Get in touch with us today to find out how can we help you.
The security of user data is of high importance, and that importance only grew with the implementation of the EUโs General Data Protection Regulation (GDPR). These sweeping new regulations went into effect on May 25, 2018. They are European Union regulations, but they have sweeping effects since they apply to any business that stores personal information of any EU citizen.
Itโs important to comply with GDPR. The first step, though, is to understand what exactly GDPR requires for your business.
PII Under GDPR
The short answer to the question of what PII is under GDPR is that itโs not a thing.ย Personally, identifiable informationย is an American term. The rough European equivalent isย personal data. Itโs important to note, though, that the two are not identical. The European standards are more restrictive, and the European category (personal data) is, therefore, more inclusive.
Hereโs the bottom line: donโt assume that if youโre PII compliant that youโre automatically GDPR compliant. You need to do more for the latter.
Defining Terms
If youโre asking the question โwhat is PII under GDPR?โ thereโs a good chance you know some of the lingo already, but itโs worth reviewing.
This term refers to any number of pieces of information that a company might store that can be used to identify individuals. Bad actors who accumulate enough PII on an individual may be able to compromise the individualโs accounts or even steal the individualโs identity. Examples of PII include (but arenโt limited to) driverโs license numbers, social security numbers, full names, physical addresses, and credit card numbers.
Remember, this is an American term, not a global one.
Non-PII is whatโs left thatโs not PII, in the American way of viewing things. This is the kind of information that can be used in aggregate forms. Itโs useful data, but it canโt be used to identify individuals on its own. Examples include IP addresses, device IDs, and cookies left behind on devices while browsing the web.
Personal Data
Personal data is the EU equivalent of PII. Itโs the information that businesses store on customers that could be used to identify those customers. The important difference here is the breadth of the definition.
GDPR concludes that even non-PII can be personal data. Cookies and IP addresses, for example, can be used in conjunction with PII to help reconstruct a personโs identity. For this reason, even these forms of information are considered personal data and are protected under GDPR.
The ruling that even cookies can be considered personal data is why youโve started seeing cookie warning messages all over the internet. Those companies are seeking to comply with GDPR by receiving permission from all visitors to use cookies.
Given the changing landscape of privacy regulations, businesses must adapt and stay compliant. Here are a few best practices for complying with GDPR.
Survey What Data You Collect
The first step toward compliance is to know what your business is collecting. Conduct a comprehensive survey of the data that you collect and store through your site.
Keep Only What You Need
Second, ask the hard questions about what personal data your business truly needs. If itโs not providing real value, dump it.
Get Permission to Keep It
Whatever you decide is essential, ask permission to keep it. Thatโs what the cookie notices are doing, and you need to do the same.
Data privacy regulations are complex. You might not want to go it alone. If not, weโre here to help. Contact us today!
ICS is a Texas-based 40-year-old technology company specializing in Managed IT, VoIP, Video Conferencing and Video Surveillance solutions for US and International businesses. ICS has over 4000 regional installations and specializes in multi-site businesses between 25 and 2500 employees. ICS’s customers enjoy the experience of ICS’s Total Care program which provides clients flat fee services with obsolescence and growth protection. Whether a customer elects to deploy their IT, Video Conferencing or VoIP in the cloud or on the customer’s premise, ICS can provide a full turn-key solution for our clients under one flat monthly fee.