Guidance on processing personal data off campus

(This guidance should be read in conjunction with the University's Mobile and Remote Working Policy)

Many data security breaches occur when personal data is being taken off work premises, when working from home for example. While it is permitted to take personal data off University premises for work purposes, staff must take appropriate security measures to protect against the loss or theft of that data.

Staff Responsibilities

Under the Data Protection Act, personal data can only be processed off campus if all of the following conditions are met:

Any breach of these responsibilities could lead to disciplinary action and the University receiving a fine of up to £500,000 from the Information Commissioner.

Use of non-University owned computing equipment

Staff should not store or process personal data on personally owned computing equipment. The University should provide adequate computing facilities for your role at the University. Please speak to your line manager or zonal IT team if you need additional IT hardware to be able to work effectively. Accessing the Staff Desktop from a personally owned computer/device is acceptable as this is simply accessing the University network remotely and no data should be retained on your computer/device. When using the Staff Desktop, it is important to ensure that no data is copied or saved to any end user computer/device.

Do not send documents including personal data to a private, non-University email address to access these documents remotely – storing personal data with an unauthorised third party (without consent) is likely to be a breach of the Data Protection Act. Similarly, storing personal data with third party cloud storage providers that do not meet security standards acceptable to the University is not permitted.

For further guidance on the use of cloud storage providers, please see the Cloud Storage Wiki.

Also ensure any backup devices used to store personal data are fully encrypted and physically secure at all times.

In very exceptional circumstances that create a need to use non University-owned computing equipment, permission must be obtained in writing from the Head of School/Department with the agreement of the University Secretary. In this circumstance, it may also be necessary for the member of staff to register with the Information Commissioner’s Office as a data controller.

Alternatives

Always consider how necessary it is to take personal data off University premises, taking the following into account:

Security measures

If taking personal data off University premises, it is the responsibility of individual members of staff to ensure that they have adequate security measures in place to protect against loss or theft.

For guidance on secure mobile storage devices for electronic personal data, please see the Information Security website.

For hard copy personal data, you should consider -

Security of data when in transit:

Security of data at home:

Personal data overseas

For guidance about the processing of personal data overseas, please see the University’s advice regarding personal data and the European Economic Area/USA or contact the Information Rights Officer for advice.