2 - If yes , do we need to encrypt all the data or we need to classify the data?
In case you have risks or legal requirements that justify implementing encryption, the data to be encrypted will depend on the rules defined by the organization, usually defined in the Information Classification Policy.
So, before defining which data will be classified, you will need to classify it first.
3 - Who will decide what data should be encrypted?
The person who will decide if data should be encrypted or not is the person responsible for the data (also called in ISO 27001 as information owner). The decision will be related to the classification level attributed to the data.