Data Privacy Basics for Employees
A scenario-based self-paced course for workplace data privacy awareness.
- Duration: 35โ45 minutes
- Level: Beginner
- Audience: General workforce
- Format: Self-paced and interactive
- Prior knowledge: Not required
A scenario-based self-paced course for workplace data privacy awareness.
Every workplace uses different kinds of data. Some data is about people, some is about business work, and some gives access to systems or files.
Before you use, store, or share any information, it is important to understand what type of data you are handling. This helps you decide how carefully it should be protected.
Meaning
Personal data is any information that can identify a person directly or indirectly.
Simple Explanation
This data may look ordinary, but it belongs to a real person. If shared carelessly, it can affect their privacy.
Examples
Name, email address, phone number, address, customer ID, employee ID, photograph, location details.
Meaning
Sensitive data is personal information that needs extra care because misuse can cause greater harm.
Simple Explanation
This type of data can affect a personโs safety, reputation, finances, dignity, or professional life.
Examples
Health details, salary details, bank details, identity documents, biometric information, performance records, disciplinary records, personal complaints.
Meaning
Business data is information related to the organisationโs work, operations, plans, or decisions.
Simple Explanation
This data may not always identify a person, but it may still be confidential for the organisation.
Examples
Sales reports, product plans, vendor lists, meeting notes, business forecasts, internal strategy documents, project documents, department reports.
Meaning
Credentials or restricted information gives access to systems, accounts, files, or confidential data.
Simple Explanation
This information should never be casually shared because it can allow someone to enter systems or access protected information.
Examples
Passwords, OTPs, admin links, access tokens, recovery codes, login credentials, system access details, private file links.
A spreadsheet contains customer names, phone numbers, purchase history, and complaint notes.
Ask yourself:
Sort the given data into the correct data types. On desktop, drag each item into the correct category. On mobile, tap the correct category for each item.
Information that identifies an individual.
Information that can cause harm if misused.
Information related to work, operations, or plans.
Login, passwords, or restricted access data.
Public or general information.
Item to classify
Choose the correct category:
Privacy risks often appear during normal work. They may happen while sending emails, sharing folders, using messaging apps, filling forms, taking screenshots, using AI tools, or handling printed documents.
Let us understand privacy risks in more detail.
Read each situation and choose the most appropriate option.
Okay to do.
Could cause a privacy issue.
Check before proceeding.
Handling workplace data safely does not mean refusing to share information. Many jobs require employees to collect, use, store, and share data every day.
Before you collect, open, download, forward, upload, or share data, use the 5-Check Privacy Habit.
Meaning
Use only the data that is necessary for the task.
Explanation
Sometimes we collect or share more information than required because it is already available. This increases privacy risk.
Example
If a vendor only needs customer email IDs for a campaign, do not share phone numbers, payment status, complaint notes, or full profiles.
Learner takeaway
Collect and share only what is needed.
Meaning
Do not access information only because you can see it.
Explanation
A file may be visible in a shared folder, but that does not always mean you are authorised to use it.
Example
You find an employee salary sheet in a shared drive. Even if the file opens, you should not download or use it unless your role requires it.
Learner takeaway
Access should be based on role, purpose, and permission.
Meaning
Check whether the receiver genuinely needs the data.
Explanation
Working in the same company does not automatically mean someone should receive all information.
Example
A colleague from another department asks for a customer list. Before sharing, check why they need it and whether they are authorised.
Learner takeaway
Share data only with people who need it for a valid work purpose.
Meaning
Use approved platforms for storing and sharing workplace data.
Explanation
Personal email, unofficial messaging apps, open links, or unapproved AI tools can expose data.
Example
Do not upload customer complaints, employee records, or confidential files into an unapproved AI tool for quick summarisation.
Learner takeaway
Use secure and approved tools, not the fastest shortcut.
Meaning
Do not keep personal or sensitive data longer than required.
Explanation
Old files, downloaded sheets, screenshots, and printed documents can create privacy risks if forgotten.
Example
If a project is complete, follow the organisationโs process to delete, archive, or return data safely.
Learner takeaway
Store data responsibly and remove it when it is no longer needed.
Your manager asks you to share a customer list with an external agency for a campaign.
The file includes: customer names | email IDs | phone numbers | purchase history | payment status | complaint notes
Check 1: Do I need this data?
Does the agency need all columns or only selected fields?
Check 2: Am I allowed to access it?
Is this file approved for campaign use?
Check 3: Am I sharing it with the right person?
Is the agency authorised to receive it?
Check 4: Am I using the right channel?
Should it be sent through an approved secure method?
Check 5: Am I keeping it only as long as needed?
Should the file be deleted or access removed after use?
Now that you know the 5-Check Privacy Habit, let us apply it to a workplace situation. Read the scenario carefully and choose the safest action.
Your manager asks you to share a customer list with an external agency for a promotional campaign.
The file includes: customer names | email IDs | phone numbers | purchase history | payment status | complaint notes
The agency says:
โPlease send the full file. We will decide what is useful.โ
What should you do?
Mistakes can happen at work.
When something goes wrong, the most important thing is to act quickly and responsibly.
Ignoring the issue or hiding the mistake can make the problem worse.
Do not forward the file again. Do not continue using the wrong channel or tool.
Report the issue to your manager, IT team, compliance team, data protection contact, or the approved reporting channel.
Explain what happened, what data was involved, who may have accessed it, and when it happened.
Do not try to fix everything alone. Follow the instructions given by the responsible team.
Think about what caused the mistake and what can be done differently next time.
You accidentally send an employee salary file to an external email address.
What should you do?
The right action is to report it immediately through the correct workplace channel.
Quick reporting helps the organisation reduce harm.
Apply everything you learned in one realistic workplace case.
You have completed Data Privacy Basics for Employees.
You can now: