Privacy and preparation
Sensitive personal information hiding in work records
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Sensitive personal information hides in ordinary work records: health remarks on dispatch tickets, card numbers in billing emails, immigration status in HR threads and precise location trails in fleet systems. Map each sensitive category to the systems where it appears, then exclude record families where it is routine and redact it where it is incidental.
Key takeaways
- Sensitive categories usually appear as side remarks in operating records, not in labeled fields.
- When a record family exists to hold sensitive data, such as HR case files or payroll, exclude it rather than redact it.
- Precise location often comes from devices and file metadata, such as telematics trails and photo tags, rather than typed addresses.
- California gives sensitive personal information extra protection, and some other states require opt-in consent before it is processed.
What counts as sensitive personal information?#
Sensitive personal information is a defined subset of personal information that California's CCPA, as amended by the CPRA, protects more strictly than the rest. Other state privacy laws keep their own lists of sensitive data, which overlap with California's but are not identical.
California's list has been amended more than once, adding categories such as citizenship or immigration status and neural data, so check the current text with counsel. For a licensing project, the harder question is not the definition but where each category turns up in your own records.
- Government identifiers: Social Security, driver's license, state ID and passport numbers.
- An account log-in, financial account, debit card or credit card number in combination with the security code, password or credentials that allow access to the account.
- Precise geolocation.
- Racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, and union membership.
- The contents of mail, email and text messages, unless the business is the intended recipient.
- Genetic data and neural data.
- Biometric information processed to uniquely identify a person.
- Personal information collected and analyzed concerning a person's health, sex life or sexual orientation.
Where does each category show up in work records?#
Each sensitive category shows up in predictable places once you look at how work is actually recorded. The table maps the categories to the systems and record types where they tend to hide in an operating company.
Use it as a starting map, then add rows for your own systems. A recruiting firm's applicant tracking system and a manufacturer's quality system will each add places this table does not list.
| Category | Where it hides | Example record |
|---|---|---|
| Government identifiers | HR onboarding files, vendor setup emails, fleet and driver records | Scanned driver's license attached to a vehicle assignment ticket |
| Log-in or card number with access code | Password reset tickets, billing emails, call transcripts | Customer reads a card number and security code to an agent |
| Precise geolocation | Telematics, dispatch app check-ins, photo metadata | Technician GPS trail stored with each job |
| Ethnic origin, citizenship or immigration status | HR and recruiting records, visa sponsorship email threads | Work authorization discussion in a hiring manager's inbox |
| Religious beliefs | Scheduling notes and accommodation requests | Shift swap approved for a religious observance |
| Union membership | Payroll deductions, grievance correspondence | Union steward copied on a discipline email |
| Health information | Dispatch notes, leave requests, incident reports | 'Customer on oxygen, call before arriving' on a work order |
| Contents of communications | Email and chat archives | Personal messages sent from a work account |
| Biometric data | Time clocks and building access systems | Fingerprint or face templates in a timekeeping export |
| Sex life or sexual orientation | Benefits enrollment, HR complaints | Domestic partner enrollment noted in an HR ticket |
Why operating records are harder than HR files#
Operating records are harder than HR files because sensitive details appear in free text, with no field name to flag them. An HR system tells you where the health and immigration data sits; a dispatch note, a support ticket or a project email does not.
Customers volunteer sensitive facts to get better service: a mobility limitation that affects access to a basement, a medical device that needs power restored first, a religious holiday that rules out an appointment date. Employees do the same in chat when they explain an absence. Each remark is incidental to the work, yet it is the kind of detail state laws treat as sensitive.
Search for these remarks with keyword lists built from your own vocabulary, such as condition names, leave types, accommodation, visa and union, and review samples by hand. Generic detectors catch structured items like card numbers far more reliably than a health remark written in plain English.
Exclude, redact or coarsen: choosing a treatment#
Excluding, redacting and coarsening are the three main treatments for sensitive data, and the right one depends on how central the data is to the record family. The working rule: exclude families that exist to hold sensitive data, redact sensitive remarks inside useful operating records, and coarsen location or time values that still carry analytical value. Card security codes are a clear case for removal: PCI DSS says sensitive authentication data, including card verification codes, is not retained after authorization, even if encrypted, so a code typed into a billing note should not survive into any copy.
