On this page
The single most useful question you can teach your team to ask before they paste anything into an AI tool is this: “What tier is this?”
That question only works if your team knows what the tiers are. Most small and mid-sized businesses in Northern Ontario have never formally classified their data. Which means every employee — the project manager, the bookkeeper, the office administrator, the service technician — is making the call on their own, every day, every prompt.
This post gives you a four-tier classification model that fits on one page, maps cleanly to real AI tools, and actually works for the kinds of businesses we serve: construction firms, professional services offices, non-profits, health practices, municipal offices, and Indigenous organizations across Thunder Bay, Nipigon, Timmins, and the surrounding region.
Why Classification Is the Foundation
An AI policy that says “use AI responsibly” is worthless. Employees need a rule they can apply in five seconds, at their desk, with a document open in one window and Copilot open in another.
Data classification is that rule. It takes the question “can I paste this?” and turns it into a yes/no/maybe based on what the data actually is — not on how rushed the employee feels.
Under PIPEDA, your business is accountable for personal information under your control, including when it passes through third-party systems. Under PHIPA (Ontario’s Personal Health Information Protection Act), health information has its own strict rules. Under most funding agreements, grant contracts, and professional confidentiality obligations, there are additional requirements layered on top. Classification is how you translate those obligations into something your staff can act on in real time.
The Four Tiers
Tier 1 — Public
What it is: Information already published or intended for public release. Your website copy, press releases, published pricing, marketing brochures, job postings, public-facing product documentation, social media posts.
Who it’s meant for: Anyone. If it leaked, nothing would happen, because it’s already out there.
AI rule: Any approved AI tool is fine. Consumer ChatGPT, Copilot, Gemini — all acceptable for Public data.
Real-world examples for a Northern Ontario SMB:
- “Rewrite this service page in a friendlier tone.”
- “Suggest five taglines based on our public value proposition.”
- “Summarize these three competitor websites.”
- “Draft a LinkedIn post announcing our new hire — based on the press release we already published.”
Tier 2 — Internal
What it is: Everyday business information that isn’t secret but isn’t meant for the outside world. Internal memos, meeting agendas, draft marketing copy, non-sensitive project plans, general operational notes, routine emails between staff.
Who it’s meant for: Your own employees.
AI rule: Enterprise or business-tier AI tools only — ones where your organization has a contract that prevents the vendor from training on your data. Microsoft 365 Copilot inside your tenant, ChatGPT Enterprise/Team, or Gemini for Google Workspace Business. No consumer accounts. No free tools. No personal logins.
Examples:
- “Summarize the notes from yesterday’s operations meeting.”
- “Draft an internal email announcing the new vacation policy.”
- “Turn these bullet points into a Q2 planning document.”
- “Rewrite this proposal draft — make it tighter.”
Tier 3 — Confidential
What it is: Information that would cause real harm if it leaked. Client lists, contract terms, non-public financials, HR records, performance reviews, strategic plans, unreleased product roadmaps, vendor agreements under NDA, donor and funder information, governance records.
Who it’s meant for: Specific people inside your business who need it to do their jobs.
AI rule: Only AI tools that are contractually bound, tenant-isolated, and covered by your organization’s data processing agreement. In practice this means Microsoft 365 Copilot inside your own tenant, or a purpose-built enterprise tool your IT partner has formally reviewed and approved. Free and consumer AI tools are a hard no. Personal Gmail accounts, browser extensions, “free trial” AI tools — none of them belong near this tier.
Examples (in an approved tool only):
- “Summarize this signed client contract and flag unusual clauses.”
- “Draft performance review feedback based on these manager notes.”
- “Compare these two vendor proposals side by side.”
- “Turn this funder reporting data into a narrative summary.”
Tier 4 — Restricted
What it is: Data that is legally protected or would cause catastrophic harm if exposed. Personal health information (PHI), financial account numbers, Social Insurance Numbers, government-issued IDs, payment card data, privileged legal communications, trade secrets, authentication credentials, and anything covered by specific regulatory frameworks.
Who it’s meant for: A very narrow set of authorized people — often legally defined.
AI rule: Do not put Restricted data into any general-purpose AI tool, even an enterprise one, unless it has been explicitly assessed and approved for that specific data type, with the appropriate data processing agreements in place. For most SMBs, the honest answer for Restricted data is “no AI at all, yet.” When a purpose-built, vetted, regulated-industry tool is available and approved, the answer can change. Until then, keep it out.
