Share the right information with the right people
Daily work depends on sending files, inviting collaborators and giving people access to shared spaces. Stratiis helps Scottish organisations make those choices safer through clear ownership, suitable tools and practical guidance that staff can use before they share.
What is safe data sharing at work?
Safe data sharing means checking what information is needed, who should receive it, why they need it and how access will be controlled. For personal or sensitive information, the business should also check its applicable privacy obligations. A clear process lets staff collaborate while reducing accidental disclosure and lingering access.
Make sharing easier to check and manage
A reliable approach helps people make sensible choices before a file leaves its usual location.
Fewer wrong recipients
Pause to confirm the person or group before sending sensitive material.
Clearer access
Give people the level of access they need and review it when work changes.
Better control of links
Choose who can open a link and how long access should last.
Faster reporting
Give staff a simple route when a file or message goes to the wrong place.
What should a business data sharing plan include?
Start with the information, the recipient and the business purpose, then choose the right access method.
| Area | Question to answer | Useful output |
|---|---|---|
| Information | What is being shared, and is any of it personal or commercially sensitive? | Simple handling categories. |
| Purpose | What does the recipient need to do with the information? | A clear reason for sharing. |
| Recipient | Is the person, team or external organisation correctly identified? | Verified recipient list. |
| Location | Which approved system should hold the master copy? | Known storage location. |
| Permission | Does the recipient need view, comment or edit access? | Minimum suitable access. |
| Link settings | Who can open the link, and should it expire? | Restricted sharing settings. |
| Review | When should access be checked or removed? | Named owner and review date. |
| Response | How will an accidental disclosure be reported and assessed? | Clear escalation route. |
Where personal data is shared between organisations, use the ICO data sharing guidance to inform the legal and governance review. Your privacy lead should decide which requirements apply to a particular arrangement.
Where do sharing mistakes usually happen?
Use examples that reflect your team’s real tools, documents and partners.
Recipient checks
Confirm addresses and group membership before sending a sensitive message or file.
Link permissions
Prefer named people over open links when the material calls for restricted access.
External guests
Know who invited a guest, what they can see and when access will end.
Sensitive documents
Check whether the chosen channel, approval and access level fit the information.
Mobile and remote work
Use approved apps and accounts when sharing from a phone or away from the office.
Departed users and partners
Remove access when a project ends or a person changes role.
Turn sharing rules into usable habits
Test the process against a normal file share, an external request and an accidental disclosure.
Discover
Identify common files, tools, recipients and current approval routes.
Design
Agree handling guidance, permissions and reporting responsibilities.
Practise
Walk through real sharing scenarios with the people who do the work.
Improve
Review access, feedback and incidents, then simplify unclear steps.
Information Governance connects sharing decisions to ownership and wider information controls.
Give staff a clear decision and reporting route
The safest process is one people can follow while work is moving quickly.
What Stratiis can help plan
A review of collaboration tools and sharing settings.
Role-based examples and awareness guidance.
Access review and guest lifecycle steps.
A straightforward route for reporting errors.
What your team owns
The business reason and approval for sharing.
Classification of sensitive information.
Recipient verification and partner relationships.
Prompt reporting when information is misdirected.
How should staff choose a sharing method?
Match the channel and access controls to the information and the recipient.
| Situation | Practical check | Action to plan |
|---|---|---|
| Internal collaboration | Does the team already have an approved shared space? | Use role-based access and a clear owner. |
| External file exchange | Does the recipient need a copy or controlled access to a live file? | Use an approved sharing tool and restricted link settings. |
| Email attachment | Could auto-complete or forwarding expose the file? | Check recipients and use an approved safer option when needed. |
| Recurring partner access | Is sharing repeated or large scale? | Agree ownership, permissions and periodic review. |
| Public material | Has publication been authorised? | Use the approved publishing and review process. |
The ICO’s data sharing advice is a useful starting point when personal information is involved. Seek your organisation’s privacy advice for a specific arrangement.
Make accidental sharing easy to report
Early reporting gives the response team a better chance to limit access and assess what happened.
Wrong recipient
Report the message or file immediately and give the exact recipient and time.
Open link
Tell the owner or support team so the link can be reviewed or disabled.
Lost access control
Report unexpected guest or group access for investigation.
Sensitive material exposed
Preserve the details and follow the organisation’s incident route.
Monitoring and Response explains how reports connect to investigation and action.
Connect safe sharing to the wider plan
Useful habits need the right access, collaboration settings and information ownership behind them.
Data and Sharing FAQs
Answers to common questions about sharing business information safely.
What should I check before sharing a file?
Check the information, purpose, recipient, approved location and access level. For sensitive material, confirm the business approval and any privacy requirements.
Is an email attachment always suitable?
No. Email can be useful, but recipient mistakes and forwarding can be hard to control. An approved sharing system with restricted access may be more suitable for sensitive or changing files.
Should links be open to anyone?
Use the least open setting that meets the business need. Named recipients and expiry settings can help limit access where the platform supports them.
What is the difference between view and edit access?
View access lets a person read a file. Edit access lets them change it. Give edit rights only when the work requires them and review permissions later.
How should external guests be managed?
Give each guest a named business owner, suitable access and a review or end date. Remove access when the work ends.
What if information is sent to the wrong person?
Report it immediately through the agreed route, with the file, recipient and time. Follow the response team’s instructions rather than assuming that asking for deletion resolves the issue.
Does this guidance cover personal data law?
It provides practical security guidance. Personal data sharing may also require a lawful basis and other checks. Use the ICO guidance and your organisation’s privacy lead for that decision.
How can we tell whether sharing guidance is working?
Review access exceptions, guest accounts, reporting, near misses and staff questions. Use the findings to improve both settings and instructions.
Make everyday sharing safer and easier to manage
Tell us how your team exchanges files and where access decisions are difficult. We can help shape practical guidance and supporting controls.


