If you've ever heard of PII (personally identifiable information), it's likely been a story about a data breach in a company’s digital network or identity theft from a person’s credit card.
When personal data ends up on the dark web, it can take months or years to clean up the damage. Thus, eCommerce merchants must take stringent measures to ensure the security of their personal information and that of customers and employees.
To better manage the data you collect, you need a thorough understanding of PII.
Different Categories of PII
In general, PII covers sensitive information↗ that can be used to identify an individual, and it is divided in two categories:
1. Sensitive PII
This includes any information that directly and objectively identifies an individual, including legal statistics such as:
- Full name
- Social Security Number (SSN)
- Driver’s license
- Mailing address
- Credit card information
- Passport information
- Financial information
- Medical records
2. Non-sensitive PII
Also referred to as indirect PII, this type of information is freely available from public sources such as phonebooks, the internet, and company directories. When coupled with another data item, it can distinguish a person but is insufficient to positively identify them. For instance:
- Zip code
- Race
- Gender
- Date of birth
- Place of birth
- Religion
Any data that cannot be used to identify a specific individual or customer falls under this category. Non-sensitive PII is also known as anonymous data, which companies typically use in advertising applications. Businesses that share client data for advertisements typically use anonymization techniques to encrypt the PII so that it is received in an unidentifiable form.
In eCommerce, PII is usually associated with collecting data to easily identify customers and tailor marketing communications to their interests. Customer data can also be used to improve the shopping experience by displaying relevant goods or speeding up the checkout process by storing relevant information.
However, retailers can safely assume that most customers would not choose to share their PII. If they really need to, it would be the bare minimum, and they would prefer it not be saved for future marketing purposes.
The Importance of Securing PII
PII is a valuable asset used in identity theft. As a retailer, protecting PII↗ is your responsibility. Failure to do so could lead to serious consequences.
A staff member with website access will typically have a pass to a customer’s confidential and sensitive information↗, including their name, email, address, and phone number. This, along with their credit card or payment info, is enough to commit identity fraud.
Retailers must also realize that cybercriminals can breach data systems to steal PII, which is then sold on illegal marketplaces. Because of the exploitation and abuse of private data for profit, governments worldwide have tightened regulations on who can collect data, how it should be stored, and its use for marketing or other purposes.
All online stores dealing with customer data need an eCommerce privacy policy↗ that can be easily accessed by customers. Even if you don't gather personal information, it is a way to boost your business’s credibility.
In the US, the California Consumer Privacy Act is one legislation that should be on your radar. If you're not based there, be aware of similar regulations in other economic areas.
For example, The General Data Protection Regulation (GDPR) protects those in Europe (both EU and non-EU citizens). GDPR compliance↗ prevents companies from collecting or storing PII and other sensitive data without clear consent.
For more info about this, read Understanding GDPR and Cookie Consent in eCommerce↗.
PII Violations With Examples
Though self-governance is laudable, compliance with local, regional, and national laws and regulations is just as important. Regulatory bodies have started levying hefty fines for compliance violations.
The three main types of PII violations are:
- Identity theft — The most common type of PII violation, this involves stealing someone’s personal information and using it for fraudulent purposes like opening credit accounts or taking out loans.
- Financial fraud — This is where criminals use someone’s identity to open credit card accounts, make charges on existing accounts, or even steal money from bank accounts and retirement funds by transferring it out through electronic channels.
- Medical identity theft — Offenders can also use stolen medical records to access health care benefits paid for by someone else.
There are plenty of ways for customers to manage their privacy online and for businesses to avoid over-sharing information—but data privacy is a concern that will only continue to grow as the world becomes increasingly connected. Businesses and consumers need to keep this in mind and pay attention to the data collection and management processes involved in every transaction.
Did you know that there are differences between PII and personal data? Read PII vs. Personal Data: What's the Difference↗ to learn more.
How PII Flows Through Your eCommerce Stack
Your Shopify store, email marketing platform, analytics tools, and ad networks all collect and share customer data. Understanding this flow is critical because each touchpoint is a potential exposure point for PII.
When a customer completes a purchase on your site, their name, email, shipping address, and payment information move through multiple systems. That email might sync to Klaviyo for marketing automation. Their browsing behavior gets tracked by Google Analytics and the Meta Pixel. Their phone number could be pulled into SMS marketing tools. Each connection creates a data chain—and if any link is misconfigured or breached, PII leaks.
