Minimum data
Share only what is required for the current step.

Safe communication starts with channel verification, minimal personal data and an understanding of what information is actually needed at each stage.
The best way to protect personal data is not to send more than necessary. Before sending, ask whether the information is needed for this exact step, whether the recipient is verified, whether a safer channel exists and what would happen if the file reached the wrong person. This short pause prevents more problems than trying to recall a document after it has already been sent. Be particularly careful with identity scans, medical information, other people’s contacts, location and files containing service-related material. Initial recruiting contact normally does not require a full set of sensitive information.
Send only the amount of data required for a reply or a specific procedure. If a year of birth is enough, a full document may not be needed; if one page is required, do not automatically send the entire file. Check website addresses, phone numbers or accounts, and confirm important requests through another official channel when necessary. Be cautious with pressure that discourages verification—fraud often relies on urgency such as “immediately,” “you will lose the opportunity” or “do not tell anyone.” A legitimate process should allow a clear explanation of why data is needed and who will receive it.
A file can contain more information than is visible on screen. A photo may store time, device information and coordinates; a document may contain author details, editing history or hidden comments. Before transferring sensitive material, inspect file properties, create a safe copy without unnecessary metadata when appropriate and make sure no unrelated information appears in the image. Do not publish exact location, routes or information about protected sites. Separate details that appear harmless can become risky when combined, so digital hygiene includes checking both the message and what is embedded inside its files.
Do not rush to reply or open attachments from an unknown source. Save the request or take a screenshot without forwarding sensitive data, verify the contact through the official website and reach a confirmed representative separately. If information has already been sent to the wrong recipient, report the incident and change anything that can be compromised, such as a password accidentally included in a message. Do not hide a mistake out of embarrassment; early action often reduces the consequences. It is better to verify a suspicious request twice than to send information once and discover it cannot be recovered.
Before active correspondence, check the basic security of your own accounts: unique passwords, two-factor authentication, current recovery contacts, device updates and screen locking. Reusing one password across many services means a compromise in one place can expose others. Recruiting communication can contain personal information, so account security is part of overall digital hygiene. Never share verification codes even with someone claiming to be an official representative; those codes are intended only for the account owner.
Name, role, channel and purpose should be clear.
Remove unnecessary pages, metadata and hidden information.
Avoid precise location unless the need is verified.
Call back through an official contact and verify the request.
Share only what is required for the current step.
Use contacts from the official website and confirm the recipient.
Updates, screen lock, unique password and access control.
The website form asks only for information needed to handle and answer the inquiry.