Privacy & regulation · also called Personally identifiable information, personal data, personal information
PII (personally identifiable information)
PII (personally identifiable information) is information that identifies, or can be used to identify, a specific person, such as a name, email, phone number or government ID number.
PII is a mostly American term. It traditionally meant directly identifying details: name, address, email, phone number, Social Security number, passport number. The advertising industry long argued that cookie IDs and device IDs were "non-PII" because they did not reveal names.
Modern laws take a broader view. GDPR's "personal data" covers any information relating to an identifiable person, including online identifiers such as cookie IDs, IP addresses and advertising IDs. California's CCPA / CPRA "personal information" similarly includes identifiers, browsing history and inferences, and COPPA treats persistent identifiers as personal information for children. So the old "non-PII" label no longer means "unregulated".
In ad tech practice, direct identifiers like emails are usually hashed before sharing, becoming pseudonymous data, which is still regulated. Some categories, such as health, financial, biometric, precise location and children's data, are treated as sensitive with stricter rules. Many platforms forbid passing PII in ad requests or URL parameters.
Think of it like this
PII is like the parts of your life that let a stranger find your front door; modern law says a unique key to your door counts too, even without your name on it.
An example
A publisher discovers that its sign-up page puts users' email addresses in URL parameters that are visible to ad tags; it fixes the leak because passing PII to ad partners this way breaks platform policies and privacy law.
Related terms
Pseudonymous data
Pseudonymous data is personal data where direct identifiers are replaced with a code, such as a hashed email or random ID, so it cannot identify someone without additional information kept separately.
Hashed email
A hashed email is an email address transformed by a one-way cryptographic function, usually SHA-256, into a fixed string used to match users across systems without sharing the plain address.
GDPR
The GDPR (General Data Protection Regulation) is the European Union's data protection law, applying since May 2018, which governs how organisations collect and use personal data about people in the EU.
CCPA / CPRA
The CCPA, as amended by the CPRA, is California's consumer privacy law giving residents rights to know, delete, correct and opt out of the sale or sharing of their personal information.
Data minimization
Data minimization is the privacy principle that organisations should collect and keep only the personal data that is adequate, relevant and necessary for a specific, stated purpose.
Sources: GDPR Article 4: definitions, California Attorney General: CCPA