Security & governance · Glossary term
What is Data Classification?
Assigning data to documented sensitivity or impact classes so handling, access, retention, sharing, and incident rules follow the consequences of disclosure or loss.
Why does Data Classification matter?
An AI pipeline cannot apply proportionate controls if source documents, prompts, traces, and generated artifacts are treated as equally sensitive.
Data Classification in practice
Classify data at ingestion, carry the label through derived artifacts, restrict tools and destinations by class, and define how labels change after transformation or aggregation.
What is the common confusion about Data Classification?
Data classification describes protection requirements. It is not the same as a machine-learning classification task or a claim that the data is accurate.
Learn Data Classification in the course
No lesson links to this term yet. Search the course catalog for it.
Related terms
- Data MinimizationFor personal data, limiting what is collected, processed, exposed, and retained to what is necessary for a specified purpose.
- Trust BoundaryAn interface where data, instructions, identity, or authority crosses between components or principals that operate under different trust…
- Least PrivilegeGiving a model, agent, tool, or user only the permissions required for the current task, for only as long as those permissions are needed.
- Audit LogA durable, access-controlled record of security- or accountability-relevant events, including who or what acted, what changed, when it…
- AI Risk AssessmentA documented analysis of how an AI system can affect people, organizations, and environments, including context, hazards, likelihood,…
- Membership InferenceAn attack that estimates whether a particular record or example was included in a model's training data by observing model outputs or…
- Purpose LimitationFor personal data, collecting and using it only for specified, explicit purposes unless a new use has an appropriate compatible or…
Sources
More terms in Security & governance
- AI Risk Assessment
- Audit Log
- Content Provenance
- Data Exfiltration
- Data Lineage
- Data Minimization
- Datasheet for Datasets
- Defense in Depth
- Indirect Prompt Injection
- Jailbreak
- Membership Inference
- Provenance Attestation
- Purpose Limitation
- Red Teaming
- Separation of Duties
- Software Bill of Materials (SBOM)
- Threat Model
- Trust Boundary
- Zero Trust
This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.