Protect What Matters
Strengthening Data Protection Across State Government
Protecting the information entrusted to us is essential to serving the public and maintaining its confidence. As part of the State of North Carolina’s continued commitment to data privacy and protection, the N.C. Department of Information Technology is introducing sensitivity labels.
What Are Sensitivity Labels?
Sensitivity labels are a structured way to classify information based on the potential harm to an individual, agency, or entity if the data were improperly accessed, shared, or exposed.
Think of it as assigning a protection level to files and emails to ensure only the right people have access to the relevant information. These labels then trigger rules behind the scenes to keep data safe. These labels then trigger rules behind the scenes to keep data safe.
They also help us better understand where sensitive information is stored across state government so we can make more informed decisions to reduce the risk of data being misused or exposed.
This careful, step by-step approach helps avoid disruptions and keeps everyone’s work running smoothly while improving data safety over time.
Why They Are Important
Sensitivity labels help improve and support statewide data security, privacy, and compliance requirements. They also prepare us for more modern data protection tools and smarter automation. Labeling will help:
- Strengthen protection of data and organizational information.
- Create a more consistent approach to handling sensitive data.
- Help employees make informed decisions about the information they create and share.
- Apply protections based on the sensitivity of information.
- Build data protection into our everyday ways of working.
- Provide more flexibility in helping agencies meet the public’s needs.
Deployment
NCDIT is taking a phased approach, initially rolling out sensitivity labels to NCDIT employees. This lets us evaluate the employee experience, gather feedback, and make improvements before expanding to other agencies who use NCDIT’s Microsoft 365 service.
Frequently Asked Questions
There are four sets of sensitivity labels, which are based on the Statewide Data Classification and Handling Policy:
- Public: Accessible to anyone as it contains no sensitive information or high-risk data.
- Internal: Accessible only to state government employees.
- Confidential: Accessible only within state government and is automatically encrypted and labeled CONFIDENTIAL.
- Restricted: Our highest level of protection, accessible only to designated recipients and is automatically encrypted and marked RESTRICTED.
Other than selecting the appropriate label in emails and Microsoft 365 files, such as Word, Excel, and PowerPoint, nothing will change.
Initially, we will only use sensitivity labels to help the state better understand where sensitive data is stored and how it is being shared. Eventually, some labels will trigger restrictions (such as printing or blocking access) to better protect sensitive data.
Simply change the label and, if prompted, let us know why. Nothing breaks. Emails and files send and open normally.
Turning on protections too early could unintentionally block work or disrupt business processes. By starting with labels only, agencies avoid disruption and gain time to understand data flows before deciding on any future restrictions.
Future protections will be introduced gradually after NCDIT and agencies better understand their data and validate business needs. Any future enforcement will be communicated clearly and well in advance.
Yes. We will provide training that is short, practical, and focused on helping you identify and select labels correctly. We will also hold virtual office hours before and after we roll out sensitivity labels to demonstrate how to use them and to answer any questions you have.
For technical assistance, contact your agency’s IT help desk.
For questions about data privacy, consult with your agency’s security or privacy office. The following policies are also available for review: