PII vs NPI: Understanding the Difference
Two critical data classifications with distinct regulatory requirements. Understanding the difference is essential for compliance.
PII is any information that identifies a specific person — a name, Social Security Number, email address, or biometric record — and is regulated across every sector. NPI is the narrower set of nonpublic financial information a consumer gives a financial institution, defined by the Gramm-Leach-Bliley Act.All NPI is PII, but not all PII is NPI.
Personally Identifiable Information
PII is any information that can be used to identify, contact, or locate a specific individual — either on its own or when combined with other data sources. It is broadly defined across multiple federal and state regulations.
Examples
- Full name
- Social Security Number
- Email address
- Phone number
- Physical address
- Date of birth
- Biometric data
Key Regulations
NIST SP 800-122, HIPAA, state privacy laws (CCPA, CPRA), GDPR (for EU data subjects), FERPA, and various sector-specific requirements.
Nonpublic Personal Information
NPI is a narrower category defined primarily by the Gramm-Leach-Bliley Act (GLBA). It refers to financial information that a consumer provides to a financial institution, or that results from a transaction, and that is not publicly available.
Examples
- Account numbers
- Income and credit history
- Insurance claim data
- Loan or mortgage details
- Tax return information
- Transaction history
- Account balances
Key Regulations
GLBA (Gramm-Leach-Bliley Act), FTC Safeguards Rule, SEC Regulation S-P, state financial privacy laws, and NYDFS Cybersecurity Regulation.
Key Differences
| Aspect | PII | NPI |
|---|---|---|
| Scope | Broad — any identifying info | Narrow — financial data only |
| Primary Law | Multiple (HIPAA, CCPA, etc.) | GLBA |
| Industries | All sectors | Financial services |
| Overlap | All NPI is PII, but not all PII is NPI | |
| Enforcement | FTC, HHS, state AGs | FTC, SEC, state regulators |
Compliance Implications
Organizations that handle both PII and NPI must implement controls satisfying multiple regulatory frameworks simultaneously. A unified compliance approach — mapping controls across GLBA, HIPAA, CCPA, and sector-specific regulations — reduces duplication and strengthens the overall security posture.
Common questions
What does PII mean?
PII stands for Personally Identifiable Information: any data that can identify, contact, or locate a specific person on its own or when combined with other information — a name, Social Security Number, email address, phone number, or biometric record.
Is a Social Security Number PII?
Yes. A Social Security Number is a direct identifier and one of the clearest examples of PII. Of the common exam-style options — plan premium amount, Social Security Number, star rating score, formulary tier — only the Social Security Number is PII, because the others describe a product or plan rather than a person.
Is an account number NPI or PII?
A financial account number held by a financial institution is Nonpublic Personal Information (NPI) under GLBA, and it is also PII. All NPI is PII, but not all PII is NPI.
What is the difference between PII and NPI?
PII is the broad category covering any identifying information across all sectors and is governed by many laws (HIPAA, CCPA, GDPR, FERPA). NPI is a narrower, financial-sector category defined by the Gramm-Leach-Bliley Act and enforced through the FTC Safeguards Rule and SEC Regulation S-P.
Need help with data classification?
Our compliance team can help you identify, classify, and protect sensitive data across your organization.
Contact Expert