Cyber Security Awareness 002: Understanding PII (Personally Identifiable Information)
PII (Personally Identifiable Information)
What is PII and what should I be aware of?
In the EU the GDPR (General Data Protection Regulation) law was formed to make businesses and organisations accountable and give individuals more control and rights over their personal data.
In most other countries privacy laws about digital data and PII fall back to updates to traditional privacy laws.
The loose definition of PII in Australia is:
An example of some PII relating to Cyber Security is:
You can find regulatory details and resources in Australia through:
- Federal Register of Legislation
- At the time of writing this, the current Act In force (latest version) is C2021C00452
- OAIC (Office of the Australian Information Commissioner) - What is Personal Information?
- ACCC (Australian Competition and Consumer Commission) - Be safe, be alert online
- Business - Protect your customer's information
You should be aware of where the risks lie within your company
Here's a short list to get you started:
- What if any training is provided on PII to new and existing staff?
- Where and how is employee information stored?
- What Databases exist or could possibly exist holding PII and who manages them
- Any documentation left in a public area (such as reception and meeting rooms)
- What is your archiving and retention process for PII
- What is your Privacy Policy and how do you inform everyone about how you handle their information?
Comments
Post a Comment