The GDPR defines personal data as any information relating to an identified or identifiable natural person, including someone identifiable by an online identifier, and treats pseudonymized data that could be attributed to a person using additional information as personal data too (the GDPR text on EUR-Lex). PII, the term US federal guidance uses, is any information that can be used to distinguish or trace a person’s identity, plus any other information that is linked or linkable to that person, as NIST’s guide to protecting the confidentiality of PII defines it. Under either definition, treat a hashed email address as personal data: anyone who has the address and knows the hashing method can hash it again and match the record.

In an FDE interview

One candidate reported, in a public repo created in September 2026, that a Quilr AI take-home for a role titled “Solutions Engineer / ” included a streaming PII guardrail among its tasks. Source 1Quilr FDE take-homePublisherPalmCoast (GitHub)Source typecandidate’s take-home repository In design questions it shows up as removing personal data from support transcripts, where the weak answer assumes redaction is perfect. A strong candidate classifies fields before choosing where they live, looks for personal data in the places nobody planned (logs, prompts, traces, evaluation sets and vector indexes), and measures misses per entity type on a labeled sample rather than claiming the redactor never misses.

Where analysts still need to join on a person, replace the identifier with a keyed HMAC whose key never enters the analytics environment; a plain hash, as above, can be matched by anyone who can guess the input. The HMAC output is still pseudonymized personal data under the , because whoever holds the key can link it back, so it narrows who can re-identify people but does not take the data out of scope. For a streaming guardrail, hold back a short window of text before releasing it, because an email address can arrive split across two chunks. And data lineage is what lets a deletion request reach every derived copy.

The lesson Data, PII and compliance covers minimization, deletion and the logs nobody planned for, and a planned transcript redaction design prompt will be the practice.

GlossaryForward deployed engineerA software engineer who builds and ships production systems inside a customer’s problem and environment, accountable to that customer’s outcome.More on Forward deployed engineerGlossaryGDPRThe EU regulation governing the processing and transfer of personal data.More on GDPR