Have you classified the types of data you hold (e.g., confidential, internal, public) and given staff simple rules on how each category should be handled?
Example: A small marketing firm labels documents “Confidential,” “Internal,” or “Public,” with instructions on each label’s handling rules.
Regulatory Mapping: Article 21 (Information System Security Policies).