What it means
The simplest way to think about PII is to ask whether the information points to a real individual. A full name with a date of birth clearly does, while a single common first name on its own may not.
The danger comes from combination, because several harmless-looking details together can single out one person. Finance and accounting teams handle a great deal of PII.
Payroll files hold salaries and bank details, customer ledgers hold addresses and payment histories, and loan applications hold identification numbers and income evidence. Even an invoice with a sole trader's name and home address contains it.
Regulation is the reason this term matters to managers. Many countries have data protection laws that require organisations to collect only what they need, keep it secure, tell people how it is used and report breaches.
Fines, legal claims and loss of customer trust can follow when these duties are ignored. Good practice is practical rather than mysterious.
Collect less data in the first place, restrict who can see it, encrypt it when stored or sent, delete it when it is no longer needed and train staff to spot phishing attempts. Suppliers who process data on your behalf should be bound by contract to protect it as well.
The definition varies between laws, and some regulations use broader terms such as personal data. Sensitive categories such as health, financial account details and biometric information often get extra protection.
When in doubt, treat information that relates to an identifiable person as if it were PII, and ask your legal or data protection team. Culture is as important as technology.
Most data incidents begin with a human action, such as a mis-sent email, a lost laptop or a clicked link, rather than a sophisticated attack. Regular, short training sessions and a simple way to report mistakes quickly can limit the damage far more than expensive tools used in isolation.
In practice
Real-world examples.
Example
A payroll manager emails a spreadsheet of employee bank details to a personal account to work from home. The file includes account numbers and addresses, so the company treats this as a data protection incident and tightens its rules on file sharing.
Example
An online retailer decides to stop storing full payment card details and uses a payment provider instead. This lowers the amount of PII on its own systems and so reduces both its security burden and its potential losses after a breach.
Example
A marketing team plans to buy a list of email addresses and job titles. The compliance officer reminds them that people must usually be told how their data is used and given a chance to opt out.
Formula
Calculation
Estimated breach cost = records exposed x average cost per record + fixed response costs
This is a planning estimate, and the per-record cost is an assumption each organisation must set for itself.
Suppose a company stores PII for 20,000 customers and assumes a cost of $100 per record for notification, credit monitoring and support. The per-record cost is 20,000 x 100 = $2,000,000. Adding $150,000 of fixed costs for investigation and legal advice gives a total of 2,000,000 + 150,000 = $2,150,000. Deleting 8,000 old records first would reduce the exposed records to 12,000, cutting the per-record cost to 12,000 x 100 = $1,200,000.Case study
Seen in the real world.
Greenfield Lending is an illustrative, fictional consumer loan company that kept ten years of rejected loan applications on a shared drive. The files included scanned identity documents, income statements and home addresses of people who never became customers.
A security review showed that the drive was accessible to more than 100 employees, many of whom had no reason to open it. The compliance team recommended deleting applications older than the required retention period, moving the rest to encrypted storage and limiting access to six people.
The illustrative outcome was a sharp reduction in risk, achieved at low cost. The lesson is that the safest PII is the PII you no longer hold.
Watch out
Common mistakes.
- Assuming that only obvious items such as ID numbers count, when combinations of ordinary details can also identify someone.
- Keeping data indefinitely just in case it is useful, which increases exposure with no benefit.
- Sending PII by ordinary email or storing it on personal devices, instead of using approved, secure channels.
Questions
People also ask.
Is an email address PII?
Usually yes, especially if it contains a name or can be linked to other information that identifies the person.
Who is responsible for protecting PII in a company?
The organisation as a whole, though in practice responsibility is shared by management, IT, legal and every employee who handles the data.
What should we do if PII is lost or stolen?
Follow your incident response plan, contain the problem and consult legal advice quickly, since many laws set short deadlines for notifying regulators and affected people.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
