<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Personally Identifiable Information Archives - Zasio</title>
	<atom:link href="https://zasio.com/tag/personally-identifiable-information/feed/" rel="self" type="application/rss+xml" />
	<link>https://zasio.com/tag/personally-identifiable-information/</link>
	<description>Digital Records Management Software</description>
	<lastBuildDate>Tue, 17 Oct 2023 21:37:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://zasio.com/wp-content/uploads/2023/05/cropped-zasiopurplefavicon-32x32.png</url>
	<title>Personally Identifiable Information Archives - Zasio</title>
	<link>https://zasio.com/tag/personally-identifiable-information/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Saved $$$, Increased Efficiency, Reduced Risk? Welcome to Effective RIM!</title>
		<link>https://zasio.com/saved-increased-efficiency-reduced-risk-welcome-to-effective-rim/</link>
					<comments>https://zasio.com/saved-increased-efficiency-reduced-risk-welcome-to-effective-rim/#respond</comments>
		
		<dc:creator><![CDATA[Zasio]]></dc:creator>
		<pubDate>Mon, 09 Jul 2018 21:07:54 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[By Rick Surber]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[disposition]]></category>
		<category><![CDATA[email management]]></category>
		<category><![CDATA[legal hold]]></category>
		<category><![CDATA[Personally Identifiable Information]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[records and information management]]></category>
		<category><![CDATA[records retention schedules]]></category>
		<category><![CDATA[RIM]]></category>
		<category><![CDATA[RRS]]></category>
		<guid isPermaLink="false">https://wordpress-140425-3498808.cloudwaysapps.com/?p=890</guid>

					<description><![CDATA[<p>The post <a href="https://zasio.com/saved-increased-efficiency-reduced-risk-welcome-to-effective-rim/" data-wpel-link="internal">Saved $$$, Increased Efficiency, Reduced Risk? Welcome to Effective RIM!</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_0  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Many Records and Information Management (RIM) professionals hear the question, “Why is RIM necessary?” My short answer is that effective RIM saves your company money, makes it more efficient, and reduces its risk. I want to expand on that answer by listing some of the ways a good RIM program can work for you.</p>
<p><strong>Disposition of Records</strong></p>
<p>So why not just keep everything?  One reason is for certain types of records, disposition is required by law. For example, in some locations, it’s mandatory to dispose of Personally Identifiable Information after a short period. Also, disposition of records reduces the quantity of information to search when looking for records. Less information translates into increased retrieval efficiency for employees. It also reduces the risk that excessive billable hours will be needed to identify relevant information for discovery requests. Both are examples of how managing the growth of information reduces risk and increases efficiency.</p>
<p><strong>Records Retention Schedules</strong></p>
<p>A foundation for a good RIM Program is a Records Retention Schedule (RRS). When properly constructed and implemented, they allow for the reasonable disposition of records. Otherwise, regulators and courts might criticize the intent behind records disposition activities. To be reasonable, disposition should be based on business needs, legal requirements, and common practice.</p>
<p><strong>Legal Requirements</strong></p>
<p>RIM programs promote compliance with legal requirements. How? They research and analyze legal requirements to ensure proper retention, handling, and disposition of records. Proper retention of records prevents sanctions and other penalties for non-compliance. Sanctions for improper RIM can be significant, reaching up to seven-figures for certain offenses.</p>
<p><strong>Legal Holds and RIM Policies</strong></p>
<p>Along with the RRS, it’s necessary to create a legal hold policy. The hold delays normal disposition for records involved in pending or anticipated litigation. Also, rolling-out the RRS requires creating and revising supporting policies and procedures. Once drafted, training is necessary to educate current and future employees about the policies. It’s also necessary to conduct audits to ensure compliance with the policies.</p>
<p><strong>Disposition Days</strong></p>
<p>One way many companies promote compliance is to implement “disposition days.” These are days dedicated to organizing and disposing of records and other information. The RRS guides disposition and policies exclude records that are subject to legal holds.</p>
<p><strong>Email Management</strong></p>
<p>One common source of growth in records and information is email. However, email itself is not a record; it’s a tool used to transmit records. Avoid using it as a storage system, so it doesn’t become a dumping ground. Policies, procedures, and guidelines will help employees properly file records from email. Retain routine email short term unless needed for business reasons.</p>
<p><strong>Business Continuity</strong></p>
<p>RIM programs help reduce risks caused by disasters. They do this by planning to ensure continued operation if disaster strikes. Vital records needed for continued operation should be identified. Then, steps are taken to protect that information against the risks for potential disaster types.</p>
<p>Remember, Zasio is here to help with your RIM needs. Contact our <a href="https://www.zasio.com/about-us/contact-us/" data-wpel-link="internal">Consulting department</a> today for help kicking off or refreshing you RIM program.</p>
<p><em>Disclaimer: The purpose of this post is to provide general education on Information Governance topics. The statements are informational only and do not constitute legal advice. If you have specific questions regarding the application of the law to your business activities, you should seek the advice of your legal counsel.</em></div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row et_pb_row_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_1  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_team_member et_pb_team_member_0 clearfix  et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_team_member_image et-waypoint et_pb_animation_off"><img decoding="async" width="96" height="96" src="https://zasio.com/wp-content/uploads/2022/08/Rick-01-96x96-1.jpg" alt="Author: Rick Surber, CRM, IGP" class="wp-image-1934" /></div>
				<div class="et_pb_team_member_description">
					<h4 class="et_pb_module_header">Author: Rick Surber, CRM, IGP</h4>
					<p class="et_pb_member_position">Senior Analyst / Licensed Attorney</p>
					
