A data access control facility is implemented by assigning personally
identifying information (PII) classification labels to PII data objects,
with each PII data object having one PII classification label assigned
thereto. The control facility further includes at least one PII purpose
serving function set (PSFS) comprising a list of application functions
that read or write PII data objects. Each PII PSFS is also assigned a PII
classification label. A PII data object is accessible via an application
function of a PII PSFS having a PII classification label that is
identical to or dominant of the PII classification label of the PII
object. A user of the control facility is assigned a PII clearance set
which contains a list of at least one PII classification label, which is
employed in determining whether the user is entitled to access a
particular function.