← Resources
    Educational Guide

    PII vs NPI: Understanding the Difference

    Two critical data classifications with distinct regulatory requirements. Understanding the difference is essential for compliance.

    PII

    Personally Identifiable Information

    PII is any information that can be used to identify, contact, or locate a specific individual — either on its own or when combined with other data sources. It is broadly defined across multiple federal and state regulations.

    Examples

    • Full name
    • Social Security Number
    • Email address
    • Phone number
    • Physical address
    • Date of birth
    • Biometric data

    Key Regulations

    NIST SP 800-122, HIPAA, state privacy laws (CCPA, CPRA), GDPR (for EU data subjects), FERPA, and various sector-specific requirements.

    NPI

    Nonpublic Personal Information

    NPI is a narrower category defined primarily by the Gramm-Leach-Bliley Act (GLBA). It refers to financial information that a consumer provides to a financial institution, or that results from a transaction, and that is not publicly available.

    Examples

    • Account numbers
    • Income and credit history
    • Insurance claim data
    • Loan or mortgage details
    • Tax return information
    • Transaction history
    • Account balances

    Key Regulations

    GLBA (Gramm-Leach-Bliley Act), FTC Safeguards Rule, SEC Regulation S-P, state financial privacy laws, and NYDFS Cybersecurity Regulation.

    Key Differences

    AspectPIINPI
    ScopeBroad — any identifying infoNarrow — financial data only
    Primary LawMultiple (HIPAA, CCPA, etc.)GLBA
    IndustriesAll sectorsFinancial services
    OverlapAll NPI is PII, but not all PII is NPI
    EnforcementFTC, HHS, state AGsFTC, SEC, state regulators

    Compliance Implications

    Organizations that handle both PII and NPI must implement controls satisfying multiple regulatory frameworks simultaneously. A unified compliance approach — mapping controls across GLBA, HIPAA, CCPA, and sector-specific regulations — reduces duplication and strengthens the overall security posture.

    Need help with data classification?

    Our compliance team can help you identify, classify, and protect sensitive data across your organization.

    Contact Expert