What Is PII (Personally Identifiable Information)?

Related problems: Not sure which of our systems hold customer or employee personal data; Sensitive data is showing up in email, spreadsheets and cloud apps; A customer contract asks how we protect personal information; Working out who to notify after a data breach

Personally identifiable information (PII) is information that can be used to identify a specific person. Some items do this on their own, such as a full name with a government ID number, a passport number or a fingerprint. Others identify someone only when combined, such as date of birth, postal code and employer. The term is most common in the United States, where many laws, contracts and security programs use it, but exactly what counts depends on the law or agreement in question. This entry is an overview for buyers, not legal advice.

At a glance

  • PII includes direct identifiers that point to one person and indirect identifiers that do so in combination.
  • Sensitive PII, such as government ID numbers, financial account numbers, health data and biometrics, usually needs stronger protection.
  • Definitions vary by law, sector and jurisdiction; GDPR’s personal data is generally broader than many US uses of PII.
  • PII is typically spread across many systems: HR, CRM, support tools, email, call recordings, file shares and backups.
  • Knowing where PII lives is the first step to protecting it, answering customers and responding to breaches.

What problem it solves

PII is the information criminals most want and regulators most care about. Stolen identity data feeds fraud, account takeover and phishing; exposed records lead to notification costs, legal claims and lost trust. Most organizations hold far more of it than they realize: employee records, customer profiles, contracts, support tickets, call recordings, marketing lists and copies of all of these in backups and spreadsheets.

Treating PII as a defined category lets an organization find it, decide who may use it, protect it to a consistent standard and respond correctly when something goes wrong.

How it works

Definition. Start with the definitions that apply to you: state and national privacy and breach laws, sector rules such as HIPAA for health information, the GDPR if you handle data about people in Europe, and customer contracts. Combine them into an internal classification, usually with a higher tier for sensitive PII.

Discovery. Find where PII is stored and how it flows. Data discovery and classification tools scan databases, file shares, email and cloud apps for patterns such as ID numbers or account numbers; interviews with system owners fill in the rest.

Protection. Common controls include minimizing what is collected, limiting access by role, encryption at rest and in transit, masking or tokenization, retention limits, logging and monitoring. Data loss prevention (DLP) tools watch for PII leaving through email, uploads or devices, and a cloud access security broker (CASB) extends visibility and policy into SaaS applications.

Governance. Owners, policies and regular reviews keep the picture current as systems change. This is part of broader data governance.

Response. If PII is exposed, the organization must assess what data and which people were affected, and then follow the notification rules that apply, which can differ by state or country.

When it matters for buyers

  • When adopting a new SaaS or cloud platform. Ask what PII it will hold, where, and who at the vendor can see it.
  • When customers ask how you protect personal information. Contracts and questionnaires increasingly require specifics.
  • When rolling out DLP or CASB. Both need clear definitions of the PII they should detect.
  • When a breach or suspected breach occurs. Knowing which PII was in which system decides who must be notified.
  • When cleaning up old data. Deleting PII you no longer need reduces exposure.

Our cloud access security broker overview covers how organizations find and control sensitive data in cloud apps.

Questions to ask vendors

  • What PII will your service collect or store on our behalf, and can we limit it?
  • Where is it stored, and who on your side can access it?
  • Is it encrypted at rest and in transit, and who manages the keys?
  • Can you detect and classify PII in our data, and which types and languages are supported?
  • How long do you keep it, and how is it deleted at the end of the contract?
  • How quickly will you notify us of a breach involving our PII, and what details will you provide?
  • Which laws and frameworks do you design your handling of PII around?

How it differs from protected health information (PHI)

Protected health information is a defined category under HIPAA in the United States: individually identifiable health information held or transmitted by covered entities, such as health plans and most providers, and their business associates. PHI combines personal identifiers with health or payment-for-care details. PII is a broader, more general idea not tied to one law. Much PHI is also PII, but the rules that apply to PHI come specifically from HIPAA. Payment card data is similar: it often overlaps with PII, but PCI DSS sets the specific requirements for protecting them.

Frequently Asked Questions

What are examples of PII?
Direct identifiers such as full name, government ID numbers, passport numbers, email addresses and biometric data, and indirect identifiers such as date of birth, ZIP or postal code, job title or device identifiers that can identify someone when combined. Which items a given law treats as protected varies.
Is PII the same as personal data under GDPR?
Not exactly. GDPR's personal data covers any information relating to an identified or identifiable person, which is generally broader than many US uses of PII. Online identifiers such as IP addresses or cookie IDs can count as personal data under GDPR.
What is sensitive PII?
A subset whose exposure could cause greater harm, such as government ID numbers, financial account numbers, health information, biometrics and precise location. Many laws and contracts require stronger protection or faster breach notification for it, though definitions differ.
Do we have to notify people if PII is breached?
Often, but it depends on the data involved, where the affected people live and which laws apply. In the US, states have their own breach-notification laws with different definitions and deadlines, and sector rules add more. Involve counsel quickly; this is not legal advice.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.