Chapter 6 Data Responsibility and Confidentiality

Access to data creates obligations that continue from acquisition through final disposal. This chapter distinguishes privacy, confidentiality, security, and ethics; applies minimum-necessary-use principles; and examines how responsible practice governs storage, sharing, de-identification, external tools, and generative AI.

Learning outcomes

After completing this chapter, you should be able to:

  • distinguish privacy, confidentiality, security, and data stewardship;
  • identify responsibilities associated with organizational and client data;
  • distinguish permission to access data from permission to share or reuse it;
  • recognize disclosure risks created by outputs, software, and third-party services; and
  • apply minimum-necessary and lifecycle principles to project data.

Key terms

  • Confidentiality: The obligation to prevent information from being disclosed to people, systems, or purposes that have not been authorized.

  • Privacy: The rights and expectations associated with how information about individuals is collected, used, linked, shared, retained, and disclosed.

  • Data stewardship: The responsible management of data throughout its lifecycle so that it remains secure, understandable, reliable, appropriately used, and properly retained or disposed of.

  • Minimum necessary access: The principle that people and systems should receive only the data and permissions required for an approved purpose.

  • De-identification: The removal, masking, or transformation of direct and indirect identifiers to reduce the likelihood that a person or organization can be recognized.

  • Third-party service: An external platform, application, model, storage provider, or vendor that receives, processes, stores, or transmits project information.

  • Data-use agreement: A formal agreement that defines permitted data, users, purposes, safeguards, disclosures, retention periods, and other conditions of access.