01
Inventory information and minimize collection
The FTC emphasizes knowing what information a business has and keeping only what it needs. Begin with the project purpose, not with a request for every available file.
U.S. federal orientation
| Question | Freelancer action | Client action |
|---|---|---|
| What is needed? | Request the minimum fields, files, examples, or system access required for the agreed work. | Remove unrelated customer, employee, financial, health, credential, or confidential data before sharing. |
| Why is it needed? | Tie each category to a deliverable, test, decision, or support obligation. | Confirm the purpose and reject convenience-only collection. |
| Where will it go? | Name approved devices, services, folders, subcontractors, and AI boundaries. | Approve the channel and verify contractual or regulatory restrictions. |
| How long is it needed? | Propose a review, return, deletion, or retention point. | Identify legal, operational, dispute, or records reasons that control disposition. |
02
Secure information in transit and storage
Email and casual messages may be convenient but inappropriate for credentials, regulated data, large confidential collections, or sensitive payment and identity records.
General practice
- Agree which service handles files, formal decisions, access invitations, secrets, backups, and incident notices.
- Use encryption and secure transfer appropriate to the sensitivity and applicable obligations.
- Restrict folders and links to named people, disable unnecessary public access, and set expiration where supported.
- Keep work devices and software updated, protected, and separated from untrusted users or applications.
- Back up essential project and business records and test that authorized recovery works.
- Verify unusual file, access, or payment requests through a second known channel before acting.
03
Use individual accounts and least privilege
Give each person only the access needed for the current work and only for as long as needed. A shared password hides accountability and makes close-out harder.
U.S. federal orientation
- Create named accounts instead of sharing an owner's or employee's login where the system permits.
- Use a secure invitation or secret-sharing method; never paste passwords, recovery codes, private keys, or one-time codes into ordinary project or AI messages.
- Require multi-factor authentication where available, especially for email, administrative, financial, source-code, hosting, and customer systems.
- Choose the lowest role that supports the task and separate production, billing, identity, and security administration where practical.
- Maintain an access record with system, person, role, approval, date granted, change, and removal confirmation.
04
Do not supply client information to AI by default
Permission to use information for a project does not automatically authorize supplying it to a separate AI provider or using it for another purpose.
General practice
- Check the agreement, confidentiality terms, client policies, privacy requirements, professional duties, and tool settings before using any AI service.
- Ask for client authorization when the intended AI use is not already clearly permitted and necessary.
- Prefer a fictional example, abstracted structure, or minimal redacted excerpt over a full document or dataset.
- Remove names, contact details, identifiers, credentials, account data, customer records, private code, and unrelated confidential context.
- Review output for inaccurate disclosure, hidden sensitive detail, unsafe instructions, and material that should not enter the project record.
Understand Lucy's specific boundary before entering project material.
- Privacy →Review the site's current description of information handling and limitations.
- How Lucy works →See the request flow, appropriate uses, redaction guidance, and human decision boundary.
05
Agree retention, deletion, return, and handoff
Do not keep every copy forever or promise immediate destruction without checking legal, contract, backup, dispute, insurance, and operational needs.
General practice
| Decision | Questions to resolve | Close-out evidence |
|---|---|---|
| Return | Which originals, exports, keys, repositories, accounts, and physical items return to the client? | Itemized transfer and receipt confirmation. |
| Client ownership | Which accounts, domains, subscriptions, files, and licenses must be in the client's control? | Owner and administrator verification. |
| Retention | Which records remain, for what documented purpose, with what protection and review point? | Retention category and next review. |
| Deletion | Which working copies, downloads, temporary files, backups, devices, and vendor copies can be securely removed? | Deletion scope, method, exceptions, and confirmation. |
| Access removal | Which user, token, key, device, integration, and recovery route must be removed or rotated? | Access checklist and client verification. |
06
Know how to contain and escalate an information incident
A lost device, mistaken recipient, exposed link, reused password, malware alert, compromised vendor, or unauthorized AI upload may require fast containment and qualified assessment.
State and local follow-up
- Stop ongoing exposure when safe: revoke links or sessions, disable affected access, isolate devices, rotate secrets, and preserve evidence.
- Notify the named client and internal incident contact using the agreed route; do not conceal, speculate publicly, or make unsupported assurances.
- Record what happened, information and systems involved, people affected, timing, containment actions, and unresolved questions.
- Check contractual notice, cyber-insurance, legal, regulatory, professional, law-enforcement, and affected-person obligations promptly with qualified help.
- Recover from trusted backups or clean systems, validate the fix, monitor for recurrence, and update access and process controls.
Source register
Official starting points for this guide
Reviewed September 22, 2026. These are federal starting points, not a substitute for state, local, profession-specific, contract, or current-year review.
- FTC: Cybersecurity for small business ↗U.S. federal. Supports data protection, multi-factor authentication, vendor access, incident response and backups.
- FTC: Start with Security ↗U.S. federal. Supports data minimization, need-to-know access, secure lifecycle, retention and disposal.
Keep going
Connect administration to the actual project
Freelancer pathway
Build a clear freelance process
Connect business administration with service definition, discovery, agreements, delivery, invoicing, and close-out.
Client pathway
Prepare and manage a freelance hire
Connect vendor administration with a usable brief, fair selection, project management, acceptance, and handoff.
Client administration
Hire and onboard freelancers
Build classification, tax-document, payment, records, access, and offboarding checks into the client process.
Project close-out
Use the final delivery checklist
Confirm deliverables, ownership, credentials, documentation, approval, payment, and access removal.