Seed-stage B2B SaaS startup
Sample for a fictional organisation · 2,515 words[Company] Data Management Policy
- Version: 1.0
- Owner: CTO / Founder
- Approved by: CEO
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose
This policy sets out how [Company] classifies the data it creates, receives, and stores, and how each class of data must be handled, retained, and disposed of. It supports [Company]'s information security policy by giving staff practical rules for day-to-day data handling, including work carried out on customer accounts, internal business records, and personal data collected from employees, prospects, and website visitors.
[Company] is a small, fully remote team building business-to-business software for small and mid-sized business customers. Because the company is small, it relies on clear, consistently applied rules rather than large committees or dedicated data-governance staff. This policy tells every employee what data they may be handling, where it can be stored, who it can be shared with, and how long it is kept.
2. Scope
This policy applies to all [Company] employees, contractors, and any other individual who accesses [Company] systems or data, and it covers all data the company creates, receives, stores, or processes, regardless of format, including data held in the company's cloud infrastructure, Google Workspace, GitHub, and on company-managed or personal devices used for work.
Read the full example
[Company] Data Management Policy
- Version: 1.0
- Owner: CTO / Founder
- Approved by: CEO
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose
This policy sets out how [Company] classifies the data it creates, receives, and stores, and how each class of data must be handled, retained, and disposed of. It supports [Company]'s information security policy by giving staff practical rules for day-to-day data handling, including work carried out on customer accounts, internal business records, and personal data collected from employees, prospects, and website visitors.
[Company] is a small, fully remote team building business-to-business software for small and mid-sized business customers. Because the company is small, it relies on clear, consistently applied rules rather than large committees or dedicated data-governance staff. This policy tells every employee what data they may be handling, where it can be stored, who it can be shared with, and how long it is kept.
2. Scope
This policy applies to all [Company] employees, contractors, and any other individual who accesses [Company] systems or data, and it covers all data the company creates, receives, stores, or processes, regardless of format, including data held in the company's cloud infrastructure, Google Workspace, GitHub, and on company-managed or personal devices used for work.
3. Policy
[Company] must classify all data it holds into one of four levels — Restricted, Confidential, Internal, or Public — and handle, retain, and dispose of that data according to the rules set for its level. Staff must apply the classification that matches the data they are creating or handling, and where they are unsure, they must treat the data as Confidential until the appropriate owner confirms its classification.
4. Roles and Responsibilities
- CEO: Approves this policy and any material exceptions to it, and ensures the company allocates the time and resources needed to comply with it.
- CTO / Founder (Policy Owner): Owns this policy; classifies the company's data and decides who may access each class; owns and approves access to customer data, employee data, financial records, and system credentials; approves any AI tool for use with Confidential data; runs the annual data review described in Section 9; and oversees data and device disposal.
- All Staff: Must follow the classification and handling rules in this policy, apply the correct classification to data they create, complete any related training, and report suspected data incidents or losses to [Security contact email] without delay.
5. Data Classification
[Company] classifies data into four levels, from most to least sensitive: Restricted, Confidential, Internal, and Public. Every employee is responsible for applying the correct level to the data they handle and for treating data at least as strictly as the level assigned to it.
5.1 Restricted
Restricted data is data that would cause serious harm to [Company], its employees, or its customers if it were exposed, altered, or lost. It receives the strictest handling rules in this policy.
- Cloud infrastructure credentials, root and IAM (identity and access management) access keys, and API keys
- Encryption keys used to protect company or customer data
- Production database credentials and access secrets stored in source control or configuration systems
- Employee Social Security numbers, bank account details, and other sensitive payroll or benefits information
5.2 Confidential
Confidential data is data that is sensitive but needed for normal business operations. This includes personal data [Company] processes on behalf of its business customers, which is always at least Confidential; a customer's contract may set stricter rules that must also be followed.
- Customer account data and end-user personal data processed through [Company]'s product on behalf of business customers
- Prospect and marketing contact data, such as names, email addresses, and company details of leads
- Employee personal data not listed as Restricted, such as employment history and performance records
- Financial records, contracts, and billing information
5.3 Internal
Internal data is company business information that is not intended for public release but would cause limited harm if seen by the wrong internal audience.
