The GDPR Guy Podcast

The GDPR Guy - the podcast dedicated to all things privacy, hosted by Carl Gottlieb - the trusted privacy advisor to leading tech companies, helping them gain maximum advantage through the right privacy strategy. Each episode Carl will be providing information, insights and inspiration to help you on your privacy journey.

#25 – Privacy definitions for engineers

The Privacy world has done a great job of over complicating things for engineers with conflicting definitions in the GDPR, CCPA, ISO and elsewhere. In this episode get to the heart of what you need to know for some of the main privacy terminology out there.

Audio

Transcript

Hello and welcome to the GDPR Guy. I’m Carl Gottlieb, your host and resident privacy advisor.

A quick warning for this podcast. I’m in a bit of a Candid Carl mood so there will be some swearing. If you don’t like that kind of thing then please don’t feel the need to listen any further.

Working with lots of tech clients, and therefore lots of different engineers, means I hear the same questions a lot. And I mean a LOT.

Common Questions

The most common ones centre around what some privacy terms mean as they relate to engineers, specifically:

  • What is PII?
  • What does processing mean? and
  • What does anonymous really mean?

PII

Let’s start with PII. Privacy people often act like complete dickheads when they hear the term PII, as in Personally Identifiable Information. This is mainly because they’re annoying pricks that have spent all of their time studying the GDPR and zero time in the real world helping people. And I’m here to help you, so I’m happy to use this term and I’ll explain why.

There’s a long and mixed history behind the terms Personal Information, Personal Data and PII that spans continents and decades of legislation, standards and general principles. It also spans both privacy and security domains. In each area, you’ve historically found differences in exact definitions, but the key thing to say is that all three terms are legally becoming synonymous as they relate to contracts, which for tech companies especially in B2B is most of what you need to care about.

Processing and Its Implications

Processing is almost always what it seems to us privacy people, as in any viewing, editing, touching, storing, deleting – basically anything at all that could involve some visibility of the data. Just because you don’t technically use it for anything or don’t want to use it, if you have the ability to see or interrupt that data, then you’re processing it.

Anonymisation

Anonymisation is a both simple and super complicated area. Engineers will always look to analyse it at a technical level, often debating for hours. PII only becomes anonymous when we can’t stand up in court and prove that we did everything we could to remove all identifiable parts of it. In reality, an anonymous phone number might be anonymous to me, but could easily become PII if I had access to the right information.

Key Takeaways

  1. PII will likely mean the same to you as Personal Information and Personal Data. Just read the contracts that apply to you.
  2. Processing means literally any viewing or relaying of data.
  3. Anonymous data involves stripping all bits of PII from a dataset such that you can’t reidentify someone.

If you have any further questions, just reach out to the Legal or Privacy team for clarification.