Personal information is a broad term for information that identifies or can reasonably be linked to a specific person; however, the exact legal definition varies by statute and jurisdiction. Different laws use different terms and scopes, including the COPPA Rule's personal information, the Gramm-Leach-Bliley Act's nonpublic personal information, and the Health Insurance Portability and Accountability Act’s (HIPAA's) protected health information (PHI). Some laws also cover information linked to a household or device, even if it does not directly name an individual.
Personal information can include direct identifiers, such as a name, postal address, email address, Social Security number, driver's license number, or account number. It can also include data that becomes identifying when linked with other information, such as online identifiers, Internet Protocol addresses, browsing and search history, geolocation, biometric information, purchase history, employment or education information, and inferences used to create a profile. Some statutes separately define sensitive personal information, including certain financial-account credentials, precise geolocation, health or genetic information, and the contents of a consumer's mail, email, and text messages unless the business is the intended recipient.
Federal law does not use one definition for every context. Instead, federal statutes often apply by sector or setting. The Children's Online Privacy Protection Rule defines personal information in the context of information collected online from children under age 13. The Gramm-Leach-Bliley Act defines nonpublic personal information to include personally identifiable financial information that a consumer provides to a financial institution, that results from a transaction or service, or that the institution otherwise obtains. HIPAA regulations define protected health information, and the Privacy Act of 1974 governs certain records about individuals maintained by federal agencies.
State privacy laws may define the term more broadly. For example, the California Consumer Privacy Act includes information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. It excludes specified publicly available, deidentified, and aggregate consumer information.
Whether information is legally protected can depend on who holds it, how it was collected, whether it can reasonably be linked or reidentified, and which law applies. Depending on the law, a covered classification may trigger duties or rights concerning notice, consent, access, correction, deletion, security, use, disclosure, sale or sharing, retention, and breach notification. Particular rights and obligations are not uniform, so the applicable statute and its definitions must be consulted.
See also:
[Last reviewed in August of 2026 by the Wex Definitions Team]