Data classification

Personally Identifiable Information (PII)

PII is any data that can be used to identify a specific individual, including names, addresses, email addresses, phone numbers, social security numbers, and device identifiers. Most privacy regulations govern the handling of PII.

Risk profile

PII breaches trigger notification requirements under GDPR (72 hours), CCPA, state breach notification laws, and similar regulations globally. Fines, lawsuits, and reputational damage can be severe. Vendors handling PII must have a DPA (under GDPR), appropriate technical controls, and sub-processor management.

Applicable frameworks

GDPRCCPASOC 2ISO 27018

Example vendors

SalesforceHubSpotSegmentTwilio SendGrid

Common questions

Is an email address PII?
Yes. An email address is PII because it can identify a specific individual. It is also typically personal data under GDPR.
Do I need a DPA with every vendor who handles my users' email addresses?
Under GDPR, yes — if you are an EU-established organization or targeting EU individuals and you share personal data with a processor. Email delivery providers, analytics platforms, and CRM vendors all typically require DPAs for EU customers.

Which of your vendors handle Personally Identifiable Information (PII)?

TrustVendor tracks data class exposure across your entire vendor portfolio and computes residual risk per relationship.

Book a demo