Blog / The data you hold
The data you hold
PII You Did Not Know You Were Holding: Employee Files, Web Forms and the CRM Export
PII hides in employee files, web forms and CRM exports. What counts as personally identifiable information, which laws reach a small business, what to delete.
The mail merge that never went home
The marketing coordinator at a 40-person staffing agency needs to send a holiday card. She asks the recruiting lead for "the candidate list," and the recruiting lead does the easy thing: opens the applicant tracking system, selects all, exports to a spreadsheet. Nine years of candidates. Names, home addresses, mobile numbers, dates of birth, the last four of a Social Security number the old intake form used to ask for, and a notes column with entries like "back injury, cannot lift" and "visa expires March."
The spreadsheet goes to the coordinator by email. She forwards it to the designer at the print shop. The designer saves it to her personal Dropbox so she can work from home. The recruiting lead keeps a copy on his desktop "in case they need it again."
The cards go out on a Tuesday. On Thursday the agency owner, reading about a new state privacy law, asks a simple question: "Where is our candidate data?" The answer is now: in the applicant tracking system, in three inboxes, on one desktop and in a print shop's personal cloud account, with no password on any of the copies and no way to delete them all.
Nothing has been stolen. Nothing needs to be. The exposure already happened when the file left the system that was built to protect it.
What the heck does this mean
Personally identifiable information, PII, is any data that can identify a specific person, alone or combined with something else. Name, email, phone, home address, IP address, date of birth, employee ID. The list is longer than most owners think and it includes your own staff.
Sensitive PII is the subset that does real damage when it leaks: government ID numbers, bank details, health notes, immigration status, biometrics. The "back injury" entry in that notes column is sensitive PII.
A data inventory is the list of every place PII lives, what kind it is, and who can reach it. You cannot protect what you have not listed.
Data minimization means collecting only what you need and deleting it when the need ends. It is the cheapest control there is, because deleted data cannot be breached.
Two things changed this year. In the US, comprehensive state privacy laws now cover businesses far smaller than the giants they were written for. In the UAE, the federal PDPL applies to any organization processing residents' personal data, with no small-business exemption. The spreadsheet in the story is regulated in both countries.
The numbers that matter
Twenty US state comprehensive privacy laws are in effect in 2026, with Indiana, Kentucky and Rhode Island going live on 1 January 2026 (MultiState, 2026). A staffing agency with candidates in six states now answers to several of them.
Rhode Island's law applies at a threshold of 35,000 consumers (Rhode Island state statute, 2026). Nine years of candidates plus a marketing list clears that number without noticing.
The global average cost of a data breach is USD 4.99 million (IBM 2026 Cost of a Data Breach Report). A 40-person business does not pay the average, but the components are the same: investigation, notification letters, legal fees, lost clients.
What to do this week
- Run the inventory. One spreadsheet: system or location, type of PII held, whether it is sensitive, who can access it. Include the HR folder, the CRM, the applicant tracking system, the website form backend, the shared drive and every export you can find in Sent Items. (CIS 3 Data Protection)
- Delete the exports. Search mailboxes and desktops for spreadsheets with names and phone numbers, delete them, and set a rule: exports live in a controlled folder with an expiry date, never in email. (CIS 3 Data Protection)
- Strip the fields you do not need. Remove the Social Security digits and the date of birth from the intake form. Retire the free-text notes column or restrict it to two people. (CIS 3 Data Protection)
- Review who can export. Most CRMs and HR systems let you limit "export all" to named admins. Do that, and check that the departed recruiter's login is disabled. (CIS 5 Account Management)
- Turn on export and download logging in the CRM, the HR platform and your cloud storage, and have someone look at it monthly. The question you will one day need to answer is "who took a copy, and when." (CIS 8 Audit Log Management)
- Write the one-page privacy notice and the retention schedule. Candidates: 24 months after last contact. Employees: per your legal counsel's advice. Then run the deletion. (CIS 3 Data Protection)
Where AccuSights fits
Our assessment finds the PII you did not know you had, including the exports, then maps each store to the laws that reach it and tells you what to delete first. The Cyber Hygiene Test takes three minutes and gives you a score you can show your lawyer. A 15-minute call with an engineer turns the inventory into a short list of fixes with a cost next to each.
We map the assessment to the PDPL and your sector regulator, and our read-only compliance agent shows where personal data sits and which controls have drifted, so you prioritize the right things and keep an eye on them. We have no access and do not remediate. You or your IT partner fix; we show you where.
Questions people ask
What is the difference between PII and sensitive PII? PII is anything that identifies a person: name, email, phone number, IP address, an employee number. Sensitive PII is the subset that causes real harm when exposed: government ID numbers, bank details, health information, biometrics, precise location, and in many laws anything revealing religion, ethnicity or sexual orientation. The practical difference is that sensitive PII needs encryption, tighter access and, under several state laws and the UAE PDPL, explicit consent before you collect it.
How long can I keep customer data? As long as you have a reason you could say out loud to the customer. Most privacy laws call this purpose limitation: keep it while it serves the purpose you collected it for, then delete it. A closed candidate file from 2019 has no purpose. Write a retention schedule with a number of months next to each type of record, and have someone actually run the deletion once a quarter.
Do I need a privacy policy if I only sell B2B? Yes. Your customers are companies, but the names, emails and phone numbers in your CRM belong to people, and so do the records of your own employees and job applicants. Several US state laws and the UAE PDPL apply to that data regardless of who signs the invoice. A one-page notice that says what you collect, why, how long you keep it and who to contact is the minimum.
The safest record in your business is the one you deleted last quarter. Nobody has ever had to send a breach letter about that one.
Questions people ask
What is the difference between PII and sensitive PII?
PII is anything that identifies a person: name, email, phone number, IP address, an employee number. Sensitive PII is the subset that causes real harm when exposed: government ID numbers, bank details, health information, biometrics, precise location, and in many laws anything revealing religion, ethnicity or sexual orientation. The practical difference is that sensitive PII needs encryption, tighter access and, under several state laws and the UAE PDPL, explicit consent before you collect it.
How long can I keep customer data?
As long as you have a reason you could say out loud to the customer. Most privacy laws call this purpose limitation: keep it while it serves the purpose you collected it for, then delete it. A closed candidate file from 2019 has no purpose. Write a retention schedule with a number of months next to each type of record, and have someone actually run the deletion once a quarter.
Do I need a privacy policy if I only sell B2B?
Yes. Your customers are companies, but the names, emails and phone numbers in your CRM belong to people, and so do the records of your own employees and job applicants. Several US state laws and the UAE PDPL apply to that data regardless of who signs the invoice. A one-page notice that says what you collect, why, how long you keep it and who to contact is the minimum.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
Client Financial Data: What a Law Firm, CPA or Wealth Advisor Is Really Holding
Client financial data security for law firms, CPAs and advisors: what you are holding, the 30-day breach clocks that now apply, and the folder to lock first.
Practical controlsAudit Logging for a Small Business: What to Keep, for How Long, and How to Stop Your Data Walking Out the Door
Audit logging for a small business: which logs to keep, for how long, and the DLP settings that stop a departing employee taking the whole database with them.
The data you holdCard Data: The Safest Way to Store It Is to Never Touch It
PCI scope reduction in plain terms: why a small business should never store card numbers, what tokenization does, and what changed in SAQ A in 2025.