					
				</div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
<p><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fzasio.com%2Fsaved-increased-efficiency-reduced-risk-welcome-to-effective-rim%2F&amp;linkname=Saved%20%24%24%24%2C%20Increased%20Efficiency%2C%20Reduced%20Risk%3F%20Welcome%20to%20Effective%20RIM%21" title="Facebook" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_x" href="https://www.addtoany.com/add_to/x?linkurl=https%3A%2F%2Fzasio.com%2Fsaved-increased-efficiency-reduced-risk-welcome-to-effective-rim%2F&amp;linkname=Saved%20%24%24%24%2C%20Increased%20Efficiency%2C%20Reduced%20Risk%3F%20Welcome%20to%20Effective%20RIM%21" title="X" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fzasio.com%2Fsaved-increased-efficiency-reduced-risk-welcome-to-effective-rim%2F&amp;linkname=Saved%20%24%24%24%2C%20Increased%20Efficiency%2C%20Reduced%20Risk%3F%20Welcome%20to%20Effective%20RIM%21" title="LinkedIn" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fzasio.com%2Fsaved-increased-efficiency-reduced-risk-welcome-to-effective-rim%2F&#038;title=Saved%20%24%24%24%2C%20Increased%20Efficiency%2C%20Reduced%20Risk%3F%20Welcome%20to%20Effective%20RIM%21" data-a2a-url="https://zasio.com/saved-increased-efficiency-reduced-risk-welcome-to-effective-rim/" data-a2a-title="Saved $$$, Increased Efficiency, Reduced Risk? Welcome to Effective RIM!" data-wpel-link="external" rel="external noopener noreferrer"></a></p><p>The post <a href="https://zasio.com/saved-increased-efficiency-reduced-risk-welcome-to-effective-rim/" data-wpel-link="internal">Saved $$$, Increased Efficiency, Reduced Risk? Welcome to Effective RIM!</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zasio.com/saved-increased-efficiency-reduced-risk-welcome-to-effective-rim/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>U.S. Employer in Class Action Lawsuit Over Employee Privacy Recordkeeping Violations</title>
		<link>https://zasio.com/u-s-employer-class-action-lawsuit-employee-privacy-recordkeeping-violations/</link>
					<comments>https://zasio.com/u-s-employer-class-action-lawsuit-employee-privacy-recordkeeping-violations/#respond</comments>
		
		<dc:creator><![CDATA[Zasio]]></dc:creator>
		<pubDate>Wed, 15 Nov 2017 22:03:08 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[biometric]]></category>
		<category><![CDATA[class action]]></category>
		<category><![CDATA[fingerprints]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[information management]]></category>
		<category><![CDATA[iris scans]]></category>
		<category><![CDATA[Jennifer Chadband]]></category>
		<category><![CDATA[law suit]]></category>
		<category><![CDATA[peacock foods]]></category>
		<category><![CDATA[Personally Identifiable Information]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[records management]]></category>
		<category><![CDATA[retention schedule]]></category>
		<guid isPermaLink="false">https://wordpress-140425-3498808.cloudwaysapps.com/?p=971</guid>

					<description><![CDATA[<p>The post <a href="https://zasio.com/u-s-employer-class-action-lawsuit-employee-privacy-recordkeeping-violations/" data-wpel-link="internal">U.S. Employer in Class Action Lawsuit Over Employee Privacy Recordkeeping Violations</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_1 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_2">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_2  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Employees from Peacock Foods recently filed a class action suit against their employer. The group claims the company violated the Illinois Biometric Identifier Privacy Act. The employees say the company collected their fingerprints when they clocked in and out of work. They also claim the company didn’t follow the mandates meant to protect this information.</p>
<p>This Act requires private entities who collect biometric identifiers, such as iris scans, fingerprints, and even photos to create a written retention schedule. This schedule must be available to the public, specify why this data is collected, and include plans to destroy the records as soon as the retention period ends. Before they collect data, the company must have a written release from an individual.</p>
<p>So, how long can the company keep the records? Just long enough to use them for the purpose for which they were collected.</p>
<p>This group of employees said Peacock Foods violated all three areas of this act. The employees claim they didn’t know why the company collected their fingerprints. They also assert that they didn’t permit the company to collect and retain their fingerprint records. To add to that, they weren’t given a written notice of this policy. They also allege that they didn’t know the retention period for those records.</p>
<p><strong>Peacock Foods Lessons for Records and Information Management</strong></p>
<p>Although this lawsuit stems from a specific U.S. state law, the issue of unlawful collection of sensitive personally identifiable information (PII) is an issue that affects every company. This lawsuit and other similar suits should put all companies on notice. Stricter laws that control how companies collect and retain this category of PII are increasing across the U.S. These records are subject to even stricter standards across Europe. The European Union <a href="https://www.zasio.com/consulting-services/general-data-protection-regulation-gdpr-tracker/" data-wpel-link="internal">General Data Protection Regulation</a> (GDPR), which goes into effect May, 2018, will increase regulations on these records.</p>
<p>Records and information management professionals should consider the following steps as they deal with PII:</p>
<ol>
<li>Keep a list of the of biometric identifier records the company maintains.</li>
<li>Ensure policies, procedures, and retention schedules consider the sensitivity of PII.</li>
<li>Identify the need for PII information. Make reasons to collect PII public knowledge.</li>
<li>Adopt tailored retention periods so records aren’t kept longer than necessary;</li>
<li>Stay up-to-date on relevant privacy laws. Your company is subject to privacy laws in most U.S. and international jurisdictions.</li>
</ol>
<p>As a records and information management expert, you can prepare by staying on top of evolving privacy laws. A proactive approach is the best way to adapt to new changes. Preparation ensures that your company remains compliant and reduces risks.</p>
<p><em>Disclaimer: The purpose of this post is to provide general education on Information Governance topics. The statements are informational only and do not constitute legal advice. If you have specific questions regarding the application of the law to your business activities, you should seek the advice of your legal counsel.</em></div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row et_pb_row_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_3  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_team_member et_pb_team_member_1 clearfix  et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_team_member_image et-waypoint et_pb_animation_off"><img decoding="async" width="96" height="96" src="https://zasio.com/wp-content/uploads/2023/10/Jenn-01-96x96-1.jpg" alt="Author: Jennifer Chadband, IGP, CRM, ECMp" class="wp-image-1877" /></div>
				<div class="et_pb_team_member_description">
					<h4 class="et_pb_module_header">Author: Jennifer Chadband, IGP, CRM, ECMp</h4>
					<p class="et_pb_member_position">Senior Analyst / Licensed Attorney</p>
					
