Help notes: DATA SECURITY & DATA PROTECTION

There are two questions to answer: one about data security and one about data protection (UK GDPR).

Do these questions apply to me? Is this a regulatory requirement?

Does your organisation have a policy or plans in place to keep information secure, which are shared with staff?

Data security means protecting sensitive information from risks to your organisation like unauthorised access, breaches of regulations, and cyber-attacks.  

What is a ‘Yes’ for me?

Data Security: risks, and examples of measures

Data Security: policy guidance for smaller organisations

Data Security: policy guidance for medium/ large organisations

Does your organisation have a policy or plans in place to handle personal information in line with GDPR, which are shared with staff?

GDPR (General Data Protection Regulation) is about handling a specific type of information, namely personal information about individuals (like people’s names, phone numbers, addresses, credit card details or IP addresses). It is about protecting people’s privacy rights. 

What is a ‘Yes’ for me?

GDPR: policy guidance for smaller organisations

GDPR: policy guidance for medium/ large organisations

Examples of processing personal data of individuals