer jointly approve; encrypted transfer only
RetentionStrict retention with automated deletion; no extensions without DPO approval
DisposalNIST 800-88 Purge (cryptographic erasure or physical destruction); disposal certificate required
LabellingLabel: "Restricted" in document header/footer (red), email banner, and metadata; visual marking on screens
AuditAll access logged with user identity, timestamp, and purpose; monthly audit review by DPO
DLPDLP policies active: block all external sharing, block USB copy, block print, block screenshot; alert DPO on policy trigger
Incident responseAny unauthorised access or disclosure treated as data breach; immediate DPO notification
Show full SKILL.md (443 more words)Show less

Policy Governance

Policy Document Structure
SectionContent
1. Purpose and ScopeDefines why classification is required and what data is covered
2. Classification TiersFour-tier definitions with examples
3. Roles and ResponsibilitiesData owner, data steward, DPO, IT Security, all employees
4. Classification ProceduresHow to classify new data, reclassification triggers
5. Handling RequirementsPer-tier controls matrix
6. Labelling RequirementsHow to apply labels (manual and automated)
7. Exception ProcessHow to request exceptions with risk acceptance
8. EnforcementMonitoring, audit, and consequences for violations
9. TrainingClassification awareness training requirements
10. Review ScheduleAnnual review; interim reviews on regulatory change
Roles and Responsibilities
RoleResponsibility
Data Owner (business unit head)Classify data for their business function; approve access requests; review classifications annually
Data Steward (departmental)Maintain classification labels; ensure handling compliance in their area; report classification issues
DPOOversee policy compliance; approve Restricted tier exceptions; conduct classification audits
IT SecurityImplement technical controls per tier; manage DLP policies; configure encryption; monitor audit logs
All EmployeesApply classification labels to data they create; handle data per tier requirements; report suspected misclassification
Privacy EngineeringConfigure automated classification tools; manage discovery platforms; tune detection accuracy
Exception Process
Exception Request
  │
  ├─► Step 1: Requestor documents the exception
  │     - What data? What tier? What control cannot be met?
  │     - Why is the exception needed?
  │     - What alternative controls are proposed?
  │     - Duration of exception requested
  │
  ├─► Step 2: Risk Assessment
  │     - Data Steward assesses the risk of the exception
  │     - For Confidential tier: Data Owner approves
  │     - For Restricted tier: DPO and CISO jointly approve
  │
  ├─► Step 3: Approval and Documentation
  │     - Exception recorded in exception register
  │     - Alternative controls documented and implemented
  │     - Expiry date set (maximum 12 months, renewable)
  │
  └─► Step 4: Review
        - Exception reviewed at expiry
        - Renewed only if original justification remains valid
        - Chronic exceptions trigger process improvement

Enforcement Mechanisms

MechanismImplementation
Automated labellingMicrosoft Purview auto-labelling applies Confidential/Restricted labels based on detected PII
DLP policiesMicrosoft Purview DLP blocks or warns on policy violations (external sharing, USB copy)
Access reviewsQuarterly certification of access permissions for Confidential; monthly for Restricted
Audit loggingAll access to Confidential and Restricted data logged and retained for 2 years
Classification auditsDPO conducts semi-annual audits sampling 100 items per tier for classification accuracy
Training complianceAnnual classification training required for all employees; completion tracked in LMS
Disciplinary policyViolations escalated per employee handbook: warning → formal warning → disciplinary action

Enforcement Precedents

  • ICO v Interserve Group (2022): GBP 4.4 million fine for inadequate security measures — the ICO noted that failure to classify data by sensitivity contributed to the inability to apply proportionate security controls, leading to a breach affecting 113,000 employees.
  • CNIL v Sergic (2019): EUR 400,000 fine for failing to implement adequate access controls on tenant personal data — absence of data classification meant all data was treated with the same (insufficient) controls.
  • AEPD v CaixaBank (2021): EUR 6 million fine — the DPA noted that inadequate data classification contributed to excessive data collection and retention, violating data minimisation and storage limitation principles.