					
				</div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
<p><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fzasio.com%2Fu-s-employer-class-action-lawsuit-employee-privacy-recordkeeping-violations%2F&amp;linkname=U.S.%20Employer%20in%20Class%20Action%20Lawsuit%20Over%20Employee%20Privacy%20Recordkeeping%20Violations" title="Facebook" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_x" href="https://www.addtoany.com/add_to/x?linkurl=https%3A%2F%2Fzasio.com%2Fu-s-employer-class-action-lawsuit-employee-privacy-recordkeeping-violations%2F&amp;linkname=U.S.%20Employer%20in%20Class%20Action%20Lawsuit%20Over%20Employee%20Privacy%20Recordkeeping%20Violations" title="X" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fzasio.com%2Fu-s-employer-class-action-lawsuit-employee-privacy-recordkeeping-violations%2F&amp;linkname=U.S.%20Employer%20in%20Class%20Action%20Lawsuit%20Over%20Employee%20Privacy%20Recordkeeping%20Violations" title="LinkedIn" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fzasio.com%2Fu-s-employer-class-action-lawsuit-employee-privacy-recordkeeping-violations%2F&#038;title=U.S.%20Employer%20in%20Class%20Action%20Lawsuit%20Over%20Employee%20Privacy%20Recordkeeping%20Violations" data-a2a-url="https://zasio.com/u-s-employer-class-action-lawsuit-employee-privacy-recordkeeping-violations/" data-a2a-title="U.S. Employer in Class Action Lawsuit Over Employee Privacy Recordkeeping Violations" data-wpel-link="external" rel="external noopener noreferrer"></a></p><p>The post <a href="https://zasio.com/u-s-employer-class-action-lawsuit-employee-privacy-recordkeeping-violations/" data-wpel-link="internal">U.S. Employer in Class Action Lawsuit Over Employee Privacy Recordkeeping Violations</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zasio.com/u-s-employer-class-action-lawsuit-employee-privacy-recordkeeping-violations/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>De-identification Standards to Protect Personal Information</title>
		<link>https://zasio.com/de-identification-standards-to-protect-personal-information/</link>
					<comments>https://zasio.com/de-identification-standards-to-protect-personal-information/#respond</comments>
		
		<dc:creator><![CDATA[Zasio]]></dc:creator>
		<pubDate>Tue, 12 Sep 2017 20:24:25 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[de-identification]]></category>
		<category><![CDATA[personal information]]></category>
		<category><![CDATA[Personally Identifiable Information]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[privacy]]></category>
		<guid isPermaLink="false">https://wordpress-140425-3498808.cloudwaysapps.com/?p=995</guid>

					<description><![CDATA[<p>Individuals value their privacy. In contrast, businesses value the ability to leverage personal information to deliver quality products and services to meet the needs of their clients. The legal standards that regulate the protection of personal information help bridge the gap between these two opposing interests. This article addresses when to apply de-identification, the legal standards under specific regulations for de-identifying personal information, and the effect meeting such de-identification standards has on the use of the remaining data set. The full article can be seen at ACC‘s (Association of Corporate Counsel) Docket Magazine here. Disclaimer: The purpose of this post is to provide general education on Information Governance topics. The statements are informational only and do not constitute legal advice. If you have specific questions regarding the application of the law to your business activities, you should seek the advice of your legal counsel.</p>
<p>The post <a href="https://zasio.com/de-identification-standards-to-protect-personal-information/" data-wpel-link="internal">De-identification Standards to Protect Personal Information</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Individuals value their privacy. In contrast, businesses value the ability to leverage personal information to deliver quality products and services to meet the needs of their clients. The legal standards that regulate the protection of personal information help bridge the gap between these two opposing interests.</p>
<p>This article addresses when to apply de-identification, the legal standards under specific regulations for de-identifying personal information, and the effect meeting such <a href="https://www.zasio.com/challenges-of-meeting-de-identification-standards/" data-wpel-link="internal">de-identification standards</a> has on the use of the remaining data set.</p>
<p>The full article can be seen at <a href="http://www.acc.com/" target="_blank" rel="noopener external noreferrer" data-wpel-link="external">ACC</a>‘s (Association of Corporate Counsel) Docket Magazine <a href="http://www.accdocket.com/articles/de-identification-standards-big-data.cfm" target="_blank" rel="noopener external noreferrer" data-wpel-link="external">here</a>.</p>
<div class="post_content_holder">
<div class="post_text">
<div class="post_text_inner">
<p><em>Disclaimer: The purpose of this post is to provide general education on Information Governance topics. The statements are informational only and do not constitute legal advice. If you have specific questions regarding the application of the law to your business activities, you should seek the advice of your legal counsel.</em></p>
</div>
</div>
</div>
<p><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fzasio.com%2Fde-identification-standards-to-protect-personal-information%2F&amp;linkname=De-identification%20Standards%20to%20Protect%20Personal%20Information" title="Facebook" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_x" href="https://www.addtoany.com/add_to/x?linkurl=https%3A%2F%2Fzasio.com%2Fde-identification-standards-to-protect-personal-information%2F&amp;linkname=De-identification%20Standards%20to%20Protect%20Personal%20Information" title="X" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fzasio.com%2Fde-identification-standards-to-protect-personal-information%2F&amp;linkname=De-identification%20Standards%20to%20Protect%20Personal%20Information" title="LinkedIn" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fzasio.com%2Fde-identification-standards-to-protect-personal-information%2F&#038;title=De-identification%20Standards%20to%20Protect%20Personal%20Information" data-a2a-url="https://zasio.com/de-identification-standards-to-protect-personal-information/" data-a2a-title="De-identification Standards to Protect Personal Information" data-wpel-link="external" rel="external noopener noreferrer"></a></p><p>The post <a href="https://zasio.com/de-identification-standards-to-protect-personal-information/" data-wpel-link="internal">De-identification Standards to Protect Personal Information</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zasio.com/de-identification-standards-to-protect-personal-information/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Impact of Personal Data on Records Management</title>
		<link>https://zasio.com/the-impact-of-personal-data-on-records-management/</link>
					<comments>https://zasio.com/the-impact-of-personal-data-on-records-management/#respond</comments>
		
