Skip to main content
Guidance

Security principles for protecting the most sensitive personal information in datasets

How to identify and protect against the risks associated with sensitive personal information in your data holdings.

Page 2 of 10

Principle 1. Understand what data you have and the risks to it

You should examine your data holdings and understand the risks to your data considering threat, intention and capability. You should seek expert opinion in making this assessment.

Example of a data holding which infers SPI, and the associated risks

An organisation holds data about the academic qualifications and home addresses of several individuals with PhDs. Access to this data allows an individual to ascertain that there is a higher proportion of individuals with PhDs living close to a geographically isolated rocket research company.  That individual tips this information to a foreign nation with espionage interests which subsequently attempts unauthorised access into the organisation’s network. They successfully obtain the names and home addresses of all the people with PhDs which increases the risk not only to the individuals themselves but any other people resident at their addresses. It may also negatively impact the operation of the rocket research company.  

2. Risks when receiving data from other parties

When receiving data from other parties, you should assess what further risks may arise as as result.

Reviewed

Version

1.0