Home > Cybersecurity glossary > Personal data

Personal data

The personal data refers to any information relating to an identified or identifiable natural person.

A person is considered identifiable if he or she can be recognised directly (surname, first name) or indirectly (IP address, telephone number, fingerprint, etc.) from a combination of data.


👉 Examples of personal data

  • Identification data surname, first name, date of birth, postal address, telephone number, e-mail address.
  • Connection data IP address, connection identifiers, cookiesnavigation logs.
  • Sensitive data (within the meaning of RGPD): ethnic origin, political opinions, religious beliefs, health data, biometric data.
  • Financial data credit card number, IBAN, transaction history.

In cyber security :
Personal data are a prime target for cybercriminalswho exploit them for fraud, identity theft, financial scams or the phishing.


Legal frameworks

  • General Data Protection Regulation (GDPR) (EU - 2018): sets out the obligations of companies in terms of collecting, processing and securing personal data.
  • California Consumer Privacy Act (CCPA) (USA - 2020): regulations protecting Californian consumers against the misuse of their personal data.

 


Recommended protection


✅ Use strong passwords and thetwo-factor authentication (2FA).
✅ Do not share sensitive information on non-secure platforms.
✅ Check the privacy policy online services.
✅ Encrypt stored and transferred data.

Towards the ORSYS Cyber Academy: a free space dedicated to cybersecurity