Many eCommerce brands don't realize that third-party tools they use are processors of PII. You're legally responsible for ensuring these vendors handle data properly, even if they're the ones storing it. This means reviewing their privacy policies, data processing agreements, and security certifications before integration.
The practical takeaway: Map out every tool and service that touches customer data in your business. Document what information each one receives, where it's stored, and how long it's retained. This exercise alone often reveals data you didn't need to collect in the first place. Fewer touchpoints mean fewer risks. If a tool isn't essential to your operations, disconnect it. If you must use it, ensure you have a signed data processing agreement that clarifies roles and responsibilities.
PII Retention: How Long Should You Keep Customer Data?
Most eCommerce brands keep customer data indefinitely—but they shouldn't. The longer you hold PII, the longer you're liable if it gets breached, and the more you're asking customers to trust you with sensitive information.
A practical retention policy aligns data storage with business need. You need purchase history and shipping addresses to fulfill orders and handle returns. After the return window closes (typically 30–90 days), that immediate need expires. Financial records may require longer retention for tax and accounting purposes—often 3–7 years, depending on your jurisdiction.
Here's where many brands slip up: They keep customer email addresses and purchase history indefinitely for marketing, without clear justification or customer consent. Under GDPR and similar privacy laws, this violates the storage limitation principle. You can't just hoard data "just in case."
Set explicit retention schedules for each data category. After the retention period, delete or anonymize the data. This isn't just legally sound—it's operationally smart. Less data to manage means lower security overhead and reduced liability.
If you're running email campaigns, segment by engagement and purchase recency. Inactive subscribers should be removed or re-engaged within 6–12 months. When a customer requests deletion (a DSAR), honor it within the legal timeframe—typically 30 days—rather than archiving indefinitely. Document these deletions for audit purposes.
PII and Customer Trust: What Transparency Looks Like
Customers share PII with you reluctantly. They expect transparency about what you're doing with it. Vague privacy policies and surprise marketing emails erode trust and increase the risk of complaints, chargebacks, and regulatory scrutiny.
Transparency starts with a clear, accessible privacy policy—not hidden behind legal jargon. Tell customers: what data you collect, why you collect it, how long you keep it, and who you share it with. If you use Meta Pixel or Google Analytics, say so explicitly. If you sell data or share it with partners, disclose it upfront.
Consent is the foundation. Before collecting PII beyond what's necessary for checkout, ask permission. Cookie banners should clearly distinguish between essential cookies (payment, fraud prevention) and optional ones (analytics, retargeting). Don't pre-check non-essential boxes. Many customers will uncheck them if given the choice, and that's fine—it means your marketing becomes more targeted to genuinely interested people.
When you ask for optional PII—like phone numbers or birthdates—explain why. "We'll text you exclusive offers" is transparent. Burying text details in fine print is not.
Transparency also means honoring customer preferences. If someone opts out of marketing, respect it. If they request their data or ask for deletion, respond promptly. These actions build goodwill and reduce the friction that leads customers to file complaints with regulators.
PII vs. Personal Data vs. PHI: Key Distinctions
People use "PII," "personal data," and "PHI" interchangeably, but they come from different legal worlds—and the differences decide which rules apply to you.
PII (personally identifiable information) is mainly a US concept. It refers to information that can identify a specific person, like a full name, Social Security number, or passport number. PII isn't defined by a single federal law; different states, sectors, and agencies set their own standards.
Personal data is the broader term defined by the EU's General Data Protection Regulation (GDPR). It covers any information relating to an identified or identifiable living person—even data that can't single someone out on its own, like an IP address, browsing history, or religious affiliation. All PII is personal data, but not all personal data qualifies as PII.
PHI (protected health information) is a special category of PII for health data. Under HIPAA, PHI is any health-related information tied to an identifier and handled by a "covered entity"—a healthcare provider, health plan, or business associate. A customer's shipping address is PII; the same address stored next to a prescription record is PHI, and it carries far stricter penalties.
| PII | Personal Data | PHI | |
|---|---|---|---|
| Origin | US (no single law) | EU — GDPR | US — HIPAA |
| Scope | Identifies an individual | Any data relating to a person | Health data tied to an identifier |
| Examples | Name, SSN, passport | IP address, cookies, religion | Diagnoses, treatment, insurance ID |
| Enforcement | FTC, FCC, NIST, state AGs | EU data protection authorities | HHS Office for Civil Rights |
The practical takeaway: if you serve customers internationally—or touch any health data—assume the broadest definition applies until you've confirmed otherwise.
