What Constitutes PII?

If you work in law, whether as a paralegal, attorney, or compliance professional, you’ve likely run into the term PII. It shows up in discovery requests, data breach notices, client intake forms, and privacy statutes alike. But what actually counts as PII, and why does the definition shift depending on which law you’re reading?

PII Defined

PII stands for Personally Identifiable Information. At its core, it’s any data that can be used, alone or combined with other information, to identify a specific individual. That sounds simple, but the legal definition of PII is not uniform. It varies by statute, by jurisdiction, and by the sector regulating the data (healthcare, finance, education, and so on).

For paralegals, understanding PII matters in very practical ways: spotting it during document review, flagging it in discovery, advising clients on data handling obligations, and recognizing when a data breach notification duty has been triggered.

Two Categories: Direct and Indirect Identifiers

Most privacy frameworks break PII into two buckets.

Direct identifiers point to one person and no one else:

  • Full name
  • Social Security number
  • Driver’s license or state ID number
  • Passport number
  • Biometric data (fingerprints, retina scans)

Indirect identifiers don’t identify someone on their own, but can when combined with other data:

  • Date of birth
  • Zip code
  • Job title
  • IP address
  • Educational or employment history

A single indirect identifier is usually harmless. Combine a few of them (say, birth date, zip code, and gender), and re-identification becomes surprisingly easy. This is why most statutes define PII as a combination of a name plus one or more sensitive data elements, rather than any single fact in isolation.

The New York Standard: The SHIELD Act

Since this blog is grounded in New York (Suffolk County), it’s worth looking at how state law here defines it. New York’s data breach statute, General Business Law § 899-aa, as amended by the SHIELD Act (Stop Hacks and Improve Electronic Data Security Act), draws a distinction between two terms:

“Personal information” is broadly defined as any information concerning a natural person that, because of a name, number, personal mark, or other identifier, can be used to identify that person.

“Private information” is the narrower, breach-triggering category. It means personal information combined with one or more of the following, when unencrypted (or encrypted with a key that was also compromised):

  • Social Security number
  • Driver’s license or non-driver ID card number
  • Financial account, credit, or debit card number (with or without a security code, if it could allow account access on its own)
  • Biometric information (fingerprint, voice print, retina or iris image, and similar)
  • Medical information or health insurance information

Notably, “private information” also includes a standalone category: a username or email address in combination with a password or security question and answer that would permit access to an online account. This online-credentials prong is a meaningful difference from many other states, since a compromised login file can trigger notification obligations under New York law even without a Social Security number or financial account number involved.

Publicly available information lawfully obtained from government records is excluded from the definition. The law applies to any business that owns or licenses computerized data containing private information about a New York resident, regardless of where that business is located, and it also imposes reasonable data security requirements on covered businesses under GBL § 899-bb.

Federal and Sector-Specific Definitions

Federal law doesn’t have one single PII definition either. Instead, different statutes regulate PII within their own sectors:

  • HIPAA governs “protected health information” (PHI), a subset of PII tied to medical records and healthcare data.
  • GLBA (Gramm-Leach-Bliley Act) covers “nonpublic personal information” held by financial institutions.
  • FERPA protects student education records.
  • COPPA addresses PII collected from children under 13 online.

Each of these statutes has its own list of covered data elements, its own notice and consent requirements, and its own enforcement mechanism. A paralegal working across practice areas needs to know which framework applies to the client or matter at hand, since “PII” in a healthcare case can mean something narrower or broader than “PII” in a consumer finance dispute.

Why This Matters in Practice

For a paralegal, the practical stakes usually show up in a few recurring scenarios:

  • Discovery and document review: Redacting Social Security numbers, account numbers, and other sensitive identifiers before production, consistent with court rules and protective orders.
  • Data breach response: Determining whether an incident actually involved “personal information” as statutorily defined, since that determination triggers (or doesn’t trigger) notification obligations.
  • Client intake and file management: Handling client PII responsibly, from secure storage to limiting who in the firm has access.
  • Drafting and reviewing contracts: Recognizing PII-related clauses in vendor agreements, data processing addenda, and confidentiality provisions.

Key Takeaway

PII isn’t a single, fixed category. It’s a legal concept that shifts depending on the statute, the sector, and the jurisdiction. What counts as “private information” under New York’s SHIELD Act is narrower in some ways (no general zip code or date of birth trigger) and broader in others (the online-credentials prong) than what counts as PII under a comprehensive consumer privacy framework like the CCPA. Knowing the specific definition that applies to your matter, rather than assuming a one-size-fits-all standard, is what separates careful legal work from a costly oversight.

This post is for general informational purposes and does not constitute legal advice.

References

Health Insurance Portability and Accountability Act (HIPAA), U.S. Department of Health and Human Services. https://www.hhs.gov/hipaa/index.html

N.Y. General Business Law § 899-aa, Notification; Person Without Valid Authorization Has Acquired Private Information. https://codes.findlaw.com/ny/general-business-law/gbs-sect-899-aa/

N.Y. General Business Law § 899-bb, Data Security Protections. https://www.nysenate.gov/legislation/laws/GBS/899-BB

Gramm-Leach-Bliley Act, Federal Trade Commission. https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act