Assum-ing that users know at least what data should be protected, however, it is possible to provide default poli-cies for different types of sensitive or confidential data, with facilities that enable the data owner to modify or extend these policies.