Security & safety

Personally Identifiable Information

PII

Information that identifies a specific person, alone or combined with other data: a name, an ID number, an email address, a face. It is mainly a US term; European and Turkish law use the broader concept of personal data.

COMPLAINT TEXTName: Ayşe KayaID number: 1•••••••••8Rare diagnosis · ward 3 · 14 MarchmaskingTEXT SENT TO THE MODELName: [NAME]ID number: [ID_NUMBER]Rare diagnosis · ward 3 · 14 Marchstill points to one personDirect identifiersname, ID number, phone, email: the filter catches themIndirect identifiersdetails that fit one person together: need reviewIllustrative test: 41 of 500 texts still described the patient recognisably after masking.

swipe to see the whole diagram →

MEmehmeterkek.com/glossary/pii

In plain terms

Some details point to one person straight away: a name, a national ID number, a phone number. Others do so in combination: a postcode, a date of birth and a job title together often fit a single individual. PII is the label for all such data. The useful test is a question: could someone work out who this is about? If so, the data needs care wherever it goes, including into a prompt.

Why it matters

Every prompt, uploaded file and retrieved document may carry personal details, and with an AI service that data leaves your systems for a provider's. That raises concrete questions: is there a legal basis and a contract, where is the data processed, is it kept, is it used for training, and who can read the logs? Under GDPR and Türkiye's KVKK the organisation that sends the data stays responsible for it. Masking tools help, though they can miss indirect identifiers and strip the context the model needs. Decide which data may go to which tool before staff decide for you.

Example

A hospital group wants to summarise 60,000 patient complaints with a cloud AI service. A filter replaces names, ID numbers and phone numbers with placeholders before each text is sent. In a test on 500 complaints it removes every direct identifier, and 41 texts still describe the patient recognisably: a rare diagnosis, a ward, a date. The team adds a review step for such texts and signs a data-processing agreement before going live.

Most often confused with

PII vs. Personal data (GDPR, KVKK)

PIIA US term, often read as a list of identifiers
Personal data (GDPR, KVKK)A legal concept: any information about an identifiable person

PII is commonly treated as a list: name, number, address. Personal data under GDPR and KVKK is defined by its link to a person, so it also covers IP addresses, device and cookie identifiers, location traces, voice recordings and opinions about someone. A dataset can be “free of PII” by a US-style checklist and still be personal data in Europe or Türkiye. For compliance, work from the legal definition that applies to you.

Under the hood

US guidance (NIST SP 800-122) describes PII as information that can distinguish or trace an individual's identity, alone or when linked with other information; individual US laws define their own lists. GDPR and KVKK add special categories that need stronger protection, among them health, biometric and genetic data, religion and trade-union membership. Three treatments are often confused: masking or redaction removes identifiers; pseudonymisation replaces them with tokens that can be reversed with a key, and the result is still personal data; anonymisation makes re-identification impossible in practice, and only then does the data fall outside the law. In AI systems personal data turns up in prompts, uploaded files, retrieval indexes, conversation logs, memory features and fine-tuning sets, and a model can reproduce passages from its training data. Controls: detection and masking before the model call (named-entity recognition plus patterns; Microsoft Presidio is a common open-source tool), reversible placeholders that are restored in the answer, provider settings for zero retention and no training, regional processing, access limits on logs, and deletion routines.

Written by Mehmet Erkek · Last updated: