Business data sharing awareness in Scotland

Share the right information with the right people

Daily work depends on sending files, inviting collaborators and giving people access to shared spaces. Stratiis helps Scottish organisations make those choices safer through clear ownership, suitable tools and practical guidance that staff can use before they share.

What is safe data sharing at work?

Safe data sharing means checking what information is needed, who should receive it, why they need it and how access will be controlled. For personal or sensitive information, the business should also check its applicable privacy obligations. A clear process lets staff collaborate while reducing accidental disclosure and lingering access.

Why it matters

Make sharing easier to check and manage

A reliable approach helps people make sensible choices before a file leaves its usual location.

Fewer wrong recipients

Pause to confirm the person or group before sending sensitive material.

Clearer access

Give people the level of access they need and review it when work changes.

Better control of links

Choose who can open a link and how long access should last.

Faster reporting

Give staff a simple route when a file or message goes to the wrong place.

Sharing plan

What should a business data sharing plan include?

Start with the information, the recipient and the business purpose, then choose the right access method.

Area Question to answer Useful output
Information What is being shared, and is any of it personal or commercially sensitive? Simple handling categories.
Purpose What does the recipient need to do with the information? A clear reason for sharing.
Recipient Is the person, team or external organisation correctly identified? Verified recipient list.
Location Which approved system should hold the master copy? Known storage location.
Permission Does the recipient need view, comment or edit access? Minimum suitable access.
Link settings Who can open the link, and should it expire? Restricted sharing settings.
Review When should access be checked or removed? Named owner and review date.
Response How will an accidental disclosure be reported and assessed? Clear escalation route.

Where personal data is shared between organisations, use the ICO data sharing guidance to inform the legal and governance review. Your privacy lead should decide which requirements apply to a particular arrangement.

Practical starting points

Where do sharing mistakes usually happen?

Use examples that reflect your team’s real tools, documents and partners.

Recipient checks

Confirm addresses and group membership before sending a sensitive message or file.

Link permissions

Prefer named people over open links when the material calls for restricted access.

External guests

Know who invited a guest, what they can see and when access will end.

Sensitive documents

Check whether the chosen channel, approval and access level fit the information.

Mobile and remote work

Use approved apps and accounts when sharing from a phone or away from the office.

Departed users and partners

Remove access when a project ends or a person changes role.

How support starts

Turn sharing rules into usable habits

Test the process against a normal file share, an external request and an accidental disclosure.

1

Discover

Identify common files, tools, recipients and current approval routes.

2

Design

Agree handling guidance, permissions and reporting responsibilities.

3

Practise

Walk through real sharing scenarios with the people who do the work.

4

Improve

Review access, feedback and incidents, then simplify unclear steps.

Information Governance connects sharing decisions to ownership and wider information controls.

People and safeguards

Give staff a clear decision and reporting route

The safest process is one people can follow while work is moving quickly.

What Stratiis can help plan

A review of collaboration tools and sharing settings.

Role-based examples and awareness guidance.

Access review and guest lifecycle steps.

A straightforward route for reporting errors.

What your team owns

The business reason and approval for sharing.

Classification of sensitive information.

Recipient verification and partner relationships.

Prompt reporting when information is misdirected.

Choosing a method

How should staff choose a sharing method?

Match the channel and access controls to the information and the recipient.

Situation Practical check Action to plan
Internal collaboration Does the team already have an approved shared space? Use role-based access and a clear owner.
External file exchange Does the recipient need a copy or controlled access to a live file? Use an approved sharing tool and restricted link settings.
Email attachment Could auto-complete or forwarding expose the file? Check recipients and use an approved safer option when needed.
Recurring partner access Is sharing repeated or large scale? Agree ownership, permissions and periodic review.
Public material Has publication been authorised? Use the approved publishing and review process.

The ICO’s data sharing advice is a useful starting point when personal information is involved. Seek your organisation’s privacy advice for a specific arrangement.

When something goes wrong

Make accidental sharing easy to report

Early reporting gives the response team a better chance to limit access and assess what happened.

Wrong recipient

Report the message or file immediately and give the exact recipient and time.

Open link

Tell the owner or support team so the link can be reviewed or disabled.

Lost access control

Report unexpected guest or group access for investigation.

Sensitive material exposed

Preserve the details and follow the organisation’s incident route.

Monitoring and Response explains how reports connect to investigation and action.

Related Stratiis services

Connect safe sharing to the wider plan

Useful habits need the right access, collaboration settings and information ownership behind them.

Common questions

Data and Sharing FAQs

Answers to common questions about sharing business information safely.

What should I check before sharing a file?

Check the information, purpose, recipient, approved location and access level. For sensitive material, confirm the business approval and any privacy requirements.

Is an email attachment always suitable?

No. Email can be useful, but recipient mistakes and forwarding can be hard to control. An approved sharing system with restricted access may be more suitable for sensitive or changing files.

Should links be open to anyone?

Use the least open setting that meets the business need. Named recipients and expiry settings can help limit access where the platform supports them.

What is the difference between view and edit access?

View access lets a person read a file. Edit access lets them change it. Give edit rights only when the work requires them and review permissions later.

How should external guests be managed?

Give each guest a named business owner, suitable access and a review or end date. Remove access when the work ends.

What if information is sent to the wrong person?

Report it immediately through the agreed route, with the file, recipient and time. Follow the response team’s instructions rather than assuming that asking for deletion resolves the issue.

Does this guidance cover personal data law?

It provides practical security guidance. Personal data sharing may also require a lawful basis and other checks. Use the ICO guidance and your organisation’s privacy lead for that decision.

How can we tell whether sharing guidance is working?

Review access exceptions, guest accounts, reporting, near misses and staff questions. Use the findings to improve both settings and instructions.

Talk to Stratiis

Make everyday sharing safer and easier to manage

Tell us how your team exchanges files and where access decisions are difficult. We can help shape practical guidance and supporting controls.

Contact Stratiis →