		<dc:creator><![CDATA[Zasio]]></dc:creator>
		<pubDate>Mon, 22 May 2017 19:08:05 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[data privacy]]></category>
		<category><![CDATA[data retention]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[harmonization]]></category>
		<category><![CDATA[metadata]]></category>
		<category><![CDATA[Personally Identifiable Information]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[record retention]]></category>
		<category><![CDATA[retention periods]]></category>
		<category><![CDATA[retention schedule]]></category>
		<guid isPermaLink="false">https://wordpress-140425-3498808.cloudwaysapps.com/?p=1024</guid>

					<description><![CDATA[<p>On May 25, 2018, the General Data Protection Regulation (GDPR) goes into effect. The GDPR harmonizes data protection and reshapes the way businesses approach data privacy. To achieve this goal, the GDPR holds businesses accountable for how they manage personal data in a digital world. In preparation, many are evaluating current practices and planning to bring their programs into compliance to avoid strict fines and penalties. However, there are challenges aligning current practices with the Data Protection Principles set out in the GDPR. For our purposes, we’ll address the principle of “data retention periods,” which requires businesses to retain personal data only as long as necessary to achieve the purpose for which it was collected. This creates tension with the competing interests of records retention programs—where legal requirements generally set the floor—with the operational needs of the business. These operational needs often eclipse retention periods with deletion practices mandated by data protection laws that set a ceiling for retaining personal data. Accordingly, it is imperative to consider both and then effectively communicate clear guidance to employees to avoid unnecessary risk and exposure. The main policy document for managing the lifecycle of records is the retention schedule, which identifies a period [&#8230;]</p>
<p>The post <a href="https://zasio.com/the-impact-of-personal-data-on-records-management/" data-wpel-link="internal">The Impact of Personal Data on Records Management</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>On May 25, 2018, the General Data Protection Regulation (GDPR) goes into effect. The GDPR harmonizes data protection and reshapes the way businesses approach data privacy. To achieve this goal, the GDPR holds businesses accountable for how they manage personal data in a digital world. In preparation, many are evaluating current practices and planning to bring their programs into compliance to avoid strict fines and penalties. However, there are challenges aligning current practices with the Data Protection Principles set out in the GDPR.</p>
<p>For our purposes, we’ll address the principle of “data retention periods,” which requires businesses to retain personal data only as long as necessary to achieve the purpose for which it was collected. This creates tension with the competing interests of records retention programs—where legal requirements generally set the floor—with the operational needs of the business. These operational needs often eclipse retention periods with deletion practices mandated by data protection laws that set a ceiling for retaining personal data. Accordingly, it is imperative to consider both and then effectively communicate clear guidance to employees to avoid unnecessary risk and exposure.</p>
<p>The main policy document for managing the lifecycle of records is the retention schedule, which identifies a period before a record is subject to disposal. Recent trends call for a “functional” schedule, whereby records with a similar purpose are grouped together and assigned a retention period. A subset of records (<em>e.g</em>., rejected job applications) or personal data within those functional groups are subject to mandated deletion practices. Consequently, unless specifically called out, end users that abide by the retention schedule may retain personal data for longer than permitted, which exposes the corporation to liability in the form of penalties, fines, and legal action.</p>
<p>To avoid this liability, we recommend the following actions:</p>
<ul>
<li><strong>Effectively Communicate</strong>. Because the retention schedule is the primary document referenced for record retention, incorporate personal data restrictions in the published schedule. To do this, identify records and personal data subject to legal requirements, such as the GDPR and jurisdiction-specific restrictions, and offer a separate retention period for impacted records. Alternatively, citations specific to personal data restriction and the records impacted by them can be addressed in a separate document. This is attractive, as data protection restrictions often contain information that relate to the management of personal data and records that aren’t in the scope of a retention schedule <em>e.g.,</em> exceptions to deletion or continued retention. However, for this approach to be effective, you must take steps to ensure there is continuity between the retention schedule and the separate data protection document.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li><strong>Identify and Train</strong>. Whether the restrictions are incorporated into the retention schedule or in a separate data protection document, train employees to read and interpret the subject documentation, as well as appropriate actions to execute their responsibilities.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li><strong>Understand Data Flow</strong>. You must understand how data flows and where information is ultimately stored, with a focus on personal data. This provides insight into the applications and systems through which personal data travels, as well as access points. Accordingly, understanding the data flow may identify a subset of employees that have access to the personal data or records that require more detailed processes, training, and communications.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li><strong>Augment Metadata</strong>. You may need to enhance information stores with additional metadata fields to capture personal data restrictions at the record level to help identify records so you don’t retain them longer than the law allows. For example, you may need to add a ‘PII’ flag to make queries for PII data within your repositories easier to obtain.</li>
</ul>
<p>&nbsp;</p>
<p>The GDPR and its impending effective date brings new awareness and urgency to businesses to assess current practices. However, these restrictions account for only part of the laws that currently exist from jurisdictions in and outside of the European Union. To avoid confusion amongst the workforce, restrictions on retaining personal data must be carefully vetted against current retention practices and associated documentation. You can identify and align the competing interests where they intersect by implementing sound strategies, some of which are noted above. Failure to proactively take these steps will lead to out-of-compliance-programs subject to severe sanctions.</p>
<p><a href="https://www.zasio.com/about-us/contact-us/" data-wpel-link="internal">Contact Zasio</a> today to see how our consulting services can help you stay complaint and minimize risk.</p>
<p>&nbsp;</p>
<p><em>Disclaimer: The purpose of this post is to provide general education on Information Governance topics. The statements are informational only and do not constitute legal advice. If you have specific questions regarding the application of the law to your business activities, you should seek the advice of your legal counsel.</em></p>
<p><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fzasio.com%2Fthe-impact-of-personal-data-on-records-management%2F&amp;linkname=The%20Impact%20of%20Personal%20Data%20on%20Records%20Management" title="Facebook" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_x" href="https://www.addtoany.com/add_to/x?linkurl=https%3A%2F%2Fzasio.com%2Fthe-impact-of-personal-data-on-records-management%2F&amp;linkname=The%20Impact%20of%20Personal%20Data%20on%20Records%20Management" title="X" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fzasio.com%2Fthe-impact-of-personal-data-on-records-management%2F&amp;linkname=The%20Impact%20of%20Personal%20Data%20on%20Records%20Management" title="LinkedIn" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fzasio.com%2Fthe-impact-of-personal-data-on-records-management%2F&#038;title=The%20Impact%20of%20Personal%20Data%20on%20Records%20Management" data-a2a-url="https://zasio.com/the-impact-of-personal-data-on-records-management/" data-a2a-title="The Impact of Personal Data on Records Management" data-wpel-link="external" rel="external noopener noreferrer"></a></p><p>The post <a href="https://zasio.com/the-impact-of-personal-data-on-records-management/" data-wpel-link="internal">The Impact of Personal Data on Records Management</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zasio.com/the-impact-of-personal-data-on-records-management/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>China Further Expands Reach of Data Localization Law to Multinationals</title>
		<link>https://zasio.com/china-further-expands-reach-of-data-localization-law-to-multinationals/</link>
					<comments>https://zasio.com/china-further-expands-reach-of-data-localization-law-to-multinationals/#respond</comments>
		
