PII meaning and examples: direct, indirect and sensitive PII, PII vs personal data under GDPR and CCPA, whether IP addresses count, and how to protect PII.
PII stands for personally identifiable information: any information that can be used to identify a specific person, either on its own (a name, a Social Security number, a passport number) or when combined with other data (a date of birth, a ZIP code, a device ID). Organizations that collect PII must protect it from misuse and breaches, and privacy laws such as the GDPR and the CCPA control how it can be collected, used and shared.
"Personally identifiable information" is a term from US federal privacy and security policy. The US National Institute of Standards and Technology (NIST), in Special Publication 800-122 (April 2010), defines PII as any information about an individual maintained by an agency, including:
The US Office of Management and Budget uses the same idea: PII is information that can distinguish or trace a person's identity, either alone or when combined with other information that is linked or linkable to that person.
Outside the US, laws rarely say "PII". The EU and UK use personal data, and California uses personal information. Both are broader than many traditional PII lists, as explained below.
PII falls into two groups:
Indirect identifiers are where most organizations underestimate risk. A date of birth, a ZIP code and a gender together can narrow a large population down to one person. Once data can be linked back to someone, it is PII.
| Type | Examples |
|---|---|
| Direct identifiers | Full name, Social Security number, passport number, driver's license number, personal email address, phone number, home address, biometric records (fingerprints, face scans) |
| Indirect (linkable) identifiers | Date of birth, place of birth, ZIP or postal code, gender, race, job title and employer, IP address, MAC address, cookie IDs, mobile advertising IDs |
| Sensitive PII | Social Security number, passport and driver's license numbers, financial account and card numbers, account log-in credentials, medical and health data, biometric and genetic data, precise geolocation |
NIST SP 800-122 lists "asset information", such as an IP or MAC address or other host-specific persistent static identifier that consistently links to a particular person or small group, as an example of PII.
Sensitive PII is PII that would cause serious harm, such as identity theft, financial loss, discrimination or embarrassment, if it were lost or exposed. It needs stronger protection, for example encryption at rest and in transit and tightly limited access.
Privacy laws define their own sensitive categories:
| PII | Personal data | Personal information | |
|---|---|---|---|
| Where the term is used | US federal guidance (NIST, OMB), US state breach laws, security standards | EU GDPR and UK GDPR | California CCPA and CPRA |
| Definition | Information that can distinguish or trace an individual's identity, alone or combined with linked or linkable information | Any information relating to an identified or identifiable natural person (GDPR Art. 4(1)) | Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a consumer or household |
| Online identifiers | Included when they link to a person (e.g. persistent IP or MAC addresses) | Expressly included: "online identifier" in Art. 4(1); IP addresses and cookie identifiers in Recital 30 | Expressly included: unique personal identifiers, online identifiers and IP addresses |
| Scope | Focus on identifying a person | Very broad: any information about an identifiable person | Very broad, and also covers households |
In short: all PII is personal data, but not all personal data fits a narrow PII list. If you operate in the EU, UK or California, assume that any data you can link to a person or device is covered.
Often, yes, and under the GDPR almost always:
The same logic applies to cookie IDs and device IDs (such as mobile advertising IDs). They are designed to recognize the same browser or device over time, so they are personal data under the GDPR and personal information under the CCPA.
Most websites collect PII in more places than their owners realize:
A cookie scanner shows which cookies and trackers your site actually sets, which is the starting point for controlling PII collection.
| Pseudonymization | Anonymization | |
|---|---|---|
| What it does | Replaces identifiers (e.g. a name) with a token or key; the original can be restored with separately kept information | Removes or alters data so the person is not, or no longer, identifiable |
| Still personal data under GDPR? | Yes (GDPR Art. 4(5) and Recital 26) | No, truly anonymous data falls outside the GDPR (Recital 26) |
| Example | Customer ID 48213 instead of a name, with the lookup table stored separately | Aggregated statistics with no way to single out a person |
Hashing an email address is pseudonymization, not anonymization: the same email always produces the same hash, so it can still be linked to a person.
When PII is lost, stolen or exposed, notification duties usually apply:
Keep an incident response plan ready, including who decides, who notifies and which templates to use.
Cookies, pixels and tags are among the most common ways websites collect PII without noticing. UniConsent puts you in control:
Start with UniConsent and control PII collection on your website in minutes. For an overview of the laws that regulate PII worldwide, see our Global Privacy Laws guide.
PII stands for personally identifiable information. It means any information that can identify a specific person, either directly (such as a name or Social Security number) or when combined with other information (such as a date of birth and ZIP code).
Common examples of PII are full name, Social Security number, passport or driver's license number, email address, phone number, home address, date of birth, biometric data, financial account numbers, IP addresses and device or cookie identifiers.
Sensitive PII is information that could cause serious harm if exposed, such as Social Security numbers, passport numbers, financial account numbers, log-in credentials, medical and biometric data, and precise geolocation. It requires stronger protection such as encryption and strict access control.
Usually, yes. Under the GDPR, IP addresses are online identifiers and are personal data (Recital 30), and the EU Court of Justice held in Breyer (2016) that even dynamic IP addresses can be personal data for a website operator. The CCPA also lists IP addresses as personal information.
PII is a US term focused on information that can identify or trace a person. Personal data under the GDPR is broader: any information relating to an identified or identifiable person, including online identifiers such as cookie IDs. All PII is personal data, but not all personal data appears on narrow PII lists.
Yes. A personal email address such as firstname.lastname@example.com directly identifies a person. A work email that contains a person's name is also PII, and a hashed email is still personal data under the GDPR because it can be linked back to the person.
Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up