Skip to main content
The state of ai impact assessment
Category: Data Types & Classification

Personally Identifiable Information

Also known as:
Simply put

Personally Identifiable Information (PII) is information that can be used to identify a specific person, either on its own or when combined with other information. Examples include a person's name, Social Security number, or biometric records. It is a concept used primarily in United States privacy and information security practice to describe data that could reveal or trace an individual's identity.

Formal definition

PII denotes information that can be used to distinguish or trace an individual's identity, either alone or in combination with other information linked or linkable to that individual, per definitions used in U.S. federal guidance and standards (e.g., NIST, U.S. Department of Labor). The term is characteristic of the U.S. regulatory and information-security vocabulary and is not identical to the broader EU concept of 'personal data' under the GDPR, which covers any information relating to an identified or identifiable natural person; practitioners should not treat the two terms as interchangeable. The precise scope of PII, and what data elements qualify as identifying, is context- and jurisdiction-dependent, and agency- or sector-specific definitions may vary. Readers should verify against the applicable authoritative source, as definitions are periodically revised.

Why it matters

PII sits at the center of most U.S. privacy and information-security obligations. Because the term captures information that can distinguish or trace an individual's identity—alone or in combination with other data—it determines which data holdings trigger safeguarding duties, breach-notification analysis, and access controls. Misclassifying data as non-identifying can leave sensitive information under-protected, while treating everything as PII can impose unnecessary burden; both outcomes create compliance and operational risk.

A persistent source of error is treating PII as interchangeable with the EU concept of 'personal data' under the GDPR. The two overlap but are not identical: 'personal data' is defined broadly as any information relating to an identified or identifiable natural person, whereas PII is a term characteristic of U.S. federal and information-security practice. Organizations operating across the EU, the United States, and other jurisdictions that map controls to one term alone may leave gaps, because a data element treated as out of scope under a narrow PII reading could still be regulated as personal data elsewhere.

The practical stakes are heightened by the fact that PII has no single universal definition. Agency- and sector-specific interpretations vary, and what qualifies as identifying is context-dependent—data that seems innocuous in isolation can become identifying when linked with other information. For this reason, compliance and security teams should anchor their classification to the specific authoritative source that governs their sector or agency rather than to a generic notion of the term.

Who it's relevant to

Data Protection and Privacy Specialists
Privacy professionals use PII classification to scope safeguarding, retention, and disclosure obligations across data holdings. Where operations span the United States and the EU, they should map data against both the applicable PII definition and the GDPR concept of 'personal data,' since the two are not interchangeable and a narrow PII reading may miss data regulated elsewhere.
Information Security Professionals
Security teams rely on PII definitions—including those associated with NIST—to identify data that requires access controls, monitoring, and protection against unauthorized use. Because data that is not identifying in isolation may become identifying when linked or linkable to other information, security controls should account for the 'in combination' dimension rather than data elements alone.
Federal Agency and Sector Compliance Staff
Personnel in U.S. federal agencies and regulated sectors should apply the PII definition that governs their specific agency or sector, as interpretations vary and agency-specific guidance (for example, from bodies such as the U.S. Department of Labor) may differ in scope. Verifying against the current authoritative text is important, as these definitions are periodically revised.
Legal Counsel and Auditors
Counsel and auditors assessing data-handling practices need to distinguish PII from adjacent concepts such as the GDPR's 'personal data' to avoid conflating obligations across jurisdictions. Application of the term to a particular data set is fact-specific and depends on context and the governing source; this entry is informational and not a substitute for professional judgment on specific circumstances.

Inside PII

Direct Identifiers
Data elements that identify an individual on their own, such as full name, government-issued identification numbers, email addresses, or account credentials tied to a specific person.
Indirect (Quasi-) Identifiers
Data elements that may not identify an individual in isolation but can do so when combined with other information, such as date of birth, postal code, gender, or job title. Whether these constitute PII often depends on the surrounding context and the feasibility of linking them to a person.
Context Dependence
Whether a given data element qualifies as PII generally depends on the circumstances, including what other data is available and how readily re-identification could occur. The same element may be identifying in one context and non-identifying in another.
Terminological Scope
"PII" is a term used predominantly in United States frameworks and sectoral guidance. It overlaps with, but is not identical to, the broader concept of "personal data" used under the EU GDPR and the UK GDPR, which generally casts a wider net. Practitioners should confirm which definition applies in their jurisdiction and context.
Sensitive Subcategories
Certain categories of identifying information—such as health, financial, or similarly sensitive data—may be subject to heightened protection under specific regimes. The precise categories and obligations vary by jurisdiction and sector, so the applicable authoritative text should be consulted.

Common questions

Answers to the questions practitioners most commonly ask about PII.

