Supported Data Labels
Supported Data Types
Detection and masking of privacy data is implemented based on three types of data types:
n | PII - Personally Identifiable Information (PII) is any information connected to a specific individual that can be used to uncover that individual's identity. See Table 1 PII data labels for a detailed list of PII data labels. |
n | PHI - Protected Health Information (PHI) is any information in the medical record or designated record set that can be used to identify an individual. See Table 2 PHI data labels for a detailed list of PHI data labels. |
n |
PCI - Payment Card Industry (PCI) data apply to all entities involved in payment card processing – including merchants, processors, acquirers, issuers, and service providers. See Table 3 PCI data labels for a detailed list of PCI data labels. |
Supported Data Labels
The tables below list all the privacy data labels for each data type.
Table 1 PII data labels
Label | Description |
Policy & Regulatory Compliance |
---|---|---|
Account number |
Customer account or membership identification number Examples: Policy No. 10042992; Member ID: HZ-5235-001 |
HIPAA_SAFE_HARBOR, CCI |
Age |
Numbers associated with an individual’s age Examples: 27 years old; 18 months old When given in years, only the number is flagged, but both number and time unit are flagged when given in other units like months or weeks Also includes age ranges Examples: 29-35 years old; 18+; A man in his forties |
GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI |
Date |
Specific calendar dates, which can include days of the week, dates, months, or years Examples: Friday, Dec. 18, 2002; Dated: 02/03/97 Note: If no calendar date is specified, days of the week are not flagged: e.g. Your appointment is on Monday Note: Indexical terms are not flagged: e.g. yesterday; tomorrow |
HIPAA_SAFE_HARBOR, Quebec Privacy Act, CCI |
Date interval |
Broader time periods, including date ranges, months, seasons, years, and decades Examples: 2020-2021; 5-9 May; January 1984 |
HIPAA_SAFE_HARBOR, CCI |
DOB |
Dates of birth Example: Born: March 7, 1961 |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI |
Driver license |
Driver's permit numbers Example: DL# 134711-320 Includes International Driving Permits (IDP) and Pilot’s licenses |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI |
Duration |
Periods of time, specified as a number and a unit of time Example: 8 months; 2 years |
|
Email address |
Email addresses Example: info@private-ai.com |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI, CCI |
Event |
Names of events or holidays Examples: Olympics; Yom Kippur |
|
Filename |
Names of computer files, including the extension or filepath Example: Taxes/2012/brad-tax-returns.pdf |
CCI |
Gender |
Terms indicating gender identity, including slang terms. Note that performance is stronger for terms that are more likely to occur in formal documents, such as "male", "transgender", "non-binary", "female", "M", "F", etc. Other terms, such as "woman", "gentleman", etc., may not be captured in every context. Examples: female; trans |
CPRA, GDPR, GDPR Sensitive, APPI Sensitive |
Healthcare number |
Healthcare numbers and health plan beneficiary numbers Example: Policy No.: 5584-486-674-YM Includes medical record numbers, health insurance policy/account numbers, and member IDs, for example, German Sozialversicherungsnummer (also used as SSN), Philippine PhilHealth ID number, Ukrainian VHI number |
CPRA, GDPR, HIPAA, Quebec Privacy Act, APPI |
IP address |
Internet IP address, including IPv4 and IPv6 formats Examples: 192.168.0.1;2001:db8:0:0:0:8a2e::7334 |
CPRA, GDPR, HIPAA, Quebec Privacy Act, APPI |
Language |
Names of natural languages Examples: Korean; French |
GDPR, GDPR Sensitive, APPI Sensitive |
Location |
Metaclass for any named location reference; See subclasses below Examples: Eritrea; Lake Victoria May co-occur with Organization when the context refers explicitly to the organization’s location Example: The patient was transferred to Northwest General Hospital |
GDPR, HIPAA_SAFE_HARBOR, APPI, CCI |
Location address |
Full or partial physical mailing addresses, which can include: building name or number, street, city, county, state, country, zip code Examples: 25/300 Adelaide T., Perth WA 6000, Aus. 145 Windsor St. Mail to: Kollwitzstr 13, 10405, Berlin |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI, CCI |
