Secure Data ManagementUpdated: 2026
Classify, store, share, and destroy your data properly. Understand your legal obligations (GDPR, Quebec Law 25) and protect your organization's sensitive information.
By the end of this module, you'll be able toβ¦
- Classify your data according to its sensitivity
- Apply the right protections at each level
- Share files securely
- Understand the main legal obligations around personal data
For SMBs, data management covers customer information, contracts, HR data, and trade secrets. A leak can lead to financial losses, lawsuits, and irreparable loss of trust. Quebec's Law 25 imposes specific obligations on businesses that collect personal data.
Educational institutions handle data on minors β a particularly protected category. Grades, psychological assessments, and family information must be protected under provincial and federal law. Sharing via unencrypted email should be strictly avoided.
Nonprofits often collect sensitive data (health, financial situation, social vulnerability) and are subject to the same legal obligations as private businesses. Beneficiaries' trust is a core asset that demands rigorous data protection.
What is sensitive data
Not all data is equal. A public price list doesn't carry the same sensitivity as a medical record or a strategic business plan. The first step in good data management is understanding what you have and its intrinsic value.
Data is "sensitive" when unauthorized disclosure could cause harm: privacy violation, financial damage, national security risk, loss of competitive advantage, or legal violation.
Personal, professional and confidential data
It's useful to distinguish three broad categories of data based on context and required level of protection:
β The three classification levels
- Public: Information meant to be known by the general public β website, press releases, posted prices. No distribution restrictions.
- Internal: Information for internal use β operating procedures, company policies, org chart. Shouldn't be shared externally without authorization.
- Confidential: Information whose disclosure would cause harm β customer data, unpublished financial information, passwords, trade secrets, health data, social insurance numbers.
Some organizations add a fourth level, "Secret" or "Restricted", for the most critical data. What matters is having a consistent system everyone understands.
Risks of information leaks
Data leaks can result from an external attack, but also β and more often β from internal human error. Sending an email to the wrong recipient, sharing a link with no access restriction, forgetting a file on a lost USB drive: the leak vectors are numerous.
- Human error (23%): Email sent to the wrong recipient, misconfigured sharing, file left in a public place.
- Phishing (41%): Credentials stolen through a fraudulent email, then used to access systems.
- Unauthorized access (19%): Former employee whose access wasn't revoked, or overly broad permission sharing.
- Malware (17%): Ransomware exfiltrating data before encrypting it.
Storing data securely
Where data is stored largely determines its level of protection. Each option has its own advantages and specific risks.
β Storage best practices
- Business cloud (Microsoft 365, Google Workspace): Acceptable for internal and confidential data as long as the account is protected by MFA and sharing rights are limited.
- Local server or NAS: Good control, but requires rigorous backup and update management.
- USB drive: Avoid for confidential data unless encrypted. USB drives are easily lost.
- Personal email (Gmail, Hotmail): Avoid for professional or confidential data β this data then becomes subject to third-party providers' privacy policies.
Sharing files without putting yourself at risk
File sharing is a major source of unintentional leaks. A link shared with "anyone" on OneDrive or Google Drive, an unencrypted attachment, a printer shared over the network β all are vectors of unintended disclosure.
β Sharing securely
- Restricted links: Use sharing links that require sign-in, limit access to relevant people, and add an expiration date.
- Avoid large attachments: Share via a link to a controlled storage space rather than as an attachment β you retain control and can revoke access.
- Attachment encryption: For highly sensitive documents, encrypt the file (7-Zip with AES-256) and send the password through a separate channel (phone, text).
- Verify recipients: Before sending, double-check the recipient's address. An autocomplete mistake can send your data to the wrong person.
Permissions and access control
The principle of least privilege states that each person should only have access to the data strictly necessary for their role. In practice, many organizations grant overly broad access for convenience, creating significant risk.
β Effective access control
- Role-based access (RBAC): Define access levels by function (accounting, HR, management) rather than by individual β simpler to manage.
- Immediate revocation: As soon as an employee leaves the organization, their access must be revoked the same day. Create a formal offboarding procedure.
- Access audits: Regularly review (at least yearly) who has access to what. "Access creep" (accumulation of rights over time) is very common.
- Logging: Enable access logs for sensitive resources. If a leak occurs, you'll have the trail to understand what happened.
Secure transfer and encryption
When data travels over a network, it can be intercepted. Encrypting communications and files guarantees that, even if intercepted, the data remains unreadable to an unauthorized third party.
β Secure transfer protocols and tools
- HTTPS: Verify that any web service used to transfer data uses HTTPS (padlock in the address bar). Never transmit sensitive data over HTTP.
- SFTP/FTPS: For file transfers between servers, use SFTP (SSH File Transfer Protocol) or FTPS β never plain FTP.
- End-to-end encryption: For highly sensitive communications, use Signal or Proton Mail, which encrypt messages so even the provider can't read them.
- File encryption: 7-Zip (free) lets you create AES-256 encrypted archives β ideal for files sent by email.
Avoiding common handling mistakes
Human errors in data handling are the leading cause of unintentional leaks. Identifying and correcting these mistakes is often faster and cheaper than deploying complex technical systems.
β Common mistakes to avoid
- Email in CC instead of BCC: Sending a newsletter with all recipients in CC exposes the full contact list to every recipient.
- Sharing entire folders: Sharing a folder containing more files than necessary β access should be limited to specifically needed files.
- Copy-pasting sensitive data: Pasting a SIN or credit card number into a collaboration tool (Slack, Teams) leaves permanent traces.
- Printing sensitive documents and leaving them at the printer: Printed documents forgotten at the printer are a frequent physical leak.
- Using screenshots of confidential data: Screenshots containing sensitive data are often shared without the same protections as the original files.
Secure destruction of media
Deleting a file or formatting a disk doesn't destroy the data β it simply removes the pointer to it. Data recovery tools can retrieve information from "erased" media. Secure destruction is a mandatory step at end of a device's life.
β Destruction methods by media type
- Hard drives (HDD): Use secure wipe software (DBAN, Eraser) with at least 3 passes, or use a NAID AAA-certified destruction service.
- SSDs and flash memory: Pass-based overwriting is less effective on SSDs. Prefer prior encryption + the manufacturer's Secure Erase command, or physical destruction.
- Paper documents: Use a cross-cut (micro-cut) paper shredder for sensitive documents. Long-strip shredding isn't sufficient.
- Phones and tablets: Perform a factory reset after enabling encryption β the content then becomes unrecoverable.
Compliance basics β GDPR and Quebec's Law 25
In Quebec, Law 25 (the Act to modernize legislative provisions respecting the protection of personal information) imposes concrete obligations on any organization that collects personal data. In Europe, the GDPR applies. These laws aren't just a constraint β they define individuals' rights and organizations' responsibilities.
β Key obligations under Law 25 (Quebec)
- Privacy officer: Every organization must designate a person responsible for the protection of personal information.
- Incident reporting: Any incident involving personal information must be reported to Quebec's Commission d'accès à l'information (CAI) if it presents a serious risk of harm.
- Right of access and correction: Individuals have the right to view and correct their personal information held by your organization.
- Informed consent: Collecting personal data requires explicit, clear consent limited to the stated purposes.
- Data minimization: Only collect what's strictly necessary. "Just in case" isn't a valid legal reason.
Data classification
For each item below, choose the right classification level: Public, Internal, or Confidential.
Module quiz
Test what you've learned with 4 questions.
See also