{"id":2385,"date":"2019-06-27T13:33:16","date_gmt":"2019-06-27T12:33:16","guid":{"rendered":"https:\/\/staging.techgdpr.com\/?p=2385"},"modified":"2024-03-24T18:07:35","modified_gmt":"2024-03-24T17:07:35","slug":"difference-between-pii-and-personal-data","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/","title":{"rendered":"What is the difference between personally identifiable information (PII) and personal data?"},"content":{"rendered":"\n<p><span style=\"font-weight: 400;\">When organisations seek to protect their user\u2019s data, it is necessary that they understand the data they need to safeguard. <\/span><strong>Personal data<\/strong><span style=\"font-weight: 400;\">, in the context of GDPR, covers a much wider range of information than&nbsp;<strong>personally identifiable information (PII)<\/strong>, commonly used in North America. In other words, while all PII is considered personal data, not all personal data is PII. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">This calls for some explanati<\/span><span style=\"font-size: inherit;\">on.\u00a0<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is PII?<\/h2>\n\n\n\n<p><span style=\"font-weight: 400;\">Personally, identifiable information is defined by the US <\/span><a href=\"http:\/\/www.osec.doc.gov\/opog\/privacy\/PII_BII.html\"><span style=\"font-weight: 400;\">Office of Privacy and Open Government<\/span><\/a><span style=\"font-weight: 400;\"> as : <\/span><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><span style=\"font-weight: 400;\">\u201cInformation which can be used to <strong>distinguish or trace an individual\u2019s identity<\/strong>, such as their <\/span>name, social security number, biometric records<span style=\"font-weight: 400;\">, etc. <\/span><b>alone<\/b><span style=\"font-weight: 400;\">, <strong>or when <\/strong><\/span><strong>combined with other personal or identifying information<\/strong> which is <strong>linked or linkable to<\/strong><span style=\"font-weight: 400;\"><strong> a specific individual<\/strong>, such as date and place of birth, mother\u2019s maiden name, etc.\u201d<\/span><\/p>\n<\/blockquote>\n\n\n\n<p><span style=\"font-weight: 400;\">To <\/span>distinguish an<span style=\"font-weight: 400;\"> individual is to identify an individual by <strong>discerning one person from another<\/strong> and to <\/span><span style=\"font-weight: 400;\">trace <\/span><span style=\"font-weight: 400;\">an individual is to process sufficient information to make a <strong>determination about a specific aspect<\/strong> of an individual\u2018s activities or status. Following this definition, <\/span>name, email address, postal address, phone number, personal ID numbers <span style=\"font-weight: 400;\">(e.g., social security, passport, driver\u2019s license, bank account) are considered <\/span>PII.<\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Information is designed as <\/span><b>linked<\/b><span style=\"font-weight: 400;\">&nbsp;if any piece of personal information can<strong> be used to identify an individual<\/strong>. (e.g.: birth name). Information is categorized as <\/span><b>linkable<\/b><span style=\"font-weight: 400;\">&nbsp;information if, <strong>on its own, it may not be sufficient to enable to identify a person<\/strong>, but<strong> when combined with another piece of information<\/strong>, it <strong>could identify, trace, or locate a person&nbsp;<\/strong>(e.g.: birth date).<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Take for instance two datasets containing different PII. When both datasets are accessible to the same person, it becomes possible to identify individuals from combining the datasets or accessing additional information about the subject. This is where information security comes into play. If controls designed at keeping the data sources separate are insufficient, then data is considered linked. When an additional source of information remains external or at a distance -the case with siloed databases within organisations or via a search engine on the internet for publicly accessible information, then that data is thought to be linkable.<\/span><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span style=\"font-weight: 400;\">What is sensitive PII? <\/span><\/h3>\n\n\n\n<p><span style=\"font-weight: 400;\">PII is considered as <\/span><span style=\"font-weight: 400;\">sensitive <\/span><span style=\"font-weight: 400;\">if the <strong>loss, compromission, or disclosure<\/strong> without authorization of this data could result in <\/span><b>harm, embarrassment, inconvenience, or unfairness to an individual<\/b><span style=\"font-weight: 400;\">. For instance, the following information is considered to be sensitive PII:&nbsp;<\/span><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><span style=\"font-weight: 400;\">medical <\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400;\">educational<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400;\">financial <\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400;\">employment information<\/span><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">What is personal data under GDPR?<\/h2>\n\n\n\n<p><span style=\"font-weight: 400;\">The <\/span><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32016R0679#d1e1374-1-1\"><span style=\"font-weight: 400;\">GDPR<\/span>&nbsp;in article 4<\/a>,&nbsp;<span style=\"font-weight: 400;\">defines personal data as follows:<\/span><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><span style=\"font-weight: 400;\">&#8220;Personal data&#8221; shall mean <\/span><strong>any<\/strong> <strong>information relating to an<\/strong> <b>identified or identifiable natural person&nbsp;<\/b><span style=\"font-weight: 400;\">(&#8216;Data Subject&#8217;); an <strong>identifiable person<\/strong> is one who can be identified, <strong>directly or indirectly<\/strong>, in particular by reference to an <strong>identification number<\/strong> or <strong>to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity<\/strong> \u00bb.