FieldRegister
Every field · Identifiers

Government identifier (passport, national ID, SSN, tax number)

Government identifiers are high-risk identifiers; CPRA treats them as sensitive PI. They enable identity fraud if leaked.

personal data
personal data?
confidential
sensitivity
never
AI use
legal obligation, or contract where identity must be verified
lawful basis usually relied on

Keep it how long

Only for the verification or statutory purpose; retention set by the law that requires it.

The gap we see most

Stored in a plain text field for a one-off verification and never deleted.

What holding it is evidence for

Requirement text and artefacts from a human-verified corpus licensed to Field Register.

Government identifiers stored GDPR Art.32 · CCPA/CPRA §1798.121 · CCPA/CPRA §1798.150 · ISO/IEC 27701:2019 7.4.9
GDPR Art.32 Security of processing

Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rig...

Evidence an auditor accepts: The security risk assessment per processing activity, expressed as risk to the rights and freedoms of individuals rather than only as risk to the organisation; Encryption and pseudonymisation coverage at rest, in transit and in backup, with the decision recorded where either was judged not appropriate; Restoration testing results showing personal data was actually recovered inside the intended timeframe, with the date and outcome
CCPA/CPRA §1798.121 Right to Limit Use and Disclosure of Sensitive Personal Information

Consumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying ...

Evidence an auditor accepts: Sensitive PI inventory (SSN, drivers license, financial, geolocation, race, religion, biometric, health, sexual orientation, contents of communications); Limit Use of My Sensitive Personal Information mechanism (when required); Permitted purpose justification documentation
CCPA/CPRA §1798.150 Private Right of Action for Data Breaches

A consumer whose nonencrypted and nonredacted PI (or email address with password/security question allowing account access) is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of duty to implement and maintain reasonable security may bring...

Evidence an auditor accepts: Reasonable security program documentation (encryption, access control, monitoring); Incident response plan including 30-day cure handling; Breach notification procedure
ISO/IEC 27701:2019 7.4.9 PII transmission controls

The organization must subject personal data transmitted over a data transmission network to controls designed to ensure it reaches its intended destination, typically by ensuring only authorized individuals have access to transmission systems and by following processes, including retaining audit log...

Evidence an auditor accepts: Documented transmission controls covering authorisation, protection and recipient verification; Access controls over transmission systems; Audit logs of transmissions retained and reviewable

Do this for your whole CRM

Paste your field list and get this classification for every field at once, with the record of processing per object, the gaps, and the controls the register is evidence for. No account for the first run.

Build my field register

Criminal convictions or offences · Payment card or bank account details