Cyber Risk Compendium

Person identifiable information (PII)

Personally Identifiable Information (PII) is defined as:

Any information that can be used on its own or in combination with other data to identify, contact, or locate a specific individual.

What makes this category special is that regulation (e.g. GDPR) forces an organisation to protect assets of a third party. When you process data, you don’t need to protect only your own assets, but you may be required to restrict yourself in order to protect the third party, making yourself a potential threat agent that you must include in your analysis.

Key Characteristics:

  • Can directly or indirectly identify a person

  • Includes both sensitive and non-sensitive data

Examples of PII:

Direct Identifiers

Indirect Identifiers

Full name

Date of birth

Social Security Number (SSN)

IP address

Email address

Job title or workplace

Passport or ID number

Location data

Phone number

Cookies or device identifiers

Note:

  • In the EU (GDPR), PII is referred to as "personal data" and has a broader scope.

  • Sensitive PII (e.g., medical records, biometric data) requires stronger protection due to the higher risk of harm if compromised.