Examples of personally identifiable information (PII) run from the obvious to the surprising: your full legal name, Social Security number, passport number, driver’s license number, biometric data like fingerprints, medical records, bank account numbers, IP addresses, and even combinations of otherwise ordinary details like your ZIP code, birth date, and gender. The federal technical standard from the National Institute of Standards and Technology (NIST) defines PII in two parts: information that can distinguish or trace a specific person on its own, plus any data that is linked or linkable to that person.1National Institute of Standards and Technology. NIST SP 800-122 Guide to Protecting the Confidentiality of Personally Identifiable Information That definition matters because it stretches beyond the items most people would list, and the pieces that seem harmless in isolation often turn out to be the ones that identify you.
Direct Identifiers
Direct identifiers are data points that pin down who you are without needing any other context. A full legal name is the starting example, though names alone aren’t always unique, which is why organizations pair names with numbers tied to a single person’s government record.
The Social Security number is the most consequential direct identifier for most Americans. It’s a nine-digit number that now functions as the key to credit applications, tax filings, bank accounts, and government benefits, which makes it the single most valuable target for identity thieves.2Social Security Administration. Social Security History – Social Security Numbers
Passport numbers, driver’s license numbers, and state ID numbers belong in the same tier. Each one attaches a unique alphanumeric sequence to a specific person’s government file, and each grants access to travel, financial services, and identity verification. Theft of these numbers frequently leads to fraudulent credit applications and unauthorized benefit claims.
NIST treats sensitivity as a spectrum rather than a binary. Your Social Security number and medical history sit at the high end. A phone number or ZIP code carries lower sensitivity on its own. But the sensitivity of a data field depends heavily on what other fields sit next to it, which is where the next category comes in.
Quasi-Identifiers: When Ordinary Details Become PII
Some data points look harmless alone and become identifying in combination. These are called quasi-identifiers, and the classic trio is date of birth, gender, and ZIP code. A study of 1990 U.S. census data found that 87 percent of the population could be uniquely identified using just those three details.3Carnegie Mellon University. Simple Demographics Often Identify People Uniquely A later analysis using 2000 census data put the figure closer to 63 percent, suggesting the original estimate ran high, but the core finding held: a majority of people are still uniquely identifiable from a handful of seemingly anonymous items.4Palo Alto Research Center. Revisiting the Uniqueness of Simple Demographics in the US Population
This is why re-identification is such a practical threat. A street address paired with an age and a specific medical condition can reveal identity even after a name is stripped from a dataset. Internal Census Bureau research showed that reconstruction and re-identification techniques could accurately infer sensitive attributes like race and ethnicity from published records that appeared anonymized.5U.S. Census Bureau. Understanding Differential Privacy The takeaway for you: individual data fields don’t tell the whole story about your privacy exposure. Combinations do.
Electronic and Online Identifiers
Every device you use generates digital markers that qualify as PII. An IP address is the numerical label assigned to your device when it connects to a network, and it reveals your approximate location. A Media Access Control (MAC) address is a permanent hardware identifier built into your device’s network interface. Together, these let companies and service providers recognize returning visitors and track behavior across sites.
Biometric data occupies the highest tier of electronic PII because it’s permanent. Fingerprints, iris scans, facial geometry, and voiceprints can’t be changed the way a password can. If someone steals your fingerprint template, you can’t request a new finger. A small but growing number of states have enacted biometric privacy laws requiring informed consent before collection and imposing penalties for violations. Storing biometric data demands strong encryption for exactly this reason: a breach creates a security problem that lasts a lifetime.
Online credentials round out the digital picture. Usernames, passwords, and answers to security questions all qualify as PII because they unlock accounts holding other sensitive information. An email address is PII too, especially when it contains your real name or links to accounts storing financial or health data.
Financial and Health-Related PII
Bank account numbers, credit card numbers, and investment account details are all PII, and they carry additional protection under the Gramm-Leach-Bliley Act. That law defines “nonpublic personal information” as personally identifiable financial data a financial institution collects about you, including information from applications, transaction records, and any details the institution obtains while providing services.6Office of the Law Revision Counsel. United States Code Title 15 Chapter 94 Subchapter I The same law gives you the right to opt out of having that information shared with unaffiliated third parties.
