PII (Personally Identifiable Information) on Your Website – How to Protect Your Customers

The security of personally identifiable information (PII) is an important and often overlooked consideration when gathering customer data through a web-based form. Understanding and managing personally identifiable information is getting a lot more focus in light of the recent GDPR laws coming into effect.

PII is defined as:

“Any information that permits the identity of an individual to be directly or indirectly inferred, including any information that is linked or linkable to that individual”

PII can range from something as seemingly innocuous as full name and email, to detailed sensitive information like social security number, bank account numbers, and personal passwords.  In the wrong hands, this information can be used to steal the users identify, and/or to aid in the planning of various crimes.  Needless to say, it’s very important that you, as a website owner, are very careful in exactly what information you collect, and how it is used and stored.  The potential damage it can inflict on your customers if compromised is significant, and likewise it can be equally damaging to you through loss of reputation, or worse, substantial litigation.

What are some examples of personally identifiable information (PII)?

  • Names and aliases
  • Social Security number (SSN), full or abbreviated
  • Driver’s license and / or government identification numbers
  • Citizenship, legal status, gender, race/ethnicity
  • Birth date
  • Place of birth
  • Home and personal cell phone numbers
  • Email address
  • Mailing and home address
  • Religious preference
  • Mother’s middle / maiden name
  • Spouse information
  • Marital status
  • Child information
  • Emergency contact information
  • Biometrics
  • Financial information
  • Medical information
  • Disability information

How do you protect personally identifiable information (PII)?

Collect, send, and store as little customer data as possible

Our recommendation at Watermelon is to limit the amount of PII that you collect via your website, and to be especially careful in how this information is stored, and distributed.  In addition, all web forms should be submitted via a secure connection (SSL), so it’s important that a security certificate is enabled for the site (note: our monthly Maintenance, Security & Performance plan now includes Gravity Forms and a 256-bit SSL encryption certificate – absolutely free to clients with a 2-hr or more monthly plan).  Security certificates used to be necessary only for those websites handling e-commerce transactions. We now recommend SSL encryption for any site that collects PII (in other words: most websites).

We do not recommend emailing even basic PII such as name and email address, as even if it is submitted and received via a secure connection, the email path from here to there makes many hops along the way which you have no direct control over, and theoretically messages can be intercepted.  A safer and easier method is to send a simple email stating that a form submission was completed, with a link to the admin area of your site where you can view the submitted information as an administrator over an encrypted connection.

In terms of data storage, WordPress, Magento, and other content management systems that Watermelon Web Works regularly employs for clients are encrypted, so storing information such as name, email, phone number, and other non-sensitive PII is secure.  PII that is considered ‘sensitive PII’ includes social security number, driver’s license number, financial information, any medical or health care information, passport information, etc.  There is also a class of PII that when paired with other information can be considered sensitive PII and as such should be handled in the same manner.  This would include: mother’s maiden name, religion, date of birth, age, gender, school attended, etc.  This information can potentially cause substantial harm, embarrassment, inconvenience, or unfairness to an individual, and as such we do not advise collecting this information via a standard web form.  When asking for any user information via the web, we always emphasize to first ask yourself: “Do we really need this information, and if so, what would be the potential fallout if it was intercepted by nefarious characters?”.  If there is ever any doubt, we strongly advise you to err on the side of caution.  If the information is absolutely required, it is best to encrypt a file containing the PII, and send that via secure email.  If documents containing non-PII must be submitted, it is important that they are stored in a secure directory above the public level of the website to be accessed as needed via secure file transfer protocol.

Privacy Policy

We also advise our clients that collect any PII from their customers to have a professionally written, and highly visible privacy policy.  The safest way to make website users aware of this, is to have a checkbox that is required to submit any form with PII which acknowledges that the user has read to and agrees with the company privacy policy.

