Table of Contents
- 1. Purpose
- 2. Scope
- 3. Policy Statement
- 4. Roles and Responsibilities
- 5. Policy Requirements
- 6. Implementation Guidance
- 7. Monitoring, Evidence, and Compliance
- 8. Exceptions
- 9. Review and Maintenance
- 10. Related Standards
1. Purpose
This Information Classification and Handling Policy establishes a consistent framework for identifying, labeling, storing, transmitting, accessing, retaining, and disposing of information according to its sensitivity and business value. Ligala Tech Pte operates in legal technology, where information may include client matter data, legal documents, contracts, personal data, internal product roadmaps, support records, and commercial information. Because these information types can create legal, contractual, privacy, and reputational risk if mishandled, the organization requires clear rules that employees and contractors can follow in daily work.
The policy is intended to reduce the likelihood of unauthorized disclosure, accidental loss, improper retention, and insecure sharing of information. It also supports secure collaboration with clients, partners, vendors, and other third parties that may receive or process information on behalf of Ligala Tech Pte. In Singapore, the handling of personal data must align with the Singapore Personal Data Protection Act (PDPA), and the company’s information security controls must support ISO 27001-aligned governance and operational discipline.
This policy applies practical safeguards that fit the size and operating model of Ligala Tech Pte. As a small legal technology company, the organization relies on a limited number of staff members who may wear multiple operational hats, making it especially important that classification and handling rules are simple, understandable, and consistently enforced. The policy therefore emphasizes clear ownership, repeatable processes, and evidence-based compliance
2. Scope
This policy applies to all information created, received, processed, stored, transmitted, or disposed of by Ligala Tech Pte, regardless of format or location. This includes electronic records in cloud platforms, local endpoints, email, instant messages, collaboration tools, printed documents, removable media, backups, and records shared with third parties. It covers information owned by Ligala Tech Pte as well as information entrusted to the company by clients, prospects, vendors, and employees.
The policy applies to all personnel who access Ligala Tech Pte information, including employees, directors, interns, contractors, temporary staff, and any external service providers with authorized access. It also applies to all business functions, including product development, customer support, sales, finance, administration, and management. Where contracts or regulations impose stricter handling requirements than this policy, the stricter requirement must be followed.
This policy is especially relevant to legal technology operations because the company may handle information that carries distinct confidentiality, privacy, and retention obligations. Case files, legal correspondence, contracts, identity documents, employment records, system logs, and client metadata may require different levels of protection and different disposal timelines. The policy therefore defines a baseline handling standard for all information categories while allowing more restrictive controls where necessary.
3. Policy Statement
Ligala Tech Pte shall classify information according to sensitivity, business criticality, contractual commitments, and legal or regulatory obligations, and shall handle each classification level using proportionate safeguards. Information must be protected from unauthorized access, use, alteration, disclosure, and destruction throughout its lifecycle. Classification is mandatory for information that could affect clients, employees, operations, legal position, privacy obligations, or intellectual property if mishandled.
All personnel are responsible for protecting information they create, receive, store, transmit, or dispose of. Information must be shared only with authorized recipients and only through approved channels with appropriate security controls. Confidential and personal data must not be left unattended, transmitted insecurely, or retained longer than necessary. Documents and records must be labeled and stored in a manner that makes their sensitivity clear to users and systems.
Ligala Tech Pte shall maintain handling rules that support operational simplicity while still meeting the expectations of ISO 27001 and the Singapore PDPA. The company recognizes that legal technology services often require rapid collaboration, but convenience must not override privacy, confidentiality, or client trust. Employees must apply judgment within the boundaries of this policy and seek guidance when uncertainty exists. Noncompliance may result in disciplinary action, contract remedies, or access restrictions.
4. Roles and Responsibilities
- Managing Director: Approves the policy, sets the organization’s risk tolerance, and ensures sufficient resources are available for implementation and enforcement.
- Information Security Lead: Owns the classification framework, maintains handling standards, reviews exceptions, and coordinates monitoring, incident response, and policy updates.
- Data Protection Officer: Ensures the policy supports PDPA obligations, advises on personal data handling, reviews privacy-related incidents, and oversees responses to access or disclosure requests involving personal data.
- Department Managers: Ensure their teams classify and handle information correctly, approve business-use deviations within their authority, and verify that staff complete required training and follow approved processes.
- All Employees and Contractors: Classify information they create or receive, follow labeling and handling rules, use approved systems and channels, and report suspected mishandling, loss, or unauthorized disclosure immediately.
- IT Administrator or System Owner: Implements technical controls such as access restrictions, encryption, logging, retention settings, and secure deletion, and preserves evidence of those controls.
- Records Owner or Matter Owner: Determines business classification for specific records or client matters, confirms retention requirements, and authorizes disposal when the retention period ends.
- Human Resources and Administration: Ensures employee records, onboarding materials, and physical file controls are handled according to this policy and that departing personnel return or delete organizational information.
