Ad tech stocks
TEAD0.60▲ +16.69%CDLX2.68▼ -8.84%186013.51▲ +7.48%PSKY9.63▼ -6.73%U43.38▲ +5.99%APPS11.69▲ +5.32%APP278.40▼ -4.14%STGW8.47▲ +4.06%RDDT147.81▲ +3.77%ZETA32.61▲ +3.29%TRU63.03▲ +3.12%OMC75.56▲ +2.61%SFOR44.85▼ -2.50%IHRT2.15▲ +2.38%INUV0.58▲ +2.38%MNTN10.41▲ +2.36%CCO2.40▲ +2.34%CART43.97▲ +1.97%IBTA40.16▲ +1.92%DSP12.54▲ +1.87%PUBM19.07▲ +1.83%WPP382.90▲ +1.81%NFLX68.33▼ -1.80%LFTO15.55▼ -1.55%ILLM0.66▲ +1.54%SAX35.96▲ +1.41%SCOR4.75▲ +1.39%GOOGL339.29▼ -1.39%SPOT493.81▲ +1.32%035420191200.00▼ -1.29%4755681.70▼ -1.26%AZRN0.82▼ -1.20%AAPL329.20▼ -1.15%BIDU85.93▼ -1.08%SIRI25.60▼ -1.08%ROKU150.67▼ -1.06%SNAP5.46▲ +1.02%MGNI25.49▲ +0.91%PUB95.34▲ +0.87%CRTO15.33▲ +0.86%SST2.64▲ +0.76%META729.80▲ +0.64%47511238.50▲ +0.57%HAVAS17.55▼ -0.57%RAMP37.70▲ +0.47%24331308.00▲ +0.38%NEXN9.03▲ +0.33%TTD12.20▲ +0.25%0700431.00▼ -0.23%DEC24.68▲ +0.16%TBLA3.35▼ -0.15%BABA107.69▲ +0.14%SNOW340.01▲ +0.13%CPNG13.86▼ -0.07%PINS18.90▲ +0.05%WBD30.93▼ -0.05%43243564.00▲ +0.03%OUT27.75▼ -0.02%DV13.49▲ 0.00%PERI8.69▲ 0.00%VER12.08▲ 0.00%
Ticker byClearTrust

Privacy & regulation · also called Personally identifiable information, personal data, personal information

PII (personally identifiable information)

PII (personally identifiable information) is information that identifies, or can be used to identify, a specific person, such as a name, email, phone number or government ID number.

The short answer, from the AdTech Sumo glossary

PII is a mostly American term. It traditionally meant directly identifying details: name, address, email, phone number, Social Security number, passport number. The advertising industry long argued that cookie IDs and device IDs were "non-PII" because they did not reveal names.

Modern laws take a broader view. GDPR's "personal data" covers any information relating to an identifiable person, including online identifiers such as cookie IDs, IP addresses and advertising IDs. California's CCPA / CPRA "personal information" similarly includes identifiers, browsing history and inferences, and COPPA treats persistent identifiers as personal information for children. So the old "non-PII" label no longer means "unregulated".

In ad tech practice, direct identifiers like emails are usually hashed before sharing, becoming pseudonymous data, which is still regulated. Some categories, such as health, financial, biometric, precise location and children's data, are treated as sensitive with stricter rules. Many platforms forbid passing PII in ad requests or URL parameters.

Think of it like this

PII is like the parts of your life that let a stranger find your front door; modern law says a unique key to your door counts too, even without your name on it.

An example

A publisher discovers that its sign-up page puts users' email addresses in URL parameters that are visible to ad tags; it fixes the leak because passing PII to ad partners this way breaks platform policies and privacy law.

Related terms

Sources: GDPR Article 4: definitions, California Attorney General: CCPA