Covers best practices including using a privacy notification when personal information is collected; limiting access to personal information among staff; data residency; staff security and confidentiality agreements; and keeping a data retention schedule.