What Makes a Document Sensitive?
A document is sensitive when its exposure could cause personal, legal, financial, commercial or reputational harm.
Specialist view
Sensitivity is about consequence, not file type. A plain PDF can be high risk if it links the wrong facts to the wrong person.
Sensitivity is about impact
A document is sensitive if unauthorised access could harm someone or undermine the organisation. The file does not need to be labelled confidential to carry risk.
Examples include documents containing personal details, financial records, identity evidence, health information, employment matters, legal advice, contract terms, pricing, strategy or client case information.
Personal data and confidential information
Personal data is sensitive because it relates to identifiable people. Some data, such as health information, union membership, biometrics or information about criminal allegations, needs particular care.
Confidential business information can also be sensitive: board papers, acquisition plans, supplier pricing, security details, source documents, settlement positions and customer lists.
Context can change sensitivity
A name and email address in a public directory may be low risk. The same name and email address inside a grievance file, debt record or medical referral has a different meaning.
Who receives the document also matters. Sharing internally with an authorised colleague is different from sending to a client, contractor, personal inbox or external adviser.
Use categories to guide protection
Create simple sensitivity bands such as public, internal, confidential and high-risk. Then connect each band to controls: secure links, expiry, recipient checks, download limits and audit records.
Duckuments can support this process by analysing document content and helping identify files that need more than basic sharing.
