PII vs personal information vs personal data: how US and EU terms differ

PII is a security shorthand with no single US legal definition, personal information is the CCPA's term, personal data is the GDPR's term, and PHI is HIPAA's term for health information held by covered entities. They overlap but differ in who is protected and when data stops being covered, so match the term to the law.

Which term should you use: PII, personal information, personal data or PHI?

Use the term that belongs to the law you are talking about. PII is a common security shorthand with no single US legal definition, "personal information" is the CCPA's term, "personal data" is the GDPR's term, and PHI is HIPAA's term for health information held by covered entities and business associates. They overlap but are not interchangeable.

For a referral partner the practical rule is simple: avoid saying "it has no PII" to an owner. Say which framework you mean, and leave the legal conclusion to the company's counsel. Wrong labels create false comfort, and false comfort kills deals later in rights review.

Side-by-side: the four terms

TermWhere it comes fromRough scopeTypical workplace example
PIISecurity and federal agency practice; definitions vary by agency and by state breach lawInformation that can identify a person alone or combined with other dataEmployee Social Security number in a payroll export
Personal information (CCPA)California Civil Code section 1798.140Information that identifies, relates to or could reasonably be linked with a consumer or household, including California employees and business contactsA CRM contact's name, direct line and job title
Personal data (GDPR)Article 4 of Regulation (EU) 2016/679Any information relating to an identified or identifiable natural personA support ticket mentioning an EU customer's email address
PHI (HIPAA)HIPAA Privacy RuleIndividually identifiable health information held by a covered entity or business associateA billing note listing a member ID and date of service

Read the primary text before relying on a summary: the California Consumer Privacy Act statute holds the CCPA definitions, the GDPR text holds Article 4, and HHS explains PHI in its de-identification guidance.

How do the definitions differ in practice?

The differences that matter for business records are these.

  1. Who is protected. The CCPA speaks of consumers, a term California defines as California residents, which includes employees and business contacts. HIPAA protects patients and plan members only within covered contexts. The GDPR protects people in the EU or whose data is processed in scope.
  2. What counts as identifiable. PII lists often name direct identifiers such as a Social Security number. The CCPA and GDPR also reach information that can be linked to a person indirectly, such as a device ID or a role plus an employer.
  3. What happens after de-identification. Each regime has its own test for when information stops being covered, so removing a name column may satisfy one and not another.
  4. Who is on the hook. HIPAA obligations attach to specific entities. The CCPA applies to businesses meeting its thresholds, which the California Privacy Protection Agency FAQ lists; the GDPR can reach non-EU organizations in some situations.

Workplace examples: which label fits?

RecordPIICCPA personal informationGDPR personal dataPHI
Badge access log naming an employeeUsually yesYes if a California residentYes if in scopeNo
Jira ticket assigned to a named engineerOften yesYes if a California residentYes if in scopeNo
Invoice with a buyer contact's work emailOften yesYes, business contacts can be coveredYes if in scopeNo
Clinic billing note with a member IDYesPossiblyYes if in scopeYes, if from a covered entity or business associate
Aggregated ticket counts by weekNoNoGenerally noNo

Rows marked "if in scope" depend on where the people are and where the company operates. The employment and B2B angles for California are covered in the CCPA B2B exemption guide and the workforce question in do you need employee consent to license workplace data.

When each term wins

  • Use PII in casual conversation with a security-minded owner, then ask what their policies or contracts define as PII.
  • Use personal information when the company has California employees, customers or contacts.
  • Use personal data if the records include people in the EU; see whether the EU AI Act applies to a US company for the adjacent regulatory question.
  • Use PHI only when the company is a covered entity or business associate, or handles health plan or provider data.

Common vocabulary mistakes with owners

MistakeWhy it hurtsBetter phrasing
"Our data has no PII"PII is undefined across laws, so the claim cannot be checked"We have not yet checked which personal data laws apply"
"Anonymized, so privacy laws don't apply"Each regime tests anonymization differently; pseudonymized data often stays covered"We will confirm with counsel how the data is de-identified"
"It's B2B, so it's exempt"California's exemptions for business contacts have ended"Business contacts may count in California"
"HIPAA covers all health words"HIPAA depends on who holds the data"Is the company a covered entity or business associate?"

Questions to ask the owner

  • Which states and countries are the employees, customers and contacts in?
  • Does any system hold health, financial or children's information?
  • Who at the company, or its outside counsel, owns privacy questions?
  • Have customer contracts or employee notices said anything about reuse of records?

Those four answers let counsel pick the right framework quickly, and they keep the partner conversation factual rather than legal.

How SourceX fits

You do not need to label a prospect's data to refer it. Classification happens later, when the company inventories its systems with SourceX and rights are reviewed, with redaction requirements settled before any work begins. Strong prospects often have large operational datasets that do not depend on customer personal information; see can a company qualify without sharing customer personal information.

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting on any definition.

Next step

Screen a prospect with the company fit checker, a preliminary non-binding screen that needs no contact details, and review how it works. Then register as a partner to make the introduction.

Common questions

Is PII the same as personal information under the CCPA?

No. PII has no single US legal definition and varies by agency and state breach law, while the CCPA defines personal information broadly, including information that can be reasonably linked to a consumer or household. Much PII is also CCPA personal information, but the CCPA reaches further, including some business-contact and employee data.

Is business contact information personal data?

Under the GDPR, a work email address that relates to an identifiable person is generally personal data. Under the CCPA, business contacts in California can also be covered now that the temporary exemptions are over. Whether and how a company must treat it depends on where the people are and counsel's reading.

Is PHI the same as PII?

No. PHI is a HIPAA term for individually identifiable health information held by covered entities and their business associates. The same name and date in a retail order is PII but not PHI. A health plan's claim record containing them is PHI. The label depends on who holds the data and why.

Does de-identified data stop being personal data everywhere?

Not automatically. HIPAA, the CCPA and the GDPR each use different tests for when information is no longer covered. Data removed of names may still be personal data if it can be linked back to a person. Companies should have counsel apply the right test to the actual dataset.

What should a partner say if an owner asks whether the records are legal to license?

Say that the company decides with its own counsel, and that SourceX reviews rights and agrees redaction requirements with the company before any work begins. The partner does not classify, export or describe records. Nothing is binding until the company agrees price and terms and signs.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment