Skip to main content
Guidance

Security principles for protecting the most sensitive personal information in datasets

How to identify and protect against the risks associated with sensitive personal information in your data holdings.

Page 6 of 10

Principle 5. Avoid putting too much sensitive data together

You should recognise the risks arising from bulk data associations under the same access control, and aim to partition and separate data to reduce opportunities for inappropriate data access.

Don’t make your data too attractive a target 

Aggregating a lot of personal data increases the value of the dataset and its attractiveness to an attacker.  It can also increase the severity of a data breach if the dataset is lost or stolen.

Don’t make your data too easy to exploit

Grouping together related data about individuals creates a richer digital picture of their lives.  Even if data is not grouped together intentionally, having a broad range of data accessible in the same place or under the same access rights can allow an external attacker or inside threat user to piece together a rich digital picture of a person.

A name, address and NHS number are personal data. A bulk loss of such data by an organisation is already a serious issue.  But if this lost data was grouped with a further dataset that detailed the medication prescribed to particular NHS numbers, there would be an increased risk to those individuals.





Reviewed

Version

1.0