How much is too much?

This situation raises questions about awareness on how to handle personal data.


Text version scenario

 

As part of its plan to provide a safe and secure work site, our project team set up a controlled access system. Which allows us to know who is working on the project at any particular time and provides emergency contact information. While setting up the registration, each individual worker was required to fill out their name, date of birth, home address, wages information and government identification number.  The “good business reason” test under the Data Protection Act was applied. The conclusion was that the information was more than what was necessary for the controlled access system. Some fields of information, such as home address and wages, were removed. 

Discussion question

 

  • What is personal data?
  • What should we consider when making lists or storing information?

 

Things to consider

 

We can learn from these situations to help us truly live our values. We can consider the following actions:

 

  • The definition of personal data, and the legal requirements for safeguarding it, vary by country. It could include someone’s birthdate, contact information, family member names, personal healthcare information, photographs or identity number.
  • Do not collect more data than needed given the task.
  • Always limit access to personal data and, above all, sensitive personal data. Only those who need access to the data should access them.
  • Do not send or share sensitive personal information without ensuring that communication is safe and not shared with unauthorized persons.
  • Delete all the personal information that you no longer use.

 

For more information on how to act read our Code of Conduct chapter on Data protection