# What is Personally Identifiable Information (PII)?

> Personally identifiable information (PII) is information that can distinguish or trace an individual’s identity, either by itself or when combined with other information that is linked or linkable to that person.

- Canonical URL: https://yellowcube.eu/glossary/personally-identifiable-information/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Identifiability is contextual: the same value may identify someone in one dataset or environment but not in another, depending on available records, tools, access, and reasonable means of linkage.

PII is prominent in United States federal guidance, but it is not a universal legal category. The European Union General Data Protection Regulation (GDPR) uses “personal data,” a similar but independently defined term. Other laws use their own scopes, exclusions, sensitivity classes, and obligations.

### Key points

- **Direct and indirect identification:** Names or identification numbers may identify directly; device, location, behavioral, demographic, or combined attributes may enable indirect identification or singling out.
- **Contextual assessment:** Consider who can access the data, what other datasets and techniques are realistically available, whether identity can be traced, and the potential effects of misuse.
- **Proportionate protection:** Minimize collection, classify and restrict access, separate identifiers where useful, secure storage and transfer, govern sharing and retention, and reassess when data or context changes.
- **Important limitation:** No fixed list captures all PII, and removing obvious identifiers does not guarantee anonymity. Classification as non-PII under one framework does not establish that data falls outside another jurisdiction’s personal-data law; obtain qualified legal review.

### Related terms

[Data privacy](<https://yellowcube.eu/glossary/data-privacy/>) · [Data protection](<https://yellowcube.eu/glossary/data-protection/>) · [Data classification](<https://yellowcube.eu/glossary/data-classification/>) · [Data breach](<https://yellowcube.eu/glossary/data-breach/>) · [Identity theft](<https://yellowcube.eu/glossary/identity-theft/>)

### Sources

[NIST SP 800-122: Guide to Protecting the Confidentiality of PII](https://csrc.nist.gov/pubs/sp/800/122/final) · [European Data Protection Board: Data Protection Basics](https://www.edpb.europa.eu/sme/learn-the-basics/data-protection-basics_en) · [EU General Data Protection Regulation, Article 4(1)](https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

