But hashing the other data isnt practical - so it's the security vs. access tradeoff. You can hash passwords without much inconvenience.
Also with individual pieces of those other examples of data you mention it is not possible to gain access to the rest. Whereas with a password it IS. Damage limitation.
Finally the password and username (or email) are "front of the line". They HAVE to be accessible to an unauthorised client simply so said client can be authorised. Whereas the other data should require authorisation to access.
But hashing the other data isnt practical - so it's the security vs. access tradeoff. You can hash passwords without much inconvenience.
Also with individual pieces of those other examples of data you mention it is not possible to gain access to the rest. Whereas with a password it IS. Damage limitation.
Finally the password and username (or email) are "front of the line". They HAVE to be accessible to an unauthorised client simply so said client can be authorised. Whereas the other data should require authorisation to access.