What is PII (Personally Identifiable Information)?

PII is any data that can identify a specific individual - directly (name, SSN) or indirectly when combined with other data (date of birth + ZIP + gender).

PII is a US legal concept defined slightly differently across jurisdictions. The strictest definition (NIST SP 800-122) includes any information that can identify a person, even if multiple data points need to be combined.

'Sensitive PII' includes SSN, financial account numbers, biometrics, health information, immigration status, and similar high-impact identifiers - these warrant stronger protection than name + email.

Florida's FIPA (Florida Information Protection Act, 2014) requires breach notification when PII is exposed, with specific timelines and content requirements.

Why it matters for Florida small business

A breach of PII triggers Florida FIPA notification obligations - failing to notify within 30 days of discovery results in penalties up to $500,000 per breach.

What to do

Map where you store PII (CRM, accounting, HR), confirm encryption at rest and in transit, and document who can access each store.

Related terms