Information gets moved around all day, by email, shared links, calls and messaging apps, and now by pasting it into AI assistants. This guidance sets out the checks to make before anything leaves, whichever route it takes.
This guidance document is supplied in fully editable MS Word format and can be easily customised and edited. The document uses pre-defined style formatting throughout, with all text in Calibri font for improved readability.
The following document labelling is included in the footer:
- Guidance number and title
- Information-classification
- Version
- Page number / total pages
alphaZ documents - beautifully designed, tried and tested guidance documents. No junk, jargon or unnecessary content. Simple and usable guidance documents
developed over 25 years through practical use in the real world.
Further guidance on information security:
If you'd like hands-on help setting up secure information transfer arrangements, our remote support services provide direct expert input from our team, by the day, by project, or on an ongoing basis.
Information Transfer Guidance
General guidance on transferring information securely and keeping the right level of protection in place at every stage, whether the information goes by email, file share, post, phone, messaging, a cloud platform or an AI tool.
Topics Covered
- What counts as an information transfer, and the risks involved
- Before you transfer anything - the checks to make first
- Controls by type of transfer: email, file sharing and secure file transfer, removable media, post and courier, telephone, video calls and meetings, collaboration platforms and cloud services, and text and instant messaging
- AI tools and assistants - treating information entered into an AI tool as a transfer
- Transfers outside the UK, and what to do if a transfer goes wrong
- Further advice, with references to the related documents
Who Is It For?
All staff who send or share information, and managers setting the rules for how information leaves the organisation.
Included in the GDPR / Data Protection Toolkit
This guidance document is part of the GDPR / Data Protection Toolkit - the registers, forms, policies, procedure and guidance for documenting how you collect and process personal data, in one download.
Using the Guidance
Issue the guidance to staff who send or share information, and use it to set the approved routes for sending personal and confidential information. Record who has received it as evidence of awareness.
Why AI Tools Count as a Transfer
Entering information into an AI tool sends it to a third party, often outside the UK. Treating it as a transfer means the same checks apply as for any other route: is the tool approved, is the information allowed to go there, and is it protected.
Adapting the Guidance
The guidance is fully editable, so add your approved file sharing and messaging tools, your encryption requirements and your approved AI tools.
Related Documents
Other documents in the GDPR / Data Protection Toolkit that work alongside this one:
If a Transfer Goes Wrong
Information sent to the wrong person or through the wrong route should be reported straight away, so it can be recovered where possible and assessed as a possible data breach.
Would you rather we prepared it for you?
Our Personal Data Register and Privacy Notice Preparation service works through the personal data your organisation holds with you, including the AI tools in use, and prepares the register and privacy notice so they describe what actually happens to that data.
Personal Data Register and Privacy Notice Preparation