TechKnowSurge
ISC2 CISSP 2.1 ISC2 CISSP 2.6 CompTIA Security+ 3.3 CompTIA SecurityX 1.4
VideoSecurityFree

Data Types

Data types determine how information must be handled, protected, and whether it falls under legal and regulatory requirements. Key categories include regulated versus non-regulated data, personally identifiable information, protected health information, and business data such as trade secrets and intellectual property.

Complete this video to capture a CTF flag worth 1 point.

About this video

Data classification is the foundation of sound data management, because the type of data an organization holds directly determines how it must be handled, stored, and protected. At the broadest level, data falls into two categories: regulated and non-regulated. Regulated data is subject to specific laws and compliance frameworks, compelling organizations to meet defined standards for its handling. Non-regulated data carries no such legal obligations, though it may still warrant protection depending on its sensitivity or business value. Several data types are particularly relevant in privacy and compliance contexts. Personally identifiable information encompasses any data that can identify an individual, such as names, addresses, and Social Security numbers. Protected health information covers medical records and related health data. Financial and educational records also fall under this umbrella, each governed by their own regulatory frameworks. Beyond the content itself, data can also be distinguished by whether it is human-readable — naturally interpretable by people — or non-human-readable, such as barcodes or encoded formats that require a machine or system to interpret. Organizations also manage a range of business-specific data types that may not be legally regulated but are treated as protected assets. Trade secrets, intellectual property, legal documents, customer records, and employee information all represent data that could cause serious harm to a business if disclosed to unauthorized parties. Intellectual property in particular spans a wide range, from creative works like software, music, and design to proprietary processes that provide a competitive advantage. Regardless of the specific category, understanding what type of data is involved is the first step toward applying the appropriate level of protection and ensuring compliance with any applicable laws or regulations.

What you'll learn

What's covered

Data Types Overview

Aligned to

ISC2 CISSP
2.1 Identify and classify information and assets
2.6 Determine data security controls and compliance requirements
CompTIA Security+
3.3 Compare and contrast concepts and strategies to protect data
CompTIA SecurityX
1.4 Explain how privacy and data sensitivity impact security and business requirements

Key terms

Regulated Data
Data that must comply with specific laws and regulations, compelling organizations to meet defined protection and compliance requirements.
Non-Regulated Data
Data that is not subject to specific legal or regulatory requirements, requiring less formal compliance obligations.
Personally Identifiable Information
PII
Personally Identifiable Information is any data that can be used alone or in combination to identify, contact, or locate an individual, requiring protection under privacy laws and organizational security policies.
Protected Health Information
PHI
Protected Health Information is individually identifiable health data covered under HIPAA that requires specific administrative, physical, and technical safeguards to protect its confidentiality, integrity, and availability.
Internet Protocol
IP
The principal communications protocol for routing packets across network boundaries.
Trade Secret
Confidential business information, such as a unique manufacturing process, that provides a competitive advantage and is protected from disclosure.
Data Loss Prevention
DLP
A set of tools and processes designed to detect and prevent unauthorized access, use, or transmission of sensitive data.

Topics

Data Classification Pii Phi Regulatory Compliance Data Governance Information Security

Transcript

How we manage our different data largely depends on what the data type is, and there's several different data types.

Regulated and Non-Regulated Data

First of all, we just have data that's regulated and data that's non-regulated. There is data that we can collect, or that maybe we have, or maybe that we create, that is non-regulated, that we don't really need to worry as much about from a law and regulation standpoint. Versus regulated means that it has to comply with certain laws and regulations, and we are compelled then to make sure that we are complying with those laws and regulations.

Human Readable and Non-Human Readable

There's also this human readable type, which just means that most people can naturally read something, versus the non-human readable, which means that most people can't naturally read it. An example of this is this barcode right here, which is non-human readable, and a human readable which is the numbers that are underneath it. So this is an example of both non-human readable and human readable.

Personal Data Types

Here are some other data types that privacy often uses, because they're personal, they have to do with us as individuals. One of those is personally identifiable information. This is anything that identifies who I am. Think of things like my name and my social security number and my address, and those type of things personally identify who I am.

There are also other concerns that I have around things like my health information, so there's protected health information, or PHI. Also, a lot of laws and regulations address financial records or educational records. So these are common ones that are protected.

Business Data Types

There are also business data types. These may or may not be protected under law and regulations. Quite often they're not necessarily anything that we have to do anything crazy to protect, but we probably want to, because there's some reason compelling us to protect this. It's an asset to the company, and if it got into the wrong hands we would be concerned about it. So that would be things like trade secrets, or legal information, or intellectual property, IP, financial information, customer information, employee information.

Things that I create is something called intellectual property. So I could create something like a work of art, maybe it's a painting, or maybe it's a video, or maybe it's some sort of music, maybe I'm producing music. That's intellectual property, and there's some protection over this intellectual property.

Not only that, but I could also have a special process that I do, maybe it's a special manufacturing process that no one else does, that gives us a competitive edge. That's called intellectual property, and it's also a trade secret. It's a secret that we have that is part of how we do business, and so we call that a trade secret.

Ultimately, whatever these data types are might force us to comply with certain laws or regulations, or just protect the data to a certain degree to make sure it's safe.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →