Skip to Content

Sovereign Hosting: Sensitive Data

October 3, 2022 by
Sovereign Hosting: Sensitive Data
ST DIGITAL, Fabrice ADZRAKOU

What is sensitive data?

Sensitive data is personal data: identity card, date of birth, email address, employment contract… anything that falls under personal data and therefore, by definition, belongs to an end user. It is simply a piece of information or a successive set of information that makes it possible to identify someone.

What is/are the risk(s) for sensitive data?

The main risk is that it is stolen, misappropriated, and ends up on the internet or on the Dark Web. It may be published on public sites without any authorisation from the end user. If that is the case, it is exposed to numerous other malicious acts such as identity theft, unauthorised online purchases…

How can it be protected?

It can be protected in several ways. The first line of protection lies in prevention and anticipation. We must be able to answer the following questions for all sensitive data: Who has access to this data? Where is it? How is it accessed? When can it be viewed/modified?

To secure it, an access bastion must be put in place in order to establish traceability of consultation, processing, storage and disclosure of data. Every operation carried out on sensitive data must be recorded.

Where possible, activate the two-factor authentication system.
With this feature, you will be notified by SMS or email if someone attempts to log in to your account from an unknown device.

There is also the data encryption process, which renders all content unreadable as long as "the key" (or a specific action) that authorises access has not been entered or performed.

In summary, we must COMPREHENSIVELY CONTROL sensitive data, in order to have the ability to TRACE all movements that may occur on it, with the sole aim of SECURING it.

In the event of disclosure, great care must be taken regarding the channel used and the audience that will have access to this information.
For example, the use of collaborative tools must be closely monitored, as data can easily circulate and be recorded without our knowledge.

Finally, another important point: when sharing this data with partners, it is essential to know how they will process and use it, in order to comply with Data Protection regulations and to ensure that it is hosted with a sovereign hosting provider such as ST DIGITAL.