What Is PII?
Understanding Personally Identifiable Information

Personally Identifiable Information (PII) is information that can identify, relate to, or distinguish an individual, either on its own or when combined with other data.
Businesses collect PII every day through customer accounts, applications, transactions, employee records, healthcare systems, financial services, and online forms. Because some of this information can be highly sensitive, organizations need to understand where it's collected, where it's stored, and who has access to it.
What Does PII Mean?
PII stands for Personally Identifiable Information, data that can identify, contact, or distinguish a specific person.

Common examples include:
- Full name
- Home address
- Email address
- Telephone number
- Date of birth
- Social Security Number (SSN) or Social Insurance Number (SIN)
- Driver's licence or passport number
- Government-issued identification
- Bank account information
- Health or patient identifiers
- Employee or customer identification numbers
Not all PII carries the same level of risk. A name or business email address is generally lower-risk than a government ID number or financial account details.
Why Is Protecting PII Important?
PII often moves through many different systems — CRMs, databases, customer portals, SaaS applications, APIs, and third-party services.
Every system that stores sensitive information can increase an organization's overall data exposure.
Protecting PII helps organizations:

- Reduce the amount of sensitive data stored across business systems
- Limit access to personal information
- Reduce the impact of a data breach
- Support privacy and data-protection requirements
- Control where sensitive information is stored
- Safely share information with authorized systems and third parties
A useful guiding principle is to keep sensitive information only where it's actually needed.
What Is PII Tokenization?
PII tokenization replaces sensitive information with a non-sensitive substitute called a token.
The original information stays protected inside a secure vault, while applications, databases, and integrations use the token instead.
When an authorized business process needs the original value, it can be securely retrieved or forwarded to an approved destination. This reduces how often raw PII needs to travel through an organization's systems.
PII and Data Privacy
Organizations may be subject to different privacy and data-protection requirements depending on where they operate, the information they collect, and the industries they serve.
Protecting PII requires more than securing a database. Businesses should understand:

- What PII they collect
- Why they collect it
- Where it's stored
- Which systems can access it
- Which third parties receive it
- How long it's retained
- Where, geographically, the information is stored
- How it's deleted when no longer required
Understanding the complete data flow is an essential part of reducing privacy and security risk.
Reduce PII Exposure with Tokenization
Organizations don't need raw personal information available throughout their systems.
HostedPII allows businesses to collect, tokenize, vault, and securely distribute sensitive PII — using tokens within their applications and workflows instead.
Sensitive information stays protected inside the HostedPII vault and is securely delivered to an authorized system only when required.
Learn more about HostedPII tokenization and secure PII vaulting →