← Blog Post အားလုံးကြည့်ရန်

Data, Privacy & Risk · Protection

Student List ကို Password တပ်ထားရုံနဲ့ Data လုံခြုံပြီလား?

Student data က registration form မှာစပြီး attendance၊ assessment၊ payment၊ certificate၊ alumni support အထိ system အများကြီးဖြတ်သွားပါတယ်။ File တစ်ခုကို lock လုပ်ရုံနဲ့ copy၊ link sharing၊ staff access၊ device loss နဲ့ vendor risk မကာကွယ်နိုင်ပါဘူး။

Myanmar school administrators protecting student data across its lifecycle
အတိုချုံးအဖြေ — Student data protection က tool တစ်ခုမဟုတ်ဘဲ inventory၊ minimization၊ least-privilege access၊ secure storage/transfer၊ backup၊ monitoring၊ incident response နဲ့ deletion ကို lifecycle တစ်လျှောက် ထိန်းသော program ဖြစ်ပါတယ်။

Protect မလုပ်ခင် Data ကိုသိပါ

Collect → Validate → Use → Share → Store → Archive → Delete
အဆင့်တိုင်းမှာ Purpose · Owner · Access · Location · Retention · Risk ကိုမှတ်ပါ

Spreadsheet၊ paper form၊ Messenger export၊ email attachment၊ LMS၊ payment record၊ cloud drive နဲ့ staff device အားလုံးကို inventory ထဲထည့်ပါ။ မသိတဲ့ copy ကိုမကာကွယ်နိုင်ပါဘူး။

Data Minimization ကို Form မှာစပါ

လက်ရှိလုပ်ငန်းရည်ရွယ်ချက်အတွက် တကယ်လိုတဲ့ field ပဲစုပါ။ “နောက်မှသုံးမယ်ထင်လို့” ID၊ address၊ birthday၊ family၊ health data မစုပါနဲ့။ Purpose ပြောင်းသုံးမည်ဆိုရင် transparency၊ authority/consent နဲ့ risk ကိုပြန်စစ်ပါ။

CollectPurpose နဲ့ minimum fields
UseExpected purpose အတွင်းသာ
ShareApproved recipient/channel
KeepDefined retention period

Access Control က “Link ရှိသူအားလုံး” မဖြစ်ရ

  • Staff တစ်ဦးချင်း account၊ shared password မသုံးခြင်း
  • MFA ဖွင့်ခြင်းနှင့် password manager အသုံးပြုခြင်း
  • Role အလိုက် view/edit/export/admin permission ခွဲခြင်း
  • New joiner approval နှင့် leaver access ကိုချက်ချင်းပိတ်ခြင်း
  • Quarterly access review နှင့် exception log
  • Sensitive export/download ကိုလိုအပ်သူသာခွင့်ပြုခြင်း

Staff Permission Matrix Guide နဲ့ role၊ approver၊ review date တည်ဆောက်ပါ။

Device၊ Storage နဲ့ Transfer ကိုကာကွယ်ပါ

DeviceScreen lock၊ updates၊ disk encryption၊ remote action
StorageApproved system၊ encryption၊ region/vendor review
TransferAccess-controlled link၊ expiry၊ wrong-recipient check
BackupSeparate copies၊ limited access၊ restore tests

Personal USB၊ public link၊ personal email နဲ့ chat attachment ဖြင့် sensitive records လှည့်ပတ်ခြင်းကို policy နဲ့ပိတ်ပါ။ Backup ရှိရုံမလုံလောက်ဘဲ restore လုပ်နိုင်ကြောင်း စမ်းရပါတယ်။

Logs မှာလည်း Personal Data ရှိနိုင်တယ်

Security logs က access abuse နဲ့ incident စစ်ရာမှာလိုပေမယ့် password၊ token၊ full ID၊ payment detail၊ health information မထည့်ပါနဲ့။ Log access၊ retention၊ tamper protection နဲ့ alert owner သတ်မှတ်ပါ။

