BEFORE YOU SHARE
Personal information is any information that can identify you, describe you, locate you, contact you, or help someone understand your accounts, habits, relationships or activities. Some information may appear harmless by itself but become much more useful when combined with other details.
THE CORE PRINCIPLE
NOT EVERY REQUEST FOR YOUR INFORMATION DESERVES AN AUTOMATIC YES.
01 · UNDERSTAND WHAT IS BEING REQUESTED
Before providing information, identify exactly what is being requested. A legitimate organization should be able to explain why particular information is necessary.
02 · ASK WHAT THE INFORMATION COULD ENABLE
Consider what someone could do with the information if it were exposed or combined with information they already have. A phone number, address, date of birth, workplace or account detail may become useful in impersonation or social engineering.
03 · PROVIDE ONLY WHAT IS NECESSARY
Do not automatically provide extra information simply because a form, caller or message asks for it. Where appropriate, provide only what is required for the legitimate purpose.
04 · VERIFY THE RECIPIENT
Before sharing sensitive information, verify who is receiving it, why they need it and whether you are using the organization's legitimate channel.
05 · BE CAREFUL WITH DOCUMENTS
Identification documents, statements, tickets, invoices and screenshots can contain more information than you intended to disclose. Review what is visible before sending or posting them.
06 · REMEMBER THAT CONTEXT MATTERS
The same piece of information can have different risk depending on who has it and what else they know. Security is not only about hiding information; it is about controlling unnecessary exposure.
EXAMPLE
Someone contacts you claiming to be helping with an account problem and asks for your full name, phone number, date of birth and a code sent to your phone. Do not assume that because some of the requested details are ordinary, the entire request is safe. Verify the person and the request independently, and never disclose authentication secrets simply to prove your identity.
WHAT TO DO
- Understand why information is needed.
- Verify the recipient and channel.
- Share only what is necessary.
- Treat authentication and recovery information as highly sensitive.
- Reconsider requests that are unexpected, urgent or unusually broad.
WHY THIS MATTERS
Information that appears harmless in isolation can become more sensitive when combined with other details. Attackers often build convincing attacks from information gathered across several sources.