<\/span><\/p>\n<\/blockquote>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/PII-Personal-Data-1-.001-1024x576.jpeg\" alt=\"Overview of PII and Personal Data\"\/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">In this definition we see four main elements: \u201cany information\u201d, \u201crelating to\u201d, \u201can identified or identifiable\u201d and \u201cnatural person\u201d. &nbsp;<\/span><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">First element: &#8220;any information&#8221;<\/h4>\n\n\n\n<p><span style=\"font-weight: 400;\">The term \u201cany information\u201d contained in the <a href=\"http:\/\/eur-lex.europa.eu\/LexUriServ\/LexUriServ.do?uri=CELEX%3A31995L0046%3Aen%3AHTML\">Directive<\/a> clearly calls for a wide interpretation of the concept. Regarding the <\/span>nature of<span style=\"font-weight: 400;\"> the information, this means that both <\/span><strong>objective and subjective<\/strong> information<span style=\"font-weight: 400;\"> of a person can be considered as personal data. Regarding the <\/span><b>content<\/b><span style=\"font-weight: 400;\">, personal data covers <\/span><b>any sort of information<\/b><span style=\"font-weight: 400;\">.&nbsp;<\/span>The definition is also technology neutral, It does not matter how the personal data is stored (e.g.:&nbsp;<span style=\"font-weight: 400;\">&nbsp;alphabetical, numerical, graphical, photographic, acoustic). As an <\/span><b style=\"font-size: inherit;\">example<\/b><span style=\"font-weight: 400;\">, images of individuals captured by a video surveillance system can be personal data to the extent that the individuals are recognizable.<\/span><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Second element: &#8220;relating to&#8221;<\/h4>\n\n\n\n<p><span style=\"font-weight: 400;\">In general terms, information can be considered<strong> to<\/strong><\/span><strong>\u201crelate\u201d<\/strong> to an individual <strong>when it is about that<\/strong><span style=\"font-weight: 400;\"><strong> particular individual<\/strong>. In order to consider the data related to someone, one of the three flowing features should be present: <\/span><b>content, purpose, or result<\/b><span style=\"font-weight: 400;\">. These three features should be considered as alternative conditions and not as cumulative ones. Accordingly, the same piece of information may relate to different individuals at the same time, depending on what element is present with regard to each one. <\/span><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Third element: &#8220;identified or identifiable&#8221;<\/h4>\n\n\n\n<p><b>\u201cIdentified\u201d<\/b><span style=\"font-weight: 400;\"> when, within a group of persons, he or she is <\/span><b>&#8220;distinguished&#8221;<\/b><span style=\"font-weight: 400;\"> from all other members of the group. The natural person is <\/span><b>\u201cidentifiable\u201d<\/b><span style=\"font-weight: 400;\"> when, although the person has not been identified yet,<strong> it is possible to do it<\/strong>. &nbsp;<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">What information can be an<strong> identifier<\/strong>?&nbsp;<\/span><span style=\"font-weight: 400;\">The GDPR provides a non-exhaustive list of common identifiers that, when used, may allow the identification of the individual to whom the information in question may relate (e.g., name, identification number, location data, online identifier).&nbsp;<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">The concept of &#8220;directly&#8221; or &#8220;indirectly&#8221; identifiable implies that the extent to which certain identifiers are sufficient to achieve identification is something <\/span><b>dependent on context<\/b><span style=\"font-weight: 400;\">. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Some characteristics are so unique that someone can be identified with no effort. If I mention \u201cour boss\u201d, you\u2019ll know exactly who I am speaking about. <\/span><\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:10%\"><\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:80%\">\n<div id=\"role-block_8533035c0dd1cc98d84a8d5816db22c5\" class=\"role\">\n  <div class=\"text-t-black bg-t-pink pt-6 pl-6 pr-6 pb-2 md:pt-12 md:pl-12 md:pr-12 md:pb-6 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center\">\n    <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">Struggling with GDPR compliance?<\/h2>\n          <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">TechGDPR can help. Book a free initial consultation.<\/h3>\n                      <div data-micromodal-trigger=\"modal-contact\" class=\"mt-4 mb-4 cursor-pointer inline-flex items-center justify-center px-8 py-3 text-t-navy hover:text-white font-bodybold rounded-md border-3 border-t-navy bg-transparent hover:bg-t-navy transition-all md:py-6 hover:text-white md:px-10\">\n          Book an initial consultation<svg class=\"ml-4 fill-current\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"22\" height=\"16\" viewBox=\"0 0 22 16\">\n          <path id=\"next\" d=\"M22.707,11.293l-7-7a1,1,0,1,0-1.414,1.414L19.586,11H2a1,1,0,0,0,0,2H19.586l-5.293,5.293a1,1,0,1,0,1.414,1.414l7-7a1,1,0,0,0,0-1.414Z\" transform=\"translate(-1 -4)\"\/>\n          <\/svg>\n        <\/div>\n             <\/div>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:10%\"><\/div>\n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Fourth element: &#8220;natural person&#8221;<\/h4>\n\n\n\n<p><span style=\"font-weight: 400;\">The concept of a natural person refers to <\/span><a href=\"https:\/\/www.un.org\/en\/about-us\/universal-declaration-of-human-rights\"><span style=\"font-weight: 400;\">Article 6 of the Universal Declaration of Human Rights<\/span><\/a><span style=\"font-weight: 400;\">, according to which \u201c<strong>Everyone has the right to recognition everywhere as a person before the law<\/strong>\u201d. The right to the protection of personal data is, in that sense, a universal one that is not restricted to nationals or residents in a certain country. Thus, <strong>a natural person<\/strong> deals with the requirement that \u00ab personal data \u00bb is about \u00ab living individuals \u00bb. Under the GDPR, the personal data of deceased individuals are not covered but may still indirectly receive some protection in certain cases, in particular when that personal data involves data subjects who are still alive.<\/span><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What is sensitive data under the GDPR?<\/h3>\n\n\n\n<p><span style=\"font-weight: 400;\">The following personal data are considered as special categories of personal data and are subject to specific processing conditions according to the <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32016R0679#d1e1374-1-1\">Art. 9 of the GDPR:<\/a><\/span><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><span style=\"font-weight: 400;\">personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs;<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400;\">trade-union membership;<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400;\">genetic data, biometric data processed solely to identify a human being;<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400;\">health-related data;<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400;\">data concerning a person\u2019s sex life or sensitive data.&nbsp;<\/span><\/li>\n<\/ul>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/sensitive-data-.001-2.jpeg\" alt=\"\"\/><\/figure>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\">What about o<span style=\"font-weight: 400;\">nline identifiers?<\/span><\/h3>\n\n\n\n<p><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A32016R0679\"><span style=\"font-weight: 400;\">Recital 30 of the Regulation<\/span><\/a>&nbsp;<span style=\"font-weight: 400;\">clarifies the definition of \u201conline identifier\u201d mentioned <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">in <\/span><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32016R0679\"><span style=\"font-weight: 400;\">Article 4<\/span><\/a><span style=\"font-weight: 400;\">:&nbsp;<\/span><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><span style=\"font-weight: 400;\">&#8220;<strong style=\"font-weight: 400;\">Natural persons<\/strong> may be <strong style=\"font-weight: 400;\">associated with online identifiers<\/strong> provided by their <strong style=\"font-weight: 400;\">devices, applications, tools and protocols<\/strong>, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular w<strong style=\"font-weight: 400;\">hen combined with unique identifiers<\/strong> and <strong style=\"font-weight: 400;\">other information received by the servers<\/strong>, may be used to <strong style=\"font-weight: 400;\">create profiles of the natural persons and identify them<\/strong>.&#8221;&nbsp;<\/span><\/p>\n<\/blockquote>\n\n\n\n<p><span style=\"font-weight: 400;\">Device IDs, IP addresses and Cookies are considered as personal data under GDPR. According to the definition of the PII, they are not PII because there are<strong> anonymous<\/strong> and <strong>cannot be used on their own to identify, trace, or identify a person<\/strong>.&nbsp;<\/span><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span style=\"font-weight: 400;\">What about pseudonymised data?<\/span><\/h3>\n\n\n\n<p>A personal data is considered as anonymized if it does not relate to an identified or identifiable natural person or if it has been <a href=\"https:\/\/techgdpr.com\/consultancy\/anonymity-assessment\/\">rendered anonymous<\/a> in such a manner that the data subject is not or no longer identifiable.<\/p>\n\n\n\n<p>Pseudonymisation&nbsp;of data means replacing any identifying characteristics of data with a pseudonym, or, in other words, a value which does not allow the data subject to be directly identified. Are pseudonymised data still considered as personal data?<\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">According to the <\/span><a href=\"https:\/\/ec.europa.eu\/justice\/article-29\/documentation\/opinion-recommendation\/files\/2007\/wp136_en.pdf\"><span style=\"font-weight: 400;\">Article 29 of the Working Party opinion<\/span><\/a><span style=\"font-weight: 400;\">, personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the GDPR. Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.<\/span><\/p>\n\n\n\n<p>PII \u00a0includes any information that <a href=\"https:\/\/techgdpr.com\/consultancy\/anonymity-assessment\/\">can be used to re-identify anonymous data<\/a>. Information that is anonymous and cannot be used to trace the identity of an individual is non-PII. Device IDs, cookies and IP addresses are not considered PII for most of the United States. But some states, like California, do classify this data as PII. California classifies aliases and account names as <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=201720180AB375\">personal information<\/a> as well.<\/p>\n\n\n\n<p>In a nutshell, PII refers to any information that can be used to distinguish one individual from another.&nbsp;The GDPR definition&nbsp;<span style=\"font-size: inherit;\">of personal data is \u2013 deliberately &#8211; a very broad one.