Is personally identifiable information considered confidential?

Like any form of data, not all PII is equal. PII should be evaluated by determining its PII confidentiality impact level. PII confidentiality impact levels range from low, moderate or high to indicate the potential harm that could result to an individual or organization if the data was accessed, used or disclosed.

Can PII be publicly available?

PII does not include publicly available information that is lawfully available from federal, state, or local governmental records. PII is linked to specific individuals through direct and indirect identifiers.

What is a PII violation?

A PII breach is defined as “a loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access or any similar term referring to situations where persons other than authorized users and for other than authorized purpose have access or potential access to PII, whether physical or …

Does PII need to be protected?

DHS employees, contractors, consultants, and detailees are required by law to properly collect, access, use, share, and dispose of PII in order to protect the privacy of individuals.

What are considered personally identifiable information?

“(1) any information that can be used to distinguish or trace an individual’s identity, such as name, social security number, date and place of birth, mother’s maiden name, or biometric records; and (2) any other information that is linked or linkable to an individual, such as medical, educational, financial, and …

What laws protect personal identifiable information?

Section 5 of the Federal Trade Commission Act (FTC Act) prohibits unfair or deceptive practices and is the primary federal law protecting American PII.

What is considered to be personally identifiable information?

Further, PII is defined as information: (i) that directly identifies an individual (e.g., name, address, social security number or other identifying number or code, telephone number, email address, etc.) or (ii) by which an agency intends to identify specific individuals in conjunction with other data elements, i.e..

Is PII a security clearance?

Examples of High Risk PII include, Social Security Numbers (SSNs), biometric records (e.g., fingerprints, DNA, etc.), health and medical information, financial information (e.g., credit card numbers, credit reports, bank account numbers, etc.), and security information (e.g., security clearance information).

Are Names personal information?

Like an address, a name by itself is not personal information. A name is personal information if it appears with other personal information relating to the individual or where the disclosure of the name would reveal other personal information about the individual.