Skip to main content
Category: Privacy and Cybersecurity

Personal Information

Also known as: PII, Personal Data, Personally Identifiable Information
Simply put

Personal information is any information that relates to an identifiable individual, such as a name, address, account number, IP address, or device identifier. It can identify a person either on its own or when combined with other information. The precise scope of what counts as personal information varies by jurisdiction and by the specific privacy law that applies.

Formal definition

Personal information (also termed personal data or personally identifiable information) is generally defined as information that can be used to distinguish or trace an individual's identity, either alone or when linked or linkable to other information relating to an identifiable person. Categories can include direct identifiers (e.g., name, address, account number) and indirect or online identifiers (e.g., IP address, device identifier). The specific definition, scope, and treatment are established by applicable data privacy laws and vary by jurisdiction; under many such laws, encrypted and pseudonymized data may still be treated as personal information. Practitioners should determine the governing legal definition for their context, as coverage is fact- and jurisdiction-dependent.

Why it matters

The definition of personal information is the trigger that determines whether a data privacy law applies to a given activity at all. If information falls within the definition, obligations around notice, consent, security, retention, individual rights, and cross-border transfer may attach; if it does not, those obligations generally do not. Because the scope varies by jurisdiction and by the specific law in question, an organization can be subject to materially different requirements for the same data set depending on where individuals are located and which regime governs. Misjudging that boundary is a common source of compliance gaps.

A particularly important point for practitioners is that data an organization considers de-identified may still be regulated. Under many privacy laws, encrypted and pseudonymized data is still treated as personal information, because it can be linked back to an identifiable individual. This means that technical safeguards such as encryption reduce risk but do not necessarily remove data from the scope of a privacy law. Treating pseudonymized records as outside the regime can leave an organization exposed to obligations it did not account for.

Because coverage extends beyond obvious direct identifiers such as name and address to indirect and online identifiers such as IP addresses and device identifiers, the practical footprint of personal information within most organizations is broad. This breadth affects data inventories, risk assessments, breach analysis, and the design of controls. The specific scope is fact- and jurisdiction-dependent, so the governing legal definition for a given context should be confirmed rather than assumed.

Who it's relevant to

Chief Privacy Officers and Data Protection Leads
This function is typically accountable for determining which data privacy law governs a given activity and applying its definition of personal information to the organization's data holdings. Because scope varies by jurisdiction and because pseudonymized and encrypted data may remain in scope under many laws, privacy leaders need a defensible basis for classifying data rather than assuming technical safeguards remove it from coverage.
General Counsel and Legal Teams
Legal advisers confirm the governing legal definition for the organization's context, since coverage is fact- and jurisdiction-dependent. They are often relied upon to distinguish where a specific privacy statute or regulation creates binding obligations from where non-binding guidance applies, and to advise on how the same data set may be treated differently across regimes.
Compliance and Risk Functions
Compliance teams generally translate the applicable legal definition into monitoring, control requirements, and data inventories, while risk functions assess exposure arising from the breadth of personal information across systems. The point that encrypted and pseudonymized data may still be regulated is relevant to how these functions scope assessments and avoid treating such data as out of scope.
Boards and Audit or Risk Committees
At the oversight level, boards and their relevant committees generally seek assurance that management has correctly scoped personal information and built controls to match applicable obligations. Their role is oversight rather than operational classification, but understanding that the definition is jurisdiction-dependent helps them challenge management assumptions about what data is covered.
Internal Audit and Assurance Providers
Assurance functions test whether the organization's identification and handling of personal information aligns with the governing legal definition and internal policy. This includes evaluating whether data considered de-identified has been properly assessed, given that many privacy laws still treat pseudonymized and encrypted data as personal information.

Inside PII

Directly identifying data
Information that identifies a specific individual on its own, such as name, government-issued identifier, contact details, or account credentials. Whether a given data element qualifies as personal information depends on the applicable legal definition, which varies by jurisdiction.
Indirectly identifying data
Information that identifies an individual when combined with other data, such as an IP address, device identifier, or location signals. Many data protection regimes treat such data as personal information where an individual is reasonably identifiable, though the threshold differs across frameworks.
Special or sensitive categories
Subsets of personal information that are typically subject to heightened protection under certain regimes, such as health, biometric, or similar data. The scope of what counts as sensitive, and the additional obligations attached, generally depends on the specific statute or regulation involved.
Contextual and jurisdictional definition
The meaning of personal information is set by the applicable law rather than by a single universal standard. Definitions and their boundaries generally vary by jurisdiction, sector, and entity type, so the same data element may be in scope under one regime and out of scope under another.
Processing and lifecycle scope
Personal information is generally addressed across its lifecycle, including collection, use, storage, sharing, and disposal. The obligations attaching to each stage are typically defined by the relevant legal regime and any voluntary standards an organization chooses to adopt.

Common questions

Answers to the questions practitioners most commonly ask about PII.

