Personally Identifiable Information
Personally Identifiable Information (PII) is information that can be used to identify a specific person, either on its own or when combined with other information. Examples include a person's name, Social Security number, or biometric records. It is a concept used primarily in United States privacy and information security practice to describe data that could reveal or trace an individual's identity.
PII denotes information that can be used to distinguish or trace an individual's identity, either alone or in combination with other information linked or linkable to that individual, per definitions used in U.S. federal guidance and standards (e.g., NIST, U.S. Department of Labor). The term is characteristic of the U.S. regulatory and information-security vocabulary and is not identical to the broader EU concept of 'personal data' under the GDPR, which covers any information relating to an identified or identifiable natural person; practitioners should not treat the two terms as interchangeable. The precise scope of PII, and what data elements qualify as identifying, is context- and jurisdiction-dependent, and agency- or sector-specific definitions may vary. Readers should verify against the applicable authoritative source, as definitions are periodically revised.
Why it matters
PII sits at the center of most U.S. privacy and information-security obligations. Because the term captures information that can distinguish or trace an individual's identity—alone or in combination with other data—it determines which data holdings trigger safeguarding duties, breach-notification analysis, and access controls. Misclassifying data as non-identifying can leave sensitive information under-protected, while treating everything as PII can impose unnecessary burden; both outcomes create compliance and operational risk.
A persistent source of error is treating PII as interchangeable with the EU concept of 'personal data' under the GDPR. The two overlap but are not identical: 'personal data' is defined broadly as any information relating to an identified or identifiable natural person, whereas PII is a term characteristic of U.S. federal and information-security practice. Organizations operating across the EU, the United States, and other jurisdictions that map controls to one term alone may leave gaps, because a data element treated as out of scope under a narrow PII reading could still be regulated as personal data elsewhere.
The practical stakes are heightened by the fact that PII has no single universal definition. Agency- and sector-specific interpretations vary, and what qualifies as identifying is context-dependent—data that seems innocuous in isolation can become identifying when linked with other information. For this reason, compliance and security teams should anchor their classification to the specific authoritative source that governs their sector or agency rather than to a generic notion of the term.
Who it's relevant to
Inside PII
Common questions
Answers to the questions practitioners most commonly ask about PII.

