Protecting your customers' data

Plan requirement

Subscription Any plan
Access Admin

Most exposure comes from ordinary working habits rather than from settings. Four that make the largest difference.

One: stop collecting what you do not need

Every field on a form is data you now hold and must protect. A date of birth collected because it seemed useful is a liability with no benefit.

Go through your forms once and remove what nobody reads.

Two: tell customers what not to send

People send passwords, identity documents and full card numbers because they are trying to help. A line on the form asking them not to prevents more exposure than any redaction rule.

Three: redact as you go

When something sensitive arrives, remove it from the ticket then, not in a quarterly cleanup. Make it a normal part of handling rather than a project.

Automatic redaction of card numbers is worth switching on regardless.

Four: narrow who can see everything

Roles decide which tickets an agent can open. An agent role with access to every ticket is convenient and means one compromised account exposes the lot.

The habit that beats all four

Offboard the day somebody leaves. An active account belonging to a former colleague is the single most likely route to a real incident, and no setting compensates for it.

Exports are the quiet leak

A spreadsheet of tickets on somebody's laptop is outside every control you have configured. Agree where exports may live and who may make them.

Where the obligations come from

What you must do is set by law and by your own agreements, not by the product. If you are unsure how that applies to your setup, ask pluscloud support and we will go through it with you.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.