Integration Points

  • personal-data-test: Classification policy tiers are assigned based on personal data classification results
  • special-category-data: Art. 9 data automatically assigned Restricted tier
  • criminal-data-handling: Art. 10 data automatically assigned Restricted tier
  • data-labeling-system: Labelling system implements the policy's labelling requirements
  • auto-data-discovery: Discovery tools validate that classification labels match detected data sensitivity

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/classification-policy of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Classification Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Classification Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Classification Policy this skillmukul975/Privacy-Data-Protection-Skills295—~3kAutomated safety check: PassApache-2.0
Implementing Cloud Dlp For Data Protectionmukul975/Anthropic-Cybersecurity-Skills34k—~4.2kAutomated safety check: PassApache-2.0
Cometchat Compliancecometchat/cometchat-skills129—~1.7kAutomated safety check: PassMIT
Data Policyericrisco/rsc-harness156—~3.1kAutomated safety check: PassMIT
Nw Security And GovernancenWave-ai/nWave617—~1.7kAutomated safety check: PassMIT
Data Security Officertheneoai/awesome-skills183—~2.4kAutomated safety check: PassMIT

Similar skills

  • Implementing Cloud Dlp For Data Protection

    mukul975/Anthropic-Cybersecurity-Skills

    Implement cloud DLP using Amazon Macie, Google Cloud DLP API, Microsoft Purview, Azure Information Protection, and Nightfall AI to discover, classify, label, de-identify, and protect sensitive data…

    34k GitHub stars~4.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Cometchat Compliance

    cometchat/cometchat-skills

    Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery…

    129 GitHub stars~1.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Data Policy

    ericrisco/rsc-harness

    A skill your agent uses when building internal data-governance machinery: a retention schedule (period, lawful basis, expiry action, system where deletion runs), an Art.

    156 GitHub stars~3.1k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Database security (encryption, access control, injection prevention), data governance (lineage, quality, MDM), and compliance frameworks (GDPR, CCPA, HIPAA)

    617 GitHub stars~1.7k tokensUpdated 21 days ago
    Legal & ComplianceAuto-check passed
  • Data Security Officer

    theneoai/awesome-skills

    Expert-level Data Security Officer with deep knowledge of data classification, DLP strategy, encryption at rest and in transit, data governance frameworks, regulatory compliance (GDPR, CCPA, PIPL…

    183 GitHub stars~2.4k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check passed
  • Runs a human-first workflow for labeling PII spans in a transcript, then scores inter-annotator agreement and drafts an adjudicated gold set.

    388 GitHub stars~1.3k tokensUpdated 11 days ago
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 278 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    295 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    295 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    295 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed
  • Retention Schedule

    mukul975/Privacy-Data-Protection-Skills

    Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

    295 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Classification Policy

What does Classification Policy do?

Develops data classification policies with tiered handling (public, internal, confidential, restricted), labeling requirements, enforcement mechanisms, and procedures per tier. Classification Policy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Develops data classification policies with tiered handling (public, internal, confidential, restricted), labeling requirements, enforcement mechanisms, and procedures per tier.

When should I use Classification Policy?

Classification Policy fits situations like: tasks that involve Privacy and GDPR; tasks that involve Data governance; tasks that involve Error handling.

How do I install Classification Policy in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill classification-policy -a claude-code`. Or copy the skill folder (skills/privacy/classification-policy in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/classification-policy in your project. Claude Code loads it when a task matches its description.

How do I install Classification Policy in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill classification-policy -a codex`. Or copy the skill folder (skills/privacy/classification-policy in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/classification-policy in your project. Codex loads it when a task matches its description.

Can I use Classification Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill classification-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/classification-policy, .gemini/skills/classification-policy, .github/skills/classification-policy and .opencode/skills/classification-policy in your project.

What does Classification Policy need to run?

Going by SKILL.md and its folder, Classification Policy needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Classification Policy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Classification Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Classification Policy use?

Classification Policy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Classification Policy use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Classification Policy?

Skills that share tags, products or a category with Classification Policy: Implementing Cloud Dlp For Data Protection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Cometchat Compliance (cometchat/cometchat-skills, 129 stars), Data Policy (ericrisco/rsc-harness, 156 stars) and Nw Security And Governance (nWave-ai/nWave, 617 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Classification Policy?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.