Personally identifiable information (PII) is information that can be used to identify a specific person. Some items do this on their own, such as a full name with a government ID number, a passport number or a fingerprint. Others identify someone only when combined, such as date of birth, postal code and employer. The term is most common in the United States, where many laws, contracts and security programs use it, but exactly what counts depends on the law or agreement in question. This entry is an overview for buyers, not legal advice.
At a glance
- PII includes direct identifiers that point to one person and indirect identifiers that do so in combination.
- Sensitive PII, such as government ID numbers, financial account numbers, health data and biometrics, usually needs stronger protection.
- Definitions vary by law, sector and jurisdiction; GDPR’s personal data is generally broader than many US uses of PII.
- PII is typically spread across many systems: HR, CRM, support tools, email, call recordings, file shares and backups.
- Knowing where PII lives is the first step to protecting it, answering customers and responding to breaches.
What problem it solves
PII is the information criminals most want and regulators most care about. Stolen identity data feeds fraud, account takeover and phishing; exposed records lead to notification costs, legal claims and lost trust. Most organizations hold far more of it than they realize: employee records, customer profiles, contracts, support tickets, call recordings, marketing lists and copies of all of these in backups and spreadsheets.
Treating PII as a defined category lets an organization find it, decide who may use it, protect it to a consistent standard and respond correctly when something goes wrong.
How it works
Definition. Start with the definitions that apply to you: state and national privacy and breach laws, sector rules such as HIPAA for health information, the GDPR if you handle data about people in Europe, and customer contracts. Combine them into an internal classification, usually with a higher tier for sensitive PII.
Discovery. Find where PII is stored and how it flows. Data discovery and classification tools scan databases, file shares, email and cloud apps for patterns such as ID numbers or account numbers; interviews with system owners fill in the rest.
Protection. Common controls include minimizing what is collected, limiting access by role, encryption at rest and in transit, masking or tokenization, retention limits, logging and monitoring. Data loss prevention (DLP) tools watch for PII leaving through email, uploads or devices, and a cloud access security broker (CASB) extends visibility and policy into SaaS applications.
Governance. Owners, policies and regular reviews keep the picture current as systems change. This is part of broader data governance.
Response. If PII is exposed, the organization must assess what data and which people were affected, and then follow the notification rules that apply, which can differ by state or country.
When it matters for buyers
- When adopting a new SaaS or cloud platform. Ask what PII it will hold, where, and who at the vendor can see it.
- When customers ask how you protect personal information. Contracts and questionnaires increasingly require specifics.
- When rolling out DLP or CASB. Both need clear definitions of the PII they should detect.
- When a breach or suspected breach occurs. Knowing which PII was in which system decides who must be notified.
- When cleaning up old data. Deleting PII you no longer need reduces exposure.
Our cloud access security broker overview covers how organizations find and control sensitive data in cloud apps.
Questions to ask vendors
- What PII will your service collect or store on our behalf, and can we limit it?
- Where is it stored, and who on your side can access it?
- Is it encrypted at rest and in transit, and who manages the keys?
- Can you detect and classify PII in our data, and which types and languages are supported?
- How long do you keep it, and how is it deleted at the end of the contract?
- How quickly will you notify us of a breach involving our PII, and what details will you provide?
- Which laws and frameworks do you design your handling of PII around?
How it differs from protected health information (PHI)
Protected health information is a defined category under HIPAA in the United States: individually identifiable health information held or transmitted by covered entities, such as health plans and most providers, and their business associates. PHI combines personal identifiers with health or payment-for-care details. PII is a broader, more general idea not tied to one law. Much PHI is also PII, but the rules that apply to PHI come specifically from HIPAA. Payment card data is similar: it often overlaps with PII, but PCI DSS sets the specific requirements for protecting them.
