Security principles for protecting the most sensitive personal information in datasets
Pages
Page 8 of 10
Principle 7. When sharing data, check if SPI becomes exposed
When you share data with another party, this can have the same effect as merging data (see principle 6). In addition you might not have any visibility or influence over the other party’s computer system or security and privacy policies. You should:
discuss with the recipient organisation how they plan to use your data
check what data merging could occur
create terms and conditions of the data usage in a data sharing agreement
Data sharing agreement
A data sharing agreement should ensure that the recipient organisation is aware of:
- the potential risks to the liberty, privacy or safety of individuals from mixing your data with other datasets of personal data
- any organisational risks or legislative obligations
- the characteristics of the personal data that are being shared and the associated risks, such as threat to life, harm, prejudice or harassment.
Methods to reduce exposing SPI when sharing
If as the data originator you aren’t comfortable with possible risk exposures from sharing your data, you should consider different methods to enhance privacy in the data sharing that would achieve the same objectives for the recipient organisation.
There are several different techniques to reduce possible exposure of sensitive data characteristics when sharing data with others. For example:
- Minimise the data sharing to only those items that are absolutely necessary for the declared purposes – which should be normal practice anyway.
- Reduce the risk that your data could highlight sensitivities due to looking very different to the recipient’s data, by ensuring that your sensitive data look very similar to the destination data – a technique known as ‘hiding in plain sight’.
- Create data summaries instead of supplying whole datasets.
- Use Privacy Enhancing Technologies and anonymisation or pseudonymisation of data prior to sharing or granting shared access.
Protecting SPI in transit
Transfers of personal data should always be protected against loss or theft. However, sensitive data will stand out and become a target for theft if they are transferred, sent or packaged in a way that looks or behaves obviously differently to less sensitive data. You should aim to protect all of your data in transit at the highest level of protection required for the most sensitive data.
Splitting the data, by disaggregating and sending the parts separately, will further reduce the risk of loss or theft of data rich in SPI.
You should always use encryption in transit when sharing data with other organisations.