Privacy Principles

What is Personal Data vs PII?

Personal data and PII (personally identifiable information) are overlapping but distinct concepts: PII is the narrower, traditional US term for data that identifies a specific person, while 'personal data' under GDPR — and 'personal information' under the CCPA — covers any information relating to an identifiable person, including IP addresses, cookie IDs, and behavioral records.

PII grew out of US federal practice (NIST guidance, breach statutes) and centers on identifiability: names, Social Security numbers, driver's license numbers, financial account numbers — the fields whose exposure enables identity theft. Many US breach-notification laws still trigger on enumerated PII categories, which is why security teams often reason in PII terms: specific sensitive fields to encrypt and guard.

GDPR's 'personal data' is deliberately broader: any information relating to an identified or identifiable natural person, where identifiability includes indirect identification by reference to identifiers like location data or online identifiers. Recital 30 makes the internet consequence explicit — IP addresses, cookie identifiers, and device IDs can be personal data. Pseudonymized data remains personal data; only properly anonymized data (re-identification no longer reasonably possible) escapes the regulation. The CCPA's 'personal information' lands close to GDPR's breadth, expressly covering inferences drawn to profile a consumer, and both include household- or device-linked data that classic PII definitions would miss.

The gap between the concepts is where compliance failures breed. A team that thinks in PII will conclude its analytics are 'anonymous' because no names are stored — while the cookie IDs, IP addresses, and behavioral trails it processes are regulated personal data in the EU and California. Tracking-based litigation exploits exactly this: the identifiers marketing stacks run on are the identifiers modern laws protect.

The safe operating rule: apply PII thinking to security prioritization, but scope privacy compliance to the broad definition — if data relates to a person, device, or household, treat it as regulated.

Why it matters for eCommerce

Your analytics events, pixel payloads, device fingerprints, and hashed-email audience syncs are all personal data or personal information under modern law, even though none of them look like classic PII. Scoping your privacy program to 'we only need to protect names and card numbers' leaves your entire marketing stack outside the fence — precisely where regulators and plaintiffs are looking.

Frequently asked questions

Is an IP address personal data?
Under GDPR, generally yes — online identifiers including IP addresses can identify a person indirectly, and the CJEU has treated even dynamic IPs as personal data where identification is reasonably possible. The CCPA likewise lists IP address among identifiers constituting personal information when linkable to a consumer or household.
Is hashed or pseudonymized data still personal data?
Yes. Hashing and pseudonymization are safeguards, not exits — the data still relates to an identifiable person for whoever can match it (as ad platforms do with hashed emails). Only genuine anonymization, where re-identification is no longer reasonably possible, takes data out of scope.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Run a free scan

← Back to all glossary terms