Data classification
Personally Identifiable Information (PII)
PII is any data that can be used to identify a specific individual, including names, addresses, email addresses, phone numbers, social security numbers, and device identifiers. Most privacy regulations govern the handling of PII.
Risk profile
PII breaches trigger notification requirements under GDPR (72 hours), CCPA, state breach notification laws, and similar regulations globally. Fines, lawsuits, and reputational damage can be severe. Vendors handling PII must have a DPA (under GDPR), appropriate technical controls, and sub-processor management.
Example vendors
SalesforceHubSpotSegmentTwilio SendGrid
Common questions
Is an email address PII?
Yes. An email address is PII because it can identify a specific individual. It is also typically personal data under GDPR.
Do I need a DPA with every vendor who handles my users' email addresses?
Under GDPR, yes — if you are an EU-established organization or targeting EU individuals and you share personal data with a processor. Email delivery providers, analytics platforms, and CRM vendors all typically require DPAs for EU customers.
Which of your vendors handle Personally Identifiable Information (PII)?
TrustVendor tracks data class exposure across your entire vendor portfolio and computes residual risk per relationship.
Book a demo