GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

DAT-002 Information Labelling

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Information assets are labelled in accordance with the data classification scheme. Labels are applied to documents, data stores, outputs and transmissions so that recipients can identify the classification and apply appropriate handling controls.

Rationale

Labelling makes classification actionable at the point of use. Without visible labels, handling rules cannot be enforced consistently across teams and systems.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (6)

DSP-04Data Classificationinformative
DSP-04Data Classificationinformative
5.13Labelling of informationfull
NIS2-CIR-12.2Handling of Assetsinformative
AC-16Security and Privacy Attributespartial
SC-16Transmission of Security and Privacy Attributesinformative

Evidence (2)

configurationtechnicalautomated

System or tooling configuration demonstrating that automated classification labels are applied to data assets and documents at creation or ingestion.

Example: Microsoft Purview / Google Workspace DLP configuration screenshot or export showing auto-labelling rules applied to internal document libraries and shared drives

Test: Read the configuration of the classification and labelling tooling in use, for example a sensitivity-label service or a data loss prevention policy engine. Verify: (1) labelling policies are enabled and active, (2) the rules cover every sensitivity level the classification scheme defines, (3) automatic labelling is applied to the primary document repositories in use, (4) the policy carries a last-reviewed date within the defined interval, (5) a repository in the asset register with no labelling policy is reported as a gap.

tool_outputtechnicalautomated

Sample output from a classification or DLP tool showing labelled documents or data records, confirming labels are visibly applied.

Example: Export from Microsoft Purview Content Explorer or equivalent showing a sample of 20+ documents with their applied sensitivity labels and label origin (manual vs. auto-applied)

Test: Run a content scan or export from the classification tool. Verify: (1) at least one asset per sensitivity tier is present in the sample, (2) labels match the defined taxonomy in the classification policy, (3) no high-volume data stores show entirely unlabelled assets.

Questions (2)

boolean

Are information assets labelled in accordance with the data classification scheme so that recipients can identify the classification at the point of use?

Labels should be visible on documents, data stores, outputs and transmissions. Automated labelling via DLP or sensitivity label tooling (e.g. Microsoft Purview, Google Workspace) is preferred over purely manual labelling.

multi

Which asset types have classification labels actively applied?

Documents and files (internal collaboration tools)Emails and attachmentsDatabase records or data store metadataAPI outputs and data exportsCloud storage objects (e.g. S3 buckets, blob storage)None of the above

A mature labelling programme covers all major asset types. At minimum, documents, emails and data exports should be labelled. Gaps in cloud storage or database labelling should be noted.