<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GDPR - What is considered personal data? in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7745#M315</link>
    <description>&lt;P&gt;First of all it must belong to a living entity, not a deceased one.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Any information relating to an identified or identifiable living natural person (data subject)."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A data subject is defined as the individual whose data is being collected and can be identified from the data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this answer your question?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 25 Feb 2018 18:42:24 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2018-02-25T18:42:24Z</dc:date>
    <item>
      <title>GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7738#M313</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a very practical question: Since the regulation defines personal data as “Any information relating to an identified or identifiable natural person…”, does it mean first + last name is considered personal data? Historically we identified PII as a combination of several elements like name + address or name + social. If first + last is indeed considered personal information under GDPR the impact is much more significant so we want to make sure we're addressing it appropriately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't been able to get a straight answer yet so I figured someone here might be able to help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 17:49:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7738#M313</guid>
      <dc:creator>Francois1208</dc:creator>
      <dc:date>2018-02-25T17:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7745#M315</link>
      <description>&lt;P&gt;First of all it must belong to a living entity, not a deceased one.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Any information relating to an identified or identifiable living natural person (data subject)."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A data subject is defined as the individual whose data is being collected and can be identified from the data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this answer your question?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 18:42:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7745#M315</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2018-02-25T18:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7746#M316</link>
      <description>&lt;P&gt;So out of the data available, that you hold - can you identify the person, from the information you hold i.e. can you identify their activity by location (GPS), by IP address and/or MAC address; bio metric data, DNA or by association with their abode i.e. address, bank numbers, social number etc etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of these, could identify that living person.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 18:46:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7746#M316</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2018-02-25T18:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7752#M318</link>
      <description>&lt;P&gt;Suggest you have a look the EU's independent data protection authority's website for a definition:&amp;nbsp;&lt;A href="https://edps.europa.eu/node/3110#personal_data&amp;nbsp;" target="_blank"&gt;https://edps.europa.eu/node/3110#personal_data&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;They give examples too:&amp;nbsp;&lt;/P&gt;&lt;P&gt;"The name and the social security number are two examples of personal data which relate directly to a person. But the definition also extends further and also encompasses for instance e-mail addresses and the office phone number of an employee. Other examples of personal data can be found in information on physical disabilities, in medical records and in an employee's evaluation."&lt;/P&gt;&lt;P&gt;Recently attended a session hosted by the deputy EU data protection supervisor where they even stated IP addressed may be considered personal data.&amp;nbsp;Might make sense to keep an eye on their website as they promised to come up with guidance documents.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 19:39:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7752#M318</guid>
      <dc:creator>sminkmar</dc:creator>
      <dc:date>2018-02-25T19:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7753#M319</link>
      <description>&lt;P&gt;Good point:&amp;nbsp; I am seeing so many different interpretations of the facts - we should always go back to the original source for the true facts.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 19:33:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7753#M319</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2018-02-25T19:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7754#M320</link>
      <description>&lt;P&gt;Well given that there was a European Court case, which was upheld on the very fact that IP addresses and/or Mac Addresses could identify the activity of the individual involved - then this is also the stance taken by my organisation as well.&amp;nbsp;&amp;nbsp; However, only the lawyers, who are obviously waiting for the 25th May 2018 to delivery their lawsuits and challenges will this be tested fully.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 19:35:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7754#M320</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2018-02-25T19:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7755#M321</link>
      <description>And it goes further than "just" IP addresses. Imagine you have an outsourcing center (helpdesk, customer support, etc) somewhere in Asia (India, Phils, you name it). Seemed to be sort of an issue if data is shared (and if it was via screen only) with those folks.</description>
      <pubDate>Sun, 25 Feb 2018 19:44:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7755#M321</guid>
      <dc:creator>sminkmar</dc:creator>
      <dc:date>2018-02-25T19:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7756#M322</link>
      <description>&lt;P&gt;Yes, the Data Processor - A person or body acting on behalf of the data controllers to store or process the data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know, every contract has to be reviewed, from a risk management perspective, and agreed with the clients and appropriate Technical &amp;amp; Organisational Measures (TOMs) have to be agreed and put in place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 19:54:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7756#M322</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2018-02-25T19:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7757#M323</link>
