Launch day is one week away. Mission control sends a checklist titled Beacon Launch Review.
Comet scans it fast. "Security, privacy, fairness, licenses. Easy. Beacon only watches plants."
Wren opens his sign-in screen design. "What do you notice? You ask every crew member for their age, their phone number and a fingerprint."
"I thought it looked official," Comet says.
Nova hovers over the screen. "Every piece you collect is a piece you must protect," she says. "Which ones does Beacon truly need?"
Comet picks up an eraser. "Maybe fewer than I thought."
Personally identifiable information, or PII, is information that identifies, links, relates to or describes a person.
Examples of PII include age, phone numbers, medical information and biometric data, such as a fingerprint.
Devices, websites and networks can collect information about a user's location.
Scattered personal data, such as location, cookies and browsing history, can be combined to learn a lot about one person.
Information placed online can be used in ways nobody intended, and that can cause harm.
Once information is placed online, it is difficult to delete.
So the safest data to protect is data you never collected. Beacon should ask: does a plant app need this?
| Statement | True or false? |
|---|---|
| Age is an example of PII. | ? |
| Information placed online is always easy to delete. | ? |
| Scattered data can be combined to learn about a person. | ? |
| Networks can collect information about a user's location. | ? |
| Collecting more PII always makes an app safer. | ? |
| Field on Comet's sign-in screen | Kind of data |
|---|---|
| Crew name | Identifies a person |
| Age | PII |
| Phone number | PII |
| Fingerprint | Biometric data, PII |
| Favorite plant | Not needed for any Beacon job |
Strong start, developer. Tomorrow you will put locks and keys on Beacon.