Viewable by the world
Group Access to CIO
Can VIEW the space: cio-editors ,  anonymous ,  all-lbnl-users ,  confluence-administrators , 
Can EDIT the space: confluence-administrators , 
Can ADMINISTER the space: confluence-administrators , 

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Personal Information Rated "Controlled" - Personally Identifiable Information (PII)

The below data elements are included in the definition of personal information and are regarded as "Controlled." These Data elements under the PII category are the most sensitive types of personal information at the Lab. Any use of Controlled 

How can you help us?

Help us by making sure our Protected Information Requirements are met. Note:

...

  • Note: email, gdocs, calendar are NOT Institutional Business Systems.

...

, transmission, storage, destruction, or other processing of PII must be approved by the IT Division. Any actual 

  1. Data Breach-Notice triggering Personal Information (under the California Information Practices Act, Cal. Civ. Code 1798.29), specifically:

    1. A combination of first name or first initial and last name and:

      1. Government Identifiers: Social Security Numbers, Drivers License Numbers, Passport Numbers, Green Card Numbers, and any other government-issued identifiers commonly used to identify an individual

      2. Employee health information, including records originating from a healthcare provider containing descriptions of conditions, diagnosis, prescriptions, referrals, visits, and other health information, insurance and/or claims-related information.

      3. Biometric Information

      4. License Plate Recognition System information

      5. Financial account information (such as debit and credit account information), including PINs or other authentication information

    2. Usernames and Passwords that would permit someone to access an online account.

  2. Personally Identifiable Information stored in Department of Energy-owned records maintained in Privacy Act Systems of Records

  3. Certain Sensitive Personal Data of EU residents contained in records subject to the General Data Protection Regulation.

  4. Certain datasets determined to be highly sensitive pursuant to a documented risk assessment by the Privacy Officer.

...