Help notes: DATA SECURITY & DATA PROTECTION

There are two questions to answer: one about data security and one about data protection (UK GDPR).

Do these questions apply to me? Is this a regulatory requirement?

Do you have a policy (a set of ideas and plans) for keeping data secure at your organisation, and could you show that you follow this policy?

Data security means protecting sensitive information from risks to your organisation like unauthorised access, breaches of regulations, and cyber-attacks.  

What is a ‘Yes’ for me?

Data Security: risks, and examples of measures

Data Security: policy guidance for smaller organisations

Data Security: policy guidance for medium/ large organisations

Do you have a policy (a set of ideas and plans) for handling personal information at your organisation in line with the UK GDPR, and could you show that you follow this policy?

GDPR (General Data Protection Regulation) is about handling a specific type of information, namely personal information about individuals (like people’s names, phone numbers, addresses, credit card details or IP addresses). It is about protecting people’s privacy rights. 

What is a ‘Yes’ for me?

GDPR: policy guidance for smaller organisations

GDPR: policy guidance for medium/ large organisations

Examples of processing personal data of individuals