Skip to main content
Guidance

Protecting bulk personal data

Fifteen best-practice measures to protect digital bulk data.

Page 5 of 5

Further information

Though there are fifteen measures described above as basic protections for bulk personal data, they can be prioritised.

These are the most critical for knowing what data you have and preventing its loss:

1. Knowing what data you hold and why

8. Not exposing vulnerable interfaces externally

14. Prevent spear-phishing emails targeting an administrator from resulting in total compromise of the data

For ensuring attacks would be detected and managed, the most critical measures are:

10. Detecting basic attacks

11. Monitoring atypical access to the data

Encryption

In some scenarios, the use of encryption to protect bulk data should be the norm. For example, where data is transmitted over the internet, stored on a laptop, or stored on removable media.

However, encryption relies on good key management, and in some scenarios it is challenging to engineer a solution which makes meaningful use of encryption to protect data.

This is sometimes the case in systems which are always online, where data needs to be available to query. In these scenarios your systems architects and designers will need to think carefully about how encryption can be used in a meaningful way.

Further advice on secure design

We have published a set of security design principles to inform technical architects and developers building systems and services that need to protect important data.

Published

Reviewed

Version

1.0