Record the treatment for each category in the preparation plan, with its reason. A reviewer who finds an exclusion without a rationale tends to reopen the question; one with a stated rule can check it and move on.
| Treatment | Use when | Examples |
|---|---|---|
| Exclude | The record family exists to hold sensitive data | HR case files, payroll, benefits, workers' compensation, recruiting files with work authorization |
| Redact | Sensitive remarks are incidental to useful records | Health notes on work orders, card numbers in billing tickets, personal details in chat |
| Coarsen | Location or time adds value but not at full precision | GPS points reduced to city or region, timestamps reduced to date |
| Strip metadata | Files carry hidden location or device data | Photo location tags, document author fields |
Why sensitive data raises the bar for licensing#
Sensitive data raises the bar for licensing because state privacy laws attach extra duties to it. California gives consumers a right to limit certain uses of their sensitive personal information, and several other states make opt-in consent a precondition for processing sensitive data.
Those duties apply to personal information, so properly deidentified records sit largely outside them. The standard of review rises, though: a single health remark or card number that survives redaction can turn a deidentified dataset back into one that holds sensitive personal information.
Employee data adds another layer. California's temporary exemptions for employee and business-to-business information expired on January 1, 2023, and the law now covers employees and job applicants. HR-adjacent remarks in email and chat are therefore not exempt simply because they concern staff. Which state laws may apply, and how, is assessed deal by deal with counsel.
Illustrative: an electrical contractor reviews its dispatch history#
Illustrative: a fictional commercial and residential electrical contractor prepares several years of dispatch, estimate and invoice records from its field service software, plus vehicle telematics, for a license focused on how faults are diagnosed and repaired.
The review found health remarks on residential work orders, such as medical equipment that needed power first; driver's license scans attached to vehicle assignment tickets; card numbers in a few billing notes; and GPS trails attached to every job through the telematics integration.
The owner approved four rules: leave out telematics trails and vehicle assignment records entirely, coarsen job locations to city, redact health remarks and card numbers using a reviewed keyword list, and keep HR and payroll out of scope. The remaining records still showed symptoms, diagnoses, parts used and callbacks, which was the point of the license.
How SourceX treats sensitive categories#
SourceX treats sensitive categories as a distinct check in the Preparation step of the SourceX five-step transaction. For each dataset, the privacy record in the SourceX Evidence Packet lists the categories found, the treatment applied to each and what reviewers confirmed, and the supplier signs off on that record before release.
Record families built around sensitive data, such as HR case files and payroll, are generally left out of scope from the start. The fit check that opens a project collects metadata only, so early conversations cover which systems exist rather than what is inside them.
Frequently asked questions
Is a work email address sensitive personal information?
Generally no. A work email address is usually personal information when it identifies a person, but it is not on California's sensitive list. The contents of messages can be sensitive in some situations, so for an email archive the bigger question is what the messages say, not the addresses in the header.
Is everything in our email archive sensitive because it is message content?
Not automatically. California's category covers the contents of mail, email and text messages unless the business is the intended recipient. Customer emails sent to the company generally fall outside it, while personal messages an employee exchanged with others through a work account may fall inside it. Health or other sensitive details in any message still count under their own categories.
Is a customer's service address precise geolocation?
A typed street address is usually treated as ordinary personal information. Under the CCPA, precise geolocation means location data derived from a device and used to locate a person within a small radius the statute sets. The two can combine: an address plus visit times can locate a person as closely as a GPS point. Treat both with care and confirm the classification with counsel.
Do we need consent to license records that contain sensitive data?
Requirements vary by state and by whether the data is still personal information after preparation. Some states require opt-in consent to process sensitive data, and California adds a right to limit its use. The usual approach is to exclude or remove sensitive data before release, then confirm that approach with counsel.
Are photos and attachments a risk?
Yes. Job photos can show faces, license plates, medication or documents on a kitchen table, and image files often carry location metadata. Exclude attachments by default, then add back specific image types only after a review method is agreed and tested on a sample.
Does deidentification remove the sensitive data problem?
Properly deidentified data generally falls outside personal information, including its sensitive categories. The risk is incomplete removal, because sensitive remarks in free text are easy to miss. Test samples specifically for the categories on your map, not only for names and phone numbers.
Sources
- The California legislature ended its 2022 session without extending the CCPA employee and business-to-business exemptions, so they expired on January 1, 2023. Source
- PCI DSS v4.0 Requirement 3.3.1 states that sensitive authentication data, including card verification codes, is not retained after authorization, even if encrypted. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.