Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Knowledge hub / PII

Knowledge hub

PII

Any data that points at a specific human being.

What it means

Personally identifiable information is any data that points at a specific person. Names, email addresses, phone numbers, postal addresses, identity and tax numbers, account numbers, photographs, location history, device identifiers.

It is broader than most people assume, because identification often comes from a combination rather than one field. A postcode alone is nothing. A postcode with a date of birth and a job title usually names one person. The UK regulator asks exactly that question: can you identify somebody indirectly, using other information you hold?

Why it matters

It changes what an incident costs. A breach of internal documents is a bad week. A breach of customer personal data brings notification deadlines, a regulator, individual complaints and a story with your company's name in it.

Enterprise buyers ask about it for the same reason. Your breach becomes their breach when their customers' data sat in your system. Most of a security questionnaire is this one topic wearing different hats.

How it shows up

The problem is rarely the main database, which everybody protects. It is the copies. Logs recording full request bodies. Error reports carrying customer records. Analytics events with email addresses in them, spreadsheets on laptops, support tickets with identity documents attached, backups older than the retention policy, test environments loaded from production.

The controls that hold are unfashionable. Collect less to begin with. Delete on a schedule and prove it, mask fields by default in internal tools, and keep personal data out of logs. Above all, know which systems hold it, because you cannot protect what is not on the list.

Questions people ask

PII, answered

Is an email address PII?

A personal address that identifies one person, yes. A generic mailbox such as info at a company domain usually does not identify anybody on its own.

Treat the personal ones as personal data, because that is how regulators and your customers' lawyers will read them.

Is an IP address personal data?

It depends on context, and in the UK and EU the answer is often yes. If the address can be linked to a person directly or with other information, it counts.

The practical consequence is that your access logs are not the neutral technical records people assume.

Is PII the same as personal data under UK GDPR?

Close, and not identical. PII is the American framing and tends to list identifier types. Personal data turns on whether the information relates to an identifiable person, which reaches further.

If you sell into the UK or the EU, work to the broader definition and you will cover both.

Do encrypted databases solve this?

They cover one scenario: somebody walking off with the storage. They do nothing about an attacker who is signed in as a valid user, because the application decrypts the data for them.

Most personal data incidents involve access rather than theft of a disk.

Can we use production data in a test environment?

It is the fastest way to turn a low-value system into a high-value one. Test environments usually have weaker access control, older patches and wider access.

Mask or generate the data instead. If you genuinely need real records, treat that environment as production for every control that matters.

Which records came back to us?

Cyberlop signs in as each role and reports exactly which records it reached that it should not have, with the request and the response attached. Book a 30 day pilot on one application.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.