{"id":43214,"date":"2011-07-12T01:49:53","date_gmt":"2011-07-12T01:49:53","guid":{"rendered":"https:\/\/wp.lansa.com\/blog\/protect-customers-pii"},"modified":"2025-05-08T03:27:23","modified_gmt":"2025-05-08T08:27:23","slug":"protect-customers-pii","status":"publish","type":"post","link":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/","title":{"rendered":"Protect Your Customers\u2019 PII (Personally Identifiable Information)"},"content":{"rendered":"<p>Personally Identifiable Information (PII) is the sensitive information that can be used to uniquely identify the flesh and blood people that are our staff, partners, vendors \u2014 and especially our customers.<\/p>\n<p>Some examples include: name, birth date, address, government issued\u00a0ID numbers, email, credit card, bank account, user\u00a0ID and password. As technology evolves, biometric data and even DNA sequences will make the list as well!<\/p>\n<p>Occurrences of leaked PII make headlines quickly and can be very damaging to organizations.<\/p>\n<p>To get a sense of this, just google <a href=\"http:\/\/www.google.com\/search?q=sony+playstation+security+breach\" target=\"_blank\" rel=\"noopener noreferrer\"><em>sony playstation security breach<\/em> <\/a>and you\u2019ll be met with a flurry of customer dissatisfaction, lawsuits and real losses in revenue and market share. Fortunately for Sony, the majority of their online gamers are <em>loyal<\/em> (read <em>addicted<\/em>) and have flocked back after the network came back up a month later.<\/p>\n<p>Will your customers be as forgiving should their PII be leaked? Let\u2019s not find out \u2026<\/p>\n<p>It may be tempting to dive in and just start scrambling sensitive data, but as with any project, we need to do some planning first.<!--more--><\/p>\n<h2>Make your Plan<\/h2>\n<p>Here are 5 steps to create your own PII privacy plan:<\/p>\n<h3>Step 1 &#8211; Identify PII<\/h3>\n<p>Take your customer\u2019s perspective: what would they not want published on the Internet? Note that groups of seemingly harmless information can combine as PII (e.g., postal code, birth date, gender).\u00a0 If in doubt, include it.<\/p>\n<h3>Step 2 \u2013 Check with Authorities<\/h3>\n<p>List all related legislation, government guidelines, requirements for standards compliance and your own organization\u2019s privacy policies. A few examples that may apply to you are: <a href=\"https:\/\/www.pcisecuritystandards.org\/document_library?category=pcidss&amp;document=pci_dss\" target=\"_blank\" rel=\"noopener noreferrer\">PCI-DSS<\/a>, <a href=\"https:\/\/www.ncga.state.nc.us\/EnactedLegislation\/Statutes\/PDF\/ByArticle\/Chapter_75\/Article_2A.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Identity Theft Protection Act<\/a>, <a href=\"https:\/\/www.gpo.gov\/fdsys\/pkg\/PLAW-111publ318\/pdf\/PLAW-111publ318.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Social Security Protection Act of 2010<\/a>, <a href=\"http:\/\/laws-lois.justice.gc.ca\/eng\/acts\/P-8.6\/\" target=\"_blank\" rel=\"noopener noreferrer\">PIPEDA<\/a>, <a href=\"https:\/\/www.hhs.gov\/hipaa\/index.html\" target=\"_blank\" rel=\"noopener noreferrer\">HIPAA<\/a>. Your customers and the government will not be very forgiving if you plead ignorance, so consult with industry groups, security specialists and read up!<\/p>\n<h3>Step 3 \u2013 What\u2019s Your PII Lifecycle?<\/h3>\n<p>To know how to protect PII, first you need to consider its lifecycles in your organization. If you\u2019re lucky enough to have documented your organization\u2019s workflows, take a second pass through each with an eye on PII privacy.\u00a0Here\u2019s a high-level sample lifecycle:<br \/>\n<a href=\"\/wp-content\/uploads\/2022\/06\/lifecycle.jpg\" data-lightbox=\"lifecycle\"><br \/>\n<img decoding=\"async\" class=\"aligncenter wp-image-1253 size-full\" title=\"PII Lifecycle\" src=\"\/wp-content\/uploads\/2022\/06\/lifecycle.jpg\" alt=\"PII Lifecycle\" width=\"300\" height=\"224\" \/><br \/>\n<\/a><br \/>\n<a href=\"\/wp-content\/uploads\/2022\/06\/PII-Table.png\" data-lightbox=\"PII-Table\"><br \/>\n<img decoding=\"async\" class=\"aligncenter wp-image-1258 size-full\" title=\"PII Lifecycle Steps\" src=\"\/wp-content\/uploads\/2022\/06\/PII-Table.png\" alt=\"PII Lifecycle Steps\" width=\"540\" height=\"90\" \/><br \/>\n<\/a><\/p>\n<p>No doubt, your organization\u2019s PII lifecycles will differ. This is not an issue if you know what they are.<\/p>\n<h3>Step 4 \u2013 Target Technologies<\/h3>\n<p>You now need to match technologies and techniques to each element of PII in your PII lifecycle.<\/p>\n<p>If you\u2019re the type that spends evenings and weekends monitoring <a href=\"http:\/\/www.hackerwatch.org\/\" target=\"_blank\" rel=\"noopener noreferrer\">hackerwatch.org<\/a> <em>(my condolences)<\/em>, this may be a simple task. Others may be advised to seek some expertise from your trusted technology provider.<\/p>\n<p>Let\u2019s consider an example.