Purpose
Write one clear purpose for every important collection. ‘It may be useful later’ is not a sufficient reason to collect sensitive information.
Minimise
Remove fields that are not needed for the stated purpose. Consider ranges, anonymous counts or optional information instead of precise personal details.
Access
Give people the minimum access needed for their role. Remove access promptly when roles change and avoid shared administrator credentials.
Protect
Use MFA, secure devices, supported software, backups, encrypted transport, careful sharing and private storage. Do not place applicant or beneficiary files in public links.
Retain and delete
Set a review or deletion date. Keeping everything forever increases harm, cost and the difficulty of responding to an access or deletion request.
Respond
Make it possible to report loss, misdirection, unauthorised access or suspicious activity. Record what happened, contain it, assess harm and escalate.
