Personally identifiable information (PII) is defined in multiple ways across industry and regulatory standards, and understanding the distinctions between those definitions is essential for handling data correctly. This content breaks down three NIST definitions of PII and explains which is most practical for real-world data protection work.
Personally Identifiable Information (PII)
There's a lot of confusion around personally identifiable information, or PII, and rightfully so — there are actually a lot of different definitions when it comes to what PII actually means. So let's make sure we understand what PII is and how to identify it.
Here I'm on the NIST website. NIST stands for National Institute of Standards and Technology, so it is the organization that creates standards out there, and they do a lot of standards around cyber security. They're creating the standards, and this is showing you that they define personally identifiable information in several different ways. So no wonder there's confusion, when there are so many different definitions even from the source that's supposed to be the source that defines these things and has something that's more definitive.
Let's look at definition number one, which happens to be my favorite definition of what PII actually is. It's the most specific, and it gets to the heart of what PII is actually supposed to represent, and that is any representations of information that permits the identity of an individual — so we identify a specific individual.
The best way to really drive home what this definition means is by looking at some real world examples.
In this first example, this is somebody's name. This is actually Elon Musk's child's name — he named one of his kids this, which I can't really even pronounce. So this is somebody's name here, and is it personally identifiable information? Well, yes it is, that identifies a specific person.
Next one: Andrew, that's me. Does that personally identify me? Well, not exactly. There are a lot of Andrews in the world, it's a very common name, and so does this identify specifically me? No, it doesn't.
How about my address? Does my address itself identify who I am? No, and the reason why is because I have multiple people living in my household. So how about my address with just one resident, maybe I'm living alone — does that identify me? Since there's only one individual in that household, that address now becomes personally identifiable information.
How about a combination of my address, which has multiple people living in it, and me? This combination right here identifies a specific person, Andrew, me, because there's no other Andrews that live at this address, and so now that's personally identifiable information.
A social security number is what Americans use to identify people. That is always personally identifiable information, that will never change.
My phone is just my phone, it's something that no one else really uses, it identifies me, so my phone number is personally identifiable information. If I have a household phone that is downstairs and there's a phone number, that phone number is not personally identifiable information, because there are multiple people living in this household, so that would be no.
If I have a grade on a school paper, then that grade — hey, I got an A on this paper that I had to turn in to my math class, let's say — that right there is not personally identifiable information.
If I have some sort of financial deposit information, maybe I deposited a check, then that would be no, that does not personally identify who I am.
I like this definition because it's the most technical, and it really drives to the heart of what personally identifiable information actually is and what it's supposed to represent.
Let's take a look at definition number two of how people define what PII is, and this is information that can be used to distinguish or trace an individual's identity, such as name, social security number, biometric data records.
Essentially this is going to be very similar — it sounds very similar to our definition number two — but the key difference is we're always going to categorize name as being PII information. So in that case it doesn't matter if it's a very unique name or there's a ton of people that have that same name, whether it's my address, whether I'm the only one or there are multiple people living at my address. So whatever combination of these, these are all personally identifiable information. Grade on a school paper, no, not necessarily. Financial deposit information, no, not necessarily. So these are all personally identify who I am. So this is definition number two.
Even though I like definition number one the best, this is the most practical, and there are several reasons why this is the most practical and the one that probably most of us should adopt.
The reason this is the most practical definition of what PII is, and what generally most organizations will use as the definition of PII, is because we have to think of things from a data set perspective. Let's say I have a table here — maybe it's a table part of a database, maybe it's part of a spreadsheet, whatever the case may be. I have people's personal information right here. This is PII with definition number two but not in number one, because I don't have anybody's name in here that isn't a common name right here, so it by itself is not PII information according to definition number one, but it is for definition number two.
The problem with treating this as not being PII is, number one, we have other data sets that are part of this, so now in the combination of this we've now created PII information. And also number two is that we have the potential that somebody could have a very unique name that no one else ever has in the world, and in that case then it becomes PII as well.
So what we're going to do is treat this data as being PII either way. So definition number two, where name is always going to be PII, is going to be probably the best operational definition that we have for PII.
Then there's definition number three, and if we read through this it kind of comes into two parts. It's once again any information about an individual maintained by an agency, and then the first part here that we see that's outlined is pretty much the same definition that we saw with definition number one and definition number two, so this is just a repeat of that. But then it adds to it, and what it adds is any other information that is linked or linkable to an individual, such as medical, educational, financial and employee information.
Well, now it's just really any information that is on you that is defined by this definition number three. So in other words, all of those pieces of information we said were PII before are still PII in this definition, but we also include that grade on the school paper, the financial deposit — anything that is linkable to you is now PII.
I'm not a big fan of this definition, because it doesn't tell me really how to treat my information in a more granular way. When I am dealing with this information that I have here, I will treat PII information in a certain way, and then I may treat some of these other pieces of information in a little different fashion, and this doesn't allow that granularity of control to define how I treat these different pieces of information.
Even with definition number one and number two, where we have personally identify information which identifies who you are, we can still identify other aspects like your health records, financial records, educational records. We just call it all personal information, or PI. So we've got personal information and personally identifiable information, and we can delineate between the two and address those two types of data separately.
PII is not the only term that's used when it comes to these laws and regulations. A good example of that is GDPR. It uses the term personal data, and in similar ways it protects this personal data, but it defines it as anything that's personally identifiable information as well as any other records about that individual. So that's just one example of another law and regulation out there.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →