Security principles for protecting the most sensitive personal information in datasets
Pages
Page 3 of 10
Principle 2. Ensure only appropriate access to sensitive data
Considerations for technical implementation
You would only be storing and permitting access by someone or something to personal data because there is a legal basis for it. You should ensure that only those people or systems that are authorised to access data containing SPI can do so. This might mean using enhanced methods of proving identity for access to data, such as multi-factor authentication (MFA). For guidance on using MFA see Mandating strong MFA for access to sensitive data.
To ensure only authorised access to your sensitive data, you should undertake regular audits of actual and attempted access to the SPI. You might achieve this by implementing automated data access logging and alerting on attempts to access sensitive data. For more on logging and alerting, see below Principle 3 Ensure you know who is accessing data which contains SPI.
If you identify any unauthorised access to any sensitive data you should notify it as part of your Incident Management Processes.