      <description>&lt;P&gt;&lt;A href="https://www.irishtimes.com/business/technology/european-court-of-justice-rules-ip-addresses-are-personal-data-1.2835704" target="_blank"&gt;https://www.irishtimes.com/business/technology/european-court-of-justice-rules-ip-addresses-are-personal-data-1.2835704&lt;/A&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Well given that there was a European Court case, which was upheld on the very fact that IP addresses and/or Mac Addresses could identify the activity of the individual involved - then this is also the stance taken by my organisation as well.&amp;nbsp;&amp;nbsp; However, only the lawyers, who are obviously waiting for the 25th May 2018 to delivery their lawsuits and challenges will this be tested fully.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 19:58:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7757#M323</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2018-02-25T19:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7759#M324</link>
      <description>&lt;P&gt;There is a really good paper on this on the ICO (Information Commissioners Office) web site in the UK with lots of examples&amp;nbsp;&lt;A href="https://ico.org.uk/media/for-organisations/documents/1554/determining-what-is-personal-data.pdf" target="_blank"&gt;https://ico.org.uk/media/for-organisations/documents/1554/determining-what-is-personal-data.pdf&lt;/A&gt; .&amp;nbsp; It builds up the scenarios really well - ultimately you have to make a sensible decision.&amp;nbsp; For me it boils down to some simple questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Is it an organised electronic or paper store&lt;/P&gt;&lt;P&gt;- can identify a living person (or use identifiers to get to that living individual e.g. IP address)&lt;/P&gt;&lt;P&gt;- the attributes and information that relate to that living person are personal information.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 20:23:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7759#M324</guid>
      <dc:creator>Witheaaxw</dc:creator>
      <dc:date>2018-02-25T20:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7760#M325</link>
      <description>&lt;P&gt;Thanks for the replies. So it sounds like having someone's first and last name could be considered personal data if I can identify who that person really is. For example there could be many John Smith at my company but I wouldn't consider that personal information if I don't have anything else to say who it is (e.g. phone #, employee ID, job title, etc.). Conversely if the name is unique then I should assume it is considered personal (assuming I'm just talking within the boundaries of my companies information systems).&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 20:23:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7760#M325</guid>
      <dc:creator>Francois1208</dc:creator>
      <dc:date>2018-02-25T20:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7761#M326</link>
      <description>&lt;P&gt;That's great - just what I was looking for. Now the next question is how does what the ICO says hold true in regards to European regulations? Can we assume they all have the same definitions and views?&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 20:28:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7761#M326</guid>
      <dc:creator>Francois1208</dc:creator>
      <dc:date>2018-02-25T20:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7762#M327</link>
      <description>&lt;P&gt;It depends.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your only information is "John Smith" who lives in London there are probably many 1000's so not PI. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you say "John Smith" in my company where there are just 5 of them then probably PI, especially if you add with other information (age, job title, department etc).&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 20:30:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7762#M327</guid>
      <dc:creator>Witheaaxw</dc:creator>
      <dc:date>2018-02-25T20:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7765#M328</link>
      <description>&lt;P&gt;Yes, the GDPR was introduced to standardise the approach across the EEA - as the DPA directive went off in many different directions in each state (or region in the case of Germany).&amp;nbsp; It comes into force on 25 May 2018. That said, there will be a period of adaption.&amp;nbsp; There is scope for some limited divergence (but it is miniscule).&amp;nbsp; What is missing is people that can apply the rules in a sensible, practical, risk based manner. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The GDPR quickly gets us into the IT Security realm and here the legislation is not a lot of help other than calling out for 'appropriate organisation and technical standards' - which is where the CISSP is incredibly helpful as a starter.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The challenge is for someone to put a practical slant on all the specialists (Data Protection Officer, Security Officer, Lawyer, IT professionals, Business User, Compliance (in Financial Services), Risk (in Financial Services), internal/external audit etc.).&amp;nbsp; You get&amp;nbsp; the challenge.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Slight challenge because the UK is (probably) leaving the EU.&amp;nbsp; Nevertheless, the draft new DPA Bill seeks to implement the GDPR in full and deal with some of the gaps.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 20:46:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7765#M328</guid>
      <dc:creator>Witheaaxw</dc:creator>
      <dc:date>2018-02-25T20:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7772#M329</link>
