One of the key principles of GDPR is the security principle, which builds on the requirement in the legislation's predecessor (the Data Protection Act 1998). The principle requires that ‘appropriate technical and security measures' are in place. In short, this means organisations have to look after the data that they process. 

Remote working poses a number of challenges, including maintaining control over the data that organisations process. If it’s not managed effectively, the security of personal data might be compromised.

While data breaches caused by remote working are rare, they can unfortunately be serious. The impact on individuals can be significant, especially where you’re working with sensitive or ‘special category’ data. Disclosure of this information could cause distress to the affected individual or even material damage in certain cases.

For example, if someone’s data is compromised, this could make it possible for another individual to commit fraud using their personal details. Data breaches can also be damaging to the organisation responsible in terms of fines or reputational damage.

Remote working - keeping information secure

Top tips on information security during remote working:

  1. Handle personal data as carefully as you would in your usual workplace.
  2. Ensure that you lock your computer and don’t leave devices or papers unattended.
  3. Be aware of your surroundings. Can family access, view or overhear anything sensitive?
  4. Store personal data securely when not in use.
  5. Raise awareness within your organisation about the risks to data when working remotely and consider providing additional training of staff members. 
  6. Don’t send any work to or from your personal email address.
  7. Use headsets or headphones during Skype meetings or phone calls to prevent family or neighbours overhearing something sensitive.
  8. Avoid leaving drinks or food on or near paperwork, tablets or laptops – if it spills it could destroy information that you need.
  9. Don’t throw paper files with personal information in your rubbish or recycling bin. Shred with a cross-cutting shredder, or keep it securely until it can be returned to the office to destroy safely. 

Veritau provides information governance and data protection services to over 500 public sector clients. If you need advice from a member of the team, contact us.

More information and resources
:

Sign up for the Veritau Alerts Click subscribe to receive the monthly bulletin