Choose Your Reading Style
A professional-level summary covering key definitions, frameworks, and exam-relevant points.
PII Categories and Examples
| Category | Examples | Risk Level |
|---|---|---|
| Direct identifiers | Full name, national ID, passport number, SSN | Very high |
| Contact information | Email address, phone number, home address | High |
| Financial data | Bank account number, credit card number, tax ID | Very high |
| Biometric data | Fingerprints, facial recognition, DNA | Very high |
| Health data | Medical records, diagnoses, prescriptions (PHI) | Very high |
| Quasi-identifiers | Date of birth, postcode, gender, job title | Medium (high when combined) |
| Online identifiers | IP address, cookies, device IDs, location data | Medium to high |
CDMP Exam Relevance
PII is a key concept in the Data Security knowledge area (6% of the CDMP exam) and is also relevant to Data Governance (policies for PII handling) and Data Lifecycle Management (retention and disposal of PII). Key exam topics include: the definition of PII and examples, the difference between direct and indirect PII, the regulatory requirements for PII under GDPR and other regulations, and the governance practices needed to protect PII (classification, access control, encryption, retention policies, breach notification).