There’s a useful example of a Data Classification Policy from George Washington University here.
They only have three categories of information and responsibility for implementing the policy is delegated to the departments of the University. Here’s an exerpt:
Data owned, used, created or maintained by the University is classified into the following three categories:
- Public
- Official Use Only
- Confidential
Departments should carefully evaluate the appropriate data classification category for their information.
When provided in this policy, examples are illustrative only, and serve as identification of implementation practices rather than specific requirements. Nothing in this policy is intended to identify a restriction on the right of departments to require policies and/or procedures in addition to the ones identified in this document.
An archived copy of the policy is here.
