Personally Identifiable Information (PII)

Any information that can be used to identify, contact, or locate a specific individual, either alone or combined with other sources.

Also known as:Personal InformationPersonal Data

What is Personally Identifiable Information?

Personally Identifiable Information (PII) is any data that could potentially identify a specific individual. This includes information that can directly identify someone or information that, when combined with other data, could lead to identification.

Categories of PII

Direct Identifiers

  • Full name
  • Social Security number
  • Driver's license number
  • Passport number
  • Email address
  • Phone number
  • Physical address

Indirect Identifiers

  • Date of birth
  • Place of birth
  • Race/ethnicity
  • Gender
  • Job title
  • Education history

Sensitive PII

  • Financial account numbers
  • Medical information
  • Biometric data
  • Sexual orientation
  • Religious beliefs
  • Political opinions

PII Under Various Regulations

RegulationTerminology
GDPRPersonal Data
CCPAPersonal Information
HIPAAPHI (health context)
NISTPII

Protection Requirements

  • Data minimization
  • Purpose limitation
  • Encryption at rest and in transit
  • Access controls
  • Retention policies
  • Secure disposal
  • Breach notification procedures

Best Practices

  • Inventory PII in your systems
  • Classify by sensitivity
  • Implement data masking
  • Regular access reviews
  • Employee training
  • Incident response planning