Personally identifiable information (PII) is information that can identify a person, either on its own or when combined with other information that can be linked to them.
A name, phone number, email address, and government ID are obvious examples. But PII can also include information that looks purely technical, such as an IP address, advertising identifier, device identifier, or precise location, depending on the context and the rules that apply.
That distinction matters more than ever. A modern business may never store a customer’s passport number, yet still handle large amounts of information that can be connected to a real person through an app account, device, location history, or online activity.
For mobile businesses in particular, understanding what counts as personal data means looking beyond the obvious fields. It means examining how data is collected, combined, shared, and used across the entire customer journey.
What Is Personally Identifiable Information (PII)?
Personally identifiable information is data that can be used to trace an individual, either by itself or together with other sets of data linked to that person.
It is also important to note that PII is a widely used term in US government and information-security contexts, while other jurisdictions use terms such as “personal data” or “personal information” and may define them differently.
This is why there is no universal list containing every possible piece of personally identifiable information.
Consider a person’s full name. It can be a direct identifier, especially when paired with a unique account or contact detail. But a first name alone may not distinguish one person from thousands of others.
The same applies to an IP address, postcode or device identifier. A technical identifier may not tell you who someone is at first glance. Once it is combined with account information, location data or other records, however, it may become possible to identify or distinguish that person.
For practical purposes, it helps to think about PII in three groups:
- Direct identifiers: information that can point to a specific person relatively easily.
- Indirect identifiers: information that may identify someone when combined with other information.
- Digital identifiers: online or device-related information that can distinguish or help identify a person.
The legal terminology varies by jurisdiction. For example, European privacy law generally uses personal data rather than PII, and its definition is broad.
Common Examples Of Personally Identifiable Information
Common PII examples include names, email addresses, phone numbers, home addresses, government identification numbers, financial information, biometric data and medical identifiers.
Here are some of the most familiar examples:
| PII example | How it can identify a person |
| Full name | Directly identifies a person in many contexts |
| Personal email address | Identifies or contacts a specific individual |
| Phone number | Can be linked to a subscriber or account |
| Home address | Identifies where a person lives |
| Passport number | Uniquely identifies an individual |
| Driver’s licence number | Links a person to a government record |
| National ID number | Used as a unique identity identifier |
| Bank account number | Links financial activity to an account holder |
| Medical record number | Links records to a specific patient |
| Biometric data | Can distinguish a person using physical characteristics |
| Employee ID | Identifies a person within an organisation |
| Student ID | Links records to a student |
NIST specifically gives examples such as names, Social Security numbers and biometric records, while also recognising information that becomes identifying when combined with other linked information.
Government privacy guidance also commonly treats financial, employment, education and medical information as PII when it is linked or linkable to an individual.
The practical rule is simple: don’t judge whether something is PII only by whether it looks personal. Judge what the information can reveal when it is used in context.
Direct And Indirect Personally Identifiable Information Examples
Direct PII identifies a person with little additional information, while indirect PII becomes identifying when combined with other data.
A passport number is a straightforward direct identifier. A date of birth, postcode and occupation are different: each may identify very few people on its own, but the combination can significantly narrow the possibilities.
For example:
Age: 47
Occupation: specialist surgeon
Area: small town
Workplace: one hospital
None of these details necessarily identifies the person individually. Together, they may.
Other indirect examples include:
- Date of birth
- Age
- Gender
- Postcode
- Employer
- Job title
- Education history
- Purchase history
- Browsing behaviour
- Location history
- IP address
- Device identifier
This is also why deleting someone’s name from a dataset does not automatically make that dataset anonymous.
A dataset can still contain enough information to identify someone through combination or linkage.
For example, if you know someone’s job title, company name, place of residence, IP address, and gender, then it can become increasingly easy to narrow down who the person actually is.
What Is Sensitive Personally Identifiable Information
Sensitive PII generally refers to information where misuse or exposure can create a greater risk of harm, although the exact categories depend on the law and context.
