PII Examples: What Is Personally Identifiable Information?
See clear PII data examples, learn what PII means, and discover how to protect bank statements, payslips, invoices, and other personal records.
What Is Personally Identifiable Information?
If you need a quick definition, **personally identifiable information (PII)** is information that can identify, distinguish, or trace a person. A full name, Social Security number, email address, bank account number, or face image can be PII on its own. A date of birth, ZIP code, employer, device identifier, or transaction detail can also become PII when it is linked or combined with other information. NIST describes PII in this direct-or-combined way, which is why there is no single universal list that covers every situation. [1](https://csrc.nist.gov/glossary/term/personally_identifiable_information)
This guide explains **what PII is**, gives practical **PII data examples**, answers common questions such as **what does PII stand for**, and shows how to protect PII in bank statements, payslips, and invoices before you share them. The examples are educational, not legal advice; the exact definition of PII depends on the country, industry, contract, and purpose of processing.
What Does PII Stand For?
PII stands for **personally identifiable information**. In simple terms, it is information about an individual that can identify the person directly or make the person reasonably identifiable when combined with other data.
A direct identifier points to one person clearly. Examples include a legal name with a unique identifier, a Social Security number, passport number, driver’s-license number, personal email address, or biometric record. Indirect identifiers may look harmless separately, but become identifying as a group. For example, a birth date, ZIP code, employer, job title, and a partial account reference may identify a specific person when matched with another database.
That is the key answer to **what constitutes PII**: ask whether the information can identify a person alone or through reasonable linkage. The answer is about context, not just the field name. A business name may not be personal PII, while the name, direct phone number, and home address of a sole proprietor may be.
PII Data Examples: Common Categories
The following examples of PII cover the information most often found in applications, websites, financial documents, HR systems