PII Privacy Policy

Protect your customers and yourself

In this age of rapid and voluntary personal information distribution via cell phone apps and social media platforms, it is easy (and detrimental) to overlook the potential harm to your customers and your business if PII is intercepted.  However, it is the very nature of today’s modern digital world which makes protecting that information more important than ever, as identify theft, financial fraud, and other horrific crimes are now much easier to perpetrate by would be bad guys if they are able to get their hands on PII.  Protect your customers and yourself by limiting the collection and distribution of this information, and putting in place best practices and maximum protection for anything you must collect.

We take PII seriously, and we can help you do the same. Get in touch to discuss your needs.

Additional Reading

http://www.opin.com/secure-personally-identifiable-information-pii/

https://piwik.pro/blog/what-is-pii-personal-data/

Work With Us

We've been building websites for over twenty years, and have learned a thing or two about how to make web projects go smoothly.

What Our Clients Say

Watermelon Web Works, LLC place picture
4.7
Based on 19 reviews
powered by Google
OMS Anita profile picture
OMS Anita
22:20 29 Nov 24
Watermelon Web Works has been incredible to work with. They are patient, understanding, and quick to answer any questions (or emergencies) you might have. After switching over to them to help re-vamp our online retail store, we hired them to build our wholesale website as well. I can't recommend them enough - Thank you team!
Garrett Lister profile picture
Garrett Lister
19:55 10 Jul 24
Jared and the watermelon team were great - they quickly interpreted our website needs and designed a wonderful site. The project management site worked great to keep track of project.
N B profile picture
N B
21:23 14 Nov 23
My previous web developer who I was very happy with retired and I was pretty sad about it because it seems now days it is hard to hire a web developer close by with a good set of skills who is interested in helping small business at reasonable prices. Then I found Watermelon and I have been very happy. They are responsive, are able to solve problems, and work at reasonable prices.
Dark Star Magick profile picture
Dark Star Magick
18:05 03 May 23
We hired Watermelon to help us with our website. They were very thorough and took the time to explain in layman's terms what they were doing and how we could improve SEO and site functionality. We will definitely be back for future website needs!
Astoria Column profile picture
Astoria Column
18:42 24 Apr 23
Great work and amazing service! We're a non-profit, and our priorities are always focused on maintaining the Astoria Column. We had a website built by someone else a few years ago, but without regular updating and maintenance, sections of our site were no longer functional. Joanna and the rest of the team came in and had everything working within a week and it's been smooth sailing since then!
Ben Harris profile picture
Ben Harris
19:25 26 Aug 19
Watermelon has been a fantastic web development partner. Through every phase of our project they have always been 100% responsive to our requests and have always provided highly knowledgeable, creative, prompt, and personable team members to work with. As a financial institution we’re always concerned about the security and maintenance or our website and Watermelon has always provided the appropriate resources in order to meet and/or exceed our compliance and security requirements. We would surely refer them to any business associates looking for a qualified WordPress web designer in the future. – Denali Federal Credit Union
Mohr IP Law Attorneys profile picture
Mohr IP Law Attorneys
00:33 11 Apr 19
Watermelon Web Works did a great job creating a custom shopping cart page for our firm. Gavynn in particular was especially helpful and responsive. We appreciated the upfront costs and the technical competency of Watermelon Web Works and would not hesitate to work with the people there again.
Kim Markle profile picture
Kim Markle
23:36 08 Feb 19
Our company has been working with the Watermelon team for more than 10 years to help build and grow our website and customer portal. They are not only extremely talented and responsive, but are continuously looking for ways for us to enhance our current website. They are consistent, provide excellent customer service and really know what they are doing. Highly recommend!
Rick Brodner profile picture
Rick Brodner
23:23 12 May 17
I cannot say enough good things about Watermelon. They are terrific communicators, highly competent coders, and really, really nice people. They were instrumental in helping us to assemble a very usable, easily maintainable website for our organization. They' have demonstrated great flexibility in accommodating our evolving needs. They have been highly responsive to any technical issues, typically resolving them in less than 4 hours. Watermelon Web Works will make your organization better, and your CFO/Treasurer will be happy when they see the bill - what more can you ask for?
CLOSE