Examples can include:
- Government identification numbers
- Passport details
- Financial account information
- Payment information
- Health information
- Biometric information
- Authentication credentials
- Certain employment records
- Certain criminal records
- Religious or highly sensitive personal information
There is no single worldwide definition of “sensitive PII”. China, the EU, the US and other jurisdictions use different classifications.
For example, China’s PIPL explicitly defines sensitive personal information to include biometrics, religious beliefs, medical and health information, financial accounts, whereabouts and information relating to children under 14.
That difference is important for multinational businesses. A field that is treated as ordinary personal data in one market may trigger stronger requirements in another.
Personally Identifiable Information On Websites And Mobile Apps
Digital PII can include IP addresses, cookie identifiers, advertising IDs, device identifiers, location data, account IDs, and other online identifiers when they can identify or distinguish a person.
This is where traditional PII lists start to become less useful for digital businesses.
A mobile app can collect information without ever asking for a user’s full name. For example, an app may process:
- IP address
- Device ID
- Advertising ID
- Account ID
- Precise location
- App events
- Session information
- Purchase activity
- Browsing behaviour
- Device characteristics
The European Commission explicitly lists IP addresses, cookie IDs, mobile advertising identifiers, location data and identification numbers as examples of personal data under the GDPR framework.
That does not mean every digital identifier is automatically identifying in every situation. Context still matters.
A random event number, for example, may tell an analytics system that something happened without identifying a person. A stable identifier linked to a user account is a different matter.
For app marketers, this is one reason privacy reviews need to consider data relationships, not just individual fields.
Is An IP Address Personally Identifiable Information?
An IP address can be personal information when it can be linked to an identifiable individual or otherwise used to distinguish them.
The answer depends on the legal framework and what information the organisation has available.
The European Commission explicitly includes IP addresses among examples of personal data.
The important part is not that an IP address contains a person’s name. It is that the address can form part of a broader set of information used to identify or distinguish someone.
For that reason, businesses should avoid treating IP addresses as automatically anonymous.
How To Decide What Is PII?
You can check if the data is PII by confirming whether the information can identify, distinguish, or reasonably be linked to a person in the context in which your organisation holds it.
A name is obvious. An email address is obvious. A passport number is obvious.
An IP address, device ID or advertising identifier requires more thought.
The right question is not:
“Does this data contain a person’s name?”
The better question is:
“What could someone determine about the person by combining this field with the other information we already have?”
That shift in thinking is particularly valuable for mobile businesses because app data is rarely isolated. Identifiers, events, devices, accounts, campaigns, and behaviour often exist as connected records.
The European Commission and NIST both take this broader approach to identification and linkability.
When Can Ordinary Information Become Identifying?
Information that looks harmless in isolation can become identifying when enough individual data points are combined.
Imagine a dataset containing:
52 years old + lives in a small town + rare profession + precise location + unusual purchase
None of those fields necessarily gives you the person’s name. Together, however, they may make the person recognisable. The same principle applies to pseudonymous identifiers.
A customer record such as:
User ID: 847293
The above doesn’t reveal a person’s name by itself.
But if that ID can be connected to an email address, purchase history, or device record, the dataset may no longer be meaningfully anonymous.
The European Commission makes a similar point under the GDPR: pseudonymised or encrypted information can still be personal data if a person can be re-identified.
That is why privacy programmes should focus on linkability, not just obvious names and addresses.
Personally Identifiable Information Policies By Region
Businesses cannot use one global PII checklist because privacy rules differ by jurisdiction, industry, data type, and processing activity.
This matters particularly for apps operating across several markets. The same identifier can have different regulatory implications depending on where the user is located and which law applies.
- USA – State-wise Privacy Policies
The USA does not have one comprehensive federal privacy law covering all personal information; businesses may need to comply with state privacy laws and sector-specific federal rules.
