TechKnowSurge
NIST NICE K0917 NIST NICE K1194 NIST 800-53 PT-2 ISC2 CISSP 2.1 NIST 800-53 PT-3 CompTIA SecurityX 1.4
VideoSecurityFree

Personally Identifiable Information (PII)

Personally identifiable information (PII) is defined in multiple ways across industry and regulatory standards, and understanding the distinctions between those definitions is essential for handling data correctly. This content breaks down three NIST definitions of PII and explains which is most practical for real-world data protection work.

Complete this video to capture a CTF flag worth 1 point.

About this video

Personally identifiable information, or PII, does not have a single universal definition, and that ambiguity creates real challenges for organizations trying to protect the data they collect and store. Even NIST, the National Institute of Standards and Technology and a primary source of cybersecurity standards in the United States, offers multiple definitions — which helps explain why confusion around the term is so widespread. The first NIST definition is the most technically precise: PII is any information that permits the identity of a specific individual to be determined. Under this definition, context is everything. A common first name like Andrew does not qualify on its own because it could apply to many people. An address shared by multiple household members also falls short. However, a name paired with an address where that person is the sole resident, or a Social Security number that is inherently tied to one individual, does meet the standard. This definition is useful for understanding what PII is at its core, but it is less practical when managing large datasets where context cannot always be evaluated on a case-by-case basis. The second definition treats certain categories of information — names, Social Security numbers, biometric records, and similar identifiers — as PII by default, regardless of how common or unique they may be in a given context. This approach is better suited for organizational data governance because it removes the need to assess each data point individually. When a name is stored alongside other records in a database or spreadsheet, the risk of combined identification is real, and treating names as inherently PII reduces the chance that sensitive datasets are misclassified. For most practical purposes, this is the definition organizations should adopt. The third definition extends the scope further, classifying any information linked or linkable to an individual — including financial records, educational records, and medical data — as PII. While comprehensive, this definition limits an organization's ability to apply differentiated handling policies, since it places all personal data under the same umbrella. A more useful operational approach distinguishes between PII, which directly identifies an individual, and broader personal information, which includes associated records like health or financial data. This distinction allows for more granular data classification and more targeted protective measures. It is also worth noting that regulations outside the United States, such as GDPR in Europe, use different terminology — personal data rather than PII — but the underlying protective principles are closely aligned.

What you'll learn

What's covered

Personally Identifiable Information (PII)

Aligned to

NIST NICE
K0917 Knowledge of Personally Identifiable Information (PII) data security standards and best practices
K1194 Knowledge of Personally Identifiable Information (PII) attributes
NIST 800-53
PT-2 Authority to Process Personally Identifiable Information
PT-3 Personally Identifiable Information Processing Purposes
ISC2 CISSP
2.1 Identify and classify information and assets
CompTIA SecurityX
1.4 Explain how privacy and data sensitivity impact security and business requirements

Key terms

Personally Identifiable Information
PII
Personally Identifiable Information is any data that can be used alone or in combination to identify, contact, or locate an individual, requiring protection under privacy laws and organizational security policies.
Personal Data
A term used in regulatory frameworks such as GDPR to describe any information relating to an identified or identifiable individual, encompassing both PII and other linked personal records.
Personal Information
PI
Data that is personal to an individual, such as medical, financial, or school records, that a person would not want disclosed publicly.

Topics

Personally Identifiable Information Data Privacy Nist Standards Data Classification Information Security

Transcript

There's a lot of confusion around personally identifiable information, or PII, and rightfully so — there are actually a lot of different definitions when it comes to what PII actually means. So let's make sure we understand what PII is and how to identify it.

Here I'm on the NIST website. NIST stands for National Institute of Standards and Technology, so it is the organization that creates standards out there, and they do a lot of standards around cyber security. They're creating the standards, and this is showing you that they define personally identifiable information in several different ways. So no wonder there's confusion, when there are so many different definitions even from the source that's supposed to be the source that defines these things and has something that's more definitive.

Definition number one

Let's look at definition number one, which happens to be my favorite definition of what PII actually is. It's the most specific, and it gets to the heart of what PII is actually supposed to represent, and that is any representations of information that permits the identity of an individual — so we identify a specific individual.

The best way to really drive home what this definition means is by looking at some real world examples.

