What is PII?

Personally Identifiable Information (PII) is any data that can identify a specific person, on its own or combined with other data. Your name is PII. Your home address is PII. Your IP address plus your browsing history is PII. The category is broad on purpose: identifying someone rarely takes one unique data point. It usually takes a combination.

The two-tier model: standard vs. sensitive

Modern privacy laws (CCPA, CPRA, GDPR, the state-by-state US laws) split PII into two tiers:

Standard PII: name, address, phone, email, date of birth, IP address, customer-ID numbers, browser cookies, family relationships. Covered by deletion and opt-out rights under most privacy laws. Routinely published in the open by data brokers.

Sensitive PII: Social Security number, driver's-license number, passport number, financial-account numbers, medical or health information, race, religion, sexual orientation, precise geolocation, biometric data, login credentials. Covered by stronger rights, including (in California) the right to limit use, not just delete.

The split matters because regulators treat sensitive PII more strictly. CCPA's "limit the use of sensitive personal information" right (§1798.121) applies only to the sensitive tier. GDPR's "special category data" definition (Art. 9) is the European equivalent and triggers heightened consent and security requirements.

What counts as PII when combined

This is where most data-broker exposure happens. None of these alone identifies you. All of them together is your full profile:

Data brokers' business is selling these combinations: not one identifier, but the constellation that pins down exactly who you are.

Where to remove it

Removing your PII is the work the rest of Delist covers in depth. The short version:

Find what's actually exposed

A free Delist scan shows which sites publish your PII, and which categories.

Run my free exposure scan