What counts as PII? A guide to Personally Identifiable Information

PII, or Personally Identifiable Information, is information that can identify a person, either on its own or when combined with other data.

Names, email addresses, Social Security numbers, passport numbers, and biometric data are all common examples of PII, but less obvious information, such as an IP address or date of birth, may also be personally identifiable depending on the context.

The term PII is commonly used in the US, particularly in privacy and cybersecurity. Other privacy laws use different terms: the GDPR refers to personal data, while the California Consumer Privacy Act (CCPA) uses personal information.

The definitions overlap, but they aren’t exactly the same. Here’s exactly what businesses need to know.

Examples of PII

Some types of PII can directly identify a person, while others may only become identifying when connected with additional information.

Common examples of PII include:

– full name

– home address

– personal email address

– phone number

– Social Security number

– passport or driver’s license number

– date and place of birth

– financial information

– employment information

– medical information

– biometric identifiers

– IP addresses and other online identifiers, depending on the context

NIST guidance includes both direct identifiers, such as names and Social Security numbers, and information that is linked or linkable to a person, including medical, educational, financial, and employment information.

For a broader look at how privacy laws classify this kind of information, see our guide to personal information under major privacy laws.

What is sensitive PII?

Sensitive PII generally refers to information that could create a greater risk of harm if it were exposed, stolen, or misused.

Examples can include:

  • Social Security numbers
  • financial account information
  • passwords and account credentials
  • passport and driver’s license numbers
  • health information
  • genetic information
  • biometric data
  • precise location information

There isn’t a single universal definition of sensitive PII that applies across all laws or frameworks.

Under the GDPR, the equivalent concept is called “special categories of personal data” (Article 9) — a specifically defined set covering data such as health, genetic and biometric data, racial or ethnic origin, religious or philosophical beliefs, and sexual orientation.

Under the CCPA, the equivalent term is “sensitive personal information.” It covers much of the general list above — government identifiers, account log-in and financial-account credentials, precise geolocation, and genetic or biometric data — and adds further categories, including a consumer’s racial or ethnic origin, religious or philosophical beliefs, union membership, the contents of certain private communications, and information concerning health, sex life, or sexual orientation.

What counts as PII?

Whether something counts as PII depends on whether it can identify a person on its own or, when combined with other information, can identify a person.

Some examples are straightforward. A Social Security number, passport number, or personal email address can often be linked directly to an individual.

Other information depends more heavily on context. A name, date of birth, phone number, IP address, location, or device identifier may not identify someone by itself, but could become personally identifiable when combined with other data.

For example:

  • a common name alone may not identify one specific person
  • a personal email address may clearly point to an individual, while a generic address such as support@company may not
  • an IP address may be personally identifiable where it can be linked to a person or combined with other identifying information

The key is to look at the information in context, rather than deciding whether each data point is PII in isolation.

What is not considered PII?

Information that cannot reasonably identify or be linked to a particular person generally falls outside the usual definition of PII.

That can include:

  • truly anonymized data
  • aggregated statistics that cannot be traced back to individuals
  • information about a company rather than a person
  • generic contact information that doesn’t identify an individual

But simply removing a name doesn’t automatically make information anonymous.

If someone can still be identified from the remaining information, or by combining it with another dataset, it may still be personally identifiable.

PII vs personal data: what’s the difference?

PII and personal data are closely related, but they aren’t interchangeable legal terms.

PII is widely used in US privacy and cybersecurity guidance.

The GDPR uses the term “personal data” to mean information relating to an identified or identifiable natural person.

That definition can cover both direct and indirect identifiers.

So if your business is subject to the GDPR, the better question isn’t simply:

“Is this PII?”

It’s:

“Does this qualify as personal data under the GDPR?”

This distinction matters because relying on a narrower or different definition could lead to overlooking information that remains protected by law.

PII under the GDPR

The GDPR doesn’t use Personally Identifiable Information as its legal term.

Instead, Article 4 defines personal data broadly as information that relates to an identified or identifiable person.

This can include:

  • names
  • identification numbers
  • location information
  • online identifiers
  • information relating to someone’s physical, economic, cultural, or social identity

The GDPR also provides additional protection for certain special categories of personal data.

