Two terms describe roughly the same idea and they do not mean the same thing. “Personally identifiable information” comes from American practice. “Personal data” is a defined term in European law. The gap between them is not pedantry. It changes what counts. It also changes how much of you falls inside the definition.
What follows describes how each term is defined and where the two diverge. It sets out the wording of the law. This is not legal advice and we are not a compliance service. Our interest is narrower. The European definition happens to describe, with some precision, the method an investigator uses to identify a person. That makes it useful to anyone trying to understand their own exposure.
What is PII, and what does PII stand for?
PII stands for personally identifiable information. No single statute defines it. The term comes from United States federal practice. The most cited formulation appears in NIST Special Publication 800-122, published April 2010, which frames PII as information that can be used to distinguish or trace an individual’s identity, either alone or combined with other linkable information.
The American approach is organised around lists: names, social security numbers, account numbers, biometric records. It is applied by an organisation to its own holdings, asking which fields in a database need protecting. Both points matter below.
PII has no single legal definition in the United States. Sectors carry their own rules and the term works as shorthand across them.
What is personal data under the GDPR?
European law does not use the term PII at all. The equivalent concept is personal data, defined in Article 4(1) of Regulation (EU) 2016/679:
“personal data” means any information relating to an identified or identifiable natural person (‘data subject’)
“Any information” sets no limit by category. “Relating to” reaches wider than “about”. “Identifiable” extends the definition past people who are already named.
That last word is where the frameworks separate. A list asks whether a field appears on a schedule of protected types. Article 4(1) asks whether a person can be identified. Those are different questions. They produce different answers.
What must data do to be considered personal data by the GDPR?
It must relate to someone identified or identifiable. Recital 26 explains how to judge the second half. Account should be taken of:
all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly
Reasonably likely to be used. Not merely conceivable. The recital directs attention to cost, the time required and available technology.
Singling out. Identification does not require a name. Distinguishing one person from everyone else is sufficient.
By the controller or by another person. Whoever holds the data is not the only relevant actor.
Directly or indirectly. Identification by inference and by combination both count.
The result is a standard with no fixed list to memorise. That is also why the definition reaches material that feels anonymous.
PII vs personal data: what is the difference under the GDPR?
The practical difference is scope. Personal data is the wider category. Most things treated as PII in American practice are personal data in Europe. The reverse does not hold.
The gap shows in practice:
- An IP address, a cookie identifier or a device identifier can be personal data. They appear on few PII schedules.
- Pseudonymised records remain personal data where re-identification stays reasonably possible. Removing a name does not remove the record from scope.
- Information that reveals rather than states a characteristic falls inside the special categories described below.
A second difference matters more for this article. PII guidance addresses an organisation classifying its own records. Article 4(1) and Recital 26 are written from the position of the person being identified. They account for what third parties are able to do.
Examples of PII and personal data: what is considered PII?
Direct identifiers. Legal name, home address, telephone number, email address, national identity number, passport or driving licence number, bank account number.
Personal details that identify in combination. Date of birth, place of birth, employer, job title, city, nationality, education history, family relationships.
Technical identifiers. IP address, cookie identifier, advertising identifier, device fingerprint, account username.
Records generated about you. Purchase history, location traces, call records, browsing history, CCTV footage, voice recordings.
Almost everything in the second and third groups is what people have in mind when they say nothing sensitive leaked. Taken singly, each item looks harmless. The European definition does not make that assumption. The inventory above is also the one you would compile when mapping a digital footprint.
What is sensitive personal data under GDPR Article 9?
“Sensitive personal data” is the common phrase. The regulation calls these special categories of personal data. Article 9(1) lists them: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data where used for identification, health data and data concerning sex life or sexual orientation.
Article 9 describes a narrower set inside personal data, not a separate category sitting alongside it. The test is whether data reveals one of those characteristics. A gym membership, a dietary preference or a place of worship appearing in a location history can reveal a special category without ever stating it.
Is an IP address personal information under the GDPR?
Usually. The reasoning matters more than the answer.