Is 'personally identifiable information' the same thing as 'personal data' under the GDPR?
Not exactly. 'PII' is a term rooted primarily in United States law and practice, where its scope can vary by statute and sector and often centers on data that identifies a specific individual. 'Personal data' under the EU GDPR is generally defined more broadly to cover any information relating to an identified or identifiable natural person, which can capture data that some U.S. frameworks would not treat as PII. Treating the two terms as interchangeable can lead to under-scoping obligations, particularly where the GDPR's extraterritorial reach applies. Because definitions differ across jurisdictions and instruments, you should verify the specific definition that governs your data against the applicable authoritative text.
If information is anonymized or does not include a name, does that mean it is no longer PII and falls outside scope?
Not necessarily. The absence of a direct identifier such as a name does not automatically remove data from scope, because individuals can often be identified through combinations of attributes or by linking datasets. Many frameworks distinguish between truly anonymized data, which may fall outside certain requirements, and pseudonymized data, which generally remains within scope because re-identification is still possible. Whether a given dataset qualifies as anonymized is fact-specific and depends on the applicable legal standard, the re-identification risk, and available linking data. This determination should be assessed case by case rather than assumed.
How should an organization go about identifying what counts as PII in its systems?
Organizations generally begin with data discovery and mapping to locate where personal information is collected, stored, processed, and transferred. Because the relevant definition depends on the applicable law or framework, the classification criteria should be aligned to the jurisdictions and sectors in which the organization operates. Data inventories are commonly used to record data categories, sources, purposes, and recipients. Given that definitions and interpretations continue to evolve, classification rules should be reviewed periodically and validated against current authoritative sources; application to specific systems typically requires professional judgment.
Does classifying data as PII determine which security controls we must apply?
Classification often informs, but does not by itself dictate, the controls applied. Many organizations use a risk-based approach in which the sensitivity of the data category, the applicable legal obligations, and the assessed risk level influence the safeguards selected. It is worth keeping privacy and security distinct here: classifying data addresses privacy and data-governance obligations, while the technical and organizational measures that protect it fall within information security. Specific control requirements may derive from binding regulation, from voluntary standards adopted contractually, or from internal policy, and these should be verified against the relevant source.
When PII is shared with a third party, how do responsibilities typically divide?
Responsibility allocation depends heavily on the roles the parties play and the governing framework. Under regimes that use the controller and processor distinction, the party determining the purposes and means of processing generally carries different obligations from the party processing on another's behalf, and these roles are frequently addressed through contractual terms. It is important not to conflate these roles, as obligations, liability, and required documentation can differ significantly between them. The precise division should be confirmed against the applicable law and the agreements in place, and complex arrangements typically warrant professional review.
How should organizations keep their PII handling practices current over time?
Because the definitions, obligations, and enforcement practices surrounding personal information are periodically amended or reinterpreted across jurisdictions, many organizations maintain a process to monitor regulatory changes and update their data inventories, classification criteria, and policies accordingly. Where voluntary standards or certification schemes are used to support these practices, note that scheme versions change over time and adherence is generally contractual or voluntary rather than legally binding in itself. Periodic review against the latest authoritative sources is advisable, and how any change applies to a particular organization is a matter for informed judgment rather than a fixed rule.

Common misconceptions

"PII" and "personal data" mean exactly the same thing everywhere.
The terms overlap but are not synonymous. "PII" is chiefly a United States concept and is sometimes defined more narrowly, while "personal data" under the EU and UK GDPR generally covers a broader range of information relating to an identified or identifiable person. The applicable definition depends on the governing regime, and readers should verify against the relevant current text.
A data element is either always PII or never PII.
Whether information qualifies as PII is frequently context-dependent. Indirect identifiers such as a postal code or date of birth may not identify anyone alone but can become identifying when combined with other available data. Classification therefore requires assessing the specific circumstances rather than applying a fixed universal list.
Removing names is sufficient to ensure data is no longer PII.
Stripping direct identifiers does not necessarily prevent re-identification, because quasi-identifiers may still allow an individual to be singled out when linked with other information. Whether data has been sufficiently de-identified is a fact-specific determination and may be evaluated differently across jurisdictions and regimes.

Best practices

Confirm which definition governs your situation—for example, "PII" under applicable United States frameworks versus "personal data" under the EU or UK GDPR—before classifying data, since scope and obligations differ by jurisdiction.
Assess data elements in context rather than relying on a fixed list, giving particular attention to indirect or quasi-identifiers that may become identifying when combined with other available information.
Maintain a documented inventory of the categories of identifying information your organization holds, noting where sensitive subcategories may trigger heightened requirements.
Treat de-identification as a fact-specific outcome, evaluating re-identification risk rather than assuming that removing direct identifiers alone renders data non-identifying.
Verify classification decisions and any thresholds against the latest authoritative text of the applicable regulation, standard, or guidance, as these are periodically amended.
Engage qualified legal or privacy professionals for application to specific circumstances, since classification and resulting obligations depend on facts that a general definition cannot resolve.
Promotional banner for the Pentest Readiness checklist download