PII is the term used predominantly in US law and organizational policy to describe data requiring privacy protection. Unlike the GDPR's 'personal data', defined by regulation, PII definitions vary across US federal laws, state regulations, and organizational standards.
At minimum, PII typically includes obvious identifiers:
The definition expands in modern frameworks to include:
The distinction between 'direct PII' (information that identifies someone on its own) and 'indirect PII' (information that identifies someone in combination with other data) matters for data governance.
As data ecosystems have grown more interconnected, the bar for what constitutes indirect PII has effectively lowered. Information that was safely anonymous in isolation can become identifying when joined with other datasets, a particular consideration for AI and analytics use cases that aggregate behavioral data at scale.