5. Policy Requirements
- Information must be classified into one of four levels: Public, Internal Use, Confidential, or Restricted. The Records Owner or Department Manager owns the classification decision upon creation or receipt, and it must be reviewed at least annually or when the content changes materially. Evidence: labeled documents, matter records, or system metadata showing the assigned classification.
- All information assets must display or carry their classification where practical, including file names, headers, footers, system tags, or folder labels. The creator or system owner owns the labeling action, and it must occur at the time of creation or ingestion into a managed repository. Evidence: screenshots, file samples, or system configuration showing labels.
- Confidential and Restricted information must be stored only in approved corporate systems with access controls, encryption at rest where supported, and role-based permissions. The system owner owns storage controls, and access reviews must occur quarterly. Evidence: access control lists, encryption settings, and quarterly access review records.
- Restricted information, including sensitive client matter data and high-risk personal data, must be additionally protected by stronger controls such as MFA, limited group membership, and named-user access. The Information Security Lead owns the control baseline, and it must be enforced continuously. Evidence: MFA enforcement reports, access logs, and privileged access records.
- Information must be transmitted using approved secure channels such as corporate email with encryption, secure file-sharing platforms, or authenticated client portals. The sender owns compliance for each transmission, and the requirement applies every time information is shared externally or internally. Evidence: email logs, portal audit trails, or transfer records.
- Personal data must be collected, used, disclosed, and retained only for authorized business purposes and in line with PDPA obligations. The Data Protection Officer owns privacy guidance, and reviews must occur before new workflows are launched and during annual privacy assessments. Evidence: privacy review forms, consent or notification records, and workflow approval notes.
- Printed Confidential and Restricted documents must be minimized, controlled, and stored in locked cabinets or secure rooms when not in use. The person printing or handling the document owns this requirement, and it applies every time such documents are printed or moved. Evidence: physical security checks, sign-out logs, and spot inspection results.
- Portable media may not be used for Confidential or Restricted information unless expressly approved by the Information Security Lead and protected by encryption. The requester owns justification for use, and approval is required per event. Evidence: exception approval, device inventory, and encryption status.
- Retention periods must be defined for each record category, and disposal must occur securely when legal, contractual, or business retention requirements expire. The Records Owner owns retention decisions, and review must occur at least annually and at matter close. Evidence: retention schedule, disposal certificates, and deletion logs.
- Backups containing Confidential or Restricted information must be protected with the same sensitivity controls as the source data, including restricted access and secure storage. The IT Administrator owns backup protection, and checks must occur with each backup cycle and during quarterly control reviews. Evidence: backup configuration, restore test results, and access logs.
- Sharing information with third parties requires a valid business purpose, a need-to-know basis, and contractual safeguards where personal or confidential data is involved. The contracting owner and Department Manager share accountability, and review occurs before onboarding the third party and before any material change in scope. Evidence: executed agreements, due diligence records, and sharing approvals.
- Information incidents, including misdelivery, loss, unauthorized access, or improper disposal, must be reported immediately to the Information Security Lead and Data Protection Officer. The person who detects the incident owns the initial report, and reporting must occur without delay and no later than the end of the business day. Evidence: incident tickets, investigation notes, and corrective action records.
- Employees must complete mandatory classification and handling training on onboarding and annually thereafter, with refresher training after a policy breach or significant process change. Human Resources owns training assignment and tracking, and completion is required within 30 days of assignment. Evidence: LMS completion reports and attendance records.
6. Implementation Guidance
Ligala Tech Pte should implement this policy by starting with a small, practical classification model that employees can understand without extensive training. Public information should be limited to approved marketing content and externally published material. Internal Use should cover ordinary business information. Confidential should include contracts, internal financials, client communications, and non-public operational information. Restricted should be reserved for highly sensitive client matter data, identity documents, credentials, and information whose disclosure would cause substantial harm.
The company should embed classification into everyday workflows rather than treating it as a separate administrative task. Document templates should include visible classification markers in headers or footers. Cloud storage folders should be labeled by classification and matter owner. Email and collaboration platforms should use approved sensitivity labels or naming conventions. For a small organization, this may be implemented through a combination of policy-based user guidance, standard templates, and default settings in Microsoft 365, Google Workspace, or a comparable platform.
Operationally, the rollout should begin with the highest-risk information sets: client matter files, employee personal data, contracts, and credential-related documents. The Information Security Lead and Data Protection Officer should work with department managers to identify where these records are stored, who accesses them, and what sharing paths exist. Existing repositories should be cleaned up through a short remediation exercise that relocates sensitive files into approved systems, removes stale access, and applies labels. This initial effort should be followed by periodic spot checks and short refresher communications.
Technical controls should support the policy without creating unnecessary friction. Where available, enforce MFA, device encryption, secure sharing links, download restrictions for external recipients, and audit logging. Use approved secure file transfer methods for large files rather than ad hoc consumer services. For printing, scanning, and physical records, establish a simple process for sign-out, lockable storage, and secure shredding. If the company uses external cloud vendors, their configuration should be reviewed to ensure that access permissions and retention settings align with this policy.