- Internal business communications, meeting notes, and planning documents
- Source code that does not contain embedded secrets
- SOC 2 audit evidence, such as internal policies, procedures, and risk assessments
- System and access logs from company tools
5.4 Public
Public data is information [Company] intends for anyone to see and that carries no risk if disclosed.
- Published marketing and website content
- Public blog posts and press materials
- Job postings and other publicly posted recruiting content
5.5 Data Labels
Staff must indicate a document's classification level in the document itself (for example, in the file name, a document header, or a folder name) or by storing it in a folder or system area designated for that level. Data that carries no label is called "unlabelled" and must be treated as Confidential until the data owner confirms its correct classification.
6. Data Handling
Each classification level has its own rules for where data may be stored, whether it may be shared, printed, copied to removable media, or entered into AI tools, and whether encryption is required. Staff must follow the rules for the level assigned to the data they are handling, and where data is unlabelled, the Confidential rules apply until it is classified.
6.1 Restricted Data Handling
Restricted data must be handled with the highest level of care and access must be limited to individuals who need it for their role, as approved by the data owner.
- Store only in the company's approved cloud infrastructure or password manager, protected with encryption at rest and in transit
- Never store on removable media (such as USB drives) or personal devices
- Never email unless the recipient is specifically authorized by the data owner and the transmission is encrypted
- Never share outside the company without written approval from the data owner
- Never print; if printing is unavoidable, the copy must be collected immediately and destroyed after use
- Never enter into any AI tool unless the data owner has specifically approved that use
6.2 Confidential Data Handling
Confidential data must be stored only in the company's approved cloud services and access limited to staff who need it for their role.
- Store only in the company's approved cloud services (its cloud infrastructure or Google Workspace) with role-based access controls
- May be shared with third parties only where a contract or non-disclosure agreement permits it, and only with the intended recipient
- Must be encrypted in transit; do not store on personal devices, other than accessing Google Workspace through an approved, secured mobile app
- Do not copy to removable media
- Avoid printing; where printing at home is necessary, the document must be collected immediately and destroyed by cross-cut shredding, and Confidential data must only be accessed over a secured, password-protected home Wi-Fi network, never public Wi-Fi
- Staff must not enter Confidential or Restricted data into any AI tool unless the tool has been approved for that purpose by the policy owner
6.3 Internal Data Handling
- Store in the company's approved cloud services; may be shared freely within the company
- Do not share outside the company without manager approval
- May be emailed internally without restriction
- May be printed for legitimate business purposes, including at home, provided printed copies are kept secure
- Avoid long-term storage on personal devices; access through company-managed accounts is preferred
6.4 Public Data Handling
- May be stored, emailed, shared, printed, or copied without restriction
- Must be reviewed and approved by the CEO or CTO/Founder before external publication to confirm accuracy
7. Data Retention
[Company] keeps data only for as long as it is needed for the purpose it was collected or created, subject to the periods it has chosen and any legal minimums that apply. Appendix B (Section 15) sets out the retention period, legal or business basis, and disposal method for each type of data the company holds.
8. Data and Device Disposal
Company devices and media (including laptops, phones, and any physical storage) must be wiped or destroyed before they are reused, returned at the end of a lease, or thrown away, using a recognized method such as those described in NIST SP 800-88. A record must be kept of each device disposed of, including its identifier, the method used, and the date. Where [Company] uses an outside disposal service, it must obtain a certificate of destruction for each batch of devices disposed of.
Because [Company]'s systems run on cloud infrastructure and software-as-a-service tools, disposal of data itself depends on where it is held. For data held in the company's cloud infrastructure, deleting or destroying the encryption keys that protect the data (cryptographic erasure) is an accepted disposal method. For data held in Google Workspace, GitHub, or other software-as-a-service tools, deletion relies on each tool's own built-in deletion features, used according to that provider's documented process.
9. Annual Data Review
The CTO/Founder must run an annual review of this policy's classification and retention rules. The review must confirm that each data type is still classified correctly, that data past its retention period has been deleted, and that the retention matrix in Appendix B still reflects how [Company] actually collects, uses, and stores data.
10. Legal Requirements
[Company]'s data handling is shaped by the laws that apply to its US operations and its SOC 2 program.
- The California Consumer Privacy Act (CCPA) and other applicable US state privacy laws give individuals rights to access, correct, or delete their personal information. Where [Company] controls the purpose of processing personal data itself — such as data about its employees, prospects, or website visitors — it must respond to such requests within CCPA's 45-day period, which can be extended once by a further 45 days; for other applicable state laws, requests must be answered within the period that law requires.
