Privacy

Personally identifiable information

Also called PII.

Personally identifiable information is data that identifies a person under a given legal or policy test. The label and its edges change by statute.

How it is measured

US breach laws often list items such as a name plus a Social Security number. NIST guidance also covers data that is linkable to a person. There is no single definition to cite.

Pick the law that applies to your obligation first, then map your fields to its list. Keep one map per law.

Worked example

A health-club app stores name, email, date of birth, and a workout log. Under one state's breach statute, name plus date of birth triggers a notice duty. Under GDPR, the workout log with a device ID counts as well.

The team keeps a table per legal definition, so a breach response starts with the right list.

How it differs

PII is a US-style label tied to particular statutes. Personal data is the broader GDPR concept. PII may leave out online identifiers; personal data includes them.

Common errors

Using PII to mean everything sensitive. Ignoring linkable data. Skipping state differences. Treating pseudonyms as safe. Never updating the map.

In practice

Name the law first and map fields to it second. Review the map once a year, or after you add a new form.

See also

Personal data, IP address, User ID

Sources

Count this on a real site.

Watch my website