{"id":9919,"date":"2024-04-03T06:05:49","date_gmt":"2024-04-03T10:05:49","guid":{"rendered":"https:\/\/joindeleteme.com\/?post_type=glossary&#038;p=9919"},"modified":"2024-04-03T06:05:49","modified_gmt":"2024-04-03T10:05:49","slug":"sensitive-personal-information","status":"publish","type":"glossary","link":"https:\/\/joindeleteme.com\/glossary\/sensitive-personal-information\/","title":{"rendered":"Sensitive Personal Information"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">What Is Sensitive Personal Information?<\/h2>\n\n\n\n<p>Sensitive personal information generally refers to data that, if disclosed, could harm someone or violate their privacy.&nbsp;<\/p>\n\n\n\n<p>Although the exact definition varies depending on the privacy law in question, sensitive personal information typically includes information like precise geolocation, health information, Social Security numbers, financial information, and religious or philosophical beliefs.&nbsp;<\/p>\n\n\n\n<p>This type of information usually requires a higher level of protection due to its potentially harmful nature if misused.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Third-party definition&nbsp;<\/h3>\n\n\n\n<p>Personal information that reveals: (a) consumer\u2019s social security, driver\u2019s license, state identification card, or passport number; (b) A consumer\u2019s account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; (c) A consumer\u2019s precise geolocation; (d) A consumer\u2019s racial or ethnic origin, religious or philosophical beliefs, or union membership; (e) the contents of a consumer\u2019s mail, email, and text messages unless the business is the intended recipient of the communication; (f) A consumer\u2019s genetic data; (g) health related data. &#8211; <a href=\"https:\/\/clym.io\/documentation-glossary\" target=\"_blank\" rel=\"noreferrer noopener\">Clym<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Sensitive Personal Information vs. Personal Information<\/h2>\n\n\n\n<p>Sensitive personal information is a subset of personal information, which is data that identifies a person.&nbsp;<\/p>\n\n\n\n<p>Sensitive personal information requires more robust protection than personal information due to its nature and potential harm that could come from its compromise or misuse.&nbsp;<\/p>\n\n\n\n<p>The distinction lies in the level of impact on the individual&#8217;s privacy and the potential risks involved if the data were to be accessed or disclosed without authorization.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Sensitive Personal Information Under the GDPR<\/h2>\n\n\n\n<p>As per the European General Data Protection Regulation (GDPR), sensitive data (or special categories of personal data) includes genetic data, biometric data, and health data.&nbsp;<\/p>\n\n\n\n<p>It also includes personal data that reveals ethnic and racial origin, religious\/ideological convictions, trade union membership, and political opinions.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Sensitive Personal Information Under US State Laws<\/h2>\n\n\n\n<p>The definition of sensitive personal information is similar across different US state laws.&nbsp;<\/p>\n\n\n\n<p>For example, in California, the <a href=\"https:\/\/oag.ca.gov\/privacy\/ccpa\" target=\"_blank\" rel=\"noreferrer noopener\">California Consumer Privacy Act<\/a> (CCPA) defines sensitive personal information as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Government identifiers (like Social Security numbers).<\/li>\n\n\n\n<li>Precise geolocation.<\/li>\n\n\n\n<li>Account details (like logins and passwords).<\/li>\n\n\n\n<li>Financial information (like debit\/credit card numbers with security codes).<\/li>\n\n\n\n<li>Genetic data.<\/li>\n\n\n\n<li>Biometric information.<\/li>\n\n\n\n<li>Private communications (like text messages, mail, and email).<\/li>\n\n\n\n<li>Racial or ethnic origin.<\/li>\n\n\n\n<li>Union membership.<\/li>\n\n\n\n<li>Religious or philosophical beliefs.<\/li>\n\n\n\n<li>Information about a person\u2019s health, sexual orientation, or sex life.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>In 2023, California Gov. Gavin Newsom signed Assembly Bill 947 (<a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=202320240AB947\" target=\"_blank\" rel=\"noreferrer noopener\">AB 947<\/a>) into law, which <a href=\"https:\/\/www.akingump.com\/en\/insights\/blogs\/ag-data-dive\/california-expands-definition-of-sensitive-personal-information-covered-under-ccpa\" target=\"_blank\" rel=\"noreferrer noopener\">added <\/a>citizenship and immigration status to the CCPA&#8217;s definition of \u201csensitive personal information.\u201d<\/p>\n\n\n\n<p>Under the CCPA, consumers can limit how businesses use and disclose personal information that\u2019s deemed sensitive.