Zum Hauptinhalt springen

Using confidentiality classes – classify documents and control access

Confidentiality classes rate documents in preeco | data protection on five levels that build on one another – from „Not classified" to „Strictly confidential". For each user group you define the highest class its members may see and assign under „Settings → User groups and rights → Edit → Document settings"; „Deactivated" lifts the restriction and is reserved for administrators. The class is shown in the „General" section of a document, as a column and filter in the tables, and via the placeholder {CONFIDENTIALITY_LEVEL} in PDF and Word exports. Documents rated above a group's class are completely invisible to it; the class only narrows existing permissions, it never widens them.

Last updated:
Video transcript
Confidentiality classes let you classify documents in preeco | data protection – and control who is allowed to see them. You set them up per user group. Open a user group. In the “Document settings” section the confidentiality class is set to “Deactivated” at first. Click “Edit” and choose the highest class this group may see – from “Public” to “Strictly confidential”. Each class automatically includes the lower ones: “Internal use only” also covers “Public” and “Not classified”. In every document the class is shown in the “General” section – marked in colour. When editing, you set the class yourself. Classes above your own clearance are not available. In the overview tables the “Confidentiality class” column shows how your documents are classified. The filter lets you find all documents of a particular class. For members of the group everything above their class stays invisible – in lists, search and reports. For PDF and Word exports, add the placeholder for the confidentiality class to the header or footer.

Data protection and information security documents often contain sensitive content that not everyone in the team should see. With confidentiality classes you rate individual documents and use the user group to control the level up to which its members may see – and assign – content.

1. The five confidentiality classes

preeco | data protection knows five classes that build on one another: „Not classified", „Public", „Internal use only", „Confidential" and „Strictly confidential". Each class automatically includes all lower ones – whoever may see „Confidential" therefore also sees „Internal use only", „Public" and „Not classified".

2. Setting up confidentiality classes for a user group

Open „Settings → User groups and rights" and select the user group. Click „Edit" and, in the „Document settings" section, set the „Confidentiality class" field to the highest class this group may see and assign. Then save the user group.

3. The „Deactivated" setting

If a user group's confidentiality class is set to „Deactivated", no restriction applies to its members: they see all documents regardless of their rating, and the classification field is not shown to them. „Deactivated" is therefore the widest – not the narrowest – setting and may only be assigned by administrators.

4. Where the class appears in a document

On a document's detail page the confidentiality class is shown in the „General" section as a colour-coded field. When editing, you select it in the same section via the „Confidentiality class" field. Classes above your own clearance are not available for selection.

5. Column and filter in the overview tables

The tables of the modules gain a „Confidentiality class" column – it can be sorted, searched and shown or hidden via the „Columns" button. The „Confidentiality class" filter shows all documents of a particular rating.

6. Printing the class in PDF and Word exports

Under „Settings → Document settings" select the document type and add the placeholder {CONFIDENTIALITY_LEVEL} to the header or footer. On every export the document's class is inserted there. Documents rated „Not classified" deliberately leave the placeholder empty so that no misleading notice appears on unclassified documents.

7. Effects on permissions

Members of a user group only see documents up to the class released for them. Documents rated higher are completely invisible to them – in overview tables, in the search, in related documents and in reports. The confidentiality class works in addition to the user group's permissions and the organisation assignment: it can only narrow access, never widen it. Administrators see all documents regardless of the rating.

8. Which content can be classified

All document-based content can be classified – including processing activities and processing activities carried out on behalf of a controller, data protection impact assessments, transfer impact assessments, risk analyses and risks, rule sets, deletion policies, data processing agreements and joint controllership agreements, privacy policies, data processing systems, technical and organisational measures, information obligations, consent declarations, audits and audit catalogues, checklists, training courses, data subject requests, incidents, surveys and tasks – as well as tags, text modules, contacts, reports and revisions.

Note: Existing documents keep the class „Not classified" until you rate them anew. Because raising a class withdraws access from colleagues, you should agree your classification concept within the team first and set up the user groups accordingly.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.