Personally Identifiable Information (PII) is defined as:
Any information that can be used on its own or in combination with other data to identify, contact, or locate a specific individual.
What makes this category special is that regulation (e.g. GDPR) forces an organisation to protect assets of a third party. When you process data, you don’t need to protect only your own assets, but you may be required to restrict yourself in order to protect the third party, making yourself a potential threat agent that you must include in your analysis.
Key Characteristics:
Can directly or indirectly identify a person
Includes both sensitive and non-sensitive data
Examples of PII:
Direct Identifiers | Indirect Identifiers |
|---|---|
Full name | Date of birth |
Social Security Number (SSN) | IP address |
Email address | Job title or workplace |
Passport or ID number | Location data |
Phone number | Cookies or device identifiers |
Note:
In the EU (GDPR), PII is referred to as "personal data" and has a broader scope.
Sensitive PII (e.g., medical records, biometric data) requires stronger protection due to the higher risk of harm if compromised.