Protecting data is extremely important and an imperative for any business that holds their customers information. If people are willing to provide you with their details then you have an obligation to protect it. Here are 10 ways to do just that.
1) Secure Consent
Whenever personal data is collected, stored, or used, the consent of the individuals who submit it needs to be secured. Every form that solicits personal information, whether online or on paper, needs to make it clear what the information will be used for and who will have access to it.
2) Respect Sensitive Information
Personal data that could be considered sensitive (e.g. racial, political, religious, medical, sexual, or criminal information) should be handled with special care. According to River Cohen, this information should never be collected or disclosed unless it is absolutely necessary. Obtaining the consent of individuals before collecting this type of information – and informing them of what it will be used for – is absolutely vital.
3) Transparency
Individuals should always have access to their personal information. This means that notes or reports entered into official records which relate to individuals should be prepared with the understanding that the subjects have the right to see them. This general principle applies to all forms of data and communication. Note in particular that it applies to e-mails; exercise caution when discussing specific individuals in e-mail.
4) Eliminate Unneeded Data
Personal data should only be collected and stored when there is a clear need for it. Personal information which is no longer in use or which has become outdated needs to be disposed of in a secure fashion. Review files regularly and have a system in place for discarding unneeded data.
5) Secure Disposal
Records on paper which contain personal information should be treated as confidential when it is time to dispose of them. That means such files need to be shredded rather than simply discarded. Electronic records which are no longer needed should be deleted. All University computers need to be sanitized by Information Services (i.e. to verify that all information has been erased) before they are sold or otherwise disposed of.
6) Accuracy
All personal information should be maintained in a current and up-to-date fashion. Changes of address and similar updates should be applied as quickly as possible. Personal data should not be used if there is any question about its accuracy.
7) Security
Personal data should be kept secured at all times. Physical records should be stored in lockable rooms or lockable filing cabinets. Records which might contain personal information should never be left unattended in areas which are accessible to the general public. Computers whose displays are visible to passers-by should not be used to access personal information. The same security precautions should be applied to any records removed from University grounds (for external meetings or after-hours work, for example). The security weaknesses of e-mail make it unsuitable for use in discussing sensitive matters involving personal data.
8) Disclosure
Personal information cannot be shared with third parties unless the individual(s) in question give express consent or there is a compelling reason to do so. Note that parents, guardians, friends, and other social connections do not necessarily have a right to access a person’s information without their knowledge. Information can be disclosed to third parties when it is necessary to comply with statutes and to further a student’s studies. Sharing with HEFCE, LEAs, Council Tax Offices and the like is allowed. The legitimacy of information requests – and the identity of the enquirer – must be verified before sharing.
Organisations like the inland revenue and the police occasionally request personal data from the University. Cooperation with these authorities is encouraged, but the legitimacy and appropriateness of the information requests should always be verified before information is shared.
9) International Transfer
Individuals must provide consent before their personal information is sent outside of the European Union, Lichtenstein, Norway, or Iceland. Consent is also needed before personal data is placed on the internet.
10) Third Party Data Handling
Exercise caution when feeding personal data to third-party data processing firms (e.g. database management). The third party firm must have a written contract in place that verifies they will uphold the confidentiality and security of personal data and comply fully with the Data Protection Act.