Working resource / Draft

Responsible data starter guide

A small organisation can improve data responsibility without building a large compliance department. Begin by knowing what you hold, why you hold it and who can reach it.

01

Purpose

Write one clear purpose for every important collection. ‘It may be useful later’ is not a sufficient reason to collect sensitive information.

02

Minimise

Remove fields that are not needed for the stated purpose. Consider ranges, anonymous counts or optional information instead of precise personal details.

03

Access

Give people the minimum access needed for their role. Remove access promptly when roles change and avoid shared administrator credentials.

04

Protect

Use MFA, secure devices, supported software, backups, encrypted transport, careful sharing and private storage. Do not place applicant or beneficiary files in public links.

05

Retain and delete

Set a review or deletion date. Keeping everything forever increases harm, cost and the difficulty of responding to an access or deletion request.

06

Respond

Make it possible to report loss, misdirection, unauthorised access or suspicious activity. Record what happened, contain it, assess harm and escalate.