Location address street |
A subclass of Location address, covering: a building number and street name, plus information like a unit numbers, office numbers, floor numbers and building names, where applicable Examples: 25/300 Adelaide T., Perth WA 6000, Aus. 145 Windsor St. Mail to: Kollwitzstr 13, 10405, Berlin |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI, CCI |
Location city |
Municipality names, including villages, towns, and cities Examples: Toronto; Berlin; Denpasar |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI, CCI |
Location coordinate |
Geographic positions referred to using latitude, longitude, and/or elevation coordinates Example: We’re at 40.748440 and -73.984559 |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI |
Location country |
Country names Examples: Canada; Namibia |
GDPR, APPI, CCI |
Location state |
State, province, territory, or prefecture names Examples: Ontario; Arkansas; Ich lebe in NRW |
GDPR, APPI, CCI |
Location zip |
Zip codes (including Zip+4), postcodes, or postal codes Examples: 90210; B2N 3E3 Optimized for various English-speaking locales (Australia, Canada, United Kingdom, United States), as well as international equivalents |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI, CCI |
Marital status |
Terms indicating marital status Examples: single; common-law; ex-wife; married |
APPI Sensitive |
Money |
Names and/or amounts of currency Examples: 15 pesos; $94.50 |
CCI |
Name |
Names of individuals, not including personal titles such as ‘Mrs.’ or ‘Mr.’ Examples: Dwayne Johnson; Mr. Khanna |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI |
Name family |
Names indicating a person’s family or community; often a last name in Western cultures and first name in Eastern cultures Examples: François Truffaut; Ozu Yasujirō |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI |
Name given |
Names given to an individual, usually at birth; often first / middle names in Western cultures and middle / last names in Eastern cultures Examples: François Truffaut; Ozu Yasujirō |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI |
Name medical professional |
Full names, including professional titles and certifications, of medical professional, such as doctors and nurses Example: Attending physician: Dr. Kay Martinez, MD |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI |
Numerical PII |
Numerical PII (including alphanumeric strings) that doesn't fall under other categories. See also a section below on international variants as some of them are mapped to this category, for example, Belgian BTW nummer or European VAT number. Includes the following: numbers in the medical field, such as device serial numbers, POS codes, NPI numbers, etc.; computer numbers like MAC addresses, cookie IDs, VPNs, error codes, access codes, message IDs, etc.; business-related numbers like DUNS numbers, company registration numbers, provider IDs, etc.; numbers related to purchasing, like order IDs, transaction numbers, confirmation numbers, tracking numbers, etc.; also numbers assigned to various forms of IDs, files, documents, proceedings, invoices, claim IDs, record IDs, etc. |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI, CCI |
Occupation |
Job titles or professions Examples: professor; actors; engineer; CPA |
Quebec Privacy Act, APPI, CCI |
Organization |
Names of organizations or departments within an organization Examples: BHP; McDonald's; LAPD May co-occur with LOCATION when the context refers explicitly to the organization’s location, for example, Donations can be brought to Royal Canadian Legion Branch 43 |
Quebec Privacy Act, APPI, CCI |
Organization medical facility |
Names of medical facilities, such as hospitals, clinics, pharmacies, etc. Examples: Northwest General Hospital; Union Family Health Clinic |
Quebec Privacy Act, APPI |
Origin |
Terms indicating nationality, ethnicity, or provenance Examples: Canadian; Sri Lankan |
CPRA, GDPR, GDPR Sensitive, Quebec Privacy Act, APPI Sensitive |
Passport number |
Passport numbers, issued by any country Examples: PA4568332; NU3C6L86S12 |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI |
Password |
Account passwords, PINs, access keys, or verification answers Examples: 27%alfalfa; temp1234 My mother's maiden name is Smith |