\u00a0You\u2019re a federal electric utility with a desire to survey your customers on their consumption habits and willingness to support <em>green<\/em> initiatives.\u00a0Funny \u2026 this was <em>supposed<\/em> to be a fictitious example, but then I easily found a <a href=\"https:\/\/sse.co.uk\/forms\/energy-efficiency-form\" target=\"_blank\" rel=\"noopener noreferrer\">Scottish Hydro survey<\/a>. Cool! The publicly available online form is capturing: name, email, age range, telephone, address, house ownership status, government benefits, house features and the appetite for green initiatives.<\/p>\n<p>Now let\u2019s go through the high-level PII lifecycle mentioned above and see what technologies can help us.<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-1261 size-full\" title=\"Capture\" src=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/capture.jpg\" alt=\"Capture\" width=\"80\" height=\"49\" \/><\/p>\n<p>Standard 128 bit SSL Encryption should be used to protect the data stream between the user\u2019s browser and the web server. That way, if the data stream is intercepted, it\u2019s worthless to a hacker.<\/p>\n<p><a href=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/transform.jpg\"><img decoding=\"async\" class=\"alignnone wp-image-1263 size-full\" title=\"Transform\" src=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/transform.jpg\" alt=\"Transform\" width=\"80\" height=\"48\" \/><\/a><\/p>\n<p>SSL protection ends when the data hits your web application, so all the PII is in memory in clear text format.\u00a0At this point, additional data could be combined before storage. Maybe the house features are combined to predict an overall energy efficiency rating. Maybe the address is cross-referenced to an existing utility account number.\u00a0Maybe the data on home ownership, government benefits and appetite for going green are combined to create a marketing priority level (i.e., the homeowner has money and wants green energy).\u00a0You can start to see how a simple survey becomes powerful information \u2013 in good hands or bad.<\/p>\n<p><a href=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/store.jpg\"><img decoding=\"async\" class=\"alignnone wp-image-1264 size-full\" title=\"Store\" src=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/store.jpg\" alt=\"Store\" width=\"80\" height=\"49\" \/><\/a><\/p>\n<p>Storing the data is really the <em>key<\/em> <em>(pun intended)<\/em>.\u00a0You have a lot of options:<\/p>\n<p><strong>Clear text<\/strong> is perhaps the default of most developers. After all, you have a physically secure building, network security and security on the database objects themselves right? Umm \u2026 wrong. You don\u2019t want to rely on these layers alone. All it takes is one disgruntled insider and all your customer survey PII is exposed \u2014 and now your organization is backpedaling for years!<\/p>\n<p><strong>Data scramble<\/strong> This is my own non-technical categorization of little custom\u00a0algorithms to modify data before storage.\u00a0For example, change the order of the characters, mix with some predefined static characters, use the ASCII 3-digit equivalent of each byte of data and perform some mathematical operation like multiplying by 47. This approach will stop a <em>snoop<\/em> but not a motivated <em>hacker<\/em>.<\/p>\n<p><strong>Hash<\/strong> functions like MD5 and SHA-2 scramble the data in more sophisticated ways and produce harder to decipher output.\u00a0They&#8217;re relatively simple to implement and pretty common.\u00a0Unfortunately, they&#8217;re so common that hackers have some pretty common attacks to break them.\u00a0Going back to the most recent headlines, Sony indicates that their data was hashed.\u00a0If a couple of customers\u2019 records were leaked, the hash would have deterred most hackers, but in this case 77 million records were leaked \u2014 enough to make the computing effort of hash-cracking worthwhile for the nefarious.\u00a0One other practical limitation of hash algorithms is that they are <em>one-way<\/em>.\u00a0For example, for an application to see if a user supplied a valid password, it must MD5-hash their password and compare to see if it matches the MD5-hashed value in the database.\u00a0One cannot just run the hashed value through some algorithm to get back the clear text.<\/p>\n<p><strong>Encryption<\/strong> uses a more sophisticated algorithm involving large prime numbers, mod and exponentiation.\u00a0Public key cryptography (RSA) is the basis of SSL. With large enough numbers, it\u2019s generally considered the gold standard.\u00a0Also, unlike hash functions which are one-way, encryption has two keys.\u00a0The public key is used for encryption while the private key is used for decryption. The cool part is that knowing the public key doesn\u2019t help you decipher anything.\u00a0Of course, it&#8217;s critical that the private key remain private!\u00a0However, even encryption has limitations.\u00a0If the same public key is used, two encrypted messages will have the same cipher.