Vendor ကို Feature နဲ့မရွေးပါနဲ့

  • ဘာ data ပို့မလဲ၊ ဘယ်မှာသိမ်းမလဲ
  • Vendor/subprocessor ဘယ်သူတွေ access ရမလဲ
  • Encryption၊ authentication၊ backup နဲ့ audit evidence
  • Incident notification နဲ့ support process
  • Export၊ deletion၊ termination နဲ့ data return
  • Contract responsibility နဲ့ cross-border considerations

Incident Response အဆင်သင့်ထားပါ

  1. Report channel နဲ့ incident lead သတ်မှတ်ပါ။
  2. Account/session ပိတ်ပြီး credentials rotate လုပ်ပါ။
  3. Evidence/logs မဖျက်ဘဲ scope နဲ့ timeline ဆုံးဖြတ်ပါ။
  4. Affected people/data/system နဲ့ harm risk စစ်ပါ။
  5. Vendor၊ leadership၊ legal/compliance ကို escalate လုပ်ပါ။
  6. Applicable notification requirement ကိုအတည်ပြုပါ။
  7. Recover၊ monitor၊ root-cause fix နဲ့ lessons learned လုပ်ပါ။

Public Credential မှာ Privacy-safe Data ပဲပြပါ

Credential Link က employer/recipient စစ်ရန်လိုသော issuer၊ achievement၊ issue date၊ credential ID နဲ့ status ကဲ့သို့ approved data ပဲပြသင့်ပါတယ်။ Email၊ phone၊ ID document၊ address၊ payment၊ private grades/notes မပြပါနဲ့။ Revoke လုပ်လည်း private reason ကို public မဖော်ပြပါနဲ့။

Authoritative Reference

ဒီ operational checklist ကို ICO data-protection principles ရဲ့ purpose limitation၊ minimization၊ storage limitation၊ security နဲ့ accountability နှင့် NIST Cybersecurity Framework 2.0 ရဲ့ Govern၊ Identify၊ Protect၊ Detect၊ Respond၊ Recover approach ကို reference လုပ်ထားပါတယ်။ Logging အတွက် OWASP Logging Cheat Sheet ကိုလည်းကြည့်နိုင်ပါတယ်။ ဒါဟာ legal advice မဟုတ်ပါ။

FAQ

Student data ဆိုတာဘာတွေလဲ?

အမည်၊ contact၊ ID၊ photo၊ attendance၊ assessment၊ payment၊ health/accessibility information၊ communications၊ device/account identifiers နှင့် credential records ကဲ့သို့ လူတစ်ဦးနဲ့ဆက်စပ်နိုင်သော data ပါဝင်နိုင်ပါတယ်။

Google Sheet ကို password တပ်ရုံလုံလောက်လား?

မလုံလောက်ပါ။ Account MFA၊ least-privilege sharing၊ link access review၊ download/export control၊ backup၊ activity monitoring နဲ့ staff offboarding လိုပါတယ်။

Data breach ဖြစ်ရင်ဘာလုပ်မလဲ?

Access ပိတ်/credential rotate လုပ်၊ evidence ကိုမဖျက်ဘဲထိန်း၊ affected data/people/systems သတ်မှတ်၊ leadership/legal/vendor ကို escalate လုပ်ပြီး applicable notification duties ကိုအချိန်မီစစ်ပါ။

Student data ကိုဘယ်လောက်ကြာထားရမလဲ?

Record purpose၊ contract၊ dispute၊ finance/education obligations နဲ့ applicable law ပေါ်မူတည်ပါတယ်။ Category အလိုက် retention period၊ owner၊ deletion method နဲ့ hold exception သတ်မှတ်ပါ။

ဒီ Guide က legal advice လား?

မဟုတ်ပါ။ General operational guidance ဖြစ်ပြီး Myanmar နှင့် သက်ဆိုင်ရာ jurisdiction/contract requirements အတွက် qualified legal or compliance professional ထံအတည်ပြုသင့်ပါတယ်။

← Blog ဆောင်းပါးအားလုံးသို့ ပြန်သွားရန်