1. Purpose
This policy defines how Murzo Group classifies, handles, stores, transmits, and disposes of information in order to protect confidentiality, integrity, and availability.
The objective is to ensure that information is handled consistently, lawfully, and proportionately based on sensitivity and risk, while reducing ambiguity in responsibility and liability.
2. Scope
This policy applies to:
- All information created, received, or processed by Murzo Group
- Digital, physical, and verbal information
- Employees, contractors, consultants, and authorised third parties
- Internal systems, client platforms, devices, and storage media
This policy applies regardless of geographic location or format.
3. Information Classification Levels
Murzo Group classifies information into the following categories:
3.1 Public
Information intended for public release.
Examples:
- Public website content
- Marketing materials
- Published research or statements
Handling:
- No special restrictions
- Accuracy and integrity must be maintained
3.2 Internal
Information intended for internal business use.
Examples:
- Internal communications
- Operational procedures
- Non-sensitive project documentation
Handling:
- Access limited to authorised Murzo Group personnel
- Not to be disclosed externally without permission
3.3 Confidential
Information that could cause harm, disadvantage, or contractual breach if disclosed.
Examples:
- Client communications and project materials
- Commercial agreements
- Design files and technical documentation
- Non-public business strategies
Handling:
- Access restricted on a need-to-know basis
- Encrypted storage and transmission where feasible
- Disclosure only under NDA or contractual protection
3.4 Restricted
Highly sensitive information requiring enhanced protection.
Examples:
- Security-related information
- Access credentials and system configurations
- Export-controlled or defence-adjacent data
- Proprietary algorithms, AI models, or sensitive datasets
Handling:
- Strict access controls
- Enhanced monitoring and logging
- Storage in approved secure environments only
- Transmission permitted only via authorised channels
4. Classification Responsibility
Information owners are responsible for assigning an appropriate classification.
Where classification is unclear, information must default to the higher sensitivity level.
Murzo Group reserves the right to reclassify information at any time.
5. Handling & Access Controls
Murzo Group applies controls proportionate to classification, including:
- Role-based access
- Authentication and authorisation mechanisms
- Physical security controls
- Secure storage and transmission requirements
Access may be revoked immediately where misuse or risk is identified.
6. Data Transmission
Information must be transmitted using methods appropriate to its classification.
- Public/Internal: standard secure channels
- Confidential/Restricted: encrypted channels and approved platforms only
Unsecured personal email, messaging apps, or unauthorised cloud storage must not be used for Confidential or Restricted information.
7. Storage & Retention
Information must be stored:
- In approved systems or physical locations
- In accordance with Murzo Group’s Data Protection Statement and retention schedules
- With safeguards against unauthorised access, loss, or corruption
Retention periods vary by information type and legal requirement.
8. Disposal & Destruction
When information is no longer required:
- Digital data must be securely deleted or overwritten
- Physical records must be shredded or destroyed securely
- Devices and media must be sanitised before disposal
Disposal must align with classification level and legal obligations.
9. Third-Party Handling
Third parties handling Murzo Group information must:
- Comply with this policy or equivalent standards
- Be subject to contractual confidentiality and security obligations
- Access only the minimum information required
Murzo Group is not responsible for misuse beyond its legal obligations where third parties act independently.
10. Client Responsibilities
Clients using Murzo Group platforms or services:
- Are responsible for classifying information they provide
- Must not upload Restricted or sensitive personal data unless expressly agreed
- Accept responsibility for inappropriate data disclosure
Murzo Group shall not be liable for consequences arising from client misclassification.
11. Monitoring & Enforcement
Murzo Group reserves the right to:
- Monitor access and usage
- Investigate suspected misuse
- Suspend access or take disciplinary action
Breaches of this policy may result in termination of access, contractual remedies, or legal action.
12. Limitations
This policy:
- Does not guarantee absolute information security
- Does not override legal disclosure obligations
- Does not create contractual rights
Murzo Group applies controls proportionately based on risk and feasibility.
13. Review & Updates
This policy is reviewed periodically and updated to reflect:
- Changes in law or regulation
- Emerging security risks
- Operational changes
Updated versions will be published on Murzo Group platforms.