If your business carries out processing that is likely to result in a high risk to individuals (which can include, but is not limited to, processing special categories of data on a large scale) you may also need to carry out a Data Protection Impact Assessment (DPIA).

PII under the CCPA

The CCPA takes another approach.

It uses the term “personal information,” defined as information that identifies, relates to, or could reasonably be linked to a consumer or household.

Examples include:

  • names and email addresses
  • purchase history
  • browsing history
  • IP addresses
  • geolocation information
  • employment information
  • fingerprints
  • profiles and inferences about people’s preferences

The reference to a household is particularly important. Information doesn’t always have to identify one specific person to fall within the CCPA’s definition.

The law also creates a separate category of sensitive personal information with additional rights and restrictions around certain uses.

For a deeper look at the rules, see our guide to the CCPA and CPRA.

PII, personal data, and personal information at a glance

TermCommonly used inWhat it covers
PIIUS privacy and cybersecurityInformation that can identify or be linked to an individual
Personal dataGDPRInformation relating to an identified or identifiable natural person
Personal informationCCPAInformation reasonably linked to a consumer or household

The concepts overlap considerably, but the exact definition you use depends on the applicable law or framework.

Why does identifying PII matter?

Most businesses handle personally identifiable information every day, often across several different tools.

Think about:

– account registrations

– email marketing platforms

– analytics tools

– payment systems

– customer support software

– CRMs

– HR systems

– cookies and tracking technologies

– mobile apps

Understanding what information you’re collecting makes it easier to determine which privacy requirements apply and what needs to happen next.

That might include providing appropriate privacy information, responding to privacy requests, reviewing third-party vendors, setting retention periods, or applying additional safeguards to sensitive data.

How can businesses identify PII?

Start by getting a clear picture of the information moving through your business.

1. Look beyond obvious identifiers

Names and email addresses are easy to recognize.

Technical data can be less obvious. Websites and apps may also collect IP addresses, cookie identifiers, device information, location data, and other online identifiers.

2. Look at data in context

Don’t assess each data point in isolation.

Ask whether information could identify someone when combined with other data your business, or another party, can access.

3. Map where the data goes

Identify where information is collected, stored, shared, and transferred.

A data mapping exercise can help you see which data your organization holds and how it moves between systems, teams, and third parties.

4. Check which privacy laws apply

PII, GDPR personal data, and CCPA personal information are not identical concepts.

If you operate across jurisdictions, assess the information against the relevant legal definitions rather than assuming a single standard applies everywhere.

How should businesses protect PII?

The right safeguards depend on the information you process and the risks involved.

Good practices can include:

  • collecting only the information you actually need
  • limiting access based on roles and responsibilities
  • using appropriate authentication and security controls
  • encrypting data where appropriate
  • setting clear retention and deletion periods
  • reviewing third-party vendors
  • keeping systems and software updated
  • training people who handle personal information
  • regularly reviewing your data-processing activities

Knowing what information you’re collecting, why you need it, where it goes, and how long you’ll keep it makes privacy much easier to manage than trying to untangle those questions later.

PII FAQs

What does PII stand for?

PII stands for Personally Identifiable Information.

It generally means information that can identify, distinguish, or be linked to an individual, either directly or indirectly.

What are five examples of PII?

Five common examples are:

  1. full name
  2. home address
  3. personal email address
  4. Social Security number
  5. passport number

Many other types of information may also qualify depending on the context.

Is a phone number PII?

Generally, yes, if it can be linked to a particular person.

Is a date of birth PII?

It can be. A date of birth may help identify someone, particularly when combined with information such as their name, address, or place of birth.

Are cookies PII?

They can contain or generate identifiers that relate to a person or device.

Whether cookie data qualifies as PII or personal data depends on what is collected, how it can be linked to other information, and which privacy rules apply.

For more on how cookies collect and share information, see our guide to third-party cookies.

Is anonymized data PII?

Generally not, if the data has been genuinely anonymized so that the individual can no longer reasonably be identified.

Removing obvious identifiers isn’t necessarily enough if the person can still be identified using other information.

Know what personal information you’re working with

PII isn’t always obvious. It can span forms, analytics tools, CRMs, cookies, and third-party services, making it easy to lose track of what you’re actually collecting.

iubenda can help you map those data flows, document the services you use, and keep your privacy information aligned with how your business really works. See how iubenda can help.

Follow us on: