Wikimedia Georgia/Data Classification Policy
Approved by
the Wikimedia Georgia's Board of Trustees
On May 16, 2026.
Wikimedia Georgia's
Data Classification Policy
TBILISI
2026 y.
General Information
Data classification is based on the data's level of sensitivity and its impact on Wikimedia Georgia if disclosed, altered, or destroyed without authorization. The current data classification helps determine which baseline security and privacy controls are necessary to protect the appropriate data. All data must be classified into one of the sensitivity categories listed below.
Scope of the Policy
This policy applies to all persons employed by Wikimedia Georgia (including contractual and temporary employees), members, volunteers, and any other persons associated with the organization. All such persons are required to comply with this policy.
Categories
Wikimedia Georgia categorizes the information it possesses according to the categories below to determine who has access to it and what security measures must be taken to protect it from unauthorized access.
There are three categories of information accessibility:
- Public;
- Confidential;
- Restricted.
Public Information
Public information includes all data that is publicly available to everyone, including the Wikimedia movement, Wikimedia Georgia employees and members, and the wider global public. Modifications to this data may be subject to access controls, but the data itself does not pose a confidentiality risk.
Public information and data are accessible to everyone regardless of their role, function, or status. Restricting or limiting access to public information is prohibited.
Public information includes the following types of information and data:
- Any information already publicly available;
- Data produced and presented by Wikimedia Georgia is available to everyone;
- Research publicly published by Wikimedia Georgia;
- Any information related to Wikimedia Georgia shared on its public websites and social media channels;
- The identities of Wikimedia Georgia members (first and last name only);
- Wikimedia Georgia reports, plans, guides, and similar information;
- Protocols, decisions, minutes, and similar information issued by Wikimedia Georgia administration (except personal information contained therein);
- Memorandums signed by Wikimedia Georgia;
- Rules and policies adopted by Wikimedia Georgia;
- Wikimedia Georgia contact information;
- Any other information that does not fall under the confidential or restricted categories.
Confidential Information
Confidential information consists of restricted-access, secret data (official, commercial, or personal) whose disclosure, publication, or transfer to unauthorized persons is prohibited.
Confidential information includes the following types of information and data:
- Residential and registration addresses of individuals;
- Personal data, including personal identification/passport number and series, date of birth, age, gender, nationality, religion, sexual orientation, and similar information;
- Email addresses, phone numbers, or mobile numbers;
- Bank account details, bank card information, and credit status;
- Information about real identities, including first and last names, if employees/volunteers/members act under pseudonyms;
- Passwords, PIN codes, or other access codes;
- Ongoing litigation and attorney-client privileged communication;
- Incident investigations;
- Any other information designated as confidential by Wikimedia Georgia’s Board of Trustees and administration.
Access to Confidential Information
Access to confidential information is restricted and generally available only to the Wikimedia Georgia administration, based on each member's specific role. Accordingly, access depends on role-based authorization. Access to confidential information may be granted to a person, including employees and members of the organization, by the Executive Director and the Board of Trustees upon an appropriate decision.
Restricted Information
Restricted information includes data related to Wikimedia Georgia’s activities, which, although not confidential, should also not be shared with external actors because of its sensitive nature. Such information must be handled with the utmost care and security to avoid accidental or inadvertent public disclosure.
Restricted information includes the following types of information and data:
- Wikimedia Georgia activities declared confidential by decision of the administration or Board of Trustees;
- Activities aimed at improving the security of the organization’s projects and programs;
- Personal life of persons connected in any way to the organization;
- Raw or sensitive analytical data;
- Records of internal organizational meetings;
- Internal legal agreements, contracts, and arrangements;
- Any other data designated as restricted by the Wikimedia Georgia administration or the Board of Trustees.
Access to Restricted Information
Access to restricted information is limited only to the Wikimedia Georgia administration and the Board of Trustees. Additionally, access may be granted to third parties upon a corresponding decision by the Board of Trustees.
Data Access Control
Permission to access data is granted based on a person’s specific role (role-based access control).
Wikimedia Georgia employees and members are granted access to systems based on their roles and responsibilities. Appropriate permissions, depending on the information category, are granted based on a decision of the organization’s administration or Board of Trustees.
Access to information is managed by the organization’s administration.
Access Requests and Approval
Access to information is requested through an internal organizational request specifying the need for access. Access may be permanent or temporary.
Temporary access is granted based on a relevant request. Each temporary access request must include an explanation of why the access is necessary. Temporary access must have an expiration date, after which it must be revoked immediately.
Access to information is approved by an authorized person (Executive Director, Deputy Director, or relevant official) or by the Board of Trustees based on an appropriate decision.
Data Retention
There is no defined retention period for public information, and its storage is not time-limited. The retention period for confidential information is three (3) calendar years unless otherwise noted or decided for permanent retention. The retention period for restricted information is five (5) calendar years unless otherwise noted or decided for permanent retention. Additionally, if required by Georgian legislation, the retention period for any type of information may be shortened or extended beyond the periods established in this policy.
Data Disposal
Stored information and data must be deleted or destroyed when or after the retention period expires. The Wikimedia Georgia administration is responsible for developing and enforcing data deletion procedures.
Final Provision
In the event of inconsistency between this policy and Georgian legislation, the law shall prevail.
The Wikimedia Georgia Board of Trustees has the authority to amend and modify this policy.
