Principles for securing personal data in government services

Document preview15 pages
Cover of Principles for securing personal data in government services
Page 1 of 15

Download this document free

Get this document with your free trial. Choose from the full Complyzard library.

Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.
Document information

Data security control principles to use when processing and sharing personal data in your service.

Adapted edition

Document type
Reference Guide
Format
DOCX
Pages
15
Language
English
Version
1.0
Updated
2026-09-16
Description

Data security control principles to use when processing and sharing personal data in your service. Consult the original guidance for current legal and operational details.

Contents
  • Who these principles are for
  • Why these principles are important
  • Definition of personal data
  • Identify your data assets
  • Identify risks
  • Activities to consider
  • Principles: introduction
  • 1. Plan your response to personal data breaches before they occur
  • 2. Minimise the attack surface when sharing personal data
  • 3. Make sure personal data is secure throughout your supply chain
  • 4. Process all personal data lawfully and ethically
  • 5. Know who owns and is accountable for your data
  • 6. Apply appropriate data security controls
  • 7. Enhance privacy controls when combining data from different sources
  • 8. Match data using appropriate personal identifiers
  • 9. Treat vulnerable or at-risk individuals inclusively
Source and licence
Principles for securing personal data in government services

Government Digital Service

AttributionGovernment Digital Service, ‘Principles for securing personal data in government services’ (updated 25 June 2025), reused under the Open Government Licence v3.0.

ChangesNeutral text-only adaptation from the official GOV.UK Content API body: headings, paragraphs, ordered and unordered list items and clickable source-link destinations in an appendix preserved. Images, logos, page design, accessible-format request widgets and linked attachments excluded; normalised whitespace, invisible format marks and typography.

Version history
  • v1.016/09/2026
Report this document