Personally identifiable information (PII)
PII is information that identifies an individual or can be linked to an individual in the relevant context. Direct examples include names and contact details, but indirect combinations may also be identifying. NIST uses a context-based approach to protecting PII; legal definitions such as the EU GDPR’s “personal data” are related but not interchangeable in every setting.
Also known as: Personally identifying information, PII
How it works
An inventory looks beyond dedicated identity fields. Free-text notes, exact locations, timestamps, device identifiers, images, and unusual events can matter when combined with other sources. The assessment considers who can access the information and what they could reasonably link it with.
Protection should reflect sensitivity, identifiability, volume, and possible harm. Data minimization and access controls can reduce exposure, while transformations require their own effectiveness assessment.
Why it matters for licensing
Business records frequently mix operational facts with information about customers, employees, or suppliers. A licensing assessment should identify that mixture before choosing exclusions, transformations, or a controlled-access model. A technical export is not itself permission to disclose personal information.
Example
Fictional example: A work-order export omits customer names but retains exact addresses and appointment times. The team recognizes that removing one identifier has not removed the ability to identify customers and revises the proposed fields before disclosure.
Limitations and misconceptions
A fixed list of sensitive column names is insufficient for every dataset. Information that is not identifying in one setting may become identifying when linked elsewhere. Compliance depends on the applicable law and use, not merely whether a field is labeled PII in a schema.
Questions to ask
- Which structured fields and attachments can identify or single out people?
- What other information could recipients use for linkage?
- Which legal definition and protections apply to this particular use?
Sources
Explore whether your business data could be a fit.
Start with a description of your systems—not a data upload.