you are viewing a single comment's thread
view the rest of the comments
[–] 14 points 2 years ago (3 children)

PII data at rest (i.e. in a database) must be encrypted.

  • source
  • parent
  • hideshow 3 child comments
  • [–] [S] 1 point 2 years ago (2 children)

    If the DB is running, it's not at rest. Clients side encrypted data would be the way.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago (1 child)
  • [–] [S] 1 point 2 years ago

    The catch is interpretation, which the wiki points out:

    “Inactive data” could be taken to mean data which may change, but infrequently.

    Any company like this one would consider this data "in use" but "inactive" because any person could need a loan at any point.

  • source
  • parent