That could be gigantic to those who deal with HIPAA, PCI, GLBA, etc. Although I guess this has no impact on the European Union regulations and what they consider PII -- those are much tougher to deal with anyway.
That could be gigantic to those who deal with HIPAA, PCI, GLBA, etc. Although I guess this has no impact on the European Union regulations and what they consider PII -- those are much tougher to deal with anyway.
Just because an IP address alone is not enough to legally beyond doubt identify a person doesn't mean collecting IP addresses in combination with online behavior doesn't violate people's privacy.
These are two fundamentally different things. The only real way to identify someone is through things like DNA or fingerprints. Everything else is just an indication, it may not be enough to serve as evidence in court, but it's definitely personal.
The birthmark on my ass may not be unique, but it doesn't give you the right to collect pictures of it without my permission.
An opposing example to this would be the recent ruling in Massachusetts, and why I found this one so interesting. The court there found that zip codes are PII[2].
[2] http://blog.martindale.com/massachusetts-federal-district-co...