ProtonBlog
What is personally identifiable information

Personally identifiable information: What it is and how to protect it

If you’re a little tech savvy, you probably know you need to protect personally identifiable information, also known as PII. But what is considered personally identifiable information exactly? And how can you best protect your personal data?

What is PII?

Personally identifiable information can be defined as any data that can identify an individual. It’s different from personal data in that personal data can be any information you want to keep private, while PII is data that can be used to track you online — or even offline.

PII includes data that can identify somebody by itself, like a person’s name, but it could also be data points that can identify someone when combined with other data (see indirect PII below). A good example is a birth date or your IP address(new window)

How identifiable any piece of information is can be a subject of debate, however. For example, the United States Department of Labor(new window) maintains a different set of criteria from the European Union’s General Data Protection Regulation(new window) (GDPR). In general terms, though, we can consider these types of information directly identifiable (note that this list is by no means complete):

  • Name and surname
  • Taxpayer number (SSN in the US)
  • Passport or other ID document number
  • Email address
  • Personal address
  • Phone numbers
  • Bank account or card numbers
  • Birth date

You could even include biometric data on this list, or photographs that clearly show your face. Pretty much anything that another person or a computer could use to make a nearly direct identification of you as a person is PII.

Indirect PII

On top of this there’s also more indirect PII, which can be used to puzzle together who you are along with other data points — hence why it’s also known as “linked” data. Note that the line between what’s direct and indirect personally identifiable information can be a little blurry, depending on different regulatory authorities, and in which situation the PII is being used.

  • Date or place of birth
  • Mother’s maiden name
  • IP address
  • Race or religion
  • Financial information
  • Education data
  • Political information (trade union membership or party affiliation, for example)

It should be noted that different entities may have different opinions on how important this information is. For example, the GDPR is a lot stricter concerning political data than the US, as union organizers(new window) have found out. Some other countries, especially those with strong clerical establishments, will have religious affiliation even on ID cards.

How PII can be used against you

As you can imagine, your personally identifiable information can be used against you. There are more than a few parties interested in getting their hands on people’s PII for their own ends. Let’s go over some of the worst offenders.

Big Tech

The biggest collectors of data are probably companies like Google, Microsoft, Apple, Facebook, and others who make their money selling ads. The more effective the ad, the more money it makes, giving these companies a lot of incentive to know a lot about you so they can better target ads. 

The result is something called surveillance capitalism(new window), where PII is just another commodity to be traded, like lumber or oil or steel. As the basis of these companies’ business strategy, this way of using people’s data for their own gain isn’t going anywhere, either.

Data brokers

Assisting Big Tech are data brokers, who help collect, bundle, and sell people’s data, often working directly with these giants (here’s just one example(new window)). They’ll take data from the web, add it to publicly available information — land registries or even phonebooks — and sell it off in bundles. There’s little you can do about it, with some of the biggest players in this space even lobbying government(new window) to not pass privacy measures.

Cybercriminals

The last group interested in PII are cybercriminals, who often want to use it for phishing attempts. In these cases, your personal information is used to gain your trust (or that of somebody close to you) so you’ll give up something the attackers want, usually money or access.

For example, somebody pretending to be a family member suddenly urgently needs money, or you get an email from a colleague needing to use your credentials. The more the attackers know about you, the more convincing these scams are.

PII protection

Protecting your personally identifiable information is important. Thankfully, it’s something that’s relatively straightforward to do. While you won’t be able to stop the activities of data brokers single-handedly, there’s a lot you can do to secure your information.

This is where Proton comes in. We’re a security and privacy-focused company that offers several products you can use to keep yourself safe online. For example, our VPN(new window) will protect your true IP address so you can no longer be tracked in this manner, while our secure mail service, Proton Mail uses state-of-the-art encryption to keep your email from being intercepted.

To protect your online identity, we offer Proton Pass. As a password manager it makes sure you always have strong, random passwords, but thanks to its use of email aliases it also gives you the option of hiding your email address when signing up for new accounts. Using aliases takes away a very important identifier for data brokers and other online predators.

Finally, our secure cloud storage service, Proton Drive, can help you store digital copies of any important documents, photos, or videos. Thanks to our use of end-to-end encryption across our services, whatever you keep in our cloud can be seen only by you; even we don’t have access to it. This means that even if there’s a breach, all the attackers will get away with are encrypted files.

Proton Drive is the best possible place for all your personally identifiable information also because when you do decide to share it, you have a lot of control. Not only can you fine-tune who gets to see it, you can terminate sharing whenever you want or even decide to let sharing expire on a set date and time.

We can offer these kinds of features because, unlike many of our competitors, we’re entirely funded by you, our community. We don’t have shareholders pushing us to sell personal data to turn a quick buck, we just need to make sure our product is good enough so you’ll stay. If that sounds like something you would want to be a part of, join Proton today. Drive offers up to 5GB of storage for free.

Keep your files private, share them securely
Hanki Proton Drive ilmaiseksi

Related articles

en
From the very beginning, Proton has always been a different type of organization. This was probably evident from the way in which we got started via a public crowdfunding campaign that saw 10,000 people donate over $500,000 to launch development. As
en
Your online data is valuable. While it might feel like you’re browsing the web for free, you’re actually paying marketing companies with your personal information. Often, even when you pay for services, these companies still collect and profit from y
en
Password spraying attacks pose a major risk to individuals and organizations as a method to breach network security by trying commonly used passwords across numerous accounts. This article explores password spraying attacks, explaining their methods
en
A secure password is your first defense against unauthorized access to your personal information. While there are tools that generate strong passwords, remembering these complex combinations can become a challenge. Even if you use mnemonic devices,
en
Choosing the best email hosting provider for your small business is crucial for maintaining security, control, and compliance with data protection laws.  For one, many popular providers, such as Gmail and Outlook, don’t apply end-to-end encryption b
en
Today, we’re excited to announce new enhancements to Proton Drive’s sharing functionality, giving you greater control over who you share with and how you share your files and folders. This feature builds on how sharing currently works in Drive by le