Who should be able to see personal data in our systems?
Short answer: Only those who need it, reviewed every quarter
Only people who need it for their job, and only the part they need. Use named accounts, give access by role, review it every quarter and remove it on the day someone leaves. Watch privileged accounts closely.
What the law says
Rule 6 names access control as a minimum safeguard, along with logs and monitoring that can detect misuse.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Steps
Write a role matrix for each key system.
Replace shared logins with named accounts.
Use multi-factor sign-in for admin and remote access.
CISO / Security head: Prioritise privileged and remote access. One review of admin accounts across core systems usually finds the biggest gaps.
CIO / IT head: Role-based access needs application changes as well as policy. Budget for it in the next release cycle.
IT department: Run the quarterly access review with system owners and close leavers on the last day.
Finance department: Limit who can see bank details and salary data, and log access.
What a good answer from management sounds like
“Access is by role, reviewed every quarter, and removed the day people leave. Shared logins are gone.” Effort and time: Medium to heavy · 8 to 16 weeks.