S-117 · Theme 5 · Cybersecurity & Risk
Personal Data Check-In
Use Personal Data Check-In to protect club systems and information through simple, shared security habits and a practiced response.
Developed further: this summary now draws on an initiative-specific internal editorial draft and attributed references. Human review has not started and will open only at the Full-Corpus Review Build.
What could this idea change?
It makes follow-up more caring and consistent, while leaving people in control of how they respond.
It may suit: Members who may welcome support or renewed contact, and the trusted club members following up.
A simple way to start
- Write the decision brief for Personal Data Check-In: define which accounts, devices, data and response capability the club will protect first, the starting evidence, people affected, local authority, resource limit, success signals and stop conditions. Who could lead it: Board sponsor and information owner
- Identify users and non-users, map access and digital-confidence barriers, explain data use and permissions and retain an equivalent human or non-digital route where essential participation is involved. Apply this specifically to Personal Data Check-In and record which relevant experiences or users are still missing. Who could lead it: Board sponsor and information owner with the access and privacy contacts
- Build and test a bounded evidence review with defined inputs, participation gaps and interpretation limits for Personal Data Check-In; complete the Personal Data Check-In Diagnostic Evidence Matrix, rehearse the boundary wording and confirm who may decide, refer, pause, recover or close the work. Who could lead it: System lead, privacy contact and access tester
- Use synthetic or minimised test data, least privilege, versioned configuration, accessible instructions, exception handling and a rollback; do not expose live credentials or private member information. Capture only the evidence needed to judge whether Personal Data Check-In advances practical cyber resilience. Who could lead it: System lead, privacy contact and access tester
- Compare the evidence with the starting point, validate meaning with affected participants or users, record gaps and unintended effects and prepare a dated findings summary that separates facts, experience, assumptions and unanswered questions without overstating what the trial proves. Who could lead it: System lead, privacy contact and access tester with an independent reviewer
What should we look for?
- After 90 days, review Personal Data Check-In. Look for current access records, stronger authentication, tested recovery and incidents being contained, recorded and reviewed promptly.
- Personal Data Check-In produces a dated findings summary that separates facts, experience, assumptions and unanswered questions by the promised decision date, with evidence limitations, participation gaps and unintended effects stated.
- People affected can explain the purpose, their choices, the boundary and how to raise an access, privacy, safety or governance concern.
- The trial shows whether practical cyber resilience improved from the recorded starting point without shifting hidden workload, risk or exclusion elsewhere.
- Every accepted action has an owner, due date and completion evidence, and the club records a reasoned continue, adapt, refer, scale or stop decision.
Before we say yes
- Does it fit a real local need?
- Can people take part safely and fairly?
- Are the facts, permissions and Rotary branding right?
- Who will lead it, and when will we review it?
