How to Identify Personally Identifiable Information (PII)
Personally Identifiable Information (PII) is any data that can be used to identify a specific person — on its own or combined with other data. If your business collects names, payment details, health records, or even email addresses, you are handling PII, and mishandling it can lead to identity theft, breach-notification obligations, and regulatory fines. This guide shows you how to recognize PII, find where it hides in your systems, and protect it.
🚀 Brought to you by Axio Networks, an award-winning Managed IT provider in Scottsdale, Arizona.
We help businesses find, classify, and secure sensitive data to stay compliant and breach-ready.
📌 Step 1: Understand What Counts as PII
✔ Direct identifiers point to a person immediately — a full name, Social Security number, or driver’s license number.
✔ Indirect identifiers only identify someone when combined — a birth date, ZIP code, or job title alone may be harmless, but together they can pinpoint one individual.
✅ The practical test: if data could trace back to a specific person — alone or combined with other data you hold — treat it as PII and protect it.
📌 Step 2: Know the Common Types of PII
| Type of PII | Examples | Risk Level |
|---|---|---|
| Direct identifiers | Full name, Social Security number, driver’s license, passport number | 🚨 High |
| Financial data | Credit card numbers, bank account details, tax ID | 🚨 High |
| Health information | Medical records, insurance details, prescriptions | 🚨 High (HIPAA-protected) |
| Biometric data | Fingerprints, facial recognition data | 🚨 High |
| Contact information | Phone number, email address, home address | ⚠️ Medium |
| Employment data | Employee ID, salary, performance reviews | ⚠️ Medium |
| Online identifiers | IP address, login credentials, security questions | ⚠️ Medium |
✅ Combinations matter: a date of birth plus a home address can uniquely identify someone even though neither is a direct identifier on its own.
⚖️ Why it matters in Arizona: the state’s breach-notification law requires businesses to notify affected individuals when unencrypted personal information is compromised — and industry rules like HIPAA (healthcare), the FTC Safeguards Rule (mortgage, title, dealerships, tax preparers), and PCI DSS (anyone taking card payments) add their own requirements.
📌 Step 3: Find Where PII Hides in Your Business
PII is rarely confined to one database. Check:
- Documents and spreadsheets — customer lists, invoices, contracts, HR files
- Email — attachments and message bodies with SSNs, card numbers, or medical details, often years old
- Web forms and applications — anything collecting personal, payment, or login details
- Cloud storage — OneDrive, SharePoint, and shared drives with copied or exported records
- Line-of-business systems — CRM, practice management, loan origination, POS, and scanned-document folders
- Backups and old devices — retired laptops, USB drives, and archives that still hold everything above
✅ Rule of thumb: wherever data enters your business (forms, email, scanners) or gets copied (exports, backups, shared folders), PII accumulates.
📌 Step 4: Inventory and Classify It
✔ Build a simple data inventory — list each system, what PII it holds, and who can access it.
✔ Use built-in discovery tools — Microsoft Purview and sensitivity labels in Microsoft 365 can automatically find and tag SSNs, credit card numbers, and other patterns across email and files.
✔ Rank by risk — prioritize direct identifiers, financial, and health data first.
✔ Delete what you don’t need — data you no longer store is data you can’t lose in a breach.
📌 Step 5: Protect the PII You Keep
🔒 Limit access — only the people who need a record to do their job should be able to open it (least privilege).
🔒 Encrypt it — at rest (BitLocker, encrypted storage) and in transit (encrypted email for anything sensitive).
🔒 Turn on MFA — stolen passwords are the most common way attackers reach PII.
🔒 Set retention rules — keep records only as long as legal and business requirements demand, then dispose of them securely.
🔒 Train your team — most PII exposure starts with an email sent to the wrong place or a file shared too broadly.
🚫 Never send unencrypted SSNs, card numbers, or medical records by email — and never store them in shared spreadsheets everyone can open.
💡 Axio Networks Pro Tip
You can’t protect data you don’t know you have. Start with a one-page data inventory, let Microsoft 365’s discovery tools do the heavy lifting, and review access twice a year — most businesses are surprised by how much PII sits in old email and shared folders.
Need help finding and securing the PII in your business? Axio Networks runs data-security assessments for Scottsdale and Phoenix-area businesses.
☎ 480-602-2946