Skip to main content

Sensitive Information Sharing & Storage Policy

Via policies for transmitting and storing sensitive information.

C
Written by CMM Admin
Updated over 11 months ago

In order to conduct day to day operations, Via occasionally collects sensitive private information from staff. Some types of information are okay to transmit via email and store on any approved drives. Other types of information are so sensitive that they should only be securely transmitted and/or stored in secured drives.

Via strives to protect all private information collected from staff. In order to accomplish this, all staff are expected to abide by the below policies when transmitting and/or storing private information and as indicated in the Via Privacy Policy.

Definitions

Non-Sensitive Personally Identifiable Information (PII) is information that is available in public sources the disclosure of which cannot reasonably be expected to result in personal harm.

Sensitive PII (SPII) is information which, when disclosed, could result in harm to the individual whose privacy has been breached. Sensitive PII should therefore be encrypted in transit and when data is at rest.

Personally Identifiable Financial Information (PIFI) is any type of personally identifiable information (PII) that is linked to that person's finances.

Examples

PII

  • Name

  • Home Address

  • Email Address

  • Phone Number

SPII

  • Social Security Number

  • Driver’s License

  • State ID card

  • Passport Number

  • Biometric Identifiers

  • Healthcare related information

  • Medical Insurance Information

PIFI

  • Bank Account number

  • Credit Card Number

  • Voided Check

Transmission & Storage Policy

PII

  • Transmission: This type of Information is okay to transmit via email.

  • Storage: This type of information may be stored on all Via approved drives. (i.e. Google Drive, Microsoft OneDrive, Via computer hard drives)

SPII

  • Transmission: This type of Information may only be transmitted using DocuSign or ADP.

  • Storage: This type of Information may only be stored in DocuSign or ADP.

PIFI

  • Transmission: This type of Information may only be transmitted using using DocuSign or ADP.

  • Storage: This type of Information should never be stored. After receiving this data, it should be used immediately and then permanently deleted.

Did this answer your question?