Information Classification & Handling Policy

Version 1.0 · Last Updated:

1. Purpose

This policy defines how Murzo Group classifies, handles, stores, transmits, and disposes of information in order to protect confidentiality, integrity, and availability.

The objective is to ensure that information is handled consistently, lawfully, and proportionately based on sensitivity and risk, while reducing ambiguity in responsibility and liability.

2. Scope

This policy applies to:

  • All information created, received, or processed by Murzo Group
  • Digital, physical, and verbal information
  • Employees, contractors, consultants, and authorised third parties
  • Internal systems, client platforms, devices, and storage media

This policy applies regardless of geographic location or format.

3. Information Classification Levels

Murzo Group classifies information into the following categories:

3.1 Public

Information intended for public release.

Examples:

  • Public website content
  • Marketing materials
  • Published research or statements

Handling:

  • No special restrictions
  • Accuracy and integrity must be maintained

3.2 Internal

Information intended for internal business use.

Examples:

  • Internal communications
  • Operational procedures
  • Non-sensitive project documentation

Handling:

  • Access limited to authorised Murzo Group personnel
  • Not to be disclosed externally without permission

3.3 Confidential

Information that could cause harm, disadvantage, or contractual breach if disclosed.

Examples:

  • Client communications and project materials
  • Commercial agreements
  • Design files and technical documentation
  • Non-public business strategies

Handling:

  • Access restricted on a need-to-know basis
  • Encrypted storage and transmission where feasible
  • Disclosure only under NDA or contractual protection

3.4 Restricted

Highly sensitive information requiring enhanced protection.

Examples:

  • Security-related information
  • Access credentials and system configurations
  • Export-controlled or defence-adjacent data
  • Proprietary algorithms, AI models, or sensitive datasets

Handling:

  • Strict access controls
  • Enhanced monitoring and logging
  • Storage in approved secure environments only
  • Transmission permitted only via authorised channels

4. Classification Responsibility

Information owners are responsible for assigning an appropriate classification.

Where classification is unclear, information must default to the higher sensitivity level.

Murzo Group reserves the right to reclassify information at any time.

5. Handling & Access Controls

Murzo Group applies controls proportionate to classification, including:

  • Role-based access
  • Authentication and authorisation mechanisms
  • Physical security controls
  • Secure storage and transmission requirements

Access may be revoked immediately where misuse or risk is identified.

6. Data Transmission

Information must be transmitted using methods appropriate to its classification.

  • Public/Internal: standard secure channels
  • Confidential/Restricted: encrypted channels and approved platforms only

Unsecured personal email, messaging apps, or unauthorised cloud storage must not be used for Confidential or Restricted information.

7. Storage & Retention

Information must be stored:

  • In approved systems or physical locations
  • In accordance with Murzo Group’s Data Protection Statement and retention schedules
  • With safeguards against unauthorised access, loss, or corruption

Retention periods vary by information type and legal requirement.

8. Disposal & Destruction

When information is no longer required:

  • Digital data must be securely deleted or overwritten
  • Physical records must be shredded or destroyed securely
  • Devices and media must be sanitised before disposal

Disposal must align with classification level and legal obligations.

9. Third-Party Handling

Third parties handling Murzo Group information must:

  • Comply with this policy or equivalent standards
  • Be subject to contractual confidentiality and security obligations
  • Access only the minimum information required

Murzo Group is not responsible for misuse beyond its legal obligations where third parties act independently.

10. Client Responsibilities

Clients using Murzo Group platforms or services:

  • Are responsible for classifying information they provide
  • Must not upload Restricted or sensitive personal data unless expressly agreed
  • Accept responsibility for inappropriate data disclosure

Murzo Group shall not be liable for consequences arising from client misclassification.

11. Monitoring & Enforcement

Murzo Group reserves the right to:

  • Monitor access and usage
  • Investigate suspected misuse
  • Suspend access or take disciplinary action

Breaches of this policy may result in termination of access, contractual remedies, or legal action.

12. Limitations

This policy:

  • Does not guarantee absolute information security
  • Does not override legal disclosure obligations
  • Does not create contractual rights

Murzo Group applies controls proportionately based on risk and feasibility.

13. Review & Updates

This policy is reviewed periodically and updated to reflect:

  • Changes in law or regulation
  • Emerging security risks
  • Operational changes

Updated versions will be published on Murzo Group platforms.

Murzo Group signature