Data Minimisation in Practice Print

  • 0

Collecting less.

WHY IT IS THE MOST UNDERUSED PROTECTION

What you do not hold cannot be breached, misused, requested or mishandled.

WHAT TO REVIEW

Every form you collect through.

WHAT TO ASK OF EACH FIELD

What is this used for?

WHAT TO DO WITH FIELDS THAT HAVE NO ANSWER

Remove them.

WHAT COMMONLY HAS NO ANSWER

Date of birth, where age is not relevant Gender, where nothing depends on it Full address, where a city would do Title

WHAT TO CONSIDER INSTEAD OF RAW DATA

Storing whether someone is over an age, rather than their birth date Storing a region rather than a precise location Storing a hash where you only need to compare

WHAT TO REVIEW IN SYSTEMS

Fields collected years ago and never used.

HOW TO TELL

Whether anything reads them.

WHAT TO DO ABOUT LOGS

Log what is needed for operation, not everything.

WHY

Logs accumulate personal data invisibly.

WHAT TO AVOID LOGGING

Full request contents Credentials Personal data beyond identifiers

WHAT TO SET

Retention on logs, deliberately.

WHAT TO DO ABOUT FREE-TEXT FIELDS

Recognise they contain anything, and treat them accordingly.

WHAT TO MEASURE

How much personal data you hold, and whether it is growing.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot