Personally Identifiable Information (PII)
Personally Identifiable Information (PII)
Personally Identifiable Information (PII) is any data that can be used, either on its own or when combined with other information, to identify a specific individual. The term is closely associated with U.S. federal government usage and information security standards, though it is now widely used across the private sector as well, including by boards of directors and the organizations they govern.
Board members regularly handle sensitive material in board packets, meeting minutes, and director records that may contain PII belonging to employees, customers, donors, or fellow directors. Knowing what qualifies as PII, and how to handle it responsibly, is a core part of modern corporate governance and regulatory compliance.
Definition of PII
The most widely referenced definition comes from the U.S. National Institute of Standards and Technology (NIST). According to NIST guidance, PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to that individual.
This definition breaks down into two broad categories:
-
Direct Identifiers: Information that can identify a person on its own. This includes data elements such as a full legal name, Social Security number, passport number, or biometric record (such as a fingerprint or facial recognition data).
-
Indirect Identifiers: Information that becomes identifying when linked to other data. This includes details such as date of birth, place of birth, mother's maiden name, or employment history, which may not identify a person in isolation but can do so when combined with other available information.
Common Examples of PII
PII is generally grouped into two tiers based on the level of risk it poses if exposed.
Sensitive PII typically includes:
-
Full legal name
-
Social Security number
-
Driver's license or state ID number
-
Passport number
-
Financial account numbers
-
Biometric data
-
Date and place of birth
Non-sensitive PII (often only identifying when combined with other data) typically includes:
-
Business or personal mailing address
-
Business phone number or email address
-
Race, gender, or general demographic information
-
Employment information
Because non-sensitive PII can become identifying in combination with other records, most organizations—including boards and governance teams—apply careful handling standards to both categories rather than treating non-sensitive PII as low-risk.
PII vs. Personal Information (PI): Why the Distinction Matters
One of the more confusing aspects of U.S. privacy terminology is that "PII" is not the only term in use, and it is not defined the same way everywhere. State privacy laws often use a different, broader term: Personal Information (PI).
Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), "personal information" is defined far more expansively than traditional PII. California law defines PI as information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. This includes identifiers such as a real name, alias, postal address, email address, or account name.
Under this broader standard, data such as IP addresses, biometric data, geolocation data, and device identifiers all qualify as personal information, whereas many would fall outside the narrower, traditional PII definition. This broader approach aligns California's law more closely with the European Union's General Data Protection Regulation (GDPR).
The United States does not have a single, overriding federal law governing PII. The definition can vary from jurisdiction to jurisdiction and from state to state. Organizations operating across multiple states, including nonprofit and for-profit boards with directors or stakeholders in different jurisdictions, need to be aware that the definition may shift depending on which state's law applies.
Why PII Matters to Boards and Governance Teams
Boards of directors routinely handle information that qualifies as PII, even when it is not the primary subject of a meeting. Examples include:
-
Director and officer contact details, dates of birth, and compensation information
-
Employee records referenced in HR or compensation committee reports
-
Donor or member information in nonprofit board materials
-
Customer or patient data referenced in risk, audit, or compliance reports
Mishandling this information—whether through insecure file sharing, unencrypted email, or inadequate access controls—can expose an organization to regulatory penalties, reputational harm, and legal liability. This is why governance best practice increasingly calls for board-level oversight of data privacy and security policy.
A secure board portal reduces this risk by centralizing sensitive materials behind two-factor authentication, AES-256 encryption, and role-based access control, rather than relying on email attachments or printed board packets. BoardCloud's approach to data handling is outlined further in its U.S. Data Compliance page and Privacy Policy.