Using AI safely at work
What is PII data, and what counts as PII?
Last reviewed
Short answerPII, or personally identifiable information, is any information that identifies a person on its own or when combined with other information. Names, Social Security numbers, email addresses, and account numbers are PII. So are details such as a date of birth or ZIP code that point to one person together. The law that applies changes the exact list.
There is no single legal definition of PII in the United States. The most widely used one comes from the National Institute of Standards and Technology (NIST), which describes PII as “any information about an individual maintained by an agency, including (1) any information that can be used to distinguish or trace an individual’s identity, such as name, social security number, date and place of birth, mother’s maiden name, or biometric records; and (2) any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information.”
Two parts of that sentence matter in practice. Information can identify a person directly, and information that does not identify anyone alone can still be PII when it can be linked to a person.
Direct and indirect identifiers
A direct identifier points to one person without help. NIST lists names, personal identification numbers such as a passport, Social Security, driver’s license, taxpayer identification, or financial account number, address information such as a street address or email address, and personal characteristics such as a photograph of a face, fingerprints, handwriting, or other biometric data.
An indirect identifier identifies someone only in combination. NIST lists date of birth, place of birth, race, religion, weight, activities, geographical indicators, and employment, medical, education, and financial information as information that is linked or linkable to one of the direct identifiers. NIST gives an example of how context decides: ZIP codes and dates of birth can indirectly identify individuals or significantly narrow a large dataset, while an area code and gender alone usually would not, depending on the context and the size of the sample.
Examples of PII
| Category | Examples |
|---|---|
| Names | Full name, maiden name, mother’s maiden name, alias |
| Government and tax numbers | Passport number, Social Security number, driver’s license number, taxpayer identification number |
| Contact details | Street address, email address, telephone number |
| Financial | Bank account number, credit card number |
| Biometric and physical | Fingerprints, voice signature, facial geometry, photograph of a face, handwriting |
| Digital and device | IP address, device identifier, web address (URL) |
| Linked details | Date and place of birth, employment, education, medical, and financial records, geographic indicators |
Sensitive categories of PII
Some PII carries more risk if it leaks. NIST asks organizations to weigh how sensitive the data fields are, how many records are involved, how identifiable the person is, and the context and obligations that apply. Under the European Union’s GDPR, Article 9 names special categories of personal data that get extra protection: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify a person, data concerning health, and data concerning a person’s sex life or sexual orientation.
PII, PHI, and personal data under GDPR
The terms overlap but are not interchangeable.
| Term | Where it comes from | What it covers |
|---|---|---|
| PII | US federal guidance, including NIST SP 800-122 | Information that distinguishes or traces an individual’s identity, or that is linked or linkable to an individual. |
| PHI | HIPAA, 45 CFR 160.103 | Individually identifiable health information that a covered entity or its business associate transmits or maintains in any form. It relates to a person’s health, care, or payment for care and identifies the person or could reasonably identify them. |
| Personal data | GDPR, Article 4(1) | “Any information relating to an identified or identifiable natural person,” including by reference to an identifier such as a name, an identification number, location data, or an online identifier. |
HIPAA also defines what counts as de-identified. The Safe Harbor method in 45 CFR 164.514(b)(2) requires removing 18 kinds of identifiers of the individual and of relatives, employers, or household members, including names, geographic units smaller than a state, all elements of dates except year, telephone and fax numbers, email addresses, Social Security numbers, medical record numbers, account numbers, device identifiers, web addresses, IP addresses, biometric identifiers, and full-face photographs. For how HIPAA applies to AI tools, see Is AI HIPAA compliant?.
The UK Information Commissioner’s Office adds a point that applies to the same idea under GDPR: pseudonymised data is still personal data when the person can be linked back using additional information held separately.
How organizations find and protect PII
NIST organizes protection into operational safeguards, privacy-specific safeguards, security controls, and incident response. In practice that means:
- Find it. List the systems, files, and tools where PII is created, stored, or sent, including the AI tools staff use.
- Rate it. NIST recommends weighing identifiability, quantity, data field sensitivity, context of use, the obligation to protect it, and who can access it and where it sits.
- Collect and keep less. NIST calls minimizing the use, collection, and retention of PII a basic privacy principle, and recommends reviewing holdings and destroying PII that serves no current purpose.
- Write the policy and train people. NIST lists policy and procedure creation and awareness training as operational safeguards.
- Remove identifiers when you can. De-identifying records removes enough PII that the remaining information does not identify a person and there is no reasonable basis to believe it can be used to do so. De-identified data can sometimes be re-identified, so treat the method as a risk decision.
- Control access and plan for a breach. Apply security controls, and have an incident response process for a loss of PII.
Detection tools find values that match PII patterns, and masking or redaction replaces them. The glossary entries for PII detection, PII masking, and PII redaction define each term, and the guide to redacting PII before an LLM shows where those controls sit in a request to an AI tool.
PII and AI tools
PII reaches an AI tool when a person types or pastes it into a prompt or uploads a file. What happens next depends on the account and plan. What happens to what you type into an AI chat? explains the path, and how to stop company data leaking into AI tools covers the controls.
Frequently asked questions
- What are examples of PII?
- Names, passport numbers, Social Security numbers, driver’s license numbers, taxpayer identification numbers, financial account and credit card numbers, street and email addresses, telephone numbers, and biometric data such as fingerprints or a photograph of a face. Dates of birth, geographic indicators, and employment, medical, and financial records are PII when they can be linked to a person.
- Is an email address PII?
- Yes. NIST lists address information, such as a street address or email address, among its examples of PII, and HIPAA lists electronic mail addresses among the identifiers to remove for de-identification.
- Is a name PII?
- NIST lists names, including full name, maiden name, and alias, as PII. Whether a name identifies one person depends on context, so a name together with any other detail should be treated as PII.
- What is the difference between PII and PHI?
- PII is a general term for information that identifies a person. PHI is the HIPAA term for individually identifiable health information held or sent by a covered entity or its business associate. Employment records that a covered entity holds as an employer are excluded from PHI, but health details in them can still be PII.
- What is the difference between PII and personal data under GDPR?
- Personal data under GDPR is any information relating to an identified or identifiable person, and the regulation names online identifiers and location data among the identifiers. Pseudonymised data stays personal data when the person can be linked back with additional information.
Next
Keep going
Sources
- NIST, Special Publication 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information (PII), April 2010. Read October 10, 2026.
- eCFR, 45 CFR 160.103, definitions of protected health information and individually identifiable health information. Read October 10, 2026.
- eCFR, 45 CFR 164.514(b)(2), the Safe Harbor method of de-identification. Read October 10, 2026.
- EUR-Lex, Regulation (EU) 2016/679 (GDPR), Articles 4(1) and 9(1). Read October 10, 2026.
- UK Information Commissioner’s Office, What is personal data? Read October 10, 2026.