Are Cookies and Device IDs Considered PII?
It depends on who's asking—and which law you're subject to. Cookies, device IDs, and IP addresses sit right on the boundary of what counts as personal information.
Under the GDPR, cookies are treated as personal data, because they can be combined with other identifiers to single out an individual. The California Consumer Privacy Act (CCPA) takes a similarly broad view, explicitly naming cookies, device IDs, and IP addresses as personal information. By contrast, the US National Institute of Standards and Technology (NIST) frames these identifiers more narrowly, which is why parts of the advertising industry still label them "non-PII."
That gap creates real risk for cross-border businesses: a cookie ID a US team treats as harmless must be handled as sensitive personal data the moment a European visitor is involved. The trend is one-directional—if an identifier can point back to a person, even indirectly, regulators increasingly treat it as protected.
Linked vs. Linkable: Direct and Indirect Identifiers
NIST splits PII into two types based on how directly it identifies someone.
Linked information (direct identifiers) points to one person on its own. A single data point is usually enough to determine identity: names, Social Security numbers, passport numbers, and biometric data like fingerprints—and, per NIST, asset identifiers such as IP addresses, MAC addresses, cookies, and device IDs.
Linkable information (indirect identifiers, or quasi-identifiers) can't identify someone alone, but becomes identifying when combined. ZIP code, gender, and date of birth seem harmless individually—yet a landmark study by Latanya Sweeney found those three data points alone uniquely identified roughly 87% of the US population (using 1990 Census data). Job title, employer, and general age range are other common quasi-identifiers.
The lesson for eCommerce: "anonymous" data often isn't. Stripping names from a dataset doesn't make it safe if the remaining fields can be recombined to re-identify the people in it.
How to Protect PII: Operational, Privacy, and Security Controls
Regulatory compliance is the floor, not the ceiling. NIST recommends a layered approach across three categories of control—all directly applicable to an online store.
Operational Safeguards
- Write clear policies for how you collect, store, share, and dispose of PII.
- Train staff regularly on breach risks and social engineering—not just password hygiene.
- Apply data minimization: collect only what a transaction actually requires, never "just in case."
- Keep an incident-response plan so a breach triggers a practiced sequence, not chaos.
Privacy Safeguards
- Anonymize or de-identify data before using it for analytics or marketing.
- Use pseudonymization and encryption—mask credit card numbers and other sensitive fields at rest and in transit.
- Enforce purpose limitation: use customer data only for the purposes you disclosed and obtained consent for.
Security Controls
- Restrict access by role, following the principle of least privilege.
- Separate duties so staff working with de-identified data can't reach the re-identification keys.
- Secure remote access with VPNs and multi-factor authentication.
- Monitor systems for unusual transfers or logins, and audit access logs on a schedule.
How much protection you need scales with the sensitivity of the data, the number of records, how easily it links to an individual, and the laws that govern your operations.
Anonymization, Pseudonymization, and De-Identification
These three techniques reduce risk in different ways, and the distinction matters under the GDPR.
- Anonymization transforms data so it can never be traced back to a person, even with additional information. Truly anonymized data falls outside the scope of most privacy laws (GDPR Recital 26).
- Pseudonymization replaces identifying fields with codes or tokens. It lowers risk, but because the data can be re-linked with a key, it's still regulated as personal data.
- De-identification removes or masks the details that directly identify someone—a middle ground often used for analytics.
Building these into your systems from the start—rather than bolting them on later—is the essence of privacy by design. Defaulting to the most privacy-protective settings, and collecting the minimum data needed, is privacy by default. Both are explicit GDPR requirements.
What Counts as Non-Personal Data?
Not everything you collect is PII. Non-personal data can't identify an individual on its own or in combination with other available information, which makes it generally safe to use for analytics and planning. Examples include:
- Demographic summaries and age ranges (e.g., "18–24" rather than a birthdate)
- Aggregated website analytics, like daily visitor counts or top products, not tied to individuals
- Government statistics such as census summaries
- Truncated or masked IP addresses that can't pinpoint a household
The catch: data is only non-personal if it can't reasonably be re-identified. As the 87% figure above shows, weak anonymization can quietly turn "non-personal" data back into PII.