\u00a0So, you may not know what postal code a person has by looking at the encrypted data, but you\u2019ll know that they share a postal code with 200 other people on file.\u00a0If somehow you determine one, you have them all.<\/p>\n<p><strong>Tokenization<\/strong> is a step beyond encryption.\u00a0Tokenization aims to create a <em>data vault<\/em> in which all PII is kept.\u00a0Outside the data vault, the operational database contains only <em>tokens<\/em> to the data in the vault.\u00a0The data in the vault is encrypted such that it is virtually useless to a hacker. The tokens themselves are typically unique keys, which when appropriately passed to the <em>token server<\/em> get you back the clear text data.\u00a0You could just as easily store the encrypted data in the operational database, but then your database would need to accommodate very long strings for each encrypted PII field \u2014 this can pose problems especially when retrofitting security into an existing system.\u00a0If the data tokens in the operational database need to be readable for pragmatic purposes (e.g., last 4 digits of a customer\u2019s phone number for CSRs to validate a caller), that can be left in clear format \u2014\u00a0either as part of the token or in a separate database field.\u00a0As with any encryption, the decryption key(s) need to be stored in the most secured location possible, entrusted to a bare minimum of individuals.<\/p>\n<p>The above options for PII storage go from simple to sophisticated. There\u2019s no one right answer for all situations, so consider your needs and consult an expert.<\/p>\n<p><a href=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/com_.jpg\"><img decoding=\"async\" class=\"alignnone wp-image-1265 size-full\" title=\"Comm\" src=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/com_.jpg\" alt=\"Comm\" width=\"80\" height=\"52\" \/><\/a><\/p>\n<p>Using and communicating data has always been a part of business, but with the advent of websites, email engines, web services and other automated interchange methods, data is being transmitted en masse outside of your organization more than ever.\u00a0Use and communication of PII should be <em>planned<\/em>.\u00a0Who should be exposed to it?\u00a0Why?\u00a0In turn, how will they respect PII privacy?\u00a0For new initiatives (like the electric utility survey), a <em>privacy policy<\/em> should be created or affirmed and published.\u00a0For PII in the more traditional business, communication of a privacy policy may not be appropriate \u2014\u00a0but rather may be governed by contracts such as confidentiality agreements.\u00a0Regardless, the process is similar: plan and implement your PII communications and ensure your policies or contracts match.<\/p>\n<p><a href=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/copy.jpg\"><img decoding=\"async\" class=\"alignnone wp-image-1266 size-full\" title=\"Copy\" src=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/copy.jpg\" alt=\"Copy\" width=\"80\" height=\"50\" \/><\/a><\/p>\n<p>Beyond &#8220;copying&#8221; of data for communications as outlined above, organizations often create copies of data for dashboards, reports, marketing, telemarketing, etc.\u00a0In our example, marketing will no doubt want access to the survey database so that they can run queries, extract the data to an Excel pivot table, feed email campaigns, etc. Without proper encryption in the database, control over PII would quickly be lost, or left up to the <em>honor system<\/em>. Under the tokenization approach, users can be given more freedom to query the operational database, because it is only through authorized applications that PII is available in clear text format.<\/p>\n<p>System backups and mirroring create copies of the database as well.\u00a0Without proper encryption in the database, the backup media\/disk needs to be secured and controlled as much as the original. With proper encryption techniques, there is no readable PII in the database to worry about.<\/p>\n<p><a href=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/destroy.jpg\"><img decoding=\"async\" class=\"alignnone wp-image-1267 size-full\" title=\"Destroy\" src=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/destroy.jpg\" alt=\"Destroy\" width=\"80\" height=\"54\" \/><\/a><\/p>\n<p>This one is pretty simple, and no special technology is required. When you no longer need the PII for any important reason, destroy it by permanently deleting the associated records in the data vault. Note that the data tokens can remain in your operational database if desired \u2013 for historical reporting etc. Purging PII from data backups happens naturally. As your organization may only keep a 30-day cycle of nightly backed-up data, the PII will be removed over time.<\/p>\n<h3>Step 5 \u2013 Implement &amp; Monitor<\/h3>\n<p>Your research is done, requirements defined, PII policies and contracts written and technologies chosen for each aspect of your PII lifecycles.