Defining PII (Personally Identifiable Information)

업데이트됨: 2026년08월13일 Time to read: ~

TL;DR 

Personally identifiable information (PII) covers any data that can be used to identify or profile an individual — from email addresses and Social Security numbers to IP addresses and usernames. The definition is intentionally broad, requiring organizations to conduct case-by-case assessments to determine what qualifies. Multiple regulations govern how PII must be handled: the European Union (EU)'s General Data Protection Regulation (GDPR) is the most prominent, granting consumers rights to protection, access, notification, and deletion of their data — and it applies to any organization doing business with European consumers, not just EU-based companies. In the United States, laws like HIPAA impose additional obligations on healthcare organizations. Any organization that collects user data — including website operators — must understand and comply with applicable PII regulations to avoid steep fines and privacy violations. Practical risks extend to everyday tools as well: marketing cookies and cloud migration can both introduce PII compliance exposure if not carefully managed.

Defining PII and its impact

Personally identifiable information (PII) is data someone could use to identify you. If someone had access to your PII, with a bit of time and talent, that person could figure out who you are. And sometimes, that sleuthing comes at great risk to your privacy, peace of mind, or both.

For example, PII could help a hacker discover that the head of a major nonprofit organization also spends time online gambling. Or PII could help a reporter determine that a lawmaker has a terminal illness.

Years ago, any digital company could collect scads of data about you. Blocking collection, manipulation, sharing, or deletion of that information was difficult. Now, many countries have PII laws on the books that give you rights. The biggest among them: The European Union (EU)'s General Data Protection Regulation (GDPR).

What is PII?

Information unique to you, or data that could be used to build a profile of you, is PII. If the definition seems nebulous, that's intentional. 

These data points are commonly considered PII:

  • Account numbers
  • Email addresses
  • Formal names (first and last)
  • Internet Protocol (IP) addresses
  • Phone numbers
  • Physical addresses
  • Social Security numbers
  • Usernames

But often, legislation allows companies to determine what is and is not PII. And the rules can shift periodically.

As the U.S. General Services Administration puts it, managing PII means conducting case-by-case assessments. Sometimes, a data point that doesn't seem like PII could become so at a later point. Truly taking stock of the data collected and its relevance is a full-time endeavor.

How does GDPR protect your PII?

As we mentioned, most countries have some kind of PII legislation. Consumers want control over their data, and they rely on government agencies to craft appropriate laws. One of the biggest comes from Europe.

The GDPR is legislation designed to protect European consumers as they make online transactions and otherwise conduct business. The law was years in the making, but in 2018 or so, companies had to enforce the law or face the consequences.

Under GDPR, consumers have the right to:

Protection Companies must ensure that PII they collect is secure. Access Consumers can request their PII and change inaccuracies. Notification Consumers must opt-in to data collection. Notifications tell them what PII is collected, what it's used for, and how long it's retained. Deletion Consumers can ask companies to wipe their digital slate clean.

Companies located within the EU must follow GDPR. But any company that works with European consumers must also comply.

To give an example, an American company selling airline tickets to an Irish customer must comply with GDPR. That airline must collect a variety of PII, including the passenger's name, address, and banking data. GDPR protects that Irish family, and the American company is on the hook to comply.

Who enforces GDPR and what are the penalties?

The European Data Protection Board (EDPB) manages this legislation, and this group can levy fines against companies that break the rules. Fines are steep, and they're applied at the breach level.

What other regulations govern PII beyond GDPR?

GDPR is one of the most far-reaching PII regulations in the world, but it is not the only one organizations must consider. Depending on where a company operates or what data it handles, additional laws — including U.S.-specific regulations — may also apply.

How does U.S. healthcare law relate to PII compliance?

American companies, for example, must also wrestle with Health Insurance Portability and Accountability Act (HIPAA) regulations. This healthcare law protects private information about patients, and insurance companies, hospitals, and others in the healthcare space are required to comply.

What PII do websites typically collect?

If you collect data from any consumer at any point, you must be thinking about PII. If you run a website, you're in this group.

When people visit an online entity like a website, you might track their:

  • IP address
  • Usernames
  • Addresses (if you have contact forms)
  • Bank accounts (if you accept payments)

How do cookies and cloud services create PII risks?

You may also have online trackers installed. So-called "cookies" can help you ensure your marketing plans are working, so you can attract even more customers down the line. If your cookies aren't PII compliant, and many of them are not, you could be facing privacy violations.

And the way you manage your services, such as tapping into the cloud, could come with its own PII risks.

Let us help. Read our blog about protecting PII while migrating to the cloud. And find out how Very Good Security lets us work on sensitive data without putting PII at risk.

Frequently asked questions

What makes a piece of data count as PII?

PII is any information that can uniquely identify an individual, or that can be combined with other data to build a profile of them. The definition is intentionally broad — common examples include Social Security numbers, email addresses, IP addresses, and physical addresses — because what qualifies as PII can shift over time. Organizations must evaluate each data point on a case-by-case basis rather than relying on a fixed list.

Does GDPR apply to companies outside of Europe?

Yes. GDPR's reach extends beyond EU borders — any company that conducts business with European consumers must comply, regardless of where it is headquartered. A U.S.-based airline selling tickets to an Irish customer, for example, is bound by GDPR rules for all PII collected during that transaction.

What rights does GDPR give consumers over their personal data?

GDPR establishes four core consumer rights: protection (companies must keep collected PII secure), access (consumers can view and correct their data), notification (consumers must opt in and be told what is collected, why, and for how long), and deletion (consumers can request that their data be erased). Together, these rights give individuals meaningful control over how their information is used.

What body is responsible for GDPR oversight, and how are penalties calculated?

The European Data Protection Board (EDPB) is responsible for overseeing GDPR enforcement. When companies violate the rules, fines are assessed at the individual breach level — meaning each separate violation can carry its own penalty, making non-compliance potentially very costly.

Does PII compliance only matter for companies subject to GDPR?

No. PII obligations extend well beyond GDPR. In the United States, the Health Insurance Portability and Accountability Act (HIPAA) requires healthcare organizations — including hospitals and insurance companies — to protect patient data. More broadly, any organization that collects user data through a website, contact form, or payment system must evaluate its PII responsibilities under whichever laws apply to its operations.

Why are marketing cookies a potential source of PII compliance violations?

Website tracking cookies are commonly used to measure marketing effectiveness, but the data they collect may qualify as PII. If those cookies are not configured to meet PII compliance requirements — and many are not — organizations can find themselves exposed to privacy violations. Cloud migration presents a similar challenge, as moving user data to cloud services introduces its own set of PII risks that must be proactively managed.

References

Rules and Policies Protecting PII. U.S. General Services Administration.

General Data Protection Regulation (GDPR): What You Need to Know to Stay Compliant. (June 2020). CSO.

Protection of Personal Data. European Commission.

The Birth of GDPR: What Is It and What You Need to Know. (May 2018). Forbes.

Who We Are. European Data Protection Board.

Continue your Identity journey