Skip to main content
Guidance

Security principles for protecting the most sensitive personal information in datasets

How to identify and protect against the risks associated with sensitive personal information in your data holdings.

Page 1 of 10

Alexandr Makarov via Getty Images

This guidance defines, and helps you identify, sensitive personal information in your organisation’s personal data holdings. It also suggests principles and considerations for technical implementation that can reduce risk to the individual data subjects.

This guidance is for anyone responsible for protecting personal data in an organisation – or who designs or implements systems that process personal data – such as policy makers, data risk owners, security architects and other cyber security professionals. It goes beyond baseline data protection approaches and should be used to supplement other guidance and controls that you already follow.


The SPI in your datasets will vary depending on the nature of your business, but could readily include many types of data which are beyond those defined in the GDPR, for example:

  • an individual’s profession, such as prison officer, technician in an animal testing laboratory or senior member of the judiciary
  • a personal life characteristic, such as a protected characteristic in the Equality Act 2010, or a victim of domestic abuse
  • a status such as high net worth individual, celebrity, VIP or refugee



Given that the potential impact of loss or discovery is often greater for sensitive data, protections around them should be proportionately more resilient to loss or discovery.

Sensitive data protections should be resistant to:

  • intentional attempts to discover data
  • data theft through cyber attack
  • failure to correctly implement other protection or detection mechanisms

Applying a defence-in-depth approach to these principles will improve resilience in case of attack or failure.

You should decide which mechanisms to use to implement protections against data discovery or theft by weighing up the risks of failure against the cost of implementation.

Published

Reviewed

Version

1.0