&nbsp;<\/p>\n\n\n\n<p>Under the <a href=\"https:\/\/portal.ct.gov\/AG\/Sections\/Privacy\/The-Connecticut-Data-Privacy-Act\" target=\"_blank\" rel=\"noreferrer noopener\">Connecticut Data Privacy Act<\/a> (CTDPA), sensitive data includes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Genetic and biometric data.<\/li>\n\n\n\n<li>Precise geolocation data.<\/li>\n\n\n\n<li>Personal data of anyone who is under the age of 13.<\/li>\n\n\n\n<li>Data that reveals a person\u2019s religious beliefs, racial or ethnic origins, sexual activity or orientation, immigration status, citizenship, and physical or mental health diagnoses and conditions.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Controllers must get consumers\u2019 consent before processing sensitive data under the CTDPA.<\/p>\n\n\n\n<p>If you live in a state with a privacy law, you can see what qualifies as sensitive data by searching for \u201c (your state law) + sensitive personal information.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Keep Your Sensitive Personal Information Private<\/h2>\n\n\n\n<p>Unfortunately, when it comes to keeping your sensitive personal information private, much of it is out of your hands and in the hands of the organization that has it\u2014especially if you live in a state without a comprehensive consumer privacy law.&nbsp;<\/p>\n\n\n\n<p>However, there are some steps you can take to improve the privacy of your sensitive personal information. These include the following:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Limiting the use and disclosure of your sensitive personal information. <\/strong>Depending on where you live, you might be able to limit how businesses use and disclose the sensitive personal information they collect about you.&nbsp;<\/li>\n\n\n\n<li><strong>Using strong passwords.<\/strong> Create complex and unique passwords (potentially with the help of a password manager) for each account to reduce the risk of criminals breaking into your accounts. Avoid using easily guessable passwords like birthdays or common words.&nbsp;<\/li>\n\n\n\n<li><strong>Enable multi-factor authentication. <\/strong>Where available, turn on multi-factor authentication (MFA). That way, even if someone has your passwords, they still won\u2019t be able to log into your accounts and potentially access even more sensitive information.&nbsp;<\/li>\n\n\n\n<li><strong>Be mindful of phishing scams. <\/strong>Watch out for phishing emails or messages that try to get you to reveal sensitive personal information.&nbsp;<\/li>\n\n\n\n<li><strong>Don\u2019t share sensitive personal information.<\/strong> Be thoughtful about the personal information you share online, especially on social media.&nbsp;<\/li>\n\n\n\n<li><strong>Shred sensitive documents.<\/strong> Before disposing of physical documents that contain sensitive information (like bank statements, utility bills, or medical records), properly destroy them.<\/li>\n\n\n\n<li><strong>Opt out of data brokers. <\/strong>Remove your name from data broker sites that might be selling your sensitive personal information to others. Remember to do so continuously &#8211; data brokers relist your information when they come across more data. Or, subscribe to a <a href=\"https:\/\/joindeleteme.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">data broker removal service like DeleteMe<\/a>.\u00a0<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>What Is Sensitive Personal Information? Sensitive personal information generally refers to data that, if disclosed, could harm someone or violate their privacy.&nbsp; Although the exact definition varies depending on the privacy law in question, sensitive personal information typically includes information like precise geolocation, health information, Social Security numbers, financial information, and religious or philosophical beliefs.&nbsp; [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":0,"menu_order":0,"comment_status":"closed","ping_status":"open","template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-9919","glossary","type-glossary","status-publish","format-standard","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/joindeleteme.com\/wp-json\/wp\/v2\/glossary\/9919","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/joindeleteme.com\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/joindeleteme.com\/wp-json\/wp\/v2\/types\/glossary"}],"author":[{"embeddable":true,"href":"https:\/\/joindeleteme.com\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/joindeleteme.com\/wp-json\/wp\/v2\/comments?post=9919"}],"version-history":[{"count":0,"href":"https:\/\/joindeleteme.com\/wp-json\/wp\/v2\/glossary\/9919\/revisions"}],"wp:attachment":[{"href":"https:\/\/joindeleteme.com\/wp-json\/wp\/v2\/media?parent=9919"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}