Personally identifiable information is any data that can distinguish or trace a specific person’s identity, either on its own or when combined with other information linked to that person. Common examples of personally identifiable information include Social Security numbers, passport numbers, fingerprints, full legal names, home addresses, email addresses, credit card numbers, medical record numbers, and IP addresses. The category is broader than most people expect, and whether a given piece of data qualifies often depends on what else it sits next to.
Two federal frameworks set the boundaries. The Office of Management and Budget’s Circular A-130 defines PII as “information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a specific individual.” NIST Special Publication 800-122 breaks that into two working categories. Linked information is data logically tied to a person inside a single system, like a Social Security number sitting next to a name in a government database. Linkable information is data that could be connected to a person through a separate source, like a zip code that becomes identifying when paired with a date of birth and gender pulled from somewhere else. Research cited by NIST found that 87 percent of the U.S. population could be uniquely identified using only those three data points.
Direct Identifiers
Direct identifiers pinpoint a specific person without needing anything else. A single exposed record in this category can enable identity theft or fraud on its own. NIST groups them into several types.
- Government-issued numbers, including Social Security numbers, passport numbers, driver’s license numbers, and taxpayer identification numbers.
- Full legal names. A name combined with any other identifier creates a high-risk pairing, and NIST treats a full name as PII even standing alone.
- Biometric records such as fingerprints, retina scans, voice signatures, and facial geometry. You can’t change your fingerprints after a breach, which is what makes biometric exposure uniquely lasting.
- Contact information: street addresses, email addresses, and phone numbers.
- Full-face photographs and comparable images that reveal a distinguishing physical characteristic.
Indirect and Linkable Data
Indirect identifiers look harmless in isolation. A date of birth, a gender marker, or a five-digit zip code wouldn’t alarm anyone on its own. The risk emerges when someone combines the fragments. Privacy researchers call this the mosaic effect: individually anonymous data points that snap together to reveal a specific person.
Protected characteristics such as race, religion, or a described medical condition also sit here. A hospital record noting a rare condition in a rural area with a small population can effectively identify the patient even with the name stripped off. That is why the HIPAA Privacy Rule requires covered entities to remove 18 specific identifiers before data qualifies as de-identified under the Safe Harbor method:
- Names
- Geographic data smaller than a state
- Dates directly related to the individual
- Phone and fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate and license numbers
- Vehicle identifiers
- Device serial numbers
- Web URLs
- IP addresses
- Biometric identifiers
- Full-face photographs
- Any other unique identifying code
That list is a useful working inventory of indirect identifiers well beyond the healthcare context, because each item is something that can single a person out when paired with the right companion data.
Digital and Technical Identifiers
Digital identifiers are the unique strings assigned to your hardware, software, or online sessions. None of them carry your name, but they let companies and agencies track behavior and build detailed profiles. The main examples are:
- Internet Protocol (IP) addresses
- Media Access Control (MAC) addresses
- Cookie identifiers
- Mobile device IDs
- Precise geolocation data from vehicles or phones
NIST classifies IP and MAC addresses as PII when they “consistently link to a particular person or small, well-defined group of people.” The European Union’s General Data Protection Regulation goes further, listing online identifiers including IP addresses and cookie identifiers as personal data in its core definition. Several U.S. state consumer privacy laws similarly treat IP addresses, browsing history, location data, and pseudonymous profiles as personal information.
Precise location data has become a specific enforcement priority. The FTC treats vehicle-generated and device-generated location tracking with the same seriousness as financial or health information. A January 2026 FTC order requires companies to obtain clear, affirmative consent, separate from general privacy policies, before collecting or sharing precise location data.
Financial and Employment Identifiers
Financial data qualifies as PII because it links directly to a specific person’s money. Examples include credit card numbers, bank account numbers, and other financial account details. The Gramm-Leach-Bliley Act defines “nonpublic personal information” as personally identifiable financial data a consumer gives a financial institution, data produced by any transaction with the consumer, or data the institution otherwise obtains.
Workplace identifiers include employee identification numbers and taxpayer identification numbers used for payroll and government reporting. These are PII because they distinguish one person within a system and connect to sensitive tax filings.
Medical and Student Record Identifiers
Beyond the 18 identifiers listed above, HIPAA treats any individually identifiable health data held by a covered entity as protected health information. That includes diagnosis codes, treatment records, prescription histories, and insurance claim details when tied to a person.
The Family Educational Rights and Privacy Act protects PII in student education records. Federal regulations define student PII to include the student’s name, family members’ names, home address, personal identifiers like Social Security numbers and student ID numbers, indirect identifiers like date and place of birth, and any other information that alone or in combination would let a reasonable person in the school community identify the student.
FERPA carves out a narrower category called “directory information” that schools may release without consent after giving public notice. Directory information typically covers a student’s name, address, phone number, dates of attendance, and participation in school activities. Families can opt out, and schools must explain that right and give a window to exercise it.
What Doesn’t Count as PII
Knowing where the line falls on the other side is just as important. Data that has been properly aggregated or de-identified so it cannot be traced back to any individual is not PII. A report stating that 40 percent of survey respondents preferred a particular product contains no personally identifiable information, even if the underlying survey collected names and emails.
Business-level information generally does not qualify. An employer identification number used as a company identifier, an organization’s public phone number, and a corporate mailing address identify an entity rather than a human being. Publicly available information that a person has voluntarily made accessible, such as a published biography used to introduce a conference speaker, is also treated differently under most federal frameworks.
Context Determines the Line
PII isn’t a fixed checklist. Whether a piece of data qualifies depends partly on what surrounds it. A zip code in a nationwide survey of millions is anonymous; the same zip code attached to a rare medical diagnosis in a small town is practically a name tag. A job title like “Chief Financial Officer” at a Fortune 500 company with thousands of employees is not PII on its own; the same title at a three-person startup effectively identifies one specific human.
NIST guidance encourages organizations to evaluate the sensitivity of each data field both in isolation and in combination with other fields in the same system, rather than relying on a rigid list. When you’re trying to decide whether a piece of information is PII, the useful question isn’t “is this on the list?” but “could this, together with what else is reasonably available, point to one person?”