What Is PII (Personally Identifiable Information)?

PII meaning and examples: direct, indirect and sensitive PII, PII vs personal data under GDPR and CCPA, whether IP addresses count, and how to protect PII.

What Is PII?

PII stands for personally identifiable information: any information that can be used to identify a specific person, either on its own (a name, a Social Security number, a passport number) or when combined with other data (a date of birth, a ZIP code, a device ID). Organizations that collect PII must protect it from misuse and breaches, and privacy laws such as the GDPR and the CCPA control how it can be collected, used and shared.

PII Meaning and Definition

"Personally identifiable information" is a term from US federal privacy and security policy. The US National Institute of Standards and Technology (NIST), in Special Publication 800-122 (April 2010), defines PII as any information about an individual maintained by an agency, including:

  1. Any information that can be used to distinguish or trace an individual's identity, such as name, Social Security number, date and place of birth, mother's maiden name, or biometric records; and
  2. Any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information.

The US Office of Management and Budget uses the same idea: PII is information that can distinguish or trace a person's identity, either alone or when combined with other information that is linked or linkable to that person.

Outside the US, laws rarely say "PII". The EU and UK use personal data, and California uses personal information. Both are broader than many traditional PII lists, as explained below.

Direct vs Indirect (Linkable) Identifiers

PII falls into two groups:

  • Direct identifiers identify a person on their own: a full name, a Social Security number, a passport number, a personal email address, a face photo.
  • Indirect (quasi or linkable) identifiers do not identify a person alone, but can when combined: a date of birth, a ZIP code, a gender, a job title, an IP address, a cookie ID.

Indirect identifiers are where most organizations underestimate risk. A date of birth, a ZIP code and a gender together can narrow a large population down to one person. Once data can be linked back to someone, it is PII.

PII Examples

TypeExamples
Direct identifiersFull name, Social Security number, passport number, driver's license number, personal email address, phone number, home address, biometric records (fingerprints, face scans)
Indirect (linkable) identifiersDate of birth, place of birth, ZIP or postal code, gender, race, job title and employer, IP address, MAC address, cookie IDs, mobile advertising IDs
Sensitive PIISocial Security number, passport and driver's license numbers, financial account and card numbers, account log-in credentials, medical and health data, biometric and genetic data, precise geolocation

NIST SP 800-122 lists "asset information", such as an IP or MAC address or other host-specific persistent static identifier that consistently links to a particular person or small group, as an example of PII.

What Is Sensitive PII?

Sensitive PII is PII that would cause serious harm, such as identity theft, financial loss, discrimination or embarrassment, if it were lost or exposed. It needs stronger protection, for example encryption at rest and in transit and tightly limited access.

Privacy laws define their own sensitive categories:

  • GDPR (Article 9): "special categories of personal data", meaning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify a person, health data, and data about a person's sex life or sexual orientation. Processing is prohibited unless an exception applies, such as explicit consent.
  • CCPA/CPRA: "sensitive personal information", including Social Security, driver's license, state ID and passport numbers, account log-in and financial account credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, the contents of mail, email and text messages, genetic data, biometric data, health data, and data about sex life or sexual orientation. Consumers can limit how businesses use it.

PII vs Personal Data vs Personal Information

PIIPersonal dataPersonal information
Where the term is usedUS federal guidance (NIST, OMB), US state breach laws, security standardsEU GDPR and UK GDPRCalifornia CCPA and CPRA
DefinitionInformation that can distinguish or trace an individual's identity, alone or combined with linked or linkable informationAny information relating to an identified or identifiable natural person (GDPR Art. 4(1))Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a consumer or household
Online identifiersIncluded when they link to a person (e.g. persistent IP or MAC addresses)Expressly included: "online identifier" in Art. 4(1); IP addresses and cookie identifiers in Recital 30Expressly included: unique personal identifiers, online identifiers and IP addresses
ScopeFocus on identifying a personVery broad: any information about an identifiable personVery broad, and also covers households

In short: all PII is personal data, but not all personal data fits a narrow PII list. If you operate in the EU, UK or California, assume that any data you can link to a person or device is covered.

Is an IP Address PII?

Often, yes, and under the GDPR almost always:

  • GDPR: Article 4(1) names "online identifiers" as a way to identify a person, and Recital 30 lists "internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags" as online identifiers that can be used to create profiles and identify people.
  • CJEU, Breyer (C-582/14, 19 October 2016): the EU Court of Justice held that a dynamic IP address is personal data for a website operator when the operator has legal means to identify the visitor with additional information held by the internet service provider.
  • CCPA: the definition of personal information expressly lists unique personal identifiers, online identifiers and Internet Protocol addresses. The CCPA's definition of unique identifier also names cookies, beacons, pixel tags, mobile ad identifiers and similar technology.
  • NIST: IP and MAC addresses count as PII when they consistently link to a particular person.

The same logic applies to cookie IDs and device IDs (such as mobile advertising IDs). They are designed to recognize the same browser or device over time, so they are personal data under the GDPR and personal information under the CCPA.

How Websites Collect PII

Most websites collect PII in more places than their owners realize:

  1. Forms: sign-ups, checkout, contact forms and newsletters collect names, emails, phone numbers and addresses.
  2. Cookies: analytics and advertising cookies store unique IDs that recognize a visitor across visits. See All About Cookies.
  3. Pixels and tags: advertising pixels such as the Meta Pixel and TikTok Pixel send page views, events, IP addresses and sometimes hashed emails to third parties.
  4. Analytics tools: web analytics records IP addresses, device and browser details, and behavior on the page.
  5. Embedded content: videos, maps, chat widgets and social buttons can set their own cookies and receive the visitor's IP address.