US Laws and Regulatory Bodies Governing PII
The US has no single federal privacy law. Instead, a patchwork of statutes and agencies governs PII:
- The US Privacy Act governs how federal agencies handle PII.
- HIPAA regulates health information held by healthcare providers, plans, and their business associates.
- COPPA restricts collection of data from children under 13.
- State laws like California's CCPA/CPRA set consumer rights—notice, access, deletion, and opt-out.
Enforcement is spread across the Federal Trade Commission (FTC), the Federal Communications Commission (FCC), NIST (which sets widely referenced security standards), the Department of Health and Human Services (HHS, for HIPAA), and the Network Advertising Initiative (NAI, for ad-industry self-regulation).
The 18 HIPAA Identifiers
If you handle health data, HIPAA defines 18 identifiers that—alone or combined—can pinpoint a patient. Remove all 18 and data is considered de-identified; keep any one alongside health information and HIPAA applies:
- Names
- Geographic detail smaller than a state (street, city, county, ZIP)
- Dates tied to an individual (birth, admission, discharge, death), except the year
- Telephone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate or license numbers
- Vehicle identifiers and serial numbers, including license plates
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers, including fingerprints and voiceprints
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
Is Consent Always Required to Collect PII?
Not always—it depends on the law and the legal basis.
Under CCPA/CPRA (California), the standard is usually notice plus the right to opt out, rather than explicit opt-in consent for every collection. Under the GDPR, consent is just one of six lawful bases for processing—alongside contractual necessity, legal obligation, and legitimate interests. When you do rely on consent, GDPR requires it to be freely given, specific, informed, and unambiguous: no pre-checked boxes, buried checkboxes, or vague language.
For an online store, that means distinguishing essential cookies (payment, fraud prevention) from optional ones (analytics, retargeting), and never firing non-essential trackers before a visitor agrees.
The Real Cost of a PII Breach
The financial stakes keep climbing. IBM's Cost of a Data Breach 2025 report puts the average breach at $4.44 million globally—and an all-time-high $10.22 million for US companies. Incidents involving extortion or ransomware run higher still, averaging $5.08 million.
Those figures cover far more than any ransom: disrupted operations, lost sales, legal fees, regulatory fines, and the slow work of rebuilding customer trust. For an eCommerce brand, skipping robust PII protection is one of the most expensive shortcuts available.
Frequently Asked Questions
When should a Data Protection Impact Assessment (DPIA) be required?
A DPIA is warranted whenever processing could pose a high risk to individuals' privacy—for example, rolling out a new technology that changes how you collect data, handling large volumes of sensitive information, or conducting systematic monitoring like extensive behavioral tracking. It helps you surface and mitigate risks before they become incidents, and it's an expectation under the GDPR.
How are the definitions of PII and personal data evolving?
The boundary keeps expanding. Identifiers once treated as anonymous—cookies, IP addresses, device IDs—increasingly count as personal information as regulators recognize how easily they can be recombined to identify someone. Staying compliant means periodically reviewing what you collect against today's definitions, not last year's.
What factors determine how much protection PII needs?
Four main factors: how directly the data identifies a person, how many people are affected, how sensitive the data is (medical and financial records sit at the top), and the laws that apply to your operations. The more private, numerous, and consequential the data, the stronger your safeguards should be.
How does CCPA define personal information compared to GDPR?
The CCPA, as updated by the CPRA, is expansive—it covers anything that identifies, relates to, or could reasonably be linked to a consumer or household, including device IDs, cookies, and IP addresses. That scope is close to the GDPR's "personal data" and much broader than the narrow, direct-identifier view NIST uses for PII.
How do organizations keep up with changing privacy regulations?
Monitor updates from authorities like the FTC and the European Data Protection Board, designate a privacy lead or Data Protection Officer, consult privacy counsel on complex rules, lean on industry resources like the IAPP, train staff regularly, and review your privacy policy on a set schedule rather than letting it go stale.
The complexity of PII management grows with every new marketing tool and data integration you add to your tech stack. Without centralized oversight, it's easy to lose track of where customer data lives, how it's being used, and whether you're complying with the rules. A consent management platform can help you maintain visibility, enforce retention policies, and document consent decisions consistently across all channels.