Module 8

Data Protection and Privacy

Protect sensitive information using safer storage, sharing, retention and disposal practices.

Learning Objectives

  • Identify sensitive and high-value information.
  • Understand encryption concepts in plain language.
  • Apply secure cloud and file-sharing habits.
  • Reduce data-loss and privacy risks.

Why This Matters

Data is often a primary target in cyber incidents.

Poor handling can lead to financial, legal and trust consequences for individuals and businesses.

Plain-Language Explanation

Data protection combines confidentiality, integrity and availability controls. Encryption helps protect data at rest and in transit, but access control and human process still matter. Keep only what you need, share only with authorised people, and dispose of information and devices securely.

Practical Examples

  • Classifying files by sensitivity before sharing.
  • Applying least-privilege access to cloud folders.
  • Using wipe/reset processes before disposing of old devices.

Common Mistakes

  • Sharing links publicly by default.
  • Keeping data indefinitely without purpose.
  • Assuming deleted files are always unrecoverable.

Security Checklist

Module checklist progress0%

Short Knowledge Check

Question 1: Is encryption alone enough for privacy?

No. Access control, retention policy and user behaviour are also important.

Question 2: Why limit cloud sharing permissions?

To reduce accidental exposure and unauthorised access.

Question 3: What should happen before disposing a device?

Securely wipe or reset storage and remove account associations.

Key Takeaways

  • Sensitive data needs deliberate handling choices.
  • Good privacy practice combines technical and procedural controls.
  • Secure disposal is part of lifecycle protection.
← PreviousModule 8 of 10Next →