Skip to main content
Oximy

Personally Identifiable Information (PII)

Any information that can be used to identify, contact, or locate a specific individual, either alone or combined with other sources.

Also known asPersonal InformationPersonal Data
Full Definition

What is Personally Identifiable Information?

Personally Identifiable Information (PII) is any data that could potentially identify a specific individual. This includes information that can directly identify someone or information that, when combined with other data, could lead to identification.

Categories of PII

Direct Identifiers

  • Full name
  • Social Security number
  • Driver's license number
  • Passport number
  • Email address
  • Phone number
  • Physical address

Indirect Identifiers

  • Date of birth
  • Place of birth
  • Race/ethnicity
  • Gender
  • Job title
  • Education history

Sensitive PII

  • Financial account numbers
  • Medical information
  • Biometric data
  • Sexual orientation
  • Religious beliefs
  • Political opinions

PII Under Various Regulations

RegulationTerminology
GDPRPersonal Data
CCPAPersonal Information
HIPAAPHI (health context)
NISTPII

Protection Requirements

  • Data minimization
  • Purpose limitation
  • Encryption at rest and in transit
  • Access controls
  • Retention policies
  • Secure disposal
  • Breach notification procedures

Best Practices

  • Inventory PII in your systems
  • Classify by sensitivity
  • Implement data masking
  • Regular access reviews
  • Employee training
  • Incident response planning