A cookie scanner shows which cookies and trackers your site actually sets, which is the starting point for controlling PII collection.

How to Protect PII

  1. Map your data: know what PII you collect, where it is stored, who can access it and which vendors receive it.
  2. Minimize: collect only the PII you need for a stated purpose, and delete it when you no longer need it.
  3. Encrypt: encrypt PII in transit (HTTPS/TLS) and at rest, especially sensitive PII.
  4. Control access: apply least-privilege access, multi-factor authentication and access logs.
  5. Pseudonymize or anonymize: replace direct identifiers where you can (see below).
  6. Sign contracts with vendors: put a data processing agreement in place with every processor.
  7. Assess high-risk processing: run a DPIA before large-scale or sensitive processing.
  8. Get consent before tracking: block non-essential cookies and pixels until the visitor agrees.

Pseudonymization vs Anonymization

PseudonymizationAnonymization
What it doesReplaces identifiers (e.g. a name) with a token or key; the original can be restored with separately kept informationRemoves or alters data so the person is not, or no longer, identifiable
Still personal data under GDPR?Yes (GDPR Art. 4(5) and Recital 26)No, truly anonymous data falls outside the GDPR (Recital 26)
ExampleCustomer ID 48213 instead of a name, with the lookup table stored separatelyAggregated statistics with no way to single out a person

Hashing an email address is pseudonymization, not anonymization: the same email always produces the same hash, so it can still be linked to a person.

PII Breach Notification Basics

When PII is lost, stolen or exposed, notification duties usually apply:

  • GDPR: the controller must notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach (Article 33), unless the breach is unlikely to result in a risk to people. If the breach is likely to result in a high risk, affected individuals must also be told without undue delay (Article 34).
  • United States: all 50 states have data breach notification laws (Alabama and South Dakota were the last to adopt one, in 2018). Deadlines, the types of PII covered and regulator notice thresholds differ by state.

Keep an incident response plan ready, including who decides, who notifies and which templates to use.

How UniConsent Helps Control PII Collection

Cookies, pixels and tags are among the most common ways websites collect PII without noticing. UniConsent puts you in control:

  • Consent before trackers fire: prior blocking keeps advertising and analytics cookies and scripts off the page until the visitor consents, so no cookie IDs or IP addresses go to third parties without permission.
  • Cookie scanner: find every cookie and tracker on your site and disclose them automatically in the cookie banner.
  • Consent logs: keep a consent audit trail as proof of consent.
  • Google Consent Mode v2: pass consent choices to Google tags with Google Consent Mode.
  • Global Privacy Control: honor GPC opt-out signals for US privacy laws.
  • Privacy portal: handle access and deletion requests (DSARs) with the privacy portal.

Start with UniConsent and control PII collection on your website in minutes. For an overview of the laws that regulate PII worldwide, see our Global Privacy Laws guide.

Frequently Asked Questions

What does PII stand for?

PII stands for personally identifiable information. It means any information that can identify a specific person, either directly (such as a name or Social Security number) or when combined with other information (such as a date of birth and ZIP code).

What are examples of PII?

Common examples of PII are full name, Social Security number, passport or driver's license number, email address, phone number, home address, date of birth, biometric data, financial account numbers, IP addresses and device or cookie identifiers.

What is sensitive PII?

Sensitive PII is information that could cause serious harm if exposed, such as Social Security numbers, passport numbers, financial account numbers, log-in credentials, medical and biometric data, and precise geolocation. It requires stronger protection such as encryption and strict access control.

Is an IP address PII?

Usually, yes. Under the GDPR, IP addresses are online identifiers and are personal data (Recital 30), and the EU Court of Justice held in Breyer (2016) that even dynamic IP addresses can be personal data for a website operator. The CCPA also lists IP addresses as personal information.

What is the difference between PII and personal data?

PII is a US term focused on information that can identify or trace a person. Personal data under the GDPR is broader: any information relating to an identified or identifiable person, including online identifiers such as cookie IDs. All PII is personal data, but not all personal data appears on narrow PII lists.

Is an email address PII?

Yes. A personal email address such as firstname.lastname@example.com directly identifies a person. A work email that contains a person's name is also PII, and a hashed email is still personal data under the GDPR because it can be linked back to the person.

Control PII Collection with UniConsent

  • Cookies scan and disclosing
  • JavaScript tags blocking and cookies blocking
  • Google Consent Mode v2 support
  • Consent logs as proof of consent
  • Global Privacy Control (GPC)
  • Certified IAB CMP
  • One-tag Implementation
  • Multiple languages support
  • Easy self-serve solution
  • Learn more from Global Privacy Laws Guide

Microsoft certified CMP - UniConsent CMPIAB certified CMP - UniConsent CMPIAB TCF V2 certified CMP - UniConsent CMPIAB TCF Canada certified consent manager - UniConsent CMPGoogle-certified CMP Gold tire - UniConsent CMPGoogle-certified CMP partner

Comply With Global Privacy Regulations

Trusted by 5000+ of global publishers and marketers
  • sej
  • football365
  • sharethrough
  • districtm
  • pf1
  • tower cast

Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc

Sign up