We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / The data you hold

The data you hold

PII You Did Not Know You Were Holding: Employee Files, Web Forms and the CRM Export

PII hides in employee files, web forms and CRM exports. What counts as personally identifiable information, which laws reach a small business, what to delete.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The mail merge that never went home

The marketing coordinator at a 40-person staffing agency needs to send a holiday card. She asks the recruiting lead for "the candidate list," and the recruiting lead does the easy thing: opens the applicant tracking system, selects all, exports to a spreadsheet. Nine years of candidates. Names, home addresses, mobile numbers, dates of birth, the last four of a Social Security number the old intake form used to ask for, and a notes column with entries like "back injury, cannot lift" and "visa expires March."

The spreadsheet goes to the coordinator by email. She forwards it to the designer at the print shop. The designer saves it to her personal Dropbox so she can work from home. The recruiting lead keeps a copy on his desktop "in case they need it again."

The cards go out on a Tuesday. On Thursday the agency owner, reading about a new state privacy law, asks a simple question: "Where is our candidate data?" The answer is now: in the applicant tracking system, in three inboxes, on one desktop and in a print shop's personal cloud account, with no password on any of the copies and no way to delete them all.

Nothing has been stolen. Nothing needs to be. The exposure already happened when the file left the system that was built to protect it.

What the heck does this mean

Personally identifiable information, PII, is any data that can identify a specific person, alone or combined with something else. Name, email, phone, home address, IP address, date of birth, employee ID. The list is longer than most owners think and it includes your own staff.

Sensitive PII is the subset that does real damage when it leaks: government ID numbers, bank details, health notes, immigration status, biometrics. The "back injury" entry in that notes column is sensitive PII.

A data inventory is the list of every place PII lives, what kind it is, and who can reach it. You cannot protect what you have not listed.

Data minimization means collecting only what you need and deleting it when the need ends. It is the cheapest control there is, because deleted data cannot be breached.

Two things changed this year. In the US, comprehensive state privacy laws now cover businesses far smaller than the giants they were written for. In the UAE, the federal PDPL applies to any organization processing residents' personal data, with no small-business exemption. The spreadsheet in the story is regulated in both countries.

The numbers that matter

Twenty US state comprehensive privacy laws are in effect in 2026, with Indiana, Kentucky and Rhode Island going live on 1 January 2026 (MultiState, 2026). A staffing agency with candidates in six states now answers to several of them.

Rhode Island's law applies at a threshold of 35,000 consumers (Rhode Island state statute, 2026). Nine years of candidates plus a marketing list clears that number without noticing.

The global average cost of a data breach is USD 4.99 million (IBM 2026 Cost of a Data Breach Report). A 40-person business does not pay the average, but the components are the same: investigation, notification letters, legal fees, lost clients.

What to do this week

  1. Run the inventory. One spreadsheet: system or location, type of PII held, whether it is sensitive, who can access it. Include the HR folder, the CRM, the applicant tracking system, the website form backend, the shared drive and every export you can find in Sent Items. (CIS 3 Data Protection)
  2. Delete the exports. Search mailboxes and desktops for spreadsheets with names and phone numbers, delete them, and set a rule: exports live in a controlled folder with an expiry date, never in email. (CIS 3 Data Protection)
  3. Strip the fields you do not need. Remove the Social Security digits and the date of birth from the intake form. Retire the free-text notes column or restrict it to two people. (CIS 3 Data Protection)
  4. Review who can export. Most CRMs and HR systems let you limit "export all" to named admins. Do that, and check that the departed recruiter's login is disabled. (CIS 5 Account Management)
  5. Turn on export and download logging in the CRM, the HR platform and your cloud storage, and have someone look at it monthly. The question you will one day need to answer is "who took a copy, and when." (CIS 8 Audit Log Management)
  6. Write the one-page privacy notice and the retention schedule. Candidates: 24 months after last contact. Employees: per your legal counsel's advice. Then run the deletion. (CIS 3 Data Protection)

Where AccuSights fits

Our assessment finds the PII you did not know you had, including the exports, then maps each store to the laws that reach it and tells you what to delete first. The Cyber Hygiene Test takes three minutes and gives you a score you can show your lawyer. A 15-minute call with an engineer turns the inventory into a short list of fixes with a cost next to each.

We map the assessment to the PDPL and your sector regulator, and our read-only compliance agent shows where personal data sits and which controls have drifted, so you prioritize the right things and keep an eye on them. We have no access and do not remediate. You or your IT partner fix; we show you where.

Questions people ask

What is the difference between PII and sensitive PII? PII is anything that identifies a person: name, email, phone number, IP address, an employee number. Sensitive PII is the subset that causes real harm when exposed: government ID numbers, bank details, health information, biometrics, precise location, and in many laws anything revealing religion, ethnicity or sexual orientation. The practical difference is that sensitive PII needs encryption, tighter access and, under several state laws and the UAE PDPL, explicit consent before you collect it.

How long can I keep customer data? As long as you have a reason you could say out loud to the customer. Most privacy laws call this purpose limitation: keep it while it serves the purpose you collected it for, then delete it. A closed candidate file from 2019 has no purpose. Write a retention schedule with a number of months next to each type of record, and have someone actually run the deletion once a quarter.

Do I need a privacy policy if I only sell B2B? Yes. Your customers are companies, but the names, emails and phone numbers in your CRM belong to people, and so do the records of your own employees and job applicants. Several US state laws and the UAE PDPL apply to that data regardless of who signs the invoice. A one-page notice that says what you collect, why, how long you keep it and who to contact is the minimum.

The safest record in your business is the one you deleted last quarter. Nobody has ever had to send a breach letter about that one.

Questions people ask

What is the difference between PII and sensitive PII?

PII is anything that identifies a person: name, email, phone number, IP address, an employee number. Sensitive PII is the subset that causes real harm when exposed: government ID numbers, bank details, health information, biometrics, precise location, and in many laws anything revealing religion, ethnicity or sexual orientation. The practical difference is that sensitive PII needs encryption, tighter access and, under several state laws and the UAE PDPL, explicit consent before you collect it.

How long can I keep customer data?

As long as you have a reason you could say out loud to the customer. Most privacy laws call this purpose limitation: keep it while it serves the purpose you collected it for, then delete it. A closed candidate file from 2019 has no purpose. Write a retention schedule with a number of months next to each type of record, and have someone actually run the deletion once a quarter.

Do I need a privacy policy if I only sell B2B?

Yes. Your customers are companies, but the names, emails and phone numbers in your CRM belong to people, and so do the records of your own employees and job applicants. Several US state laws and the UAE PDPL apply to that data regardless of who signs the invoice. A one-page notice that says what you collect, why, how long you keep it and who to contact is the minimum.

Controls this post maps to

CIS 3 Data ProtectionCIS 5 Account ManagementCIS 8 Audit Log Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.