PII
Personally Identifiable Information
Personenbezogene bzw. personenidentifizierende Daten
PII denotes information by which a concrete person can be identified — directly (name, ID number) or in combination of several attributes. In Europe the broader concept of personal data under the GDPR is authoritative. Protecting such data is not only a security but also a legal duty.
History & facts. The term PII stems mainly from the United States of America (US) context; European law works with the broader concept of personal data, which applies as soon as a person is identifiable. The key realisation is that even seemingly harmless individual pieces of information can, in combination, make a person uniquely identifiable. In a security incident involving personal data, additional duties arise — such as the separate notification to the data-protection authority within 72 hours.
Outlook & recommendation. Security and data protection interlock: an attack affecting personal data triggers, alongside the Network and Information Security Directive 2 (NIS2) reporting chain, the GDPR notification duty in parallel. In practice this means knowing one's data holdings (which PII is where?), minimising and protecting them — data minimisation is also risk reduction. In forensics, the handling of PII must be documented with particular care.