CPRA, APPI, CCI |
Phone number |
Telephone or fax numbers Example: +4917643476050 |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI |
Physical attribute |
Distinctive bodily attributes, including terms indicating race Examples: I'm 190cm tall; He belongs to the Black students’ association |
CPRA, GDPR, GDPR Sensitive, APPI Sensitive |
Political affiliation |
Terms referring to a political party, movement, or ideology Examples: liberal; Republican |
CPRA, GDPR, GDPR Sensitive, Quebec Privacy Act, APPI Sensitive |
Religion |
Terms indicating religious affiliation Examples: Hindu; Presbyterian |
CPRA, GDPR, GDPR Sensitive, Quebec Privacy Act, APPI Sensitive |
Sexuality |
Terms indicating sexual orientation, including slang terms Examples: bisexual; gay; straight |
CPRA, GDPR, GDPR Sensitive, APPI Sensitive |
SSN |
Social Security Numbers or international equivalent government identification numbers Examples: 078-05-1120; ***-***-3256 |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI |
Time |
Expressions indicating clock times Examples: 19:37:28; 10pm EST |
CCI |
URL |
Internet addresses Example: www.private-ai.com |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, CCI |
Username |
Usernames, login names, or handles Examples: privateairocks; @_PrivateAI |
CPRA, GDPR, APPI |
Vehicle ID |
Vehicle identification numbers (VINs), vehicle serial numbers, and license plate numbers Examples: 5FNRL38918B111818; BIF7547 |
CPRA, GDPR, HIPAA_SAFE_HARBOR, APPI, CCI |
Zodiac sign |
Names of Zodiac signs Examples: Aries; Taurus |
Table 2 PHI data labels
Label | Description |
Policy & Regulatory Compliance |
---|---|---|
Blood type |
Blood types Example: She's type AB positive |
CPRA, GDPR, Quebec Privacy Act |
Condition |
Names of medical conditions, diseases, syndromes, deficits, disorders Examples: chronic fatigue syndrome; arrhythmia; depression |
CPRA, GDPR, Quebec Privacy Act, APPI Sensitive |
Dose |
Medically prescribed quantity of a medication Example: limit intake to 700 mg/day |
HIPAA_SAFE_HARBOR, Quebec Privacy Act, CCI |
Drug |
Medications, vitamins, and supplements Examples: advil; Acetaminophen; Panadol |
HIPAA_SAFE_HARBOR, CCI |
Injury |
Bodily injuries, including mutations, miscarriages, and dislocations Examples: I broke my arm; I have a sprained wrist |
CPRA, GDPR, Quebec Privacy Act, APPI Sensitive |
Medical process |
Medical processes, including treatments, procedures, and tests Examples: heart surgery; CT scan |
CPRA, GDPR, Quebec Privacy Act, APPI Sensitive, CCI |
Statistics |
Medical statistics Example: 18% of patients |
Quebec Privacy Act |
Table 3 PCI data labels
Label | Description |
Policy & Regulatory Compliance |
---|---|---|
Bank account |
Bank account numbers and international equivalents, such as IBAN Example: Acct. No.: 012345-67 |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI, CCI |
Credit card |
Credit card numbers Examples: 0123 0123 0123 0123 **** **** ****4252 Includes debit, ATM, Direct Debit, PrePay, Charge Cards, and support for cards that do not have 16 digits such as American Express or China UnionPay cards. Flags mentions of complete numbers as well as the last four digits only. |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI, CCI |
Credit card expiration |
Expiration date of a credit card Example: Expires: July 2023; Exp: 02/28 |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI |
CVV |
3- or 4-digit card verification codes and equivalents Example: CVV: 080 Includes institution-specific variants: American Express: CID (card ID), CVD (card verification data) CSC / 3CSC (card security code) China UnionPay: CVN (card validation number) CIBC Mastercard: SPC (signature panel code) Discover: CID (card ID), CVD (card verification data) ELO (Brazil): CVE (Elo verification code) JCB (Japan Credit Bureau): CAV (card authentication value) Mastercard: CVC (card validation code) VISA: CVV (card verification value) |
CPRA, GDPR, HIPAA_SAFE_HARBOR, Quebec Privacy Act, APPI, CCI |
Routing number |
Routing number associated with a bank or financial institution Example: 012345678 Includes international equivalents: Canadian & British sort codes, Australian BSB numbers, Indian Financial System Codes, Branch/transit numbers, Institution numbers, and Swift codes |
CCI |
Comments
0 comments
Please sign in to leave a comment.