Step 1 of 6
Learn
Before you start
By the end of this lesson you will be able to:
- Recognize personal and confidential customer information.
- Use approved access methods.
- Apply least-privilege thinking.
- Handle customer data carefully in support tools and AI.
- Respond appropriately to a privacy/security incident.
Key idea
Customer trust includes information security. Never trade customer privacy for convenience.
Learn
Customer information
- Names and contact details
- Orders/accounts
- Addresses
- Payment-related information
- Support history
- Authentication/account-recovery information
- Other information the client treats as confidential
Learn
Safer practices, and Philippine context
- Use individual or delegated access when available.
- Use MFA and approved password practices.
- Access only what you need.
- Do not copy data into unapproved tools.
- Do not paste customer data into AI unless the client has approved that workflow.
- Verify recipients.
- Report suspected incidents promptly.
Customer information handling should be consistent with applicable Philippine privacy requirements, including the Data Privacy Act of 2012 (RA 10173) and relevant National Privacy Commission guidance. This course is educational, not legal advice.
Practice
Three quick situations
Practice → Decide
Partial verification
A customer calls to check their account, but can only provide their name and order number — not the full verification details your policy requires.
What should you do?
Apply
Work sample: Security Checklist
Mark Yes or No for each item as it genuinely applies to how you'd work, and add a short note.
💾 Save your work now. Copy this checklist into a Google Doc — that's part of your starter portfolio.
Preview / export
✓ Lesson 12 Processed
Nice work.
You've practiced choosing the safer option even when it's less convenient — and reporting a mistake honestly instead of hiding it.