← Resources
    Educational Guide

    PII vs NPI: Understanding the Difference

    Two critical data classifications with distinct regulatory requirements. Understanding the difference is essential for compliance.

    Short answer

    PII is any information that identifies a specific person — a name, Social Security Number, email address, or biometric record — and is regulated across every sector. NPI is the narrower set of nonpublic financial information a consumer gives a financial institution, defined by the Gramm-Leach-Bliley Act.All NPI is PII, but not all PII is NPI.

    PII

    Personally Identifiable Information

    PII is any information that can be used to identify, contact, or locate a specific individual — either on its own or when combined with other data sources. It is broadly defined across multiple federal and state regulations.

    Examples

    • Full name
    • Social Security Number
    • Email address
    • Phone number
    • Physical address
    • Date of birth
    • Biometric data

    Key Regulations

    NIST SP 800-122, HIPAA, state privacy laws (CCPA, CPRA), GDPR (for EU data subjects), FERPA, and various sector-specific requirements.

    NPI

    Nonpublic Personal Information

    NPI is a narrower category defined primarily by the Gramm-Leach-Bliley Act (GLBA). It refers to financial information that a consumer provides to a financial institution, or that results from a transaction, and that is not publicly available.

    Examples

    • Account numbers
    • Income and credit history
    • Insurance claim data
    • Loan or mortgage details
    • Tax return information
    • Transaction history
    • Account balances

    Key Regulations

    GLBA (Gramm-Leach-Bliley Act), FTC Safeguards Rule, SEC Regulation S-P, state financial privacy laws, and NYDFS Cybersecurity Regulation.

    Key Differences

    AspectPIINPI
    ScopeBroad — any identifying infoNarrow — financial data only
    Primary LawMultiple (HIPAA, CCPA, etc.)GLBA
    IndustriesAll sectorsFinancial services
    OverlapAll NPI is PII, but not all PII is NPI
    EnforcementFTC, HHS, state AGsFTC, SEC, state regulators

    Compliance Implications

    Organizations that handle both PII and NPI must implement controls satisfying multiple regulatory frameworks simultaneously. A unified compliance approach — mapping controls across GLBA, HIPAA, CCPA, and sector-specific regulations — reduces duplication and strengthens the overall security posture.

    Common questions

    What does PII mean?

    PII stands for Personally Identifiable Information: any data that can identify, contact, or locate a specific person on its own or when combined with other information — a name, Social Security Number, email address, phone number, or biometric record.

    Is a Social Security Number PII?

    Yes. A Social Security Number is a direct identifier and one of the clearest examples of PII. Of the common exam-style options — plan premium amount, Social Security Number, star rating score, formulary tier — only the Social Security Number is PII, because the others describe a product or plan rather than a person.

    Is an account number NPI or PII?

    A financial account number held by a financial institution is Nonpublic Personal Information (NPI) under GLBA, and it is also PII. All NPI is PII, but not all PII is NPI.

    What is the difference between PII and NPI?

    PII is the broad category covering any identifying information across all sectors and is governed by many laws (HIPAA, CCPA, GDPR, FERPA). NPI is a narrower, financial-sector category defined by the Gramm-Leach-Bliley Act and enforced through the FTC Safeguards Rule and SEC Regulation S-P.

    Need help with data classification?

    Our compliance team can help you identify, classify, and protect sensitive data across your organization.

    Contact Expert