<?xml version="1.0" encoding="UTF-8"?>
<incident>
  <arrest type="boolean">false</arrest>
  <breach-type-id type="integer">1</breach-type-id>
  <comments-count type="integer">1</comments-count>
  <data-family-id type="integer">1</data-family-id>
  <data-recovered type="boolean">false</data-recovered>
  <disputed type="boolean">false</disputed>
  <fringe type="boolean">false</fringe>
  <fringe-description nil="true"></fringe-description>
  <id type="integer">52</id>
  <lawsuit type="boolean">false</lawsuit>
  <records type="integer">2000</records>
  <submission-id type="integer" nil="true"></submission-id>
  <updated-at type="datetime">2010-03-10T20:23:18Z</updated-at>
  <user-id type="integer" nil="true"></user-id>
  <breach-types type="array">
    <breach_type>
      <name>Hack</name>
    </breach_type>
  </breach-types>
  <data-types type="array">
    <data_type>
      <short_name>SSN</short_name>
    </data_type>
    <data_type>
      <short_name>NAA</short_name>
    </data_type>
  </data-types>
  <timeline-items type="array">
    <timeline_item>
      <first_date>2004-09-23 00:00:00 UTC</first_date>
      <type>Organization reports incident</type>
    </timeline_item>
  </timeline-items>
  <vector>
    <name>Outside</name>
  </vector>
  <primary-organization>
    <business-type-id type="integer">2</business-type-id>
    <freebase-cached-data type="yaml" nil="true"></freebase-cached-data>
    <freebase-description nil="true"></freebase-description>
    <freebase-pref-name nil="true"></freebase-pref-name>
    <id type="integer">49</id>
    <is-private type="boolean" nil="true"></is-private>
    <name>Cal State Hayward</name>
    <stock-symbol nil="true"></stock-symbol>
    <updated-at type="datetime">2008-07-14T22:17:09Z</updated-at>
  </primary-organization>
  <secondary-organizations type="array"/>
  <summary>
    <summary>Over 2,000 notified about server breach</summary>
  </summary>
  <comments type="array">
    <comment>
      <content>I agree you cannot and should not speculate about data breach details, and I apologise if I implied that you should rate the Epsilon breach according to the likelihood that other data was lost.  Yet from the outset it was surely obvious that metadata to do with individuals&#8217; relationships with hotels, banks, airlines and so was also involved.  
But I want to concentrate if I may on the definition of PII and the threshold you set yourselves for the seriousness of PII.  
I actually struggle to find a consistent formal definition of Personally Identifiable Inforrmation, even in the GLBA.  So I assume that PII is more or less the same as the term &quot;Personal Information&quot; which is precisely and consistently defined in jurisdictions like Australia.  To wit: 
&quot;Personal Information is information or an opinion about an individual whose identity is apparent or can reasonably be ascertained from the information&quot;
That is, any information at all about me that is associated with my name, is PII.  That might be &quot;Steve's shoe size is 9&quot;. Or &quot;Steve's email address is swilson@lockstep.com.au&quot;.  And it includes metadata like the name of a file that includes my email address and links it to a pharmaceutical drug of interest.  
If you want to bias the working definition of PII according to a level of certainty that I am actually taking a given drug, versus having a passing interest in it, then you're buying into a complex set of subjective criteria. It is surely better set a low and objective bar and not try to second guess just &quot;how&quot; personal the information is. 
You say that NIST's approach regarding email address is &quot;silly&quot; and you make your own judgement that name + email address needs to be augmented by extra info, like SSN, for it to be counted as 'personal'. Isn't this arbitrary?  And isn't it the case that some e-mail addresses are clearly more revealing than others?  A free cloud email address mickeymouse@cloud.xyz might be anonymous and not PI, whereas corporate addresses like swilson@lockstep.com.au probably indicates my employment. Where do you draw the line?  Why draw a line? 
Finally I am really surprised that datalossdb thinks that disclosing details to a social networking site  in any way alleviates the obligations of companies under privacy principles.  LinkedIn and Epsilon are poles apart.  I tell my professional life story on LinkedIn for a specific purpose, and LinkedIn has a Privacy Policy that circumscribes what they do with my PI.  With Epsilon, few people even knew their details had been exported from the hotels, banks and pharma companies.  
As for telephone books, that&#8217;s a red herring.  Paying for a phone service involves clearly understood conventions about having one&#8217;s name, address and number published, and there is the option of silent numbers. So yes, a phone book is absolutely PII, but it&#8217;s a collection that is clearly consented.  
</content>
      <created_at>2011-05-12 18:24:25 UTC</created_at>
    </comment>
  </comments>
  <location>
    <address>USA</address>
    <thoroughfare_name></thoroughfare_name>
    <dependent_locality_name></dependent_locality_name>
    <locality_name></locality_name>
    <sub_administrative_area_name></sub_administrative_area_name>
    <administrative_area_name></administrative_area_name>
    <postal_code_number></postal_code_number>
    <country_name_code>US</country_name_code>
    <longitude>37.0902</longitude>
    <latitude>-95.7129</latitude>
    <accuracy>1</accuracy>
  </location>
</incident>