In this first example, this is somebody's name. This is actually Elon Musk's child's name — he named one of his kids this, which I can't really even pronounce. So this is somebody's name here, and is it personally identifiable information? Well, yes it is, that identifies a specific person.

Next one: Andrew, that's me. Does that personally identify me? Well, not exactly. There are a lot of Andrews in the world, it's a very common name, and so does this identify specifically me? No, it doesn't.

How about my address? Does my address itself identify who I am? No, and the reason why is because I have multiple people living in my household. So how about my address with just one resident, maybe I'm living alone — does that identify me? Since there's only one individual in that household, that address now becomes personally identifiable information.

How about a combination of my address, which has multiple people living in it, and me? This combination right here identifies a specific person, Andrew, me, because there's no other Andrews that live at this address, and so now that's personally identifiable information.

A social security number is what Americans use to identify people. That is always personally identifiable information, that will never change.

My phone is just my phone, it's something that no one else really uses, it identifies me, so my phone number is personally identifiable information. If I have a household phone that is downstairs and there's a phone number, that phone number is not personally identifiable information, because there are multiple people living in this household, so that would be no.

If I have a grade on a school paper, then that grade — hey, I got an A on this paper that I had to turn in to my math class, let's say — that right there is not personally identifiable information.

If I have some sort of financial deposit information, maybe I deposited a check, then that would be no, that does not personally identify who I am.

I like this definition because it's the most technical, and it really drives to the heart of what personally identifiable information actually is and what it's supposed to represent.

Definition number two

Let's take a look at definition number two of how people define what PII is, and this is information that can be used to distinguish or trace an individual's identity, such as name, social security number, biometric data records.

Essentially this is going to be very similar — it sounds very similar to our definition number two — but the key difference is we're always going to categorize name as being PII information. So in that case it doesn't matter if it's a very unique name or there's a ton of people that have that same name, whether it's my address, whether I'm the only one or there are multiple people living at my address. So whatever combination of these, these are all personally identifiable information. Grade on a school paper, no, not necessarily. Financial deposit information, no, not necessarily. So these are all personally identify who I am. So this is definition number two.

Even though I like definition number one the best, this is the most practical, and there are several reasons why this is the most practical and the one that probably most of us should adopt.

The reason this is the most practical definition of what PII is, and what generally most organizations will use as the definition of PII, is because we have to think of things from a data set perspective. Let's say I have a table here — maybe it's a table part of a database, maybe it's part of a spreadsheet, whatever the case may be. I have people's personal information right here. This is PII with definition number two but not in number one, because I don't have anybody's name in here that isn't a common name right here, so it by itself is not PII information according to definition number one, but it is for definition number two.

The problem with treating this as not being PII is, number one, we have other data sets that are part of this, so now in the combination of this we've now created PII information. And also number two is that we have the potential that somebody could have a very unique name that no one else ever has in the world, and in that case then it becomes PII as well.

So what we're going to do is treat this data as being PII either way. So definition number two, where name is always going to be PII, is going to be probably the best operational definition that we have for PII.

Definition number three

Then there's definition number three, and if we read through this it kind of comes into two parts. It's once again any information about an individual maintained by an agency, and then the first part here that we see that's outlined is pretty much the same definition that we saw with definition number one and definition number two, so this is just a repeat of that. But then it adds to it, and what it adds is any other information that is linked or linkable to an individual, such as medical, educational, financial and employee information.

Well, now it's just really any information that is on you that is defined by this definition number three. So in other words, all of those pieces of information we said were PII before are still PII in this definition, but we also include that grade on the school paper, the financial deposit — anything that is linkable to you is now PII.

I'm not a big fan of this definition, because it doesn't tell me really how to treat my information in a more granular way. When I am dealing with this information that I have here, I will treat PII information in a certain way, and then I may treat some of these other pieces of information in a little different fashion, and this doesn't allow that granularity of control to define how I treat these different pieces of information.

Even with definition number one and number two, where we have personally identify information which identifies who you are, we can still identify other aspects like your health records, financial records, educational records. We just call it all personal information, or PI. So we've got personal information and personally identifiable information, and we can delineate between the two and address those two types of data separately.

Other terms in laws and regulations

PII is not the only term that's used when it comes to these laws and regulations. A good example of that is GDPR. It uses the term personal data, and in similar ways it protects this personal data, but it defines it as anything that's personally identifiable information as well as any other records about that individual. So that's just one example of another law and regulation out there.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →