
Are email addresses considered PII?
Yes. Any email address is considered PII (personally identifiable information), which is any data that could potentially identify a specific individual. In other words, any information that can be used to distinguish one person from another--turning anonymous data into PII.
How to send PII email?
Emails containing personally Identifiable Information (PII) should only be sent to recipients with an official need-to-know. The email must be digitally signed and encrypted. It is against policy to send PII to group email addresses. Set Up Your Computer to Send Encrypted Emails . 1. CAC Email Certificate.
Is a home address classified as PII?
This type of information is considered to be Public PII and includes, for example, first and last name, address, work telephone number, email address, home telephone number, and general educational credentials. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified.
Is a cell phone number PII?
Personally Identifiable Information (PII), or personal data, is data that corresponds to a single person. PII might be a phone number, national ID number, email address, or any data that can be used, either on its own or with any other information, to contact, identify, or locate a person.
See 7 key topics from this page & related content

Is email address PII under GDPR?
Yes, email addresses are personal data. According to data protection laws such as the GDPR and CCPA, email addresses are personally identifiable information (PII). PII is any information that can be used by itself or with other data to identify a physical person.
Is an email address sensitive PII?
Sensitive personally identifiable information includes: Credit and debit card numbers. Banking accounts. Electronic and digital account information, including email addresses and internet account numbers.
How do you mark an email as PII?
Emailing PIIShould only be sent to recipients with an official need-to-know.The SUBJECT line must state: "CUI."The attachment file name must state: "CUI."The top and bottom of the email and the top and bottom of the attachment must state: "CUI" and include a CUI indicator block.More items...
What is not considered sensitive PII?
Non-sensitive personally identifiable information is easily accessible from public sources and can include your zip code, race, gender, and date of birth. Passports contain personally identifiable information. Social media sites may be considered non-sensitive personally identifiable information.
What are the rules of behavior for DOL contractors?
Users must adhere to the rules of behavior defined in applicable Systems Security Plans, DOL and agency guidance. DOL contractors having access to personal information shall respect the confidentiality of such information, and refrain from any conduct that would indicate a careless or negligent attitude toward such information.
Why is DOL a special responsibility?
Because DOL employees and contractors may have access to personal identifiable information concerning individuals and other sensitive data, we have a special responsibility to protect that information from loss and misuse.
What is PII in law?
Further, PII is defined as information: (i) that directly identifies an individual (e.g., name, address, social security number or other identifying number or code, telephone number, email address, etc.) or (ii) by which an agency intends to identify specific individuals in conjunction with other data elements, i.e., indirect identification.
What is PII protection?
Personal Identifiable Information (PII) is defined as: Any representation of information that permits the identity of an individual to whom the information applies to be reasonably inferred by either direct or indirect means.
Do contractors have to report PII theft?
Contractors should ensure their contract employees are aware of their responsibilities regarding the protection of PII at the Department of Labor. In addition to the forgoing, if contract employees become aware of a theft or loss of PII, they are required to immediately inform their DOL contract manager. In the event their DOL contract manager is not available, they are to immediately report the theft or loss to the DOL Computer Security Incident Response Capability (CSIRC) team at [email protected].
Can a person have access to PII?
Only individuals who have a "need to know" in their official capacity shall have access to such systems of records. The loss of PII can result in substantial harm to individuals, including identity theft or other fraudulent use of the information.
Is information permitting the physical or online contacting of a specific individual the same as personally identifiable information?
Additionally, information permitting the physical or online contacting of a specific individual is the same as personally identifiable information . This information can be maintained in either paper, electronic or other media.
What is the meaning of "back up"?
Making statements based on opinion; back them up with references or personal experience.
Is a mail server domain a company?
In regards to mail servers. It’s actually really rare that a mail server domain refers to a person, it usually refers to a company. Also is the email address itself allready PII, so considering just the domain part of it is kinda redundant.
Is a domain PII?
But basically a domain is only considered PII if it’s possible to derive a person from it. Thereby making it a PII. Doing this is a really bad idea since the DNS system requires that anyone can cache the data by design. This means anyone can make copies of the data. In regards to mail servers.
Is a single domain PII?
If you can identify someone with it, then it ( probably) is. So, a single domain with a single user would end up being deemed PII.
Can each customer be associated with a domain?
Each customer in a system can be associated with a domain, and some domains are associated with a single customer.
Is GDPR a technical question?
Your question is not a technical question, it's a legal question which depends on the specific legal framework such as GDPR.
