Identifiability is contextual: the same value may identify someone in one dataset or environment but not in another, depending on available records, tools, access, and reasonable means of linkage.
PII is prominent in United States federal guidance, but it is not a universal legal category. The European Union General Data Protection Regulation (GDPR) uses “personal data,” a similar but independently defined term. Other laws use their own scopes, exclusions, sensitivity classes, and obligations.
Key points
Direct and indirect identificationNames or identification numbers may identify directly; device, location, behavioral, demographic, or combined attributes may enable indirect identification or singling out.
Contextual assessmentConsider who can access the data, what other datasets and techniques are realistically available, whether identity can be traced, and the potential effects of misuse.
Proportionate protectionMinimize collection, classify and restrict access, separate identifiers where useful, secure storage and transfer, govern sharing and retention, and reassess when data or context changes.
Important limitationNo fixed list captures all PII, and removing obvious identifiers does not guarantee anonymity. Classification as non-PII under one framework does not establish that data falls outside another jurisdiction’s personal-data law; obtain qualified legal review.