Sensitive Data
Sensitive data is information that needs protection from unauthorized access or disclosure because its exposure could harm the privacy or security of an individual or organization. It covers a broad range of categories, which can include personal, financial, and other confidential information. In practice, what counts as sensitive depends on the context and the potential impact if the information is exposed or misused.
In general information-security usage, 'sensitive data' (also 'sensitive information') refers to information protected against unwarranted disclosure, where loss, misuse, unauthorized access, or modification could adversely affect an individual or organization. The term is used broadly across categories such as personal, financial, and other confidential data, and its classification is context-dependent, driven by the potential impact of exposure on security, privacy, or integrity. Note that this general usage is distinct from the GDPR concept of 'special category data' (which is a defined subset of personal data subject to additional protective conditions); the evidence packet does not address that regulatory definition, and practitioners should not treat this general definition as coextensive with any specific legal category.
Why it matters
Sensitive data sits at the center of most privacy and security programs because its exposure can adversely affect the security, privacy, or integrity of the individuals or organizations to whom it relates. Loss, misuse, unauthorized access, or modification of such information can cause tangible harm, which is why organizations invest in classification schemes, access controls, and safeguards proportionate to the potential impact of disclosure.
A recurring challenge is that 'sensitive data' as used in general information-security practice is broad and context-dependent, spanning personal, financial, and other confidential information. This general usage should not be confused with more precise regulatory categories. In particular, the GDPR concept of 'special category data' is a defined subset of personal data subject to additional protective conditions, and it is distinct from the wider information-security notion described here. Practitioners who treat the two as interchangeable risk either over-applying strict regulatory requirements to data that is merely confidential, or under-protecting data that triggers specific legal obligations.
Because classification is driven by the potential impact of exposure rather than a fixed list, the boundary of what counts as sensitive can vary between organizations, contexts, and jurisdictions. Teams should document their classification criteria, revisit them as context changes, and verify against applicable legal definitions and current official guidance rather than relying on a single general definition.
Who it's relevant to
Inside Sensitive Data
Common questions
Answers to the questions practitioners most commonly ask about Sensitive Data.