\u00a0Now it\u2019s time to plan the project and implement the chosen solutions.<\/p>\n<p>Like any project, one needs to determine the ROI and ensure all interested parties are onboard.\u00a0Your executives need to understand the risks of a PII breach, and your staff needs to believe in the security measures to be implemented.<\/p>\n<p>Each operating system (Windows, iSeries, Linux, etc.) and DBMS (SQL, DB2, Oracle, etc.) has its own features for hashing and encryption available to the development platform.\u00a0The architecture for tokenization is a little more complex \u2013 with a token sever in the mix.\u00a0Depending on your comfort with the subject matter, you may want to engage a technology partner to help with planning and implementation.\u00a0I welcome your questions.\u00a0<a href=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/Smiley-Face-3.png\"><img decoding=\"async\" class=\"alignnone wp-image-1238 size-full\" title=\"Smiley Face\" src=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/Smiley-Face-3.png\" alt=\"Smiley Face\" width=\"15\" height=\"15\" \/><\/a><\/p>\n<p>Once your PII protection solution is developed, tested and implemented, you can rest \u2013 sort of.\u00a0You now need to monitor activities to ensure that operations are not being unduly restricted, and that PII access patterns are as expected.\u00a0Hopefully your implementation includes logging and alerts which red-flag unauthorized or unexpected accesses (or attempted accesses) to PII information.\u00a0For example, if you detect an unusual pattern of requests to your token server from a particular user, perhaps they are using their access via authorized applications to build their own little clear-text database.<\/p>\n<p>As with monitoring any security measure, no news is good news \u2013 your deterrent is working.<\/p>\n<h2>Futures<\/h2>\n<p>As mentioned, many governments and member groups have already created policies, certifications and laws around the handling of PII.\u00a0With collections of PII becoming larger and more valuable, initiatives like PCI-DSS and HIPAA will no doubt become more prevalent in the future.<\/p>\n<p>With so much hype around cloud-based solutions and data being held on third-party servers, standards and technologies for PII privacy will have to evolve quickly.\u00a0Tokenization appears to be the emerging approach for large volume high value PII data.\u00a0However, right now it is basically implemented at the application layer.<\/p>\n<p>I predict that encryption and tokenization will descend to the layers of the data repository or DBMS.\u00a0In the not too distant future, I can envision the architect or database designer simply clicking checkboxes to nominate fields of information as PII and selecting one of several available standard protections schemes.\u00a0This would provide a very valuable level of abstraction and relieve the burden from the application developer.<\/p>\n<p>Taking this one step further, PII protection services implemented at the repository or DBMS layer will no doubt become a value-add feature of more and more cloud offerings.\u00a0It\u2019s a pretty easy sell \u2013 if you want to avoid a crippling PII leak and you can\u2019t make sense of the latest laws and standards, entrust it all to someone who can, and will maintain the necessary compliance on your behalf.<\/p>\n<p>Of course, with all this data centralized in cloud offerings, the stakes will go up for the hackers as well! Hmm \u2026<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Personally Identifiable Information (PII) is the sensitive information that can be used to uniquely identify the flesh and blood people that are our staff, partners, vendors \u2014 and especially our customers. Some examples include: name, birth date, address, government issued\u00a0ID numbers, email, credit card, bank account, user\u00a0ID and password. As technology evolves, biometric data and [&hellip;]<\/p>\n","protected":false},"author":76,"featured_media":43120,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[77],"tags":[],"class_list":["post-43214","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-rapid-app-development"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Protect Customer PII: Security Best Practices | LANSA<\/title>\n<meta name=\"description\" content=\"Protect your customers&#039; Personally Identifiable Information (PII) with security best practices. Learn how with LANSA.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Protect Your Customers\u2019 PII (Personally Identifiable Information)\" \/>\n<meta property=\"og:description\" content=\"Protect your customers&#039; Personally Identifiable Information (PII) with security best practices. Learn how with LANSA.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/\" \/>\n<meta property=\"og:site_name\" content=\"LANSA\" \/>\n<meta property=\"article:published_time\" content=\"2011-07-12T01:49:53+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-08T08:27:23+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/lifecycle.