Is personal information the same thing as personally identifiable information (PII)?
Not exactly, and treating the two terms as interchangeable can create compliance gaps. "Personally identifiable information" is a narrower concept used chiefly in US-oriented frameworks, often focused on data that directly identifies an individual. "Personal information" (or "personal data" under certain regimes) is typically defined more broadly to include any information relating to an identified or identifiable person, which may capture online identifiers, location data, and inferred attributes. Because definitions vary by jurisdiction, sector, and the specific law or framework in play, you should work from the precise statutory definition that applies to your entity rather than a generic label. This entry is educational and not legal advice.
If data is anonymized or aggregated, is it automatically outside the scope of personal information rules?
Not necessarily. Whether de-identified data falls outside scope generally depends on how a given regime defines identifiability and the standard it sets for anonymization. Under some frameworks, pseudonymized data that can be re-linked to an individual remains personal information, while genuinely anonymized data that cannot reasonably be re-identified may fall outside scope. The threshold, the re-identification risk assessment, and any documentation expectations differ by jurisdiction and framework, so the classification is fact-specific and depends on the technical measures applied. Confirm the applicable definition before assuming data is out of scope.
Who within the organization is accountable for classifying and protecting personal information?
Accountability is typically layered across the three lines. Management (first line) generally owns the operational duties of identifying, classifying, and protecting personal information within business processes. A privacy, compliance, or risk function (second line) typically sets policy, provides frameworks, and monitors adherence, and in some jurisdictions or entity types a designated data protection officer may have specific responsibilities. Internal audit (third line) provides independent assurance over the design and operating effectiveness of these controls. The board or a relevant committee typically holds oversight responsibility rather than day-to-day operational duties. The precise allocation depends on the organization's structure and applicable requirements.
How should we build an inventory of personal information across the business?
A common approach is to maintain a data inventory or record of processing that captures what personal information is held, its categories, sources, purposes, storage locations, retention periods, and onward transfers. This is generally an operational activity owned by management within each function, supported by policy and templates from the privacy or compliance function. Some regimes make maintaining records of processing a legal requirement for certain entities, while in others it is treated as good practice; scope and format vary by jurisdiction and entity type. Because completeness depends on the facts of your processing, the inventory should be reviewed and updated on a defined cadence rather than treated as a one-time exercise.
What is the difference between a control's design and its operating effectiveness when protecting personal information?
Control design concerns whether a control, as configured, is capable of achieving its objective, for example whether access to personal information is restricted to authorized roles. Operating effectiveness concerns whether that control actually functioned as intended over a period, for example whether access reviews were performed and exceptions remediated. Management typically owns the design and day-to-day operation of these controls, while assurance functions may evaluate both design and operating effectiveness. Distinguishing the two matters because a well-designed control that is not consistently operated still leaves residual risk. The appropriate testing approach depends on the control and the assurance objective.
How do we determine our risk appetite for handling personal information?
Risk appetite is generally the amount and type of risk an organization is willing to accept in pursuit of its objectives, and it is typically set or endorsed at board level, then operationalized by management. For personal information, this often involves articulating tolerances around matters such as the sensitivity of data collected, permissible processing purposes, and exposure from third-party sharing. Risk appetite should be distinguished from risk tolerance, which typically expresses acceptable variation around specific objectives, and from risk capacity, the maximum risk the organization can bear. How these are expressed and measured depends on your risk framework, and the outcome reflects the organization's own judgment rather than a fixed external standard.

Common misconceptions

Personal information means the same thing everywhere, so one definition can be applied globally.
The definition is generally set by the applicable law and varies by jurisdiction, sector, and entity type. Data treated as personal information under one regime may fall outside another's scope, so the relevant legal definition should be confirmed for each context. This entry is educational and not legal advice.
Only directly identifying data such as a name qualifies as personal information.
Many regimes also treat indirectly identifying data as personal information where an individual is reasonably identifiable, including when data elements are combined. Whether a specific element is in scope depends on the applicable definition and the facts.
Protecting personal information is solely the compliance function's responsibility.
Accountability is typically distributed. Management generally owns the operational handling and controls over personal information as a first-line activity, the compliance function generally monitors and advises, and the board or a relevant committee typically exercises oversight. Which function owns a given activity depends on the organization's governance structure.

Best practices

Confirm the definition of personal information under each applicable regime before designing controls, rather than assuming a single universal standard, and document which jurisdictions and entity types are in scope.
Maintain an inventory that distinguishes directly identifying data, indirectly identifying data, and any special or sensitive categories, since heightened obligations may attach to certain categories under certain regimes.
Clarify accountability by mapping which function owns each activity across the data lifecycle, keeping the operational handling as a first-line management responsibility distinct from second-line compliance monitoring and board-level oversight.
Address personal information across its full lifecycle, including collection, use, storage, sharing, and disposal, and align controls to the obligations the relevant legal regime attaches to each stage.
Separate binding legal requirements from voluntary standards or frameworks the organization adopts, so that discretionary practices are not mistaken for statutory obligations.
Engage qualified legal, privacy, or compliance professionals to interpret how the applicable definition and obligations apply to specific facts, treating educational summaries as a starting point rather than definitive guidance.