Storage and handling.
WHAT TO MINIMISE
What you collect.
WHY
Data you do not hold cannot be exposed.
WHAT TO ENCRYPT
Sensitive fields, where warranted Backups, which contain everything
WHAT NEVER TO STORE
Card numbers Passwords recoverably More personal data than the purpose requires
WHAT TO DEFINE
Retention periods, and apply them automatically.
WHY AUTOMATICALLY
Manual deletion does not happen.
WHAT TO CONTROL
Who can access production data, and how.
WHAT TO AVOID
Copying production data into development Exports held indefinitely Personal data in logs
WHAT TO DO IF PRODUCTION DATA IS NEEDED FOR TESTING
Anonymise it.
WHAT TO LOG
Access to sensitive records, where warranted.
WHAT TO PLAN
What you would do if data were exposed: who is notified, and within what period.
WHY IN ADVANCE
Obligations frequently run from when you became aware.
WHAT MAY APPLY
Obligations under data protection law. Take advice on your position.
WHAT TO RECORD
What personal data you hold, where, and why.