In Case C-582/14 (Breyer), decided 19 October 2016, the Court of Justice held that a dynamic IP address recorded by a website operator is personal data where that operator has the legal means to identify the person using additional data held by the internet service provider. The Court was explicit that information need not be held by a single entity to constitute personal data.
In Case C-604/22 (IAB Europe), decided 7 March 2024, the Court reached the same conclusion about the TC String, the alphanumeric code recording consent preferences in online advertising. It is personal data where reasonable means exist to identify the users it relates to.
Neither case turns on the field being sensitive. Both turn on whether identification becomes reachable by combining what one party holds with what another party holds. The parties doing that combining are frequently the data brokers and advertising intermediaries whose business is assembling those links.
Why personally identifiable information is defined by combination, not by field
Read Recital 26 once more with an investigator in mind. Means reasonably likely to be used. Singling out. By another person. Indirectly.
That is a description of open-source reconnaissance. It is what an analyst does when asked to establish who someone is from public material, and what a competent adversary does before a targeted approach. The European definition is unusual in measuring identifiability by what someone could actually accomplish, instead of by which fields an organisation has labelled important.
Your exposure is therefore not the sum of the sensitive items about you. It is the set of connections that can be drawn between the unremarkable ones. A job title is nothing. A job title alongside an employer, a city and a date of birth is a person.
This is also why a list fails as a defence. A list protects what you thought to put on it. The connections that identify you get made by someone working without a list, under no obligation to respect yours. What an assembled record is then worth to the people building it is a separate question, covered in what your digital footprint is used for.
A different question again is what happens after personal data leaks. Identifiability and revocability sit on separate axes. Some leaked material can be changed, some can be invalidated by a specific action and some simply stays true. What each kind of leaked data enables works through that item by item.
Most people underestimate their exposure because they are counting sensitive fields instead of connections. A footprint audit maps what is actually linkable about you across public sources.
See what is actually linkableWhat the GDPR definition means if you are the person, not the controller
The regulation was written to govern organisations. Read from the other side, Article 4(1) and Recital 26 amount to a working description of how identification happens to you.
Scope is broader than instinct suggests. If you have assumed that only documents and account numbers count, the definition is wider. So is the material available about you.
Anonymity is conditional. Pseudonymised and technical data stops being personal data only when re-identification stops being reasonably possible. That threshold moves as tooling improves. It rarely moves in your favour.
Identifiability cannot be assessed field by field. The standard is explicitly about combination, so a self-assessment that walks through categories one at a time will understate the result. Establishing what is actually linkable means looking at the aggregate the way someone searching for you would.
Exercising rights over that material is a separate matter from understanding it. The routes differ by country. Data brokers in Europe sets out how access and erasure requests work in practice.
Frequently Asked Questions
Does the GDPR use the term PII?
No. The regulation uses “personal data”, defined in Article 4(1). PII is an American term with no equivalent standing in EU law.
Is PII the same thing as personal data?
No. Personal data is broader. Most PII qualifies as personal data. Material such as cookie identifiers and pseudonymised records can be personal data without appearing on typical PII schedules.
Is an email address personal data under the GDPR?
Yes, where it relates to an identifiable person. A named personal address plainly qualifies. A role address can qualify where an individual is identifiable behind it.
Is a name on its own personal data?
Usually yes, though a common name held with nothing else may not identify anyone in particular. Identifiability is judged on the means reasonably likely to be used, which includes combining that name with other available information.
What is the difference between personal data and sensitive personal data?
Sensitive personal data, called special categories in Article 9(1), is a narrower set within personal data covering characteristics such as health, biometrics, religious belief and political opinion. All of it is personal data. Most personal data is not special category.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation), Article 4(1), Article 9(1) and Recital 26. EUR-Lex.
- Court of Justice of the European Union, Case C-582/14, Patrick Breyer v Bundesrepublik Deutschland, judgment of 19 October 2016. CELEX:62014CJ0582.
- Court of Justice of the European Union, Case C-604/22, IAB Europe, judgment of 7 March 2024. Court press release 44/24.
- National Institute of Standards and Technology, Special Publication 800-122, “Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)”, April 2010. NIST CSRC.