		<dc:creator><![CDATA[Zasio]]></dc:creator>
		<pubDate>Mon, 15 May 2017 19:14:58 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Cyber security]]></category>
		<category><![CDATA[Jennifer Chadband]]></category>
		<category><![CDATA[localization]]></category>
		<category><![CDATA[Measures for Security Assessment of Outbound Transmission of Personal Information and Important Data]]></category>
		<category><![CDATA[multinationals]]></category>
		<category><![CDATA[Personally Identifiable Information]]></category>
		<category><![CDATA[PII]]></category>
		<guid isPermaLink="false">https://wordpress-140425-3498808.cloudwaysapps.com/?p=1028</guid>

					<description><![CDATA[<p>The post <a href="https://zasio.com/china-further-expands-reach-of-data-localization-law-to-multinationals/" data-wpel-link="internal">China Further Expands Reach of Data Localization Law to Multinationals</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_2 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_4  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Countries are continuing to escalate restrictions on storage location and transfers of data, with China being the most recent to follow suit. China broadened its cybersecurity initiatives significantly in 2016 with the release of the Cybersecurity Law (Law). Scheduled to come into effect June 1, 2017, the Law introduced many new requirements concerning the handling of personally identifiable information (PII). Among the most controversial is the data localization mandate requiring “operators of key information structure” (CIIOs) to retain critical data and PII generated within the course of business in China. Specifically, the Law requires “personal information and other important data gathered or produced” during CIIO operations to be kept within the “mainland territory of the People’s Republic of China.” <a href="https://www.zasio.com/china-further-expands-reach-of-data-localization-law-to-multinationals/#_ftn1" name="_ftnref1" data-wpel-link="internal">[1]</a></p>
<p>The definition of a CIIO in the Law is ambiguous and described as public-facing entities that maintain “critical information infrastructure that if destroyed, losing function or leaking data might seriously endanger national security, national welfare and the people’s livelihood…” Examples of the sectors subject to this definition include businesses operating in public communications and information services, power, traffic, water, etc., which may very well implicate multinational corporations (Multinationals).</p>
<p>On April 11, 2017, the Cyberspace Administration of China released the draft Measures for Security Assessment of Outbound Transmission of Personal Information and Important Data (Draft Measures). Designed to implement the Law, the Draft Measures take a more expansive approach and extend the data localization requirements to Network Operators, in addition to CIIOs.</p>
<p>The definition of Network Operators includes, “those who own or administer a network, and to network service providers.”<a href="https://www.zasio.com/china-further-expands-reach-of-data-localization-law-to-multinationals/#_ftn2" name="_ftnref2" data-wpel-link="internal">[2]</a>  Based on this definition, the reach of the law now extends to not only network service providers, but also those who own or administer a network, which is conceivably any private company, including Multinationals.</p>
<p>Although the Draft Measures are not final, they do offer a strong indication of things to come. The language of the Law and Draft Measures appear crafted ambiguously and broadly to impose sweeping measures on a range of entities, including Multinationals. For this reason, it is important for Multinationals to stay abreast of these changes and prepare for compliance once the Law and Draft Measures are effective.</p>
<p><a href="https://www.zasio.com/about-us/contact-us/" data-wpel-link="internal">Contact Zasio</a> today to see how our consulting services can help you stay complaint and ahead of the laws evolving around the world.</p>
<p>&nbsp;</p>
<p><em>Disclaimer: The purpose of this post is to provide general education on Information Governance topics. The statements are informational only and do not constitute legal advice. If you have specific questions regarding the application of the law to your business activities, you should seek the advice of your legal counsel.</em></p>
<p>&nbsp;</p>
<p><a href="https://www.zasio.com/china-further-expands-reach-of-data-localization-law-to-multinationals/#_ftnref1" name="_ftn1" data-wpel-link="internal">[1]</a> <a href="http://www.chinalawtranslate.com/cybersecuritylaw/?lang=en" data-wpel-link="external" rel="external noopener noreferrer">http://www.chinalawtranslate.com/cybersecuritylaw/?lang=en</a></p>
<p><a href="https://www.zasio.com/china-further-expands-reach-of-data-localization-law-to-multinationals/#_ftnref2" name="_ftn2" data-wpel-link="internal">[2]</a> <a href="https://www.huntonprivacyblog.com/wp-content/uploads/sites/18/2017/04/Draft-of-Measures-on-Security-Assessments-for-Public-Comment-English-translation-c.pdf" data-wpel-link="external" rel="external noopener noreferrer">https://www.huntonprivacyblog.com/wp-content/uploads/sites/18/2017/04/Draft-of-Measures-on-Security-Assessments-for-Public-Comment-English-translation-c.pdf</a></div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row et_pb_row_5">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_5  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_team_member et_pb_team_member_2 clearfix  et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_team_member_image et-waypoint et_pb_animation_off"><img loading="lazy" decoding="async" width="96" height="96" src="https://zasio.com/wp-content/uploads/2023/10/Jenn-01-96x96-1.jpg" alt="Author: Jennifer Chadband, IGP, CRM, ECMp" class="wp-image-1877" /></div>
				<div class="et_pb_team_member_description">
					<h4 class="et_pb_module_header">Author: Jennifer Chadband, IGP, CRM, ECMp</h4>
					<p class="et_pb_member_position">Senior Analyst / Licensed Attorney</p>
					
