Chapter 6 Data Responsibility and Confidentiality
Access to data creates obligations that continue from acquisition through final disposal. This chapter distinguishes privacy, confidentiality, security, and ethics; applies minimum-necessary-use principles; and examines how responsible practice governs storage, sharing, de-identification, external tools, and generative AI.
Learning outcomes
After completing this chapter, you should be able to:
- distinguish privacy, confidentiality, security, and data stewardship;
- identify responsibilities associated with organizational and client data;
- distinguish permission to access data from permission to share or reuse it;
- recognize disclosure risks created by outputs, software, and third-party services; and
- apply minimum-necessary and lifecycle principles to project data.
Key terms
Confidentiality: The obligation to prevent information from being disclosed to people, systems, or purposes that have not been authorized.
Privacy: The rights and expectations associated with how information about individuals is collected, used, linked, shared, retained, and disclosed.
Data stewardship: The responsible management of data throughout its lifecycle so that it remains secure, understandable, reliable, appropriately used, and properly retained or disposed of.
Minimum necessary access: The principle that people and systems should receive only the data and permissions required for an approved purpose.
De-identification: The removal, masking, or transformation of direct and indirect identifiers to reduce the likelihood that a person or organization can be recognized.
Third-party service: An external platform, application, model, storage provider, or vendor that receives, processes, stores, or transmits project information.
Data-use agreement: A formal agreement that defines permitted data, users, purposes, safeguards, disclosures, retention periods, and other conditions of access.