Physical Security On-premises storage of personal information requires NHRIs to ensure the physical security of their servers, computers, laptops, phones, tablets and any other storage devices like USB sticks. If these items are stolen or tampered with, the personal information they hold can be compromised. If located in offices where visitors or contractors are given access, or other unsecured environments, this will be a significant risk. (!) Fire, flood, or other natural disasters, lack of maintenance, old equipment past its working lifespan can all be factors that lead to irretrievable data loss if adequate backups are not in place. Cyber Security Many threats to security of personal information will not come from physical intrusions but rather from intrusions that are done remotely (i.e. cyber-attack). There are some basic measures and software tools NHRIs can implement at low cost to mitigate risk of cyber security threats. • Regular software updates and patches: Keeping systems and applications up to date with the latest security patches to protect against vulnerabilities • Encryption: Converting data into a coded format to protect it during transmission or storage. Encrypted data can only be accessed by authorised parties with the correct decryption key. There are low-cost encryption tools available. • Firewalls: Security systems that monitor and control incoming and outgoing network traffic based on predetermined security rules, creating a barrier between the trusted internal network and the internet. • Anti-virus and anti-malware software: Programs designed to detect, prevent, and remove malicious software, such as viruses, ransomware, and spyware. • Access control: Implementing user authentication systems (e.g., passwords, biometrics, twofactor authentication) to ensure that only authorised individuals can access sensitive data or systems. Implementing Privilege Access Management or roles-based access control mechanisms is an effective way to achieve a good standard of access control. • Data loss prevention: Tools that monitor and protect sensitive data to prevent accidental or intentional leakage of information, such as preventing copying, emailing or printing of sensitive files. • Security policies and procedures: Clear documentation of security policies and procedures, outlining how data should be collected, accessed, stored, and protected. Policies should be regularly updated to reflect evolving threats and regulatory changes. • Password managers: NHRIs should consider using a reputable password manager with an organisational account that ensures staff will have secure passwords for their work-related accounts. Data Protection Guidelines for NHRIs Toolkit 19

Select target paragraph3