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"300\" \/>\n\t<meta property=\"og:image:height\" content=\"224\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Steve Collins\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Steve Collins\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/\"},\"author\":{\"name\":\"Steve Collins\",\"@id\":\"https:\\\/\\\/lansa.com\\\/#\\\/schema\\\/person\\\/13b9b651b2b4f2bb0798cbfd42ddb444\"},\"headline\":\"Protect Your Customers\u2019 PII (Personally Identifiable Information)\",\"datePublished\":\"2011-07-12T01:49:53+00:00\",\"dateModified\":\"2025-05-08T08:27:23+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/\"},\"wordCount\":2170,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/lansa.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/lansa.com\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/lifecycle.jpg\",\"articleSection\":[\"Rapid Application Development\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/\",\"url\":\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/\",\"name\":\"Protect Customer PII: Security Best Practices | LANSA\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/lansa.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/lansa.com\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/lifecycle.jpg\",\"datePublished\":\"2011-07-12T01:49:53+00:00\",\"dateModified\":\"2025-05-08T08:27:23+00:00\",\"description\":\"Protect your customers' Personally Identifiable Information (PII) with security best practices. Learn how with LANSA.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/#primaryimage\",\"url\":\"https:\\\/\\\/lansa.com\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/lifecycle.jpg\",\"contentUrl\":\"https:\\\/\\\/lansa.com\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/lifecycle.jpg\",\"width\":300,\"height\":224,\"caption\":\"Lifecycle\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/lansa.com\\\/blog\\\/app-development\\\/rapid-app-development\\\/protect-customers-pii\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/lansa.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Application Development\",\"item\":\"https:\\\/\\\/lansa.com\\\/blog\\\/category\\\/app-development\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Rapid Application Development\",\"item\":\"https:\\\/\\\/lansa.com\\\/blog\\\/category\\\/app-development\\\/rapid-app-development\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Protect Your Customers\u2019 PII (Personally Identifiable Information)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/lansa.com\\\/#website\",\"url\":\"https:\\\/\\\/lansa.com\\\/\",\"name\":\"LANSA\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/lansa.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/lansa.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/lansa.com\\\/#organization\",\"name\":\"LANSA\",\"url\":\"https:\\\/\\\/lansa.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/lansa.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/lansa.com\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/Lansa_ID_Logo.png\",\"contentUrl\":\"https:\\\/\\\/lansa.com\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/Lansa_ID_Logo.png\",\"width\":140,\"height\":51,\"caption\":\"LANSA\"},\"image\":{\"@id\":\"https:\\\/\\\/lansa.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/lansa.com\\\/#\\\/schema\\\/person\\\/13b9b651b2b4f2bb0798cbfd42ddb444\",\"name\":\"Steve Collins\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/88a75b5a61f8f9e499360f952447e55d5c2515a42b152ec7f12ac7bdf91ba422?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/88a75b5a61f8f9e499360f952447e55d5c2515a42b152ec7f12ac7bdf91ba422?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/88a75b5a61f8f9e499360f952447e55d5c2515a42b152ec7f12ac7bdf91ba422?s=96&d=mm&r=g\",\"caption\":\"Steve Collins\"},\"description\":\"LANSA Services Director specializing in enterprise IT strategy, system design, large-scale software implementation, and technology project management.\",\"url\":\"https:\\\/\\\/lansa.com\\\/blog\\\/author\\\/stevec\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Protect Customer PII: Security Best Practices | LANSA","description":"Protect your customers' Personally Identifiable Information (PII) with security best practices. Learn how with LANSA.