Directly from the user in the form of a password or personal information Accessed from a database or other data store by the application Indirectly from a partner or other third party Sometimes data that is not labeled as private can have a privacy implication in a different context.