Training and awareness should be concise and role-based. Staff who routinely handle client matters or personal data should receive examples specific to legal technology, such as how to send case files to a client, how to redact identity documents, and how to store draft agreements. Managers should be trained to recognize overclassification and underclassification. New hires should be introduced to the classification model during onboarding, and short annual refreshers should reinforce practical do’s and don’ts. A short reference guide or decision tree is recommended to support daily use.
7. Monitoring, Evidence, and Compliance
Compliance with this policy must be monitored through a combination of control reviews, sampling, and incident analysis. The Information Security Lead should conduct quarterly reviews of access permissions, storage locations, and encryption settings for Confidential and Restricted repositories. The Data Protection Officer should review privacy-sensitive workflows and incidents to verify that personal data is being collected and shared lawfully. Department managers should periodically sample documents and communications to confirm that classification labels, secure storage, and secure transmission practices are being used in practice.
Evidence should be retained to demonstrate that controls are operating effectively. Acceptable artifacts include labeled document samples, system screenshots, access review sign-offs, training completion reports, transfer logs, disposal certificates, incident records, and exception approvals. For a small organization, evidence collection should be lightweight but consistent, with each review producing a dated record and named reviewer. Where automated logs exist, they should be retained for a period consistent with security and audit needs and protected from tampering.
Monitoring should also focus on measurable indicators. Examples include the percentage of staff completing training on time, the number of misaddressed emails or mis-shared files, the number of open exceptions, the number of overdue access reviews, and the percentage of Restricted repositories protected by MFA and named-user access. A recurring increase in incidents, repeated failure to label sensitive documents, or overdue review actions should trigger escalation to management. Serious breaches involving personal data or client confidentiality must be assessed promptly for regulatory, contractual, and client notification obligations.
8. Exceptions
Exceptions to this policy are permitted only when business need is documented and the proposed alternative control provides equivalent or better risk management. The requester must describe the information involved, the reason the standard requirement cannot be met, the compensating control, and the duration of the exception. The Information Security Lead and, where personal data is involved, the Data Protection Officer must review the request. Approval authority rests with the Managing Director for material exceptions or with the Information Security Lead for low-risk, time-limited deviations.
All approved exceptions must be documented in a central register and must include the scope, start date, end date, approver, compensating controls, and review date. Exceptions must have a defined expiry date and may not remain open indefinitely. Before expiry, the requester must either return to compliance or submit a renewal request with updated justification. If the risk changes, the exception may be revoked immediately.
Expired or denied exceptions must not be used as precedent for future approvals. The company should periodically review the exception register to identify recurring requests, which may indicate a control gap or a need to revise the policy, toolset, or training. Any exception involving client contractual obligations, cross-border transfer risk, or personal data should be scrutinized carefully and documented with sufficient detail for later audit or incident review.
9. Review and Maintenance
This policy must be reviewed at least annually by the Information Security Lead and Data Protection Officer, with final approval by the Managing Director. Interim review is required when there is a major incident, significant regulatory change, new client contractual requirement, major platform migration, or organizational change that affects information handling. Because Ligala Tech Pte is a small and agile organization, the review process should be concise but rigorous, focusing on whether the classification model remains understandable and whether the handling rules still fit daily operations.
Review outcomes must be documented, including any policy changes, rationale, implementation actions, and target completion dates. Where updates affect staff behavior, the revised policy must be communicated promptly, and affected personnel must complete refresher training if the change is material. Supporting documents such as classification guidance, retention schedules, secure sharing instructions, and exception forms should be updated in tandem so that the policy and its operational materials remain aligned.
The company should maintain version control for the policy and related guidance. Obsolete versions should be archived in a controlled location for audit purposes. Lessons learned from incidents, audit findings, staff questions, and control monitoring should inform each review cycle. This approach helps ensure the policy remains practical, legally relevant, and consistent with the organization’s evolving technology stack and client commitments.
10. Related Standards
ISO 27001 is the primary information security management standard that underpins this policy. This policy supports ISO 27001 by defining controls for information classification, access restriction, secure handling, evidence retention, exception management, and continual review. It provides operational rules that can be used to demonstrate that Ligala Tech Pte is managing information risks systematically and assigning clear accountability for protection measures.
The Singapore PDPA is directly relevant because Ligala Tech Pte may process personal data relating to employees, clients, prospects, and other individuals. This policy supports PDPA obligations by requiring lawful and purposeful handling, limiting access to need-to-know personnel, promoting secure transfer and storage, and requiring prompt incident reporting. The policy also reinforces retention limitation and secure disposal, both of which are important for reducing privacy risk.
Together, ISO 27001 and the Singapore PDPA create a dual foundation for this policy: ISO 27001 provides the security management structure and control discipline, while PDPA ensures personal data is handled lawfully and responsibly in the Singapore context. This policy translates those standards into day-to-day expectations for a legal technology company whose work often includes sensitive client materials, contracts, and personal data.
Comments
0 comments
Please sign in to leave a comment.