Blog
Personal data and sensitive data
They overlap. They are not the same list, in law or in a chat box.
A name is personal. In ordinary European privacy language it is personal data. It is not automatically “sensitive” in the narrower sense some laws use for health, biometrics, or beliefs. An API key is sensitive, and it may not identify anyone. A diagnosis with a name on it can be both.
The distinction matters because people protect the wrong layer. They strip a surname and leave a medical story. Or they worry about a first name and paste a live secret key because it “isn’t PII”.
Two questions, asked in order
- Does this point at a real person, alone or together with other details?
- Could someone use this, or be harmed by it, even if it names nobody?
If either answer is yes, it deserves a look before you send it to an AI tool. You might delete it, replace it with a role, or swap it for a dull token.
What Vipra is actually doing
Vipra is not a legal classifier. In the review panel you will see only the types it supports: Name, Email, Phone, IBAN, Card, US Social Security numbers and Spanish DNI/NIE, IP address, API key, Token, and Secret link. A DNI is replaced on your device as [DNI_1], and a NIE as [NIE_1]. Some of those are everyday personal details. Some are secrets. Health notes, opinions, and “this plan is confidential” are outside that list.
Use the list as a checklist you no longer have to remember. Use your own judgment for everything the list cannot see.