Skip to main content
Essay Undergraduate 753 words

Protecting PII: Ethics, Law, and Cybersecurity in Organizations

~4 min read 4 sections Ethics · Organizational Ethics
Abstract

This paper examines Personally Identifiable Information (PII) from both ethical and legal perspectives, focusing on the responsibilities organizations bear when handling client and worker data. It distinguishes between direct PII — such as Social Security numbers and financial records — and linked PII, such as IP addresses and browsing activity. The paper discusses how firms collect PII through web-based tools like cookies, the legal obligations surrounding its use and sale, and the varying levels of confidentiality assigned to different data types. It concludes by noting that user perceptions of privacy often exceed what organizations formally classify as sensitive, highlighting a persistent gap between institutional risk assessment and individual expectations.

Key Takeaways
  • Introduction to PII and Organizational Ethics: Defines PII and frames organizational cybersecurity obligations
  • Collection of PII Online and Legal Obligations: Covers cookie tracking, big data, and legal compliance
  • Web Audit Systems and Data Confidentiality Levels: Examines audit tools and tiered confidentiality ratings
  • User Privacy Perceptions and the Limits of Institutional Classification: Contrasts firm risk ratings with individual privacy expectations
✍️ How to write this paper — guide, tools & examples ▾

What makes this paper effective

  • Clearly defines its central term (PII) at the outset, distinguishing between direct and linked forms — a strong academic move that anchors the entire argument.
  • Moves logically from definition to legal obligation to practical examples (web audit systems, cookie tracking), grounding abstract ethical concerns in concrete organizational scenarios.
  • Ends with an insightful observation about the gap between institutional and individual perceptions of confidentiality, which elevates the paper beyond mere summary into genuine analysis.

Key academic technique demonstrated

The paper effectively uses source authority to support normative claims. By citing NIST guidelines (McCallister et al., 2010), it grounds its ethical arguments in government-recognized standards rather than opinion alone. This technique — anchoring ethical reasoning in regulatory frameworks — is particularly effective in applied technology and information security writing, where credibility depends on alignment with established professional and legal standards.

Structure breakdown

The paper opens with a definition and ethical framing, then shifts to the legal dimensions of online data collection, followed by a practical case study of web audit systems and confidentiality tiering. The final paragraph reframes the discussion around user agency and subjective privacy, offering a critical counterpoint to the firm-centric perspective that dominates the earlier sections. References are formatted in APA style.

Essay 753 words

Introduction to PII and Organizational Ethics

Personally Identifiable Information (PII) is any information that pertains directly to an individual's identity — such as a Social Security number or birthdate — as well as any information that can be linked to an individual, such as health records, education records, or an IP address (McCallister, Grance, & Scarfone, 2010). When it comes to ethically protecting the PII of clients and workers in organizations, information technology and information systems must be engaged to ensure that cybersecurity is a top concern, especially in a digital era where information is power and where hacking accounts and firms is a probable threat regardless of the nature of one's business. Approaching PII from an ethical standpoint — one that holds regard for the personal information of both clients and workers stored by an organization — is a consideration that factors into the risk assessment and risk management guidelines used to create cybersecurity networks (Vacca, 2009).

Collection of PII Online and Legal Obligations

PII is also something that may be collected by firms via the Internet and used to gather information on consumers. For instance, organizations that operate websites can use cookies to track the online movements of Internet users and collect "big data" that can be utilized to develop a better understanding of consumer habits, interests, and how best to market to them (Wambler, 2015). The question this raises is whether the collection and storage of such data — whether on drives or in the cloud — aligns with legal requirements or violates an established ethical and legal code.

As McCallister et al. (2010) observe, firms must obey the laws, guidelines, regulations, and mandates governing the safeguarding of PII. If, for example, a firm wishes to sell PII to a company that wants to use it for marketing purposes, the firm bears the legal responsibility of informing clients that their information will be sold. However, the matter is not as straightforward as it may seem. There are many laws and guidelines regarding the collection and use of PII, and some violations are prosecuted as civil cases while others are handled as criminal cases. Understanding a firm's responsibilities in light of government regulations regarding PII is a reliable way to strengthen one's organization, ensure legal compliance, and guarantee that it is always acting responsibly and ethically with respect to personal data.

2 Sections Hidden · 265 words
Web Audit Systems and Data Confidentiality Levels145 words
By using a web audit system, a firm can monitor and keep track of user information, such as IP addresses, URLs, dates and times, and pages visited. This system would gather a substantial amount of linked PII, which…
User Privacy Perceptions and the Limits of Institutional Classification120 words
PII is not limited to a person's bank account or health records — it also encompasses browsing activity online. Individuals' habits and actions on websites are monitored by firms for…

References

McCallister, E., Grance, T., & Scarfone, K. (2010). Guide to Protecting the Confidentiality of Personally Identifiable Information (PII): Recommendations of the National Institute of Standards and Technology. NIST. Retrieved from http://csrc.nist.gov/publications/nistpubs/800-122/sp800-122.pdf

Vacca, J. (2009). Computer and Information Security Handbook. Burlington, MA: Morgan Kaufmann Publishers.

Wambler, S. (2015). Relational Databases. Retrieved from http://www.agiledata.org/essays/relationalDatabases.html

Key Concepts in This Paper
Personally Identifiable Information Cybersecurity Ethics Data Confidentiality Online Tracking Legal Compliance Risk Management Big Data User Privacy Web Audit Systems Cookie Tracking
Cite This Paper
PaperDue. (2026). Protecting PII: Ethics, Law, and Cybersecurity in Organizations. PaperDue. https://www.paperdue.com/study-guide/protecting-pii-ethics-law-cybersecurity-2155017

Always verify citation format against your institution’s current style guide requirements.