					
				</div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
<p><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fzasio.com%2Fchina-further-expands-reach-of-data-localization-law-to-multinationals%2F&amp;linkname=China%20Further%20Expands%20Reach%20of%20Data%20Localization%20Law%20to%20Multinationals" title="Facebook" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_x" href="https://www.addtoany.com/add_to/x?linkurl=https%3A%2F%2Fzasio.com%2Fchina-further-expands-reach-of-data-localization-law-to-multinationals%2F&amp;linkname=China%20Further%20Expands%20Reach%20of%20Data%20Localization%20Law%20to%20Multinationals" title="X" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fzasio.com%2Fchina-further-expands-reach-of-data-localization-law-to-multinationals%2F&amp;linkname=China%20Further%20Expands%20Reach%20of%20Data%20Localization%20Law%20to%20Multinationals" title="LinkedIn" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fzasio.com%2Fchina-further-expands-reach-of-data-localization-law-to-multinationals%2F&#038;title=China%20Further%20Expands%20Reach%20of%20Data%20Localization%20Law%20to%20Multinationals" data-a2a-url="https://zasio.com/china-further-expands-reach-of-data-localization-law-to-multinationals/" data-a2a-title="China Further Expands Reach of Data Localization Law to Multinationals" data-wpel-link="external" rel="external noopener noreferrer"></a></p><p>The post <a href="https://zasio.com/china-further-expands-reach-of-data-localization-law-to-multinationals/" data-wpel-link="internal">China Further Expands Reach of Data Localization Law to Multinationals</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zasio.com/china-further-expands-reach-of-data-localization-law-to-multinationals/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Bringing the Cloud Down to Earth</title>
		<link>https://zasio.com/bringing-the-cloud-down-to-earth/</link>
					<comments>https://zasio.com/bringing-the-cloud-down-to-earth/#respond</comments>
		
		<dc:creator><![CDATA[Zasio]]></dc:creator>
		<pubDate>Wed, 01 Mar 2017 19:07:25 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cloud privacy]]></category>
		<category><![CDATA[cloud storage]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[CPC]]></category>
		<category><![CDATA[DPC]]></category>
		<category><![CDATA[information governance]]></category>
		<category><![CDATA[Jennifer Chadband]]></category>
		<category><![CDATA[Personally Identifiable Information]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[privacy laws]]></category>
		<guid isPermaLink="false">https://wordpress-140425-3498808.cloudwaysapps.com/?p=1057</guid>

