Guidance
Security principles for protecting the most sensitive personal information in datasets
How to identify and protect against the risks associated with sensitive personal information in your data holdings.
Pages
Page 7 of 10
Principle 6. When merging data, check if SPI becomes exposed
When you join data together by merging, storing together or by using the same access mechanisms across other bulk data, you should assess whether this makes access to sensitive data easier or more obvious. If SPI does become more obvious, you should follow this guidance to remediate.
Aggregating or merging different but related personal data can result in the unintended exposure of more information than intentionally planned, some of which could be used maliciously.
For example, merging patient home address information with prescriptions could show where controlled medications are being stored and used.
If you’re putting data together, either by merging data to form a more comprehensive database or by allowing data access using a common or shared method – such as the same bulk data repository, bucket or access credentials – you should analyse any data aggregation to check if it makes your sensitive data obvious, or even undermines other sensitive data access controls.