x

12345678910111213
Across
  1. 2. Name for a data incident.
  2. 6. Only giving systems and data to those who genuinely need them.
  3. 9. How staff learn to handle personal data safely.
  4. 10. Duty to keep personal information private and secure.
  5. 12. Right to limit how personal data is used.
  6. 13. Building data protection in from the very start, not as an afterthought
Down
  1. 1. Length of time personal data is kept before deletion.
  2. 3. A basic but vital security control that should never be shared.
  3. 4. Safe disposal of confidential paper records.
  4. 5. Clear permission given for personal data to be collected and used.
  5. 7. Choices staff make every day that affect data security choices.
  6. 8. Protecting data so only authorised parties can read it.
  7. 11. A deceptive attempt to trick staff into revealing sensitive information.