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/","og_locale":"en_US","og_type":"article","og_title":"Protect Your Customers\u2019 PII (Personally Identifiable Information)","og_description":"Protect your customers' Personally Identifiable Information (PII) with security best practices. Learn how with LANSA.","og_url":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/","og_site_name":"LANSA","article_published_time":"2011-07-12T01:49:53+00:00","article_modified_time":"2025-05-08T08:27:23+00:00","og_image":[{"width":300,"height":224,"url":"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/lifecycle.jpg","type":"image\/jpeg"}],"author":"Steve Collins","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Steve Collins","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/#article","isPartOf":{"@id":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/"},"author":{"name":"Steve Collins","@id":"https:\/\/lansa.com\/#\/schema\/person\/13b9b651b2b4f2bb0798cbfd42ddb444"},"headline":"Protect Your Customers\u2019 PII (Personally Identifiable Information)","datePublished":"2011-07-12T01:49:53+00:00","dateModified":"2025-05-08T08:27:23+00:00","mainEntityOfPage":{"@id":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/"},"wordCount":2170,"commentCount":0,"publisher":{"@id":"https:\/\/lansa.com\/#organization"},"image":{"@id":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/#primaryimage"},"thumbnailUrl":"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/lifecycle.jpg","articleSection":["Rapid Application Development"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/","url":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/","name":"Protect Customer PII: Security Best Practices | LANSA","isPartOf":{"@id":"https:\/\/lansa.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/#primaryimage"},"image":{"@id":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/#primaryimage"},"thumbnailUrl":"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/lifecycle.jpg","datePublished":"2011-07-12T01:49:53+00:00","dateModified":"2025-05-08T08:27:23+00:00","description":"Protect your customers' Personally Identifiable Information (PII) with security best practices. Learn how with LANSA.","breadcrumb":{"@id":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/#primaryimage","url":"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/lifecycle.jpg","contentUrl":"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/lifecycle.jpg","width":300,"height":224,"caption":"Lifecycle"},{"@type":"BreadcrumbList","@id":"https:\/\/lansa.com\/blog\/app-development\/rapid-app-development\/protect-customers-pii\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/lansa.com\/"},{"@type":"ListItem","position":2,"name":"Application Development","item":"https:\/\/lansa.com\/blog\/category\/app-development\/"},{"@type":"ListItem","position":3,"name":"Rapid Application Development","item":"https:\/\/lansa.com\/blog\/category\/app-development\/rapid-app-development\/"},{"@type":"ListItem","position":4,"name":"Protect Your Customers\u2019 PII (Personally Identifiable Information)"}]},{"@type":"WebSite","@id":"https:\/\/lansa.com\/#website","url":"https:\/\/lansa.com\/","name":"LANSA","description":"","publisher":{"@id":"https:\/\/lansa.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/lansa.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/lansa.com\/#organization","name":"LANSA","url":"https:\/\/lansa.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lansa.com\/#\/schema\/logo\/image\/","url":"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/Lansa_ID_Logo.png","contentUrl":"https:\/\/lansa.com\/wp-content\/uploads\/2022\/06\/Lansa_ID_Logo.png","width":140,"height":51,"caption":"LANSA"},"image":{"@id":"https:\/\/lansa.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/lansa.com\/#\/schema\/person\/13b9b651b2b4f2bb0798cbfd42ddb444","name":"Steve Collins","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/88a75b5a61f8f9e499360f952447e55d5c2515a42b152ec7f12ac7bdf91ba422?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/88a75b5a61f8f9e499360f952447e55d5c2515a42b152ec7f12ac7bdf91ba422?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/88a75b5a61f8f9e499360f952447e55d5c2515a42b152ec7f12ac7bdf91ba422?s=96&d=mm&r=g","caption":"Steve Collins"},"description":"LANSA Services Director specializing in enterprise IT strategy, system design, large-scale software implementation, and technology project management.","url":"https:\/\/lansa.com\/blog\/author\/stevec\/"}]}},"_links":{"self":[{"href":"https:\/\/lansa.com\/wp-json\/wp\/v2\/posts\/43214","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lansa.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lansa.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lansa.com\/wp-json\/wp\/v2\/users\/76"}],"replies":[{"embeddable":true,"href":"https:\/\/lansa.com\/wp-json\/wp\/v2\/comments?post=43214"}],"version-history":[{"count":6,"href":"https:\/\/lansa.com\/wp-json\/wp\/v2\/posts\/43214\/revisions"}],"predecessor-version":[{"id":71338,"href":"https:\/\/lansa.com\/wp-json\/wp\/v2\/posts\/43214\/revisions\/71338"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lansa.com\/wp-json\/wp\/v2\/media\/43120"}],"wp:attachment":[{"href":"https:\/\/lansa.com\/wp-json\/wp\/v2\/media?parent=43214"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lansa.com\/wp-json\/wp\/v2\/categories?post=43214"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lansa.com\/wp-json\/wp\/v2\/tags?post=43214"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}