What data will you be collecting?
How will you be storing the data?
Who will have access to the data?
Will you be using SSL at all points where data is exchanged?
Is the server itself locked down fully? ie. no non-essential services running, ports open |