Privacy Research
Sensitive-data minimization in call notes
A source-corpus review and audit design for testing whether call notes retain only the information needed for a handoff.
Finding and scope
Authoritative privacy and security guidance consistently supports collecting and retaining information for a defined purpose, restricting access, and disposing of data safely. The sources do not provide one universal list of acceptable call-note fields. This review creates an audit design and does not inspect private calls or claim compliance.
Evidence base
The NIST Privacy Framework organizes privacy-risk activity across identification, governance, control, communication, and protection. The FTC data-security guidance advises businesses to take stock, scale down, secure, dispose, and plan. CISA data-protection guidance describes safeguarding sensitive data. The HHS minimum-necessary guidance applies within HIPAA's scope; it is informative for scoping but must not be generalized to every business.
Proposed method
Define each call queue's purpose, required fields, prohibited free-text categories, access group, and retention rule before review. Draw a reproducible sample and have trained reviewers code whether every field is required, optional but relevant, unnecessary, or unable to assess. Separately flag credentials, payment data, health details, government identifiers, children's data, and unstructured copies of documents.
Report notes reviewed, fields reviewed, unnecessary-field prevalence, records with high-risk content, reviewer agreement, missingness, and remediation status. Do not reproduce sensitive examples in the report; use synthetic patterns or redacted categories.
Decision boundaries
An assistant should use approved fields, summarize only what the next owner needs, and route uncertain sensitive material to a privacy owner. It must not collect “just in case,” paste full credentials, or decide retention and disclosure rules. Authorized privacy, security, legal, and operational owners set the policy.
Limitations
Reviewers may disagree about necessity, and a brief note can still be harmful or inaccurate. The audit does not test access enforcement, downstream exports, deletion, legal bases, consent, or caller outcomes unless those are separately measured. Requirements vary by jurisdiction and industry.
Sources
1. NIST Privacy Framework 2. FTC, Data Security 3. CISA Data Protection 4. HHS Minimum Necessary Requirement