California is one of the most important examples through the CCPA, as amended by the CPRA. California’s framework covers information that identifies, relates to or can reasonably be linked to a consumer or household, including categories such as IP addresses, browsing information, location data and profiles.
US privacy obligations can also depend on the sector involved. Healthcare, financial services, children’s services and other areas have their own rules and requirements.
For a mobile app, that means an IP address or device identifier should not simply be labelled “PII” or “not PII” for the entire US. The correct treatment depends on the specific legal and business context.
What businesses should do: map the data they collect against the states, industries and user groups they serve.
- Europe – GDPR
The GDPR treats personal data broadly as information relating to an identified or identifiable living person.
The European Commission’s examples include names, email addresses, ID numbers, IP addresses, cookie IDs, advertising identifiers and location data. Information that can be combined to identify an individual can also fall within the definition.
The GDPR also emphasises principles such as transparency, purpose limitation, data minimisation and storage limitation.
For app businesses, that makes digital identifiers particularly relevant. A piece of data does not stop being personal simply because the field contains a device identifier instead of a person’s name.
What businesses should do: assess whether data can identify or be linked to a person, including through pseudonymous identifiers and combinations of data.
- China – PIPL
China’s Personal Information Protection Law (PIPL) defines personal information broadly and creates additional rules for sensitive personal information.
PIPL covers information relating to identified or identifiable natural persons and applies to certain processing conducted outside China when it concerns people in China, including situations involving products, services or behavioural analysis.
Sensitive personal information includes biometrics, health information, financial accounts and location-related information, as well as personal information concerning children under 14. Processing sensitive information requires a specific purpose and necessity, strict protective measures and, in relevant cases, separate consent.
China’s cyberspace regulator also identifies categories such as user IDs, browsing records, software-use records, IMEI, location information, and user profiles among personal-information examples.
What businesses should do: review not only what data is collected, but also whether it falls into a sensitive category and whether cross-border processing requirements apply.
- India – DPDP
India’s Digital Personal Data Protection framework regulates the processing of digital personal data and places responsibilities on organisations handling that data.
The DPDP Act was enacted in 2023, and the government notified the DPDP Rules in November 2025. The government describes the framework around principles including consent and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards and accountability.
The Rules also provide a phased compliance timeline, rather than making every operational requirement effective in exactly the same way on the day of notification.
For digital businesses, the important lesson is that PII management should be designed into the data lifecycle rather than added after a product launches.
What businesses should do: identify what digital personal data is collected, why it is collected, where it goes, how it is protected, and which implementation requirements currently apply.
- UAE – Federal Privacy Rules
The UAE’s Federal Decree-Law No. 45 of 2021 provides a federal framework for personal data protection, while some free zones and sectors have additional rules.
The UAE government describes the federal Personal Data Protection Law as a framework covering the processing of personal data and setting controls around privacy, confidentiality and data management.
Businesses also need to consider whether they fall under a specialised regime. The UAE has additional data-protection frameworks in certain jurisdictions and sectors, so a company operating in the country cannot always rely on the federal framework alone.
What businesses should do: determine whether the federal law applies and whether a free-zone or sector-specific regime also covers the organisation.
- Singapore – PDPA
Singapore’s Personal Data Protection Act (PDPA) creates obligations around accountability, notification, consent, purpose limitation, accuracy, protection, retention and certain overseas transfers of personal data.
The Personal Data Protection Commission describes these as core organisational obligations under the PDPA. It also requires organisations to put reasonable security arrangements in place to protect personal data from unauthorised access, use or disclosure.
This makes Singapore’s framework particularly relevant to businesses that share customer or app data with external service providers.
What businesses should do: understand the reason each data field is collected, limit its use to appropriate purposes, protect it appropriately and assess transfers outside Singapore.