- Where [Company] processes personal data on behalf of a business customer, it must pass any request it receives from that customer's end users to the customer and assist the customer in responding, rather than responding itself.
- At the end of a customer contract, [Company] must return or delete the customer's data, including data derived from it, within the period set by that contract.
- Tax, employment, and accounting records must be kept for the minimum period required under applicable federal and state law.
- Records supporting [Company]'s SOC 2 program, such as policies, procedures, and evidence of controls, are retained based on business need.
11. Policy Compliance
All staff must comply with this policy as a condition of accessing [Company] systems and data. The CTO/Founder is responsible for monitoring compliance and addressing gaps identified through the annual review or otherwise.
12. Exceptions
Any exception to this policy must be requested from and approved in writing by the CTO/Founder, documented with the reason for the exception, and time-limited. Exceptions with a significant impact on customer data or legal obligations must also be approved by the CEO.
13. Violations & Enforcement
Failure to follow this policy may result in disciplinary action, up to and including termination of employment or contract, and, where the violation involves unlawful activity or a breach of contract, may lead to legal action. The CTO/Founder, with the CEO where needed, is responsible for investigating suspected violations and deciding the appropriate response.
14. Appendix A: Internal Retention and Disposal Procedure
- The data owner identifies the data type involved and confirms its classification and retention period against Appendix B.
- During the annual review, or as data is created or received, the data owner flags any data that has passed its retention period.
- Data past its retention period must be deleted within 30 days, unless it is subject to a legal hold (such as a claim, investigation, or regulator's request), in which case deletion is paused until the CTO/Founder confirms the hold has been lifted.
- Legal holds are tracked by the CTO/Founder, who notifies relevant staff when a hold begins and ends.
- Backups containing data that has been deleted from live systems are not manually edited; they are overwritten automatically on their normal backup cycle.
- Devices and physical media being reused, returned, or discarded must be wiped or destroyed using a method consistent with NIST SP 800-88 before they leave the company's control.
- Where an outside disposal service is used, the certificate of destruction it provides must be kept on file.
- The CTO/Founder maintains a log of disposed devices and media, recording the device identifier, disposal method, and date.
15. Appendix B: Data Retention Matrix
| Data type | Classification | Retention period | Basis | Disposal method |
|---|---|---|---|---|
| Cloud infrastructure and system credentials, encryption keys | Restricted | Until rotated or no longer needed | Business need | Cryptographic erasure / secure deletion |
| Customer account data and end-user personal data (processed on behalf of business customers) | Confidential | Duration of contract; deleted or returned within 30 days of contract end | Contract | Deletion via cloud infrastructure and SaaS tools per contract |
| Employee Social Security numbers, bank details, and payroll/benefits data | Restricted | 7 years after employment ends | Employment law, confirm the minimum | Secure deletion (NIST SP 800-88) |
| Other employee personal data (employment history, performance records) | Confidential | 7 years after employment ends | Employment law, confirm the minimum | Secure deletion (NIST SP 800-88) |
| Prospect and marketing contact data | Confidential | 3 years from last interaction | Business need | Deletion via approved cloud services |
| Financial and accounting records | Confidential | 7 years | Tax law, confirm the minimum | Secure deletion |
| SOC 2 audit evidence (policies, procedures, risk assessments) | Internal | 3 years | Business need | Secure deletion |
| System and access logs (cloud infrastructure, Google Workspace, GitHub) | Internal | 1 year | Business need | Secure deletion / automatic overwrite |
| Source code (non-secret) | Internal | Retained while in active use; deleted upon repository archival | Business need | Deletion via GitHub |
| Published marketing and website content | Public | Retained while published | Business need | Deletion via content management tools when retired |
Retention periods above are [Company]'s own chosen periods and may be changed as its business needs or legal obligations change; where a legal minimum is named, [Company] must confirm that minimum with a qualified adviser before shortening the period shown.
Disclaimer
This document is provided for informational purposes only and does not constitute legal advice. It is provided "as is", without warranty of any kind, express or implied, and no liability is accepted for any loss or damage arising from its use. It is used at your own discretion. Review it with a qualified adviser before adopting it.