๐Ÿ›ก๏ธ
Data Privacy Basics for Employees
Progress10%
1 of 10

Data Privacy Basics for Employees

A scenario-based self-paced course for workplace data privacy awareness.

  • โฑDuration: 35โ€“45 minutes
  • ๐Ÿ“ŠLevel: Beginner
  • ๐Ÿ‘ฅAudience: General workforce
  • ๐Ÿ’ปFormat: Self-paced and interactive
  • ๐Ÿ’กPrior knowledge: Not required
โญ
In this course, you will make decisions in realistic workplace situations and learn how to handle data responsibly.
1
A phone number is personal data.
2
It is safe to share customer details in any internal group because everyone works in the same company.
3
Before sharing data, you should check the purpose and recipient.
4
Screenshots can also contain personal data.
5
If a file is accidentally shared with the wrong person, it is better to ignore it unless someone complains.
๐Ÿ’ก
Tip: Choose the option that best reflects responsible data handling.

Module 1: What Are Different Data Types?

Every workplace uses different kinds of data. Some data is about people, some is about business work, and some gives access to systems or files.

Before you use, store, or share any information, it is important to understand what type of data you are handling. This helps you decide how carefully it should be protected.

Meaning
Personal data is any information that can identify a person directly or indirectly.

Simple Explanation
This data may look ordinary, but it belongs to a real person. If shared carelessly, it can affect their privacy.

Examples
Name, email address, phone number, address, customer ID, employee ID, photograph, location details.

Meaning
Sensitive data is personal information that needs extra care because misuse can cause greater harm.

Simple Explanation
This type of data can affect a personโ€™s safety, reputation, finances, dignity, or professional life.

Examples
Health details, salary details, bank details, identity documents, biometric information, performance records, disciplinary records, personal complaints.

Meaning
Business data is information related to the organisationโ€™s work, operations, plans, or decisions.

Simple Explanation
This data may not always identify a person, but it may still be confidential for the organisation.

Examples
Sales reports, product plans, vendor lists, meeting notes, business forecasts, internal strategy documents, project documents, department reports.

Meaning
Credentials or restricted information gives access to systems, accounts, files, or confidential data.

Simple Explanation
This information should never be casually shared because it can allow someone to enter systems or access protected information.

Examples
Passwords, OTPs, admin links, access tokens, recovery codes, login credentials, system access details, private file links.

Think About It

A spreadsheet contains customer names, phone numbers, purchase history, and complaint notes.

Ask yourself:

  • Which details can identify a person?
  • Which details may need extra care before sharing?
  • Who actually needs access to this information?
โญ
Key Takeaway
Before using or sharing workplace information, pause and ask:
โ€œWhat type of data am I handling, and what could go wrong if it reaches the wrong person?โ€

Activity: Sort the Data

Sort the given data into the correct data types. On desktop, drag each item into the correct category. On mobile, tap the correct category for each item.

Drop Zones

๐Ÿ‘ค

Personal Data

Information that identifies an individual.

Drop items here
๐Ÿ›ก๏ธ

Sensitive Data

Information that can cause harm if misused.

Drop items here
๐Ÿ’ผ

Business Data

Information related to work, operations, or plans.

Drop items here
๐Ÿ”

Credentials / Restricted

Login, passwords, or restricted access data.

Drop items here
๐Ÿ“„

General / Low-risk Data

Public or general information.

Drop items here
Item 1 of 9

Item to classify

Customer phone number

Choose the correct category:

๐Ÿ’ก
Tip: Good data privacy begins with recognising what type of information you are handling.

Module 2: Spot the Privacy Risks

Privacy risks often appear during normal work. They may happen while sending emails, sharing folders, using messaging apps, filling forms, taking screenshots, using AI tools, or handling printed documents.

Let us understand privacy risks in more detail.

Some common risk areas are:

  • Email sent to the wrong person
  • Shared drive links open to everyone
  • Screenshots shared in group chats
  • Personal data pasted into unapproved AI tools
  • Raw form responses shared widely
  • Printed documents left unattended
  • Old files kept longer than needed
๐Ÿ’ก
Most privacy risks come from speed, convenience, or assumptions. The goal is not to stop work, but to work carefully.

Safe, Risky, or Needs Approval?

Read each situation and choose the most appropriate option.

๐Ÿ›ก๏ธ

Safe

Okay to do.

โš ๏ธ

Risky

Could cause a privacy issue.

๐Ÿ‘ค

Needs Approval

Check before proceeding.

โ„น๏ธ
Note: Choose the option that best reflects responsible data handling.

Module 3: Safe Data-Handling Habits

Handling workplace data safely does not mean refusing to share information. Many jobs require employees to collect, use, store, and share data every day.

Before you collect, open, download, forward, upload, or share data, use the 5-Check Privacy Habit.

Meaning
Use only the data that is necessary for the task.

