Hacker News new | ask | show | jobs
by sprayk 2584 days ago
Does having a table called "users" with usernames, emails, password hashes, and last logged in timestamps count as customer data?
2 comments

Yes. Emails are 100% PII. Even user names can be argued to be.
The term "personally identifying information" does not occur anywhere in the text of GDPR; the regulations use the term "personal data", which is defined differently.

I raise this issue in almost every thread about GDPR, because although it might seem pedantic, the error strongly implies that people have not read or understood the legislation. The difference between personal data and personal identifiers is integral to GDPR and the legislation cannot be understood without fully understanding that distinction and the implications that follow from it.

https://gdpr-info.eu/art-4-gdpr/

It counts as personal data, and as such, under the GDPR you have a duty to handle that data sensibly and responsibly.