Which company data counts as sensitive?
Quick reply
What the GDPR treats as sensitive data, the five critical categories in a company, and how to rank them by how critical they really are.

Every company today has to manage a considerable volume of data in order to grow and hold its own against the competition. All data matters, but some of it is more sensitive than the rest. So what exactly counts as sensitive data? Here are some answers.
What is sensitive data?
According to the CNIL, France's data protection authority, and the General Data Protection Regulation (GDPR), data is said to be sensitive when it can reveal a person's race or ethnicity, their political opinions or leanings, their religion or philosophy, or their trade union membership. It can also cover genetic and biometric data allowing a person to be identified physically. Data that can reveal a person's state of health or sexual orientation is likewise considered sensitive. Take care not to confuse sensitive data with personal data: the latter means any information allowing a natural person to be identified, directly or indirectly, through one or more details particular to them. That might be a first name or surname, a phone number, a registration number, a social security number or an IP address.
What counts as sensitive data for a company?
For a company, data is described as sensitive when it can confer some advantage, economic or strategic, and when its disclosure, alteration, destruction or fraudulent use could cause harm. Broadly, there are 5 main categories of sensitive company data:
- Data about people: clients and prospects, colleagues and outside partners, suppliers and so on.
- Data about what the company does : know-how, manufacturing secrets, design methods, intellectual property documents, production plans, prototypes and so on.
- Strategic and organisational data : strategic decisions, direction, documents from governance bodies, recruitment plans and so on.
- Economic and financial data : cash position, financial arrangements, pricing policy, salary scales, forecast budgets, purchasing terms agreed with suppliers and so on.
- Legal data, meaning all information tied to legal obligations, GDPR compliance and other regulations in force among them.

What are companies' obligations around sensitive data?
Under the GDPR, in force in France and across Europe, collecting and using sensitive data is formally prohibited unless:
- The person concerned gives their express and explicit consent;
- The person concerned has manifestly made the information public;
- The data is necessary to save a human life;
- Using the data is authorised by the CNIL and justified by the public interest;
- The data concerns the members of a religious, political, philosophical or trade union organisation.
The GDPR also places companies under an obligation to protect the data they collect and use, so that it cannot be altered, diverted, modified or used by people with bad intentions. Every company therefore has to take suitable security measures. It is worth noting that this obligation covers only the sensitive data of natural persons. But given the rise in cyberattacks, which can cost companies dearly, securing the other categories of sensitive company data properly is essential too.
Why protect your company's sensitive data?
A company's sensitive data often attracts people with bad intentions, hackers and industrial spies in particular. The aim, in most cases, is either to extract money fraudulently or to disrupt how the company works, whether for competitive reasons or otherwise. According to recent studies, companies that fail to protect their sensitive data, or protect it poorly, expose themselves to 5 major risks: supplier fraud, straightforward identity theft, CEO fraud, intrusion into information systems and customer fraud. No company is spared cyberattacks these days, whatever its size and whatever it does. Statistics show that close to three quarters of companies were the target of an attempted fraud in 2018, and a quarter of those more than ten times. With remote working on the rise, companies have every reason to be more vigilant, because conditions are more favourable than ever to cyberattacks.
How do you protect your company's sensitive data?
There are various ways of protecting a company's sensitive data today. NetExplorer offers encryption, among other things, to make all of your critical information unreadable except to those with the necessary permissions. For that protection to be genuinely effective, though, the data has to be ranked and classified by how critical it is. There is no established rule for classifying sensitive company data, but the simplest approach is to sort it into 3 levels:
- Public data, whose disclosure to the general public does the company no harm at all. Customer service contact details (phone numbers and email addresses) or the address of the head office, for instance.
- Internal data, which does not call for heavy security measures but is not meant for the general public either. The company's organisation chart might fall into this category.
- Restricted data, meaning highly sensitive internal data whose disclosure could harm the company financially or legally. This covers the personal information of clients, employees, suppliers and other partners, along with credentials such as usernames and passwords.
You are then free to add further levels according to what your company needs.
Other articles you might like
Strengthening your resilience against cyberattacks
Ransomware and human error: the technical and organisational levers that build resilience and let you react quickly after an incident.


But let's be honest, our cloud-based file storage and sharing solution is much easier.



