Skip to main content

4. Access to personal confidential data should be on a strict need-to-know basis

Only those individuals who need access to personal confidential data should have access to it, and they should only have access to the data items they need to see. This may mean introducing access controls or splitting data flows where one data flow is used for several purposes.