Every major data privacy regulation – GDPR in Europe, CCPA in California, DPDPA in India, PDPA in Singapore and Thailand, PIPEDA in Canada, HIPAA in the United States, is fundamentally about the same thing: protecting the personal data of individuals that organizations collect, use, and maintain.
So, if an organisation needs to answer this question – “Are we compliant?”, then the first step would be to determine what personal data of clients is an organization collecting and how is it being maintained?
Taking a step back, it’s essential to classify the data that is being collected, used, and maintained. The organization also needs to ensure that it has the required consent from individuals to use the data the way it’s being used.
Let’s start with a simple example.
To open a bank account, one must typically submit their Name, Phone Number, Email ID, Address Proof, Identify Proof, Photograph, Income Details to the bank.
For identity proof, the bank may request a government-issued ID such as a passport, driver’s licence, or national identity card. A tax identification number is also commonly required. Depending on the jurisdiction, the same documents may serve both as identity and address proof.
If we were to classify this information, we will start with
Personal Data
Data that can be used to uniquely identify an individual. In this example: name, phone number, email address, and government-issued ID. Any information that can be used to impersonate a person falls into this category and must be protected with the greatest care.
Phone numbers and email addresses can be harvested for spam, scam calls, and phishing attacks. If leaked, this data can be exploited by anyone who obtains it to run targeted campaigns or social engineering attacks.
Under GDPR, this is referred to as “personal data.” CCPA calls it “personal information.” DPDPA uses “personal data.” The label differs across jurisdictions; the sensitivity does not.
Sensitive Data
Next comes the sensitive data. Any information that, if exposed, can cause significant harm to the individual.
Examples include government-issued identity numbers (such as national ID numbers, social security numbers, or tax identifiers), financial account details, biometric data, health and medical records, religious or political beliefs.
The misuse of this data can be severe. A leaked national ID number can be used to open fraudulent bank accounts, apply for loans, create shell companies, or claim government benefits in a victim’s name. In the process exposing them to financial liabilities and legal complications they had no part in creating. Health data, if exposed, can affect insurance eligibility or lead to discrimination. Financial data can enable direct theft.
Sensitive data combined with personal data can allow a fraudster to fully impersonate an individual. Your data is you.
Across regulations, this category attracts the highest obligations. GDPR identifies “special categories of personal data” including health, biometric, genetic, racial, and religious data, and requires explicit consent for their processing. CCPA has a dedicated “sensitive personal information” category with enhanced opt-out rights. DPDPA treats financial data, health data, official identifiers, and biometric data as sensitive. HIPAA in the US provides specific protections for health information.
Children’s Data
This category covers the personal and sensitive data of minors. The critical difference is in how consent must be obtained. Rather than collecting consent from the individual, organizations must obtain it from a parent or legal guardian.
Examples include student name, school enrolment ID, grade level, class and section details, and EdTech platform credentials.
The risks are the same as those described above, but the stakes are higher, because children are less able to recognize misuse or protect themselves.
Importantly, the age threshold for “minor” varies by jurisdiction. GDPR Article 8 sets the default at under 16 (with member states able to lower it to 13). The US Children’s Online Privacy Protection Act (COPPA) applies to children under 13. India’s DPDPA applies to anyone under 18. Organizations operating across multiple jurisdictions must apply the most restrictive threshold relevant to each user’s location.
All major privacy frameworks are aligned on the principle: if you are processing data belonging to a minor, you need verifiable consent from a parent or guardian and you need to be able to prove it.
Non-Sensitive data
Non-Sensitive data
The final category is data that is typically collected alongside personal and sensitive data and used for segmentation, analysis, reporting, and decision-making.
Examples include age group, gender, region, product preferences, and browsing behaviour.
A common misconception is that this data does not need to be protected. It does. Non-sensitive data can be used for phishing, combined with other data for detailed identity profiling, and can trigger regulatory penalties if misused or improperly retained. Even data that appears harmless in isolation can become sensitive when aggregated.
Minimum safeguards like access controls, purpose limitation, and retention limits apply to this category under all major privacy frameworks.
Having understood the data classification, we can now focus on the real question that every organisation has – Are we Compliant?
We explore this in detail in the next blog, using a practical example to show how even well-intentioned organizations often fall short of their data privacy obligations