Explanation
Sometimes we collect or share more information than required because it is already available. This increases privacy risk.

Example
If a vendor only needs customer email IDs for a campaign, do not share phone numbers, payment status, complaint notes, or full profiles.

Learner takeaway
Collect and share only what is needed.

Meaning
Do not access information only because you can see it.

Explanation
A file may be visible in a shared folder, but that does not always mean you are authorised to use it.

Example
You find an employee salary sheet in a shared drive. Even if the file opens, you should not download or use it unless your role requires it.

Learner takeaway
Access should be based on role, purpose, and permission.

Meaning
Check whether the receiver genuinely needs the data.

Explanation
Working in the same company does not automatically mean someone should receive all information.

Example
A colleague from another department asks for a customer list. Before sharing, check why they need it and whether they are authorised.

Learner takeaway
Share data only with people who need it for a valid work purpose.

Meaning
Use approved platforms for storing and sharing workplace data.

Explanation
Personal email, unofficial messaging apps, open links, or unapproved AI tools can expose data.

Example
Do not upload customer complaints, employee records, or confidential files into an unapproved AI tool for quick summarisation.

Learner takeaway
Use secure and approved tools, not the fastest shortcut.

Meaning
Do not keep personal or sensitive data longer than required.

Explanation
Old files, downloaded sheets, screenshots, and printed documents can create privacy risks if forgotten.

Example
If a project is complete, follow the organisationโ€™s process to delete, archive, or return data safely.

Learner takeaway
Store data responsibly and remove it when it is no longer needed.

Example:

Your manager asks you to share a customer list with an external agency for a campaign.

The file includes: customer names | email IDs | phone numbers | purchase history | payment status | complaint notes

Check 1: Do I need this data?
Does the agency need all columns or only selected fields?

Check 2: Am I allowed to access it?
Is this file approved for campaign use?

Check 3: Am I sharing it with the right person?
Is the agency authorised to receive it?

Check 4: Am I using the right channel?
Should it be sent through an approved secure method?

Check 5: Am I keeping it only as long as needed?
Should the file be deleted or access removed after use?

โญ
Key Takeaway
Good data privacy is not about stopping work.
It is about sharing the minimum necessary data, with the right person, for the right purpose, through the right channel.
โ†’
Next, you will apply the 5-Check Privacy Habit to a workplace scenario and choose the safest action.

Activity: Apply the 5-Check Privacy Habit

Now that you know the 5-Check Privacy Habit, let us apply it to a workplace situation. Read the scenario carefully and choose the safest action.

Scenario

Your manager asks you to share a customer list with an external agency for a promotional campaign.

The file includes: customer names | email IDs | phone numbers | purchase history | payment status | complaint notes

The agency says:

โ€œPlease send the full file. We will decide what is useful.โ€

What should you do?

Choose the safest action.
Which part of the 5-Check Privacy Habit helped you make the safest decision?
โญ
Key Takeaway:
When sharing data, do not share everything just because it is available. Share only what is needed, with the right person, for the right purpose, through the right channel.

Module 4: Incident Response

Mistakes can happen at work.

  • A file may be sent to the wrong person.
  • A shared folder may be open to too many people.
  • A printed document may be left in a meeting room.
  • A screenshot may reveal more information than intended.

When something goes wrong, the most important thing is to act quickly and responsibly.

Ignoring the issue or hiding the mistake can make the problem worse.

Do not forward the file again. Do not continue using the wrong channel or tool.

Report the issue to your manager, IT team, compliance team, data protection contact, or the approved reporting channel.

Explain what happened, what data was involved, who may have accessed it, and when it happened.

Do not try to fix everything alone. Follow the instructions given by the responsible team.

Think about what caused the mistake and what can be done differently next time.

Workplace Example

You accidentally send an employee salary file to an external email address.

What should you do?

The right action is to report it immediately through the correct workplace channel.

  • Do not wait to see if the person replies.
  • Do not simply delete the email from your sent folder.
  • Do not hide the mistake.

Quick reporting helps the organisation reduce harm.

โญ
Key Takeaway
A privacy mistake becomes more serious when it is hidden.
Report quickly, give clear details, and follow the correct process.
โ†’
You will now complete a final workplace challenge where you will apply everything you learned in a realistic data-sharing situation.

Final Workplace Challenge

Apply everything you learned in one realistic workplace case.

โญ
Key Takeaway
Data privacy is not about slowing down work. It is about making sure work happens safely.
Before sharing data, remember:
Right data. Right person. Right purpose. Right channel.

โœ“ Course Completed

You have completed Data Privacy Basics for Employees.

You can now:

  • identify personal and sensitive data,
  • recognise common privacy risks,
  • apply safe data-handling habits,
  • respond responsibly when something goes wrong,
  • and use a checklist before handling workplace data.
โญ
Data privacy is not only a compliance responsibility.
It is a daily workplace habit that protects people, trust, and professional integrity.