PII
Data & TrackingAlso: Personally Identifiable Information · Personal Information
Quick definition
PII stands for personally identifiable information. It's any data that can identify a specific person, either directly like an email address or full name, or indirectly when combined with other details like a postcode and date of birth. Marketers collect PII constantly through forms, pixels and customer relationship management (CRM) systems.
How it varies across Australia
How Australian businesses handle PII varies widely by sector. Regulated industries like finance and health tend to have stricter consent and storage practices than retail or hospitality, mostly because the penalties for getting it wrong are higher. Maturity here tracks closely with overall data and tracking discipline.
See data and tracking scores across Australian industries →What it actually means
Think of PII as the difference between a crowd and a person. An anonymous pageview tells you someone visited. An email address, a phone number or a full name tells you who. That shift from anonymous to identifiable is the line PII sits on, and it's the line most privacy law is built around.
Marketers brush up against PII everywhere. Lead forms collect it directly. Pixels and cookies sometimes capture it indirectly through hashed identifiers. Your CRM stores it deliberately. First-party data programs are, in practice, PII management programs with a friendlier name.
The complicating part is combination. A postcode alone isn't PII. A postcode plus a birth date plus a gender often is, because together they narrow down to one person. This is why data minimisation matters more than most teams think. Collecting less PII isn't just a compliance posture, it reduces the blast radius if something goes wrong with a data breach.
PII is not the same as third-party data or consent, but all three sit in the same conversation. Understanding PII is the starting point for understanding why attribution, retargeting and personalisation keep getting harder as privacy rules tighten.
PII isn't a technical category. It's a legal one, and the fine for treating it casually is real.
How it shows up
PII shows up as the fields in your form builder marked with a lock icon, the columns in your CRM export that make a compliance officer nervous, and the reason your consent banner exists at all. It also shows up in vendor contracts, where clauses about data processing and storage location are really PII clauses wearing legal language. If a data breach ever makes the news, the headline number is almost always a count of PII records exposed.
The Australian context
Australian PII handling sits under the Privacy Act 1988, enforced by the Office of the Australian Information Commissioner (OAIC). Reforms moving through Parliament are tightening notification requirements and increasing penalties for mishandling. The Notifiable Data Breaches scheme already requires businesses to report breaches involving PII that are likely to cause serious harm.
Separately, the Spam Act and rules enforced by the Australian Communications and Media Authority (ACMA) govern how PII like email addresses and phone numbers can be used for marketing outreach. Consent obtained for one purpose doesn't automatically cover another, which trips up a lot of Australian lead-gen programs that reuse contact lists across campaigns.
Where people get this wrong
Related terms
Common questions
What counts as PII in marketing data?
Names, email addresses, phone numbers and physical addresses are the obvious examples. Less obvious ones include IP addresses, device identifiers and any combination of details like postcode plus birth date that narrows down to one identifiable person.
Is a customer's email address always PII?
Yes. An email address identifies a specific person on its own, which puts it squarely in PII territory. This applies whether it's sitting in a CRM, a spreadsheet, or attached to an event in your analytics tool.
Does hashing PII make it safe to share with ad platforms?
Hashing reduces risk but doesn't reclassify the data as non-PII. Platforms like Meta and Google use hashed matching for custom audiences, but the underlying legal obligations around consent and storage still apply to the original data.
How is PII different from first-party data?
First-party data describes where the data came from, directly from your own audience rather than a third party. PII describes what the data is, information that identifies a person. First-party data is often PII, but not always. A purchase count without a name attached isn't PII even though it's first-party.
Debrief
Get the next one
No spam. No fluff. Just the next article, straight to your inbox.
Keep exploring
About New Rebellion
New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.
How we think →