PII

Data & Tracking

Also: Personally Identifiable Information · Personal Information

Full termPersonally Identifiable Information
IncludesName, email, phone, address
Governed byPrivacy law, not marketing preference
Shows up inForms, pixels, CRM records

Quick definition

PII stands for personally identifiable information. It's any data that can identify a specific person, either directly like an email address or full name, or indirectly when combined with other details like a postcode and date of birth. Marketers collect PII constantly through forms, pixels and customer relationship management (CRM) systems.

How it varies across Australia

How Australian businesses handle PII varies widely by sector. Regulated industries like finance and health tend to have stricter consent and storage practices than retail or hospitality, mostly because the penalties for getting it wrong are higher. Maturity here tracks closely with overall data and tracking discipline.

See data and tracking scores across Australian industries

What it actually means

Think of PII as the difference between a crowd and a person. An anonymous pageview tells you someone visited. An email address, a phone number or a full name tells you who. That shift from anonymous to identifiable is the line PII sits on, and it's the line most privacy law is built around.

Marketers brush up against PII everywhere. Lead forms collect it directly. Pixels and cookies sometimes capture it indirectly through hashed identifiers. Your CRM stores it deliberately. First-party data programs are, in practice, PII management programs with a friendlier name.

The complicating part is combination. A postcode alone isn't PII. A postcode plus a birth date plus a gender often is, because together they narrow down to one person. This is why data minimisation matters more than most teams think. Collecting less PII isn't just a compliance posture, it reduces the blast radius if something goes wrong with a data breach.

PII is not the same as third-party data or consent, but all three sit in the same conversation. Understanding PII is the starting point for understanding why attribution, retargeting and personalisation keep getting harder as privacy rules tighten.

PII isn't a technical category. It's a legal one, and the fine for treating it casually is real.

How it shows up

PII shows up as the fields in your form builder marked with a lock icon, the columns in your CRM export that make a compliance officer nervous, and the reason your consent banner exists at all. It also shows up in vendor contracts, where clauses about data processing and storage location are really PII clauses wearing legal language. If a data breach ever makes the news, the headline number is almost always a count of PII records exposed.

The Australian context

Australian PII handling sits under the Privacy Act 1988, enforced by the Office of the Australian Information Commissioner (OAIC). Reforms moving through Parliament are tightening notification requirements and increasing penalties for mishandling. The Notifiable Data Breaches scheme already requires businesses to report breaches involving PII that are likely to cause serious harm.

Separately, the Spam Act and rules enforced by the Australian Communications and Media Authority (ACMA) govern how PII like email addresses and phone numbers can be used for marketing outreach. Consent obtained for one purpose doesn't automatically cover another, which trips up a lot of Australian lead-gen programs that reuse contact lists across campaigns.

Where people get this wrong

Assuming hashed data isn't PII.A hashed email is still linked to a real person and can often be matched back through common hashing methods. Hashing reduces risk, it doesn't remove the data from PII status.
Collecting more fields than the campaign needs.Every extra field is more PII sitting in a database, more risk in a breach and more scrutiny in an audit. Minimal collection is a cheaper insurance policy than any security tool.
Treating consent as a one-time checkbox.Consent tied to a specific purpose doesn't transfer to a new use case. Reusing a list gathered for order updates to run marketing campaigns is a common way businesses breach both trust and the Spam Act.

Related terms

Common questions

What counts as PII in marketing data?

Names, email addresses, phone numbers and physical addresses are the obvious examples. Less obvious ones include IP addresses, device identifiers and any combination of details like postcode plus birth date that narrows down to one identifiable person.

Is a customer's email address always PII?

Yes. An email address identifies a specific person on its own, which puts it squarely in PII territory. This applies whether it's sitting in a CRM, a spreadsheet, or attached to an event in your analytics tool.

Does hashing PII make it safe to share with ad platforms?

Hashing reduces risk but doesn't reclassify the data as non-PII. Platforms like Meta and Google use hashed matching for custom audiences, but the underlying legal obligations around consent and storage still apply to the original data.

How is PII different from first-party data?

First-party data describes where the data came from, directly from your own audience rather than a third party. PII describes what the data is, information that identifies a person. First-party data is often PII, but not always. A purchase count without a name attached isn't PII even though it's first-party.

Debrief

Get the next one

No spam. No fluff. Just the next article, straight to your inbox.

Keep exploring

About New Rebellion

New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.

How we think →