&nbsp;In principle, it covers any information that relates to an identifiable, living individual.&nbsp;<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When organisations seek to protect their user\u2019s data, it is necessary that they understand the data they need to safeguard. Personal data, in the context of GDPR, covers a much wider range of information than&nbsp;personally identifiable information (PII), commonly used in North America. In other words, while all PII is considered personal data, not all [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":2431,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[10,11,53],"tags":[50,54,49],"class_list":["post-2385","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-eu","category-data-subjects","category-terminology","tag-personal-data","tag-personally-identifiable-information","tag-pii"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg",5391,3594,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash-1024x683.jpg",640,427,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg",1536,1024,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg",2048,1365,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg",200,133,false]},"post_excerpt_stackable":"<p>When organisations seek to protect their user\u2019s data, it is necessary that they understand the data they need to safeguard. Personal data, in the context of GDPR, covers a much wider range of information than&nbsp;personally identifiable information (PII), commonly used in North America. In other words, while all PII is considered personal data, not all personal data is PII. This calls for some explanation.\u00a0 What is PII? Personally, identifiable information is defined by the US Office of Privacy and Open Government as : \u201cInformation which can be used to distinguish or trace an individual\u2019s identity, such as their name, social&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/beyond-eu\/\" rel=\"category tag\">Beyond EU<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/data-subjects\/\" rel=\"category tag\">Data Subjects<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/terminology\/\" rel=\"category tag\">Terminology<\/a>","author_info":{"name":"Malia Thuret-Benoist","url":"https:\/\/techgdpr.com\/blog\/author\/malia\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg",5391,3594,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash-1024x683.jpg",640,427,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg",1536,1024,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg",2048,1365,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg",200,133,false]},"post_excerpt_stackable_v2":"<p>When organisations seek to protect their user\u2019s data, it is necessary that they understand the data they need to safeguard. Personal data, in the context of GDPR, covers a much wider range of information than&nbsp;personally identifiable information (PII), commonly used in North America. In other words, while all PII is considered personal data, not all personal data is PII. This calls for some explanation.\u00a0 What is PII? Personally, identifiable information is defined by the US Office of Privacy and Open Government as : \u201cInformation which can be used to distinguish or trace an individual\u2019s identity, such as their name, social&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/beyond-eu\/\" rel=\"category tag\">Beyond EU<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/data-subjects\/\" rel=\"category tag\">Data Subjects<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/terminology\/\" rel=\"category tag\">Terminology<\/a>","author_info_v2":{"name":"Malia Thuret-Benoist","url":"https:\/\/techgdpr.com\/blog\/author\/malia\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The difference between PII and Personal Data - blog - TechGDPR<\/title>\n<meta name=\"description\" content=\"Personal data, in the context of GDPR, covers a much wider range of information than PII, commonly used in North America. Read more about the differences.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The difference between PII and Personal Data - blog - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"Personal data, in the context of GDPR, covers a much wider range of information than PII, commonly used in North America. Read more about the differences.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2019-06-27T12:33:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-03-24T17:07:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash-1024x683.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"683\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Malia Thuret-Benoist\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Malia Thuret-Benoist\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/difference-between-pii-and-personal-data\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/difference-between-pii-and-personal-data\\\/\"},\"author\":{\"name\":\"Malia Thuret-Benoist\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/24e55dbb23c369c201bfa066da77e00c\"},\"headline\":\"What is the difference between personally identifiable information (PII) and personal data?