Which Classification Labels are Best for GDPR?
In Spirion Sensitive Data Platform, we recommend you use a tiered labeling strategy to drive different Scan Playbook behaviors based on the risk level of the data found.
1. The "Special Category" Label (High Risk)
GDPR Article 9 defines specific types of data that are prohibited from processing unless a specific exemption applies. These should be your highest priority labels.
- Label Name:
GDPR-Special-CategoryorGDPR-Article-9 - What it covers: Health data (PHI), genetic/biometric data, racial/ethnic origin, political opinions, or religious beliefs.
- Playbook Action: These should typically trigger immediate Quarantine or Encryption and an alert to the Data Protection Officer (DPO).
2. The "Standard PII" Label (Moderate Risk)
This covers data that can identify a natural person but doesn't fall into the special categories.
- Label Name:
GDPR-PIIorGDPR-Personal-Data - What it covers: Names, home addresses, personal email addresses, and identification numbers (like Passport or National ID).
- Playbook Action: Classify (MIP Label) to ensure the data is governed and Notify the file owner to verify the "Lawful Basis" for keeping the file.
3. The "Online Identifier" Label (Digital Footprint)
GDPR explicitly includes digital identifiers in its definition of personal data.
- Label Name:
GDPR-Digital-ID - What it covers: IP addresses, cookie identifiers, and unique device IDs.
- Playbook Action: Often used for Discovery only to map out where web logs or tracking data are stored.
4. The "Data Subject" Label (Contextual)
If your organization handles data for both EU and non-EU citizens, you need to distinguish them to avoid over-applying GDPR restrictions.
- Label Name:
GDPR-EU-Resident - How to use: Use this in combination with other labels (for example,
GDPR-PII+EU-Resident) to ensure you are meeting residency and "Right to Erasure" requirements specifically for EU subjects.
Best Practices for GDPR Labeling
GDPR Requirement | Recommended Label | Recommended Playbook Action |
|---|---|---|
Right to Erasure (Art. 17) |
| Shred or Delete after a retention period expires. |
Data Minimization (Art. 5) |
| Quarantine files that haven't been accessed in 2+ years. |
Security of Processing (Art. 32) |
| Apply MIP Label to enforce "View Only" permissions. |
Breach Notification (Art. 33) |
| Notify the Security Operations Center (SOC) if found in an unprotected location. |
Technical Tip: Using "AnyFinds" for GDPR
Spirion provides built-in AnyFinds specifically for GDPR-relevant data types. When building your GDPR Scan Playbook, ensure you include the following:
- United Kingdom: NINO (National Insurance Number)
- Ireland: PPSN (Personal Public Service Number)
- Germany: Steuer-ID (Tax ID)
- France: NIR (Social Security Number)
Summary
The "best" labels for GDPR are GDPR-Special-Category (for Article 9 data) and GDPR-PII (for general personal data). These enable you to prove to auditors that you have identified, categorized, and applied specific controls to EU resident data.