Tip: You Can Only Have Privacy with Security
Every company should have security guidelines that they not only follow on the Internet but also internally. Without a security policy that is adhered to, you cannot have reliable privacy. Some items to keep in mind are:
- Provide your users appropriate information on how you secure information on your websites via a link on each web page. Consider including this summary in your privacy statement as well.
- Review all your security controls periodically using an internal or external audit. Include Web applications and host, network and user accounts as part of the audit.
- Document and classify all sensitive information.
- Perform due diligence before sharing sensitive or confidential information, including all personally identifiable consumer or employee data.
- Restrict the downloading of sensitive personal information from central storage devices onto personal computers or wireless storage devices.
- Establish a process for assessing whether to contact law enforcement in case of a breach as well as contact should be made, if needed.
For more recommended security guidelines, check out TRUSTe’s thorough
Guidelines