The Everyday Collection — Learn. Make. Read. Discover.
PRINTABLES & HOW TO GUIDES

Data Protection and Cybersecurity Basics

Understand privacy, secure files, safer accounts and sensible digital habits.

Data Protection and Cybersecurity Basics collection
PUBLISHED RESOURCES

Choose a resource

Open a resource to read, save or print it using the options provided.

Browse All Resources17 resources
Protected previewPurchase this resource or use an active membership to open the complete PDF.

What Every Office Worker Needs to Know

Data protection and cybersecurity are part of everyday office work, not only the responsibility of IT. Anyone who handles emails, customer records, employee information, files, passwords, cloud storage or workplace devices can accidentally expose information or create a security risk, so the safest approach is to use only the information and access needed for the job and follow the organisation's approved procedures.

PDF · 1 page
Protected previewPurchase this resource or use an active membership to open the complete PDF.

Personal Data and UK Gdpr Basics

UK data-protection law sets rules for how organisations handle information about people. Office workers do not need to memorise legislation to work safely, but they should understand that personal data must be handled lawfully, fairly, securely and only for appropriate purposes, while organisational policies determine the practical procedures staff must follow.

PDF · 1 page
Protected previewPurchase this resource or use an active membership to open the complete PDF.

Passwords, Passphrases and Multi-Factor Authentication

Passwords protect workplace accounts, but a password alone can be stolen through phishing, malware, data breaches or reuse across different services. Strong unique credentials approved password-management tools and multi-factor authentication help reduce the chance that one stolen password will give an attacker access to workplace systems

PDF · 1 page
Protected previewPurchase this resource or use an active membership to open the complete PDF.

Phishing, Suspicious Emails and Social Engineering

Phishing and social engineering try to persuade people to reveal information, approve access, send money, open malicious files or bypass normal procedures. Attackers often create urgency, authority or familiarity, so a message that appears to come from a manager, supplier, bank or Microsoft account should still be verified when the request is unusual.

PDF · 1 page
Protected previewPurchase this resource or use an active membership to open the complete PDF.

Personal Data Breaches and Security Incidents

A security incident should be reported quickly even when it was accidental and even when you are unsure whether personal data was involved. The organisation needs time to contain the problem, understand what happened and decide whether further action or formal notification is required, so staff should report facts promptly rather than trying to investigate or hide the incident themselves.

PDF · 1 page
Protected previewPurchase this resource or use an active membership to open the complete PDF.

Retention, Deletion and Secure Disposal

Keeping information for longer than it is needed can create privacy, security and records-management risks, while deleting information too early can breach legal, contractual or organisational requirements. Workplace records should therefore follow an approved retention schedule and disposal process rather than being kept forever or deleted simply because a folder looks cluttered.

PDF · 1 page
Protected previewPurchase this resource or use an active membership to open the complete PDF.

AI Tools, ChatGPT and Workplace Data

AI tools can help with writing, summarising, analysis, planning and many other office tasks, but workplace information should not automatically be copied into every AI service. Before using ChatGPT, Copilot or another AI tool for work, check whether the organisation has approved the service, which account or workspace should be used and what types of information are permitted.

PDF · 1 page
Protected previewPurchase this resource or use an active membership to open the complete PDF.

Scams Beyond Email: Calls, Texts, Payments and Impersonation

Cyber scams do not arrive only by email. Attackers can use telephone calls, text messages, workplace chat, social media, fake websites and increasingly convincing synthetic audio or video to impersonate trusted people. An unusual request should therefore be verified through an independent trusted route, even when the voice, photograph, telephone number or video appears familiar

PDF · 1 page