4 ms·
Name and email are usually considered PII in most of the compliance world, no?
by ironchef 8y ago
Name and email are usually considered PII in most of the compliance world, no?
- jamiepenney 8y agoThey are for the purposes of the GDPR.
- skj 8y ago"personal identifying information"... Yeah I'd say name and email qualify!
- gumby 8y agoDoes it apply if they are business contacts (business address/phone number)? After all your company-issued phone isn't personal to you -- it identifies a role ("the purchasing manager for foobartronix") and if you leave that number will reach someone else. I don't know how the "compliance world" treats, that but I bet it's a loophole many many people are trying to squeeze through. (I do actually consider it personal to you. And I am a fan of what GDPR is trying to accomplish, in principle, but it's clear the law doesn't really work yet).
- cosmie 8y agoThat's a really important thing to note. Consumer protection laws don't generally stretch to business contexts. And that's true in a lot of areas - from banking regulations to federal do not call laws. Many B2B marketing companies exist in that gray area, with dubious chains of opt in guarantees that shift liability around in case it comes to it. But it never comes to it, because there just isn't the same level of freely accessible recourse channels available for B2B-oriented concerns.
- kristianc 8y agoGDPR has a broader definition of PII than is used in the US, and includes any data that can potentially be used to identify an individual (even IP address), so it’s almost certain that it is within scope.
- gumby 8y agoHere is the actual text of GDPR (there are many sites, hosted at .eu domains, that claim to tell you what the legislation says, but why not read the published law? (I chose English as HN is an English-language site): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32016R0679 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32... ) My read is that the text of the law doesn't apply to people acting on behalf of a corporation, in their corporate persona (but this is why I linked to the text itself and not someone else's interpretation. It's not that long). The law talks about identifying a person in their personal sphere (doesn't apply to being in your home; talks about ties to fundamental human rights, genetic and health info, etc) or things like credit approval, and many many many exceptions for "national security" an "legal" uses. It clearly does apply to what your employer knows about you! Normally I hate these kind of hair-splitting "gotcha" cases I write up below, so I feel weird typing them. But the economic value is so high and frankly some of the the use, and abuse, cases so clear, I wonder. It's still early days for GDPR so these questions are, at the moment, rhetorical. Here's an example: part (26) says, "The principles of data protection should apply to any information concerning an identified or identifiable natural person." But if I call a company the telephone receptionist will answer and I will know I can reach them by calling that number. If they have three I know I can reach the one I want to by calling repeatedly. Yet you don't want to prevent publication of company phone numbers (and what about suppressing them until the receptionist leaves -- that leaks personal info too). (the section is actually about pseudonymisation BTW). Likewise per your example of IP addresses (in 30) If a company uses NAT then the company's IP address does not identify any single person, though it could be presumed to identify a particular subset. (adding IP address to other info could ID one person, and that is covered in 30)