Data Management Reminders
to Deter Identity Theft
Businesses have a responsibility to protect the sensitive personal data that they manage.
Here is a short list of data management reminders to consider.

- If you don't need it, don't collect it.
- If you need it once, don't save it longer.
- If you've got it, but you don't need to save it, dispose of it carefully.
- If you have to keep it, think security.
- Formally document data life cycle that includes collection, storage, use, and destruction.
- Don't broadcast personal information.
- Create and enforce a data-removal policy that limits who can remove sensitive data from your office and how they must secure it.
- Don't use Social Security numbers as account numbers, ID badges, time cards, or other publicly exposed documents.
- Don't give out employee or customer information to anyone whose identity can't be positively confirmed.
- Locks and alarms are a real deterrent.
- Conduct background checks on all individuals with access to personal and/or sensitive information,
including cleaning and temporary service.
- Limit the number of temporary agencies your company uses. If possible, maintain the services of one trusted firm.
- Don't let customers or other unauthorized people view sensitive information on your desk, computer monitor, etc.
- Secure job applications
- Don't cover up data breaches. Have a data breach policy and procedure in place.
- Perform regular data management audits.
- Read the FTC guides
- Read the National Institute of Standards and Technology publication, "Guide to Protecting the Confidentiality of Personally Identifiable Information"
- Read the Bureau of Consumer Protection article about Copier Data Security.