Medical records, treatment histories, billing details, and health insurance information qualify as protected health information under the Health Insurance Portability and Accountability Act (HIPAA). Criminal violations carry tiered penalties: a basic violation can result in a fine up to $50,000 and up to one year in prison; obtaining or disclosing health information under false pretenses raises the maximum to $100,000 and five years; and acting with intent to sell, transfer, or use health information for commercial advantage, personal gain, or malicious harm can bring fines up to $250,000 and ten years in prison.7GovInfo. United States Code Title 42 Section 1320d-6
The HIPAA List of 18 Identifiers
The clearest concrete inventory of PII in U.S. federal law comes from HIPAA’s Safe Harbor de-identification standard. A health dataset is considered de-identified only after all 18 categories of identifiers have been removed:8U.S. Department of Health and Human Services. Guidance Regarding Methods for De-identification of Protected Health Information
- Names
- Geographic data smaller than a state (street address, city, county, ZIP code, with the first three digits of a ZIP allowed if the area has more than 20,000 people)
- Dates related to the individual (birth, admission, discharge, death) and all ages over 89
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate and license numbers
- Vehicle identifiers and serial numbers, including license plates
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers, including fingerprints and voiceprints
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
That last catch-all is doing real work. It reflects the fact that new forms of PII keep emerging, and anything that can single out a person counts, whether or not it fits neatly into the first 17 categories.
How Different Laws Define PII
The specific definition of personal information varies by law, which is one reason compliance is complicated and one reason you’ll see different lists of “examples” in different places.
California Consumer Privacy Act
The CCPA uses one of the broadest definitions in U.S. law, covering any information that identifies, relates to, or could reasonably be linked with a particular consumer or household. That reaches obvious items like names and Social Security numbers, but also browsing history, geolocation data, and inferences drawn from other data to build a profile of your preferences. When a business fails to secure this data and a breach occurs, affected California consumers can seek statutory damages between $100 and $750 per person per incident, or actual damages if those are higher.
General Data Protection Regulation
The EU’s GDPR defines personal data as any information relating to an identified or identifiable person, including names, identification numbers, location data, online identifiers, and factors specific to a person’s physical, genetic, mental, economic, cultural, or social identity.9General Data Protection Regulation (GDPR). Art. 4 GDPR Definitions The most severe violations can trigger fines up to 20 million euros or four percent of a company’s global annual revenue, whichever is higher.10General Data Protection Regulation (GDPR). GDPR Fines and Penalties
Children’s Online Privacy Protection Act
COPPA applies to online services directed at children under 13 and requires operators to get verifiable parental consent before collecting personal information from those children. Its definition covers names, home addresses, email addresses, phone numbers, Social Security numbers, IP addresses, geolocation data, photos, videos, and audio recordings. The inclusion of photos and behavioral data catches many parents by surprise.
State Breach Notification Laws
All 50 states, the District of Columbia, and U.S. territories require notification when a breach exposes PII. The specifics vary, but most laws treat unauthorized acquisition of a name combined with a Social Security number, driver’s license number, or financial account number as the trigger. If your PII is compromised, the organization that held it must tell you.
Protecting the High-Risk Items
Knowing what qualifies as PII is only useful if you also guard the pieces that matter most. A few concrete steps reduce your exposure significantly.
IRS Identity Protection PIN
An Identity Protection PIN (IP PIN) is a six-digit number that stops anyone else from filing a federal tax return using your Social Security number. Anyone with an SSN or Individual Taxpayer Identification Number who can verify their identity is eligible. The fastest enrollment is through your IRS online account, with alternatives including Form 15227 (if your adjusted gross income is below $84,000 for individuals or $168,000 for joint filers) or an in-person visit to a Taxpayer Assistance Center.11Internal Revenue Service. Get an Identity Protection PIN The PIN is valid for one calendar year and must be renewed annually. The FTC received over 1.1 million identity theft reports in 2024 alone, which puts this simple step in perspective.12Federal Trade Commission. Protecting Older Consumers 2024-2025
Credit Freezes
Federal law gives you the right to place a free credit freeze with each of the three major credit bureaus. A freeze blocks new creditors from accessing your credit report, which effectively prevents anyone from opening accounts in your name. The freeze stays in place until you lift it, and you can lift it temporarily when you need to apply for credit yourself. This is the most effective tool for preventing financial identity theft after your PII has been exposed.
If Your PII Is Compromised
The FTC operates IdentityTheft.gov as the central resource for identity theft recovery. The general steps are placing a fraud alert or credit freeze, reporting the theft to the FTC, filing a police report if needed, and contacting the specific companies where fraudulent accounts were opened. The recovery process is tedious, which is exactly why keeping your PII off unnecessary forms, outdated accounts, and poorly secured websites is worth the effort. Every piece you don’t hand over is one fewer thing that can be used against you.