How PII Rules Differ Across Regions
The biggest difference is not simply the definition of PII; it is how each jurisdiction regulates collection, use, sensitive information, individual rights, security and cross-border transfers.
| Region | Main framework | Broad approach |
| USA | State and sector-specific privacy laws | Rules vary significantly by state, industry, and data type |
| Europe | GDPR | Broad concept of personal data linked to an identifiable person |
| China | PIPL | Broad personal-information definition plus enhanced treatment of sensitive information |
| India | DPDP Act and Rules | Digital personal-data framework with consent, transparency and accountability requirements |
| UAE | Federal Personal Data Protection Law plus applicable local regimes | Federal framework with additional considerations for specialised jurisdictions |
| Singapore | PDPA | Data-lifecycle obligations covering collection, use, disclosure and protection |
That is why an international app company should avoid creating one spreadsheet column called “PII: Yes/No” and considering the job done.
A better model is:
What data is this? → Who does it relate to? → Why is it collected? → What can it be linked to? → Where is it processed? → Who receives it? → Which rules apply?
How Should Mobile App Businesses Handle PII?
Mobile app businesses should create a data inventory that maps each identifier and event to its purpose, destination, access controls, retention period, and applicable privacy requirements.
For example, an app may collect:
- Email address
- User ID
- IP address
- Advertising identifier
- Device information
- Location
- Purchase events
- App engagement events
- Attribution data
The next step is understanding how those fields move through the technology stack.
A single user journey can touch the app itself, analytics SDKs, advertising platforms, customer-data tools, cloud systems, an MMP and internal reporting.
That makes privacy a data-flow problem as much as a consent problem.
For Apptrove users, this is where PII masking can become particularly relevant. Apptrove’s Privacy Masking feature masks specified identifiers across dashboards, reports, raw logs, exports, APIs, webhooks, and partner postbacks while keeping the underlying data available for attribution and fraud-related processing.
This is a useful distinction. Protecting PII does not necessarily mean removing every identifier required by the measurement workflow. It can also mean limiting where raw identifying information is visible and who can access it. Learn how Apptrove’s Privacy Masking for PII works.
PII And Mobile Attribution: Why The Distinction Matters
Mobile attribution depends on measurement signals, but those signals do not all need to be exposed to every person who has access to campaign data.
An MMP may process identifiers and event information to connect marketing interactions with app installs and post-install activity. Apptrove describes mobile attribution as the process of identifying and analysing the sources of user interactions and conversions within a mobile marketing ecosystem.
The privacy challenge comes when the underlying measurement data contains identifiers that can reveal or help identify users.
This is why teams should distinguish between:
Data required for measurement
and
Data that every person viewing a report actually needs to see.
A marketing manager may need to know that a campaign generated 4,000 purchases. They may not need access to the raw email addresses or precise coordinates associated with those events.
Explore Apptrove’s mobile measurement platform to learn how to make privacy controls more practical without making measurement useless.
FAQs About Personally Identifiable Information
What are 10 examples of personally identifiable information?
Ten common PII examples are a person’s name, personal email address, phone number, home address, government ID number, passport number, driver’s licence number, bank account information, biometric information, and medical identifiers.
Is an IP address considered personally identifiable information?
An IP address can be considered personal information when it can be linked to or used to distinguish an individual, depending on the applicable law and context. The European Commission specifically lists IP addresses among examples of personal data under the GDPR.
Is a device ID considered PII?
A device ID can have privacy implications when it can distinguish a device or user and can be linked to information about an identifiable person. Whether it is legally classified as PII or personal data depends on the jurisdiction, the identifier itself, and what additional information the organisation can connect to it.
What is the difference between PII and personal data?
PII is a commonly used term for information that can identify or trace an individual, while “personal data” is the broader legal terminology used by frameworks such as the GDPR. The terms overlap heavily, but they should not automatically be treated as legally identical in every jurisdiction.
Is pseudonymised data still PII?
Pseudonymised data can still be treated as personal data when the individual can be re-identified using additional information. Under the GDPR, pseudonymised information remains personal data when it can be linked back to an identifiable individual.
