This is a guide for Zendesk agents and support managers on how to handle data and privacy in Zendesk.
The purpose of these guidelines is to reduce risks related to having sensitive data in our systems, while allowing us to continue working efficiently.
These guidelines apply to all users of Zendesk at Kry Livi.
Contents
- Data fundamentals in Zendesk
- Acceptable and non acceptable data in Zendesk
- Zendesk integrations
- Legal team contact details
Data fundamentals in Zendesk
When using Zendesk we must make sure that we:
- Always minimise data to what’s strictly needed. Don’t collect, request or use more data than necessary. For example, If email and name is sufficient to resolve a ticket, don’t request address and phone.
- Never request medical information and other sensitive details as outlined in the section “Acceptable and non acceptable data in Zendesk”.
- That we use the most secure method possible for gathering personal data. For example, instead of requesting personal data in Zendesk, use a more secure way of communicating with the patient such as in-App messages instead of using Zendesk (and in exceptional cases, where the patient doesn’t have the app, we use Firefox send and NHS mail in the UK).
Acceptable and non acceptable data in Zendesk
As mentioned in the section above, we should never collect, request or use more data than necessary when handling Zendesk tickets.
For specific and detailed instructions on the proper handling of data within Zendesk, kindly adhere to the guidelines outlined below.
Data that should never be included in a Zendesk ticket
This is data that should never be in Zendesk, and should be redacted as soon as it is noticed.
- Passwords (including temporary passwords and BitLocker keys)
- Photos of patient
- Photos of symptoms
- Other data on symptoms, diagnosis and treatment
- Payment card details
- Scans / photos of ID (passports, driving licence etc.)
-
Sensitive data on others other than the patient or their children that are being treated at Kry Livi ( e.g. family members, spouses etc.)
Data that should only be included when necessary
The following data should be collected only when essential, such as for verifying the identity of individuals seeking assistance with the application or patient records. It is imperative to consistently minimise data collection where possible. The screenshot shown below is an example of where we might ask for these details.
- Date of Birth
- Address
- Registered home address
- Registered phone number
Data that is acceptable to have in Zendesk
This is data that is fine to have in Zendesk, but as outlined in the section above, this data should only be collected if needed.
- Name
- Phone number
- IP Address
Zendesk integrations
When using Zendesk integrations please note that the contents of the Zendesk ticket can then be exposed to more users than the agents in your Zendesk group.
One example is the Zendesk / Jira integration for bug reporting. When using this integration, the contents of the Zendesk ticket can be seen by users with a Jira licence, exposing the information in the ticket to many more users than only the agents in your Zendesk group.
If there is information in the ticket that is not suitable for users outside your Zendesk support group to see, please either redact that information, or open up a new ticket and create a new ticket only including the relevant information needed for the bug support team.
Legal team contact details
If you have questions, identify an issue or struggle to comply with these guidelines for a use case, please reach out to the Ask Legal channel in Teams
In the event of leakage, loss, unauthorised access or other type of data breach, please reach out to #report-data-breach and use the data breach [template] (you’ll find instructions on how to report, etc in our data breach procedure).
Feedback
Your feedback is important to us, please let us know if this article was useful by voting and / or commenting below.
Comments
0 comments
Please sign in to leave a comment.