PII vs Personal Information vs Personal Data
Last reviewed: · By Victor Humenhuk (CIPP/US certified)
The three terms overlap but none has a single fixed legal meaning. PII is an American term of art with no universal statutory definition, and in U.S. breach-notification statutes it usually means a narrow list such as a name combined with a Social Security number or an account number. Personal information is the term California and most U.S. state laws use, and the CCPA version is very broad, reaching household data and inferences. Personal data is the GDPR's term and the term used by most non-California state comprehensive laws, covering information linked or reasonably linkable to an identified or identifiable person. Always apply the definition in the statute in front of you.
Why the label you use matters
Scope determines obligation. Whether a dataset is regulated, whether a breach must be notified, and whether a consumer can demand deletion all turn on a definition that changes from statute to statute. Treating the three terms as synonyms produces two predictable failures: a company assumes its data is out of scope because it holds no Social Security numbers, or it over-notifies because it applied a comprehensive-law definition to a breach statute that never covered the data.
The safest working habit is to stop asking "is this PII?" and start asking "is this within the definition in the statute I am applying?" The exam tests the same instinct, because the sectoral U.S. model means several definitions can apply to the same record at once. The topic on personal information introduces the concept before the statute-specific variants pile up.
One more distinction sits underneath all three. Data that has been deidentified or aggregated so that it cannot reasonably be linked to an individual generally falls outside these definitions, but only where the holder makes and maintains commitments not to reidentify it. See deidentified data and pseudonymization for where that line sits.
The three terms compared
| PII | Personal information | Personal data | |
|---|---|---|---|
| Where it comes from | General U.S. usage and NIST guidance; specific statutes such as FERPA define their own version | California and most U.S. state and sectoral laws | The GDPR, and most non-California state comprehensive laws |
| Typical breadth | Varies enormously; often narrow and identifier-focused | Very broad under the CCPA - anything that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a consumer or household | Broad - any information linked or reasonably linkable to an identified or identifiable natural person |
| Covers households? | No | Yes, under the CCPA - unusual among U.S. laws | No; the subject is a natural person |
| Covers inferences? | Generally not | Yes - inferences drawn to create a profile are expressly included | Yes, where linkable to an identifiable person |
| Covers online identifiers? | Sometimes, depending on the source | Yes - IP addresses, cookie identifiers and device identifiers are listed categories | Yes - online identifiers are named in the definition |
| Common exclusions | Depends entirely on the statute | Deidentified and aggregate information, and information meeting the statutory publicly available exclusion | Deidentified data, publicly available information, and data outside the law's scope such as employment or B2B data in most states |
How breach statutes narrow the definition
This is where practitioners most often get caught. State breach notification laws do not use the broad comprehensive-law definition. They typically define personal information as a first name or initial plus last name, in combination with one or more specified data elements, such as:
- Social Security number;
- driver's license or state identification number;
- financial account, credit card or debit card number with any code that would permit access to the account;
- in many states, medical information or health insurance information;
- in a growing number of states, biometric data, and a username or email address with a password or security question and answer.
Two consequences follow. First, a breach of browsing history or inferred interests may be squarely within the CCPA's definition of personal information yet fall outside the state's breach statute, so no notification duty arises. Second, most breach statutes exclude data that was encrypted, and some exclude redacted data, provided the encryption key was not also compromised - a safe harbor that has no equivalent in the comprehensive laws.
The definitions that carry their own rules
Several U.S. statutes define the concept for themselves, and those definitions control within their sector regardless of what any other law says.
- FERPA defines personally identifiable information to include direct identifiers such as name and student number, indirect identifiers such as date and place of birth and mother's maiden name, and other information that alone or in combination would allow a reasonable person in the school community to identify the student with reasonable certainty. It also captures information requested by someone the school reasonably believes knows the identity of the student.
- HIPAA uses protected health information, which is individually identifiable health information held or transmitted by a covered entity or business associate, with express exclusions for FERPA education records and employment records.
- The GLBA uses nonpublic personal information, tied to a consumer's relationship with a financial institution.
- The FCRA does not regulate a category of data at all; it regulates a type of document, the consumer report, and who may obtain it.
That last point generalizes well. Several U.S. statutes regulate a context - a report, a transaction, a communication - rather than a category of data, which is why asking whether something is "PII" often produces the wrong answer to the right question.
Related study notes
- Personal Information and Sensitive Personal Information
- Personal Information and Its Exclusions
- Personal Data and Sensitive Personal Data
- Personally Identifiable Information under FERPA
- Breach Laws: Defining Personal Information
Frequently asked questions
Is PII the same as personal data?
No. PII is a U.S. term with no single statutory definition and is often read narrowly as direct identifiers. Personal data is the GDPR's term and covers anything relating to an identified or identifiable person, including online identifiers and inferences. A dataset can be outside a narrow PII list and still be personal data.
Is an IP address personal information?
Under the CCPA, yes - IP addresses are a listed category of personal information. Under the GDPR they are personal data where the holder has means reasonably likely to be used to identify the individual. Under most state breach notification statutes an IP address on its own is not covered.
Does the CCPA really cover household data?
Yes, and it is unusual in doing so. The CCPA's definition reaches information that could reasonably be linked with a particular consumer or household, which brings smart-home and shared-device data into scope. Other state comprehensive laws define personal data by reference to an identifiable natural person only.
Is publicly available information excluded?
Usually, but the exclusion is defined differently in each law. State comprehensive laws generally exclude information lawfully made available from government records or that the consumer made available to the public, while breach statutes exclude information lawfully made available to the general public. Check the wording before relying on it.
Test yourself
Try the free CIPP/US practice questions, or read the full CIPP/US study guide - free.