Skip to main content
Guidance

Security principles for protecting the most sensitive personal information in datasets

How to identify and protect against the risks associated with sensitive personal information in your data holdings.

Page 8 of 10

Principle 7. When sharing data, check if SPI becomes exposed

When sharing data with other organisation(s), you should jointly assess whether this makes access to SPI easier or more obvious. If SPI does become more obvious, you should jointly take steps as per the rest of this guidance to remediate and agree these mitigations in a data sharing agreement.

When you share data with another party, this can have the same effect as merging data (see principle 6). In addition you might not have any visibility or influence over the other party’s computer system or security and privacy policies. You should:

  • discuss with the recipient organisation how they plan to use your data

  • check what data merging could occur

  • create terms and conditions of the data usage in a data sharing agreement




Reviewed

Version

1.0