Regulated Data
Regulated data is information that must be collected, processed, and stored in compliance with federal and/or state legislation.
A breach is where confidential or regulated data is read, copied, modified, or deleted without authorization.
- can be accidental or intentional and malicious
- a malicious breach is called a data exfiltration
- breaches of regulated data must be reported to the regulator and individuals impacted
Types of Regulated Data
- Personally Identifiable Information (PII)
- Personal Government-Issued Information
- Healthcare Data
- Credit Card Transactions
Data Retention Requirements
- Regulation might set a maximum period for the retention of data.
- Regulation might also demand that information be retained for a minimum period.