					<description><![CDATA[<p>The post <a href="https://zasio.com/bringing-the-cloud-down-to-earth/" data-wpel-link="internal">Bringing the Cloud Down to Earth</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_3 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_6">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_6  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">As companies of all sizes begin to store data in the cloud, privacy issues have become big news. Apple co-founder Steve Wozniak commented on the cloud, saying that “the more we transfer everything onto the web, onto the cloud, the less we’re going to have control over it.”<a href="https://www.zasio.com/bringing-the-cloud-down-to-earth/#_ftn1" name="_ftnref1" data-wpel-link="internal">[1]</a> A major problem for companies is a lack of control over data. Companies often depend on service providers to secure, protect, and maintain access to critical company information. The issues companies face as they try to keep data compliant in the cloud don’t end there. Privacy laws are more common and carry stricter requirements and penalties. This means it’s vital to comply with personally identifiable information (PII) mandates, including jurisdiction-specific requirements, no matter where your information is stored.</p>
<p>In response to jurisdictional issues and confusion over inconsistent Data Privacy Security and Transfer Requirements, a group of 44 lawyers from 32 countries took action. They created an initiative titled “The Data Privacy Compliance Cloud Privacy Check” (CPC/DPC) to provide straightforward guidance.<a href="https://www.zasio.com/bringing-the-cloud-down-to-earth/#_ftn2" name="_ftnref2" data-wpel-link="internal">[2]</a>  By providing a “Cloud Privacy Check process,” the CPC/DPC helps cloud users navigate data protection obligations. The questions include:</p>
<ol>
<li>Does the transaction include any personally identifiable information?</li>
<li>Does a third party involved in the setup of the cloud process have access to personal data?</li>
<li>Does the data leave the jurisdiction of the customer?</li>
<li>Is the cloud provider using subcontractors in the setup?</li>
</ol>
<p>Questions 1 and 2 guide whether PII obligations exist. Questions 3 and 4 define the obligations to manage PII in the cloud. In addition to this handy checklist, the CPC/DPC provides comparisons of privacy requirements across 32 countries. Country-specific reports help companies understand and plan for the complexities of maintaining information across borders.</p>
<p>The nature of and increasing reliance on cloud storage presents unique challenges for information and records management. Information governance holds data—local- and cloud-based—to the same standards. It is important to maintain cloud-based information in line with company policies and all governing laws and regulations. As the CPC/DPC Checklist shows, an assessment can go a long way to ensure your business manages all information appropriately.</p>
<p><a href="https://www.zasio.com/about-us/contact-us/" data-wpel-link="internal">Contact Zasio</a> today for a privacy impact assessment to help you navigate challenges proactively. Whether your data is stored locally or in the cloud, we can help you stay compliant.</p>
<p>&nbsp;</p>
<p><em>Disclaimer: The purpose of this post is to provide general education on Information Governance topics. The statements are informational only and do not constitute legal advice. If you have specific questions regarding the application of the law to your business activities, you should seek the advice of your legal counsel.</em></p>
<p>&nbsp;</p>
<p><a href="https://www.zasio.com/bringing-the-cloud-down-to-earth/#_ftnref1" name="_ftn1" data-wpel-link="internal">[1]</a> <a href="https://www.forbes.com/sites/joemckendrick/2012/08/06/apple-co-founder-steve-wozniak-distrusts-the-cloud-is-he-right/#5d2540a86042" data-wpel-link="external" rel="external noopener noreferrer">http://www.forbes.com/sites/joemckendrick/2012/08/06/apple-co-founder-steve-wozniak-distrusts-the-cloud-is-he-right/#50c5c7b47ef8</a></p>
<p><a href="https://www.zasio.com/bringing-the-cloud-down-to-earth/#_ftnref2" name="_ftn2" data-wpel-link="internal">[2]</a> <a href="https://cloudprivacycheck.eu/" data-wpel-link="external" rel="external noopener noreferrer">https://cloudprivacycheck.eu/</a></div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row et_pb_row_7">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_7  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_team_member et_pb_team_member_3 clearfix  et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_team_member_image et-waypoint et_pb_animation_off"><img loading="lazy" decoding="async" width="96" height="96" src="https://zasio.com/wp-content/uploads/2023/10/Jenn-01-96x96-1.jpg" alt="Author: Jennifer Chadband, IGP, CRM, ECMp" class="wp-image-1877" /></div>
				<div class="et_pb_team_member_description">
					<h4 class="et_pb_module_header">Author: Jennifer Chadband, IGP, CRM, ECMp</h4>
					<p class="et_pb_member_position">Senior Analyst / Licensed Attorney</p>
					
					
				</div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
<p><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fzasio.com%2Fbringing-the-cloud-down-to-earth%2F&amp;linkname=Bringing%20the%20Cloud%20Down%20to%20Earth" title="Facebook" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_x" href="https://www.addtoany.com/add_to/x?linkurl=https%3A%2F%2Fzasio.com%2Fbringing-the-cloud-down-to-earth%2F&amp;linkname=Bringing%20the%20Cloud%20Down%20to%20Earth" title="X" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fzasio.com%2Fbringing-the-cloud-down-to-earth%2F&amp;linkname=Bringing%20the%20Cloud%20Down%20to%20Earth" title="LinkedIn" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fzasio.com%2Fbringing-the-cloud-down-to-earth%2F&#038;title=Bringing%20the%20Cloud%20Down%20to%20Earth" data-a2a-url="https://zasio.com/bringing-the-cloud-down-to-earth/" data-a2a-title="Bringing the Cloud Down to Earth" data-wpel-link="external" rel="external noopener noreferrer"></a></p><p>The post <a href="https://zasio.com/bringing-the-cloud-down-to-earth/" data-wpel-link="internal">Bringing the Cloud Down to Earth</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zasio.com/bringing-the-cloud-down-to-earth/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Identifying Personally Identifiable Information</title>
		<link>https://zasio.com/identifying-personally-identifiable-information/</link>
					<comments>https://zasio.com/identifying-personally-identifiable-information/#respond</comments>
		
		<dc:creator><![CDATA[Zasio]]></dc:creator>
		<pubDate>Mon, 31 Oct 2016 20:13:13 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Jennifer Chadband]]></category>
		<category><![CDATA[Personally Identifiable Information]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[records retention schedule]]></category>
		<category><![CDATA[RRS]]></category>
		<guid isPermaLink="false">https://wordpress-140425-3498808.cloudwaysapps.com/?p=1081</guid>

