Prev | Current Page 81 | Next

Harold F. Tipton and Micki Krause

"Information Security Management Handbook, Sixth Edition, Volume 2"

1 (continued)
Personal Information Item
L
aw or Regulation
HIPAA
COPPA
SB 1386
GLBA
EU Directive
Privacy Act
of 1974
Drivers
FOIA
PIPEDA
Misc.
Income
X
X
X
X
Payment histor
y
X
X
X
Loan or deposit balances
X
X
X
Credit card purchases
X
X
X
Criminal charges,
convictions, and court
records
XX
X
X
Military history
X
X
X
Credit reports and credit
scores
XX
X
Existence of customer
relationship
Financial transaction
information
XX
X
Merchandise and product
order history
Xb
XX
Service subscription history
X
Fraud alerts
X
X
X
???Black box??? data
X
Video programming activity
information
X
Voting history
X
X
X
Conversations (recorded or
overheard)
XX
Xb
X
Planning for a Privacy Breach  37
Descriptive listings of
consumers
XX
Education records
XXX
Personnel ?¬? les
XX
Often, combinations of more than one piece of information create PII. The following, typically when combined with an element from the
above list, are also considered PII. Additionally, these are often considered ???sensitive,??? ???protected,??? or ???con?¬? dential??? information.
Racial or ethnic origin
Political opinions
Religious or philosophical beliefs
Trade-union membership
Health or sexual activity information
Marital status
Security code
Access code
Password
a
Does not include the name, title, business address, or telephone number of an employee of an organization.
b
Although this law does not explicitly list this item, it is possible that using this item could be considered a violation of the law because the law
is written in such a way that it is vague or leaves things open to interpretation.


Pages:
69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93