Skip to main content
Guidance

Protecting bulk personal data

Fifteen best-practice measures to protect digital bulk data.

Page 1 of 5

Source: iStock

Introduction

Whether they’re held by public service or private enterprise, these bulk data stores make very tempting targets for attackers of all kinds. So it’s essential to ensure they’re adequately protected.

The fifteen good practice measures outlined below provide a set of indicators against which the security of your holdings can be objectively appraised. They enable you to make a basic security assessment of any personal data stores held by your service.

This is not a definitive set of measures. The list will necessarily change over time, as the attacks and techniques used by adversaries change. So you should not see them as an alternative to a risk management strategy designed to protect your bulk personal data.

For these measures to be meaningful, they must be applied to a service or system as it exists today, not by referral to the original design intent of the service. For that purpose an audit should be carried out of the data holdings which your service is harbouring before measurement takes place.

Structure of this guidance

The measures have been broken into three groups:

  • WHAT– You should know what you are protecting and the risks you’ve already taken
  • WHO– You need to know that only those with a real need, have access to your data
  • HOW– Poor design, implementation or operations can result in data loss

Each of the 15 good practice measures is split into three sub-sections:

  • The first describes an ideal situation.
  • The second expands on the thinking behind this.
  • The third gives you a traffic-light system against which to judge your actual holdings.

Published

Reviewed

Version

1.0