Regulated industry examples in Northern Ontario:
- Health clinics handling patient records (PHIPA)
- Law firms handling privileged communications
- Accounting firms handling banking details during payroll runs
- Non-profits handling beneficiary case files
- Any business handling credit card numbers or SINs
The Matrix — One-Page Reference
| Tier | Consumer AI (free ChatGPT, Gemini, browser extensions) | Enterprise AI (tenant Copilot, ChatGPT Enterprise, Gemini Business) | Specialized regulated-industry AI |
|---|---|---|---|
| Public | ✅ | ✅ | ✅ |
| Internal | ❌ | ✅ | ✅ |
| Confidential | ❌ | ✅ (approved tools only) | ✅ |
| Restricted | ❌ | ❌ (unless explicitly approved) | ✅ (if purpose-built and approved) |
Print this matrix. Pin it next to the monitor. Put it in the Teams channel. Add it to onboarding.
The “When In Doubt” Rule
If an employee isn’t sure whether something is Internal or Confidential, they treat it as Confidential. If they aren’t sure whether it’s Confidential or Restricted, they stop and ask.
That one habit — pausing to classify before pasting — prevents the majority of AI-related data leaks we see in the field.
Making It Stick in a Real Business
Classification only works if people actually do it. Three habits make it stick:
1. Write the tiers down in one page. A laminated sheet at the desk. A pinned post in Teams. A section in the employee handbook. Ambiguity is the enemy — one page is better than a 20-page policy nobody reads.
2. Label your key documents. Put the classification in the filename or the document header: “Confidential — Client Contracts,” “Internal — Meeting Notes,” “Restricted — PHI.” When the document itself tells you the tier, there’s no guesswork.
3. Tie tiers to tools. Your approved-tool list should explicitly say which tiers each tool is cleared for. “Microsoft 365 Copilot — Public, Internal, Confidential. Not approved for Restricted. ChatGPT free — Public only, never on a work device for business data.”
Where the Tiers Meet Canadian Law
A few specifics that matter in Northern Ontario:
- PIPEDA applies to every business that handles personal information in the course of commercial activity. Personal information — client names, contact details, order histories — belongs in Confidential at minimum.
- PHIPA governs personal health information in Ontario. PHI is Restricted, full stop. No consumer AI tools. No shortcuts.
- Funding agreements for non-profits and Indigenous organizations often contain confidentiality clauses that require beneficiary and donor data to be handled with specific controls. Default that data to Confidential unless the agreement says otherwise.
- Professional regulators (law society, public accounting boards, health colleges) impose additional confidentiality standards that layer on top of PIPEDA/PHIPA.
If you’re not sure which laws apply to your business, that’s one of the first things your MSP should be able to answer.
How DVG Systems Helps
Setting up a working classification model across an SMB is one of the fastest wins we deliver as part of AI readiness work. In a typical engagement we:
- Audit your current data landscape — where documents live, who touches them, what categories they fall into
- Design a tiered classification model tailored to your industry and regulatory environment
- Roll it out with documentation and training — including a one-page reference your staff will actually use
- Configure Microsoft 365 sensitivity labels where appropriate, so tiers are enforced at the platform level, not just on paper
- Pair classification with an approved-tool list — so staff know which AI tool fits which tier
- Build the review into your Microsoft 365 Copilot rollout, so AI deployment and classification land together, not separately
The Bottom Line
You don’t need a PhD in information security. You need four buckets, a one-page cheat sheet, and an approved-tool list your team can act on without having to think twice.
The goal is not to slow AI adoption down. The goal is to make it fast, confident, and safe — because “I wasn’t sure, so I didn’t use it” costs you productivity just as surely as “I used it and it leaked” costs you trust, clients, and sometimes your business.
Classify the data. Match it to the tool. Publish the rules. Then let your team get on with the work.
DVG Systems provides managed IT services to small and mid-sized businesses across Northern Ontario, including Thunder Bay and the surrounding region. If you’d like help classifying your data and rolling out a practical AI tool list for your staff, book a free assessment or reach us at (807) 700-0061 or solutions@dvgsystems.com.