Personal Information
Personal information is any information that relates to an identifiable individual, such as a name, address, account number, IP address, or device identifier. It can identify a person either on its own or when combined with other information. The precise scope of what counts as personal information varies by jurisdiction and by the specific privacy law that applies.
Personal information (also termed personal data or personally identifiable information) is generally defined as information that can be used to distinguish or trace an individual's identity, either alone or when linked or linkable to other information relating to an identifiable person. Categories can include direct identifiers (e.g., name, address, account number) and indirect or online identifiers (e.g., IP address, device identifier). The specific definition, scope, and treatment are established by applicable data privacy laws and vary by jurisdiction; under many such laws, encrypted and pseudonymized data may still be treated as personal information. Practitioners should determine the governing legal definition for their context, as coverage is fact- and jurisdiction-dependent.
Why it matters
The definition of personal information is the trigger that determines whether a data privacy law applies to a given activity at all. If information falls within the definition, obligations around notice, consent, security, retention, individual rights, and cross-border transfer may attach; if it does not, those obligations generally do not. Because the scope varies by jurisdiction and by the specific law in question, an organization can be subject to materially different requirements for the same data set depending on where individuals are located and which regime governs. Misjudging that boundary is a common source of compliance gaps.
A particularly important point for practitioners is that data an organization considers de-identified may still be regulated. Under many privacy laws, encrypted and pseudonymized data is still treated as personal information, because it can be linked back to an identifiable individual. This means that technical safeguards such as encryption reduce risk but do not necessarily remove data from the scope of a privacy law. Treating pseudonymized records as outside the regime can leave an organization exposed to obligations it did not account for.
Because coverage extends beyond obvious direct identifiers such as name and address to indirect and online identifiers such as IP addresses and device identifiers, the practical footprint of personal information within most organizations is broad. This breadth affects data inventories, risk assessments, breach analysis, and the design of controls. The specific scope is fact- and jurisdiction-dependent, so the governing legal definition for a given context should be confirmed rather than assumed.
Who it's relevant to
Inside PII
Common questions
Answers to the questions practitioners most commonly ask about PII.