17.07.2015 Views

Download eBook (PDF) - Red Gate Software

Download eBook (PDF) - Red Gate Software

Download eBook (PDF) - Red Gate Software

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

1 – Understanding Sensitive DataThe three most common terms used to describe this information are:• Personal data• Identifiable data• Sensitive dataPersonal DataThe term 'personal data' is very broad in scope. It can apply to any data thatpertains to an individual, and does not necessarily reflect its level of sensitivity.Examples of personal data are an individual's hair color, musical preferences,criminal history, cell phone number, and the high school they attended.According to the United Kingdom's Data Protection Act of 1998, personal datais defined as:"... data which relates to a living individual who can be identified – a) fromthose data, or b) from those data and other information which is in thepossession of, or is likely to come in the possession of, the data controller."Depending upon the definitions that are used in the regulations, standards andpolicies that are being considered, data that may otherwise be considered a lowsensitivity risk could be escalated.Identifiable DataIdentifiable data is a more specific term than personal data. It appliesspecifically to information that uniquely defines an individual. For example,my personal data may indicate that I am a fan of the Beatles; but there aremillions of other people who share that interest. My federal identificationnumber, however, is assigned only to me and through this unique number myidentity can be verified.In a memorandum to the Executive Departments and Agencies of the UnitedStates Federal Government, from the White House, the definition ofidentifiable data is:"... Information which can be used to distinguish or trace an individual'sidentity, such as their name, social security number, biometric records, etc.Alone, or when combined with other personal or identifying informationwhich is linked or linkable to a specific individual such as date and placeof birth, mother's maiden name, etc."Data that is defined as identifiable requires an elevated effort in regard to itsprotection, and the prevention of improper disclosure.20

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!