1. Be aware of the types of personal and confidential information your office collects as well as where it is stored and what your office does with it.
  2. Store physical records containing personal and confidential information in secure locations, such a locked room, locked filing cabinet, or secure offsite storage area. Ensure that these areas/cabinets are locked when not in use.
  3. Limit the number of people who have access to physical locations and digital storage systems where personal and confidential information is stored.
  4. Do not leave physical records containing personal and confidential information on desks or other open, unsecure locations when not in use.
  5. Clearly label digital and physical folders containing personal and confidential information as CONFIDENTIAL.
  6. Store digital records containing confidential information on devices and in cloud storage systems, such as laptops and Box, that are password protected and encrypted.
  7. Do not leave digital devices and cloud storage software containing personal and confidential information open/unlocked when not in use.
  8. Confidentially destroy physical and digital records containing personal and confidential information as soon as their retention period has been met.
  9. Have students that may work with personal and confidential information sign a confidentiality agreement.
  10. Ensure that all employees are made aware of all privacy/confidentiality protection procedures and have read the College’s Written Information Security Policy and Data Governance Policy.

Download PDF