					<description><![CDATA[<p>The post <a href="https://zasio.com/identifying-personally-identifiable-information/" data-wpel-link="internal">Identifying Personally Identifiable Information</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_4 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_8">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_8  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Data breaches are an everyday occurrence that demonstrate no enterprise or individual is impervious to vulnerabilities. In 2015, there were 781 <em>known </em>data breaches in the U.S., the second highest year since the Identity Theft Resource Center began tracking them in 2005.<a href="https://www.zasio.com/identifying-personally-identifiable-information/#_ftn1" name="_ftnref1" data-wpel-link="internal">[1]</a> Between this influx of breaches and rapidly evolving and emerging privacy laws, it is no wonder enterprises are struggling to protect and effectively manage personally identifiable information (PII).</p>
<p>The sources of PII maintained by enterprises range from internal employee information to customers and vendors, and are pervasive because PII likely impacts a significant part of the enterprise’s records retention schedule (RRS). Identifying what records are subject to PII laws is fundamental to any strategy for effectively managing PII. While this task seems simple enough, making such a determination is ultimately dependent upon the jurisdiction(s) that are relevant to the PII. For enterprises that operate in various U.S. states and/or internationally, it becomes increasingly complex to reconcile requirements across different jurisdictions.</p>
<p>To provide initial guidance on identification and management of PII through an RRS, I’ve provided a few examples of U.S. privacy laws that may impact a company, followed by a checklist to help with this process.</p>
<p><strong>U.S. State Laws</strong></p>
<p>Within the U.S., there is no uniform definition for PII, but rather it is defined by various federal and state laws and agencies. On one end of the spectrum, California takes the lead with an aggressive privacy approach. In California, personal information includes an individual’s first name or initial combined with one or more other elements “when the name or data elements are not encrypted”, including social security number, driver’s license number, medical or health insurance information, along with an extensive list of other companion elements.<a href="https://www.zasio.com/identifying-personally-identifiable-information/#_ftn2" name="_ftnref2" data-wpel-link="internal">[2]</a> Several other states adopt a similar multi-factor approach but limit the definitional scope to fewer components that constitute PII when combined, thus imposing less restrictive standards.</p>
<p><strong>U.S. Federal Laws</strong></p>
<p>In contrast to the state approach, U.S. Federal laws take a broader approach in defining personal information. An example of this can be found in the Gramm-Leach-Bliley Act of 1999, which defines personally identifiable personal information as “nonpublic personal information.”<a href="https://www.zasio.com/identifying-personally-identifiable-information/#_ftn3" name="_ftnref3" data-wpel-link="internal">[3]</a> The General Services Administration, in its privacy policy applicable to contractors, defines PII at a minimum to include “information which can be used to distinguish or trace an individual’s identity, such as their name, social security number, biometric records, etc.”<a href="https://www.zasio.com/identifying-personally-identifiable-information/#_ftn4" name="_ftnref4" data-wpel-link="internal">[4]</a></p>
<p><strong>Initial Checklist</strong></p>
<p>By first understanding and identifying the various types of PII mandated per jurisdiction, records and information management professionals can confidently devise an RRS strategy during their efforts to initiate and maintain a program that effectively manages this information. An initial checklist to help with this process may include some of the following:</p>
<ul>
<li>Identify the relevant jurisdictions and regulators. For purposes of PII, this should consider not only the enterprise’s places of operation, but also the jurisdictions from which the PII is collected.</li>
</ul>
<ul>
<li>Identify privacy laws which may be applicable to the enterprise. These should include those that are broadly applicable to the enterprise’s business as well as those that are specific to its industry.</li>
</ul>
<ul>
<li>Survey and summarize the privacy laws applicable to the enterprise.</li>
</ul>
<ul>
<li>Where multiple jurisdictions are involved, consider focusing on the most stringent PII standards you identified when evaluating the RRS to facilitate a strategy that can be uniformly implemented and followed.</li>
</ul>
<ul>
<li>Identify examples and record series within the RRS that meet the criteria required by the identified PII laws. Identifying the particular records and business processes that involve PII and mapping those requirements to the schedule will be helpful for the initial and ongoing efforts.</li>
</ul>
<p><em>Disclaimer: The purpose of this post is to provide general education on Information Governance topics. The statements are informational only and do not constitute legal advice. If you have specific questions regarding the application of the law to your business activities, you should seek the advice of your legal counsel.</em></p>
<p>&nbsp;</p>
<p><a href="https://www.zasio.com/identifying-personally-identifiable-information/#_ftnref1" name="_ftn1" data-wpel-link="internal">[1]</a> <a href="http://www.idtheftcenter.org/ITRC-Surveys-Studies/2015databreaches.html" target="_blank" rel="noopener external noreferrer" data-wpel-link="external">http://www.idtheftcenter.org/ITRC-Surveys-Studies/2015databreaches.html</a></p>
<p><a href="https://www.zasio.com/identifying-personally-identifiable-information/#_ftnref2" name="_ftn2" data-wpel-link="internal">[2]</a> CAL. CIV. CODE § 1798.82(h)</p>
<p><a href="https://www.zasio.com/identifying-personally-identifiable-information/#_ftnref3" name="_ftn3" data-wpel-link="internal">[3]</a> 15 U.S.C. § 6809(4)(A) (2006)</p>
<p><a href="https://www.zasio.com/identifying-personally-identifiable-information/#_ftnref4" name="_ftn4" data-wpel-link="internal">[4]</a> <a href="http://www.gsa.gov/portal/content/104256" target="_blank" rel="noopener external noreferrer" data-wpel-link="external">http://www.gsa.gov/portal/content/104256</a></div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row et_pb_row_9">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_9  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_team_member et_pb_team_member_4 clearfix  et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_team_member_image et-waypoint et_pb_animation_off"><img loading="lazy" decoding="async" width="96" height="96" src="https://zasio.com/wp-content/uploads/2023/10/Jenn-01-96x96-1.jpg" alt="Author: Jennifer Chadband, IGP, CRM, ECMp" class="wp-image-1877" /></div>
				<div class="et_pb_team_member_description">
					<h4 class="et_pb_module_header">Author: Jennifer Chadband, IGP, CRM, ECMp</h4>
					<p class="et_pb_member_position">Senior Analyst / Licensed Attorney</p>
					
					
				</div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
<p><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fzasio.com%2Fidentifying-personally-identifiable-information%2F&amp;linkname=Identifying%20Personally%20Identifiable%20Information" title="Facebook" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_x" href="https://www.addtoany.com/add_to/x?linkurl=https%3A%2F%2Fzasio.com%2Fidentifying-personally-identifiable-information%2F&amp;linkname=Identifying%20Personally%20Identifiable%20Information" title="X" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fzasio.com%2Fidentifying-personally-identifiable-information%2F&amp;linkname=Identifying%20Personally%20Identifiable%20Information" title="LinkedIn" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fzasio.com%2Fidentifying-personally-identifiable-information%2F&#038;title=Identifying%20Personally%20Identifiable%20Information" data-a2a-url="https://zasio.com/identifying-personally-identifiable-information/" data-a2a-title="Identifying Personally Identifiable Information" data-wpel-link="external" rel="external noopener noreferrer"></a></p><p>The post <a href="https://zasio.com/identifying-personally-identifiable-information/" data-wpel-link="internal">Identifying Personally Identifiable Information</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zasio.com/identifying-personally-identifiable-information/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