\",\"datePublished\":\"2019-06-27T12:33:16+00:00\",\"dateModified\":\"2024-03-24T17:07:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/difference-between-pii-and-personal-data\\\/\"},\"wordCount\":1434,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/difference-between-pii-and-personal-data\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg\",\"keywords\":[\"personal data\",\"personally identifiable information\",\"PII\"],\"articleSection\":[\"Beyond EU\",\"Data Subjects\",\"Terminology\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/difference-between-pii-and-personal-data\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/difference-between-pii-and-personal-data\\\/\",\"name\":\"The difference between PII and Personal Data - blog - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/difference-between-pii-and-personal-data\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/difference-between-pii-and-personal-data\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg\",\"datePublished\":\"2019-06-27T12:33:16+00:00\",\"dateModified\":\"2024-03-24T17:07:35+00:00\",\"description\":\"Personal data, in the context of GDPR, covers a much wider range of information than PII, commonly used in North America. Read more about the differences.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/difference-between-pii-and-personal-data\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/difference-between-pii-and-personal-data\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/difference-between-pii-and-personal-data\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg\",\"width\":5391,\"height\":3594},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/difference-between-pii-and-personal-data\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What is the difference between personally identifiable information (PII) and personal data?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/24e55dbb23c369c201bfa066da77e00c\",\"name\":\"Malia Thuret-Benoist\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/PAlia_TechGDPR-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/PAlia_TechGDPR-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/PAlia_TechGDPR-150x150.jpg\",\"caption\":\"Malia Thuret-Benoist\"},\"description\":\"Malia interned with TechGDPR in 2019 on the topics of GDPR, research and business development.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/malia-thuret-benoist-7b904385\\\/\"],\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/malia\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The difference between PII and Personal Data - blog - TechGDPR","description":"Personal data, in the context of GDPR, covers a much wider range of information than PII, commonly used in North America. Read more about the differences.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/","og_locale":"en_US","og_type":"article","og_title":"The difference between PII and Personal Data - blog - TechGDPR","og_description":"Personal data, in the context of GDPR, covers a much wider range of information than PII, commonly used in North America. Read more about the differences.","og_url":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/","og_site_name":"TechGDPR","article_published_time":"2019-06-27T12:33:16+00:00","article_modified_time":"2024-03-24T17:07:35+00:00","og_image":[{"width":1024,"height":683,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash-1024x683.jpg","type":"image\/jpeg"}],"author":"Malia Thuret-Benoist","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Malia Thuret-Benoist","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/"},"author":{"name":"Malia Thuret-Benoist","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/24e55dbb23c369c201bfa066da77e00c"},"headline":"What is the difference between personally identifiable information (PII) and personal data?","datePublished":"2019-06-27T12:33:16+00:00","dateModified":"2024-03-24T17:07:35+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/"},"wordCount":1434,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg","keywords":["personal data","personally identifiable information","PII"],"articleSection":["Beyond EU","Data Subjects","Terminology"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/","url":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/","name":"The difference between PII and Personal Data - blog - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg","datePublished":"2019-06-27T12:33:16+00:00","dateModified":"2024-03-24T17:07:35+00:00","description":"Personal data, in the context of GDPR, covers a much wider range of information than PII, commonly used in North America. Read more about the differences.","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/06\/dayne-topkin-u5Zt-HoocrM-unsplash.jpg","width":5391,"height":3594},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"What is the difference between personally identifiable information (PII) and personal data?"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/24e55dbb23c369c201bfa066da77e00c","name":"Malia Thuret-Benoist","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/05\/PAlia_TechGDPR-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/05\/PAlia_TechGDPR-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2019\/05\/PAlia_TechGDPR-150x150.jpg","caption":"Malia Thuret-Benoist"},"description":"Malia interned with TechGDPR in 2019 on the topics of GDPR, research and business development.","sameAs":["https:\/\/www.linkedin.com\/in\/malia-thuret-benoist-7b904385\/"],"url":"https:\/\/techgdpr.com\/blog\/author\/malia\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/2385","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=2385"}],"version-history":[{"count":29,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/2385\/revisions"}],"predecessor-version":[{"id":8359,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/2385\/revisions\/8359"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/2431"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=2385"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=2385"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=2385"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}