Spotting Personal Data Everywhere
The Morning Spreadsheet Trap
Imagine you’re starting your Monday morning as the office hero, organizing a team lunch. You create a quick spreadsheet with names, birthdays, and dietary requirements.
In the eyes of the GDPR, you haven't just made a list—you’ve created a database of personal data.
Imagine you’re starting your Monday morning. You decide to be the 'office hero' and organize a team lunch. You create a quick spreadsheet with everyone’s names, their birthdays, and their dietary requirements. It feels like a helpful, everyday task, right? But in the eyes of the GDPR, you haven’t just made a lunch list—you’ve created a database of personal data. If this file is saved on a public drive or emailed to the wrong person, it could lead to a data breach.
- Everyday tasks can involve personal data.
- Simple spreadsheets are considered databases under GDPR.
- Improper storage of these lists can lead to a data breach.
What Exactly is Personal Data?
Think of personal data as a trail of digital breadcrumbs. Any piece of information that can identify a living person—either on its own or when combined—counts.
You don't need to be a lawyer to get this right. Think of personal data as any piece of information that can be used to identify a living person. It’s like a trail of digital breadcrumbs that leads back to a specific individual. Sometimes it's direct, like a name. Other times, it's indirect, like an ID number or a location. Each piece of data adds a layer of identity. When you combine them, the individual becomes clearly identifiable.
- Personal data identifies a specific individual.
- It can be direct (name) or indirect (IP address).
- Multiple pieces of data can 'combine' to identify someone.
Obvious vs. Hidden Data
Personal data isn't just names and addresses. It includes work-related details and hidden identifiers like IP addresses.
Let's break down the types of data you handle daily. First, we have the obvious ones: names and home addresses. Then, there's work-related data. Yes, business emails like j-smith at company dot com still count! Finally, there's hidden data like IP addresses or location data from a company phone.
- Obvious: Names, home addresses, phone numbers.
- Work-Related: Business emails and employee IDs.
- Hidden: IP addresses and location data.
Broad and Surprising Examples
The definition of personal data is wider than most realize. Common office items like birthday calendars and customer lists are strictly protected.
Some examples often catch employees off guard. A shared birthday calendar is a great team-builder, but it contains specific birth dates—that's personal data! Similarly, a simple list of 'Active Clients' with names and roles is protected. Sharing these via an unencrypted chat app is a major no-no.
- Birthday calendars reveal birth dates (personal data).
- Customer lists with roles and names are protected.
- Sharing these via unencrypted chat or email is a risk.
What Would You Do?
You are moving to a new department and want to take a list of your 50 most successful leads (names and phone numbers) to show your progress. Is this okay? Practice explaining your reasoning to the Data Protection Officer (DPO).
You're about to switch departments and want to bring your lead list with you. You've reached out to the Data Protection Officer to ask if this is okay. How would you justify or ask about this move?
- Customer lists are company property and protected data.
- Moving data between systems requires approval.
- Always check with your DPO when in doubt.
Spot the Personal Data
Examine this internal email draft. Click on all pieces of personal data you can find before the email is sent.
Before this email goes out, we need to be vigilant. Look at this draft carefully. Click on every piece of information that counts as personal data. Great job! You identified the name, the business email, the employee ID, and even the dietary requirement. All of these together make this a sensitive document.
- Identify names and email addresses.
- Spot hidden identifiers like employee IDs.
- Recognize sensitive details like dietary preferences.
The Personal Data Filter
Before you hit 'send' or 'save,' run your data through this three-question checklist.
To stay safe, use the 'Personal Data Filter'. Question 1: Identification. Can I tell exactly who this is about? Question 2: Context. Does the information tell me something about that person, like their role or a preference? And Question 3: Combination. If I combine this with other info, could I identify them? If you answer 'Yes' to any of these, follow protocol or ask your DPO.
- Identification: Can I tell who this is?
- Context: Does it tell me something about them?
- Combination: Can I identify them by linking info?
Human Error: Our Biggest Risk
Most leaks aren't from hackers; they happen because of human error. A simple mistake like using CC instead of BCC can expose an entire customer list.
It’s a surprising fact: most data leaks aren't caused by hackers. They happen because of human error. Imagine accidentally CCing a whole customer list instead of BCCing them. Everyone now has everyone else's email address. Being vigilant and double-checking your recipients is your best defense.
- Human error causes more breaches than hacking.
- Always double-check CC vs BCC.
- Vigilance is your best defense.