Katana VentraIP

Personal data

Personal data, also known as personal information or personally identifiable information (PII),[1][2][3] is any information related to an identifiable person.

The abbreviation PII is widely accepted in the United States, but the phrase it abbreviates has four common variants based on personal or personally, and identifiable or identifying. Not all are equivalent, and for legal purposes the effective definitions vary depending on the jurisdiction and the purposes for which the term is being used.[a] Under European Union and United Kingdom data protection regimes, which centre primarily on the General Data Protection Regulation (GDPR),[4] the term "personal data" is significantly broader, and determines the scope of the regulatory regime.[5]


National Institute of Standards and Technology Special Publication 800-122[6] defines personally identifiable information as "any information about an individual maintained by an agency, including (1) any information that can be used to distinguish or trace an individual's identity, such as name, social security number, date and place of birth, mother's maiden name, or biometric records; and (2) any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information." For instance, a user's IP address is not classed as PII on its own, but is classified as a linked PII.[7]


Personal data is defined under the GDPR as "any information which [is] related to an identified or identifiable natural person".[8][6] The IP address of an Internet subscriber may be classed as personal data.[9]


The concept of PII has become prevalent as information technology and the Internet have made it easier to collect PII leading to a profitable market in collecting and reselling PII. PII can also be exploited by criminals to stalk or steal the identity of a person, or to aid in the planning of criminal acts. As a response to these threats, many website privacy policies specifically address the gathering of PII,[10] and lawmakers such as the European Parliament have enacted a series of legislation such as the GDPR to limit the distribution and accessibility of PII.[11]


Important confusion arises around whether PII means information which is identifiable (that is, can be associated with a person) or identifying (that is, associated uniquely with a person, such that the PII identifies them). In prescriptive data privacy regimes such as the US federal Health Insurance Portability and Accountability Act (HIPAA), PII items have been specifically defined. In broader data protection regimes such as the GDPR, personal data is defined in a non-prescriptive principles-based way. Information that might not count as PII under HIPAA can be personal data for the purposes of GDPR. For this reason, "PII" is typically deprecated internationally.

Laws and standards[edit]

Australia[edit]

In Australia, the Privacy Act 1988 deals with the protection of individual privacy, using the OECD Privacy Principles from the 1980s to set up a broad, principles-based regulatory model (unlike in the US, where coverage is generally not based on broad principles but on specific technologies, business practices or data items). Section 6 has the relevant definition.[22] The critical detail is that the definition of 'personal information' also applies to where the individual can be indirectly identified:

Wearing masks, sunglasses, or clothing to obscure or completely hide distinguishing features, such as , skin, and hair colour, facial features, and personal marks such as tattoos, birthmarks, moles and scars.

eye

Wearing gloves to conceal , which themselves are PII. However, gloves can also leave prints that are just as unique as human fingerprints. After collecting glove prints, law enforcement can then match them to gloves that they have collected as evidence.[39] In many jurisdictions the act of wearing gloves itself while committing a crime can be prosecuted as an inchoate offense.[40]

fingerprints

Avoiding writing anything in their own .[41]

handwriting

Masking their internet presence with methods such as using a to appear to be connecting from an IP address unassociated with oneself.

proxy server

In forensics, particularly the identification and prosecution of criminals, personally identifiable information is critical in establishing evidence in criminal procedure. Criminals may go to great trouble to avoid leaving any PII, such as by:

A legal analysis of the new European regulatory framework about data privacy

Six things you need to know about the new EU privacy framework

Personal and professional information management

– J Cromack

Power to the People! Giving Citizens their Personal Data Rights Back

Rethinking Personal Data New Lens Report – World Economic Forum

Why Consent is Different to Marketing Preferences – K Dewar