      <description>&lt;P&gt;Firstly, IANAL, so this is not legal advice, secondly 'Personal Data' is not equal to 'PII', and it sounds like you have the correct definition, which is broad and needs to be interpreted by your legal counsel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First name plus last name is most definitely personal data, and you must have a contract or other legal grounds or consent to process this data. Though as NIST SP 800-122 has the following in its definition of&amp;nbsp;PII:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; 'Name, such as full name, maiden name, mother‘s maiden name, or alias'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You might want to have them look at PII as well. You can certainly distinguish&amp;nbsp;with a full name, and if not too common tracing is also quite easy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's probably the best&amp;nbsp;definition out there for a native English speaker:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="3"&gt;What information does the GDPR apply to?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Personal data&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;P&gt;The GDPR applies to ‘personal data’ meaning any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier.&lt;/P&gt;&lt;P&gt;This definition provides for a wide range of personal identifiers to constitute personal data, including name, identification number, location data or online identifier, reflecting changes in technology and the way organisations collect information about people.&lt;/P&gt;&lt;P&gt;The GDPR applies to both automated personal data and to manual filing systems where personal data are accessible according to specific criteria. This could include chronologically ordered sets of manual records containing personal data.&lt;/P&gt;&lt;P&gt;Personal data that has been pseudonymised – eg key-coded – can fall within the scope of the GDPR depending on how difficult it is to attribute the pseudonym to a particular individual.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Sensitive personal data&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;P&gt;The GDPR refers to sensitive personal data as “special categories of personal data” (see Article 9).&lt;/P&gt;&lt;P&gt;The special categories specifically include genetic data, and biometric data where processed to uniquely identify an individual.&lt;/P&gt;&lt;P&gt;Personal data relating to criminal convictions and offences are not included, but similar extra safeguards apply to its processing (see Article 10).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A href="https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/key-definitions/" target="_self"&gt;https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/key-definitions/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 02:31:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7772#M329</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2018-02-26T02:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7773#M330</link>
      <description>&lt;P&gt;Just realized there's a huge flash to bang on my post - sorry for being behind the curve.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John Smith is a name, therefore is personal data and by the GDPR can't be processed without the contract, other legal means such as John Smith explicitly&amp;nbsp;giving his consent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the question of the UK leaving the EU, if it doesn't get adequacy as a third country under the GDPR it's pretty much game over for large sections of the UK's&amp;nbsp;information economy. End state I would say is UK is bound to uphold the GDPR but has no say in subsequent revisions.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 03:03:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7773#M330</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2018-02-26T03:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7774#M331</link>
      <description>&lt;P&gt;The personal data is something which help define/identify your identity and personal belonging. It may be anything like your health data , bank data, Name and age etc.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 03:06:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7774#M331</guid>
      <dc:creator>Bhuwnesh</dc:creator>
      <dc:date>2018-02-26T03:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7775#M332</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With only First name + Last name , the person can't be said as uniquely identified. As there might be many people with same name and surname. It has to be combined with some other information like address, ID number etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The real question is " If any european citizen travelling to another country and visited an hospital. Does the hospital be liable to protect european citizen health related data" &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.isc2.org/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lot many questions and scenarios require clarity, but GDPR is really good initiative.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arif&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 03:28:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7775#M332</guid>
      <dc:creator>arifhussain</dc:creator>
      <dc:date>2018-02-26T03:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7776#M333</link>
      <description>&lt;P&gt;I got it first time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; its your identity status&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; like I said . your name itself is not your identity. Its always a combination of many things . A name can belong to many people but the identifiable make it unique . Like your name + sir name +gender + status etc .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The GDPR is a European standards&amp;nbsp; not to rest of the world. If you travel to other country and share your data then they have to protect your data&amp;nbsp; &amp;nbsp;as per local regulations/standards until unless you/others make a agreement for European&amp;nbsp; GDPR.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 03:39:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7776#M333</guid>
      <dc:creator>Bhuwnesh</dc:creator>
      <dc:date>2018-02-26T03:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - What is considered personal data?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7778#M334</link>
      <description>&lt;P&gt;Just some small points, yes, it is a European Law, but it is not just about identifying individuals, it also affects all companies who are conducting business and services with European entities.&amp;nbsp; Example:&amp;nbsp; A New Zealand Bank who has outlets in Europe, would employ European citizens for instance, so they would have to deal with this legislation as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The implications are far wider, then you think, it is not just European bound.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It will affect organisations such as Google, Facebook and many others offering services around the world.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 04:00:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-What-is-considered-personal-data/m-p/7778#M334</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2018-02-26T04:00:42Z</dc:date>
    </item>
  </channel>
</rss>

