Security principles for protecting the most sensitive personal information in datasets
Pages
Page 1 of 10

This guidance defines, and helps you identify, sensitive personal information in your organisation’s personal data holdings. It also suggests principles and considerations for technical implementation that can reduce risk to the individual data subjects.
This guidance is for anyone responsible for protecting personal data in an organisation – or who designs or implements systems that process personal data – such as policy makers, data risk owners, security architects and other cyber security professionals. It goes beyond baseline data protection approaches and should be used to supplement other guidance and controls that you already follow.
What is Sensitive Personal Information?
Whilst Sensitive Personal Information (SPI) is not formally defined anywhere, the broader concept of personal data is enshrined in UK legislation through the Data Protection Act (DPA 2018).
The DPA – the UK’s implementation of the General Data Protection Regulation (GDPR) – governs how businesses, organisations and government can use personal data, ensuring that individuals' rights and freedoms are protected when organisations process their personal data.
Personal data is defined in the UK GDPR as: any information relating to an identified or identifiable natural person (data subject).
In line with the responsibility for protecting individuals' personal data, you should consider the possible risks associated with sensitivities in that data, particularly if compromise increases the risk of harm, harassment or prejudice to the individual. You should apply higher protections to more sensitive data in such cases.
The SPI in your datasets will vary depending on the nature of your business, but could readily include many types of data which are beyond those defined in the GDPR, for example:
- an individual’s profession, such as prison officer, technician in an animal testing laboratory or senior member of the judiciary
- a personal life characteristic, such as a protected characteristic in the Equality Act 2010, or a victim of domestic abuse
- a status such as high net worth individual, celebrity, VIP or refugee
What protections do I need for protecting SPI?
If you hold or process personal data you should be aware of the severity of impact arising from misuse of any SPI you hold and use that to determine the strength of data protections you need to have in place. In making your assessment you should consider:
- What processing do you do, or could be done, with your data?
- Do you transfer data to another organisation or give them access to it?
- Are you at particular risk of data loss or data breach?
- How attractive is your data likely to be to interested parties and what extent might they go to to access it?
- What sort of interested parties might seek to access the data, such as disaffected family members, employees under duress, investigative journalists, or state-sponsored groups? What capabilities and methods might they use to get access?
Protections for SPI data may be procedural- or technology-based. The protections you select will depend on the particular type and severity of risk you are mitigating.
High-level principles for protecting SPI and example technical implementations
This section contains nine principles that help protect SPI, and includes example measures that can be used to help meet the goals of the principles. The measures provided should not be considered exhaustive, as there may be other technical measures that will fully meet the goals of the principle.
The primary considerations for protecting SPI that underpin these principles are:
- the risks arising from having SPI should be treated as higher than for most other personal data
- SPI needs better protections from insider threats as well as external cyber threats
- knowing when data has been accessed inappropriately should be part of an incident response strategy
Implementing the principles
When designing processes that access or process sensitive data you should do so in a way to withstand attempts to subvert those access processes, ideally using a mixture of prevention and detection methods.
Occasionally failures might occur in an organisation’s processes, systems or other protections which can leave data susceptible to discovery by a cyber threat or other interested party.
Given that the potential impact of loss or discovery is often greater for sensitive data, protections around them should be proportionately more resilient to loss or discovery.
Sensitive data protections should be resistant to:
- intentional attempts to discover data
- data theft through cyber attack
- failure to correctly implement other protection or detection mechanisms
Applying a defence-in-depth approach to these principles will improve resilience in case of attack or failure.
You should decide which mechanisms to use to implement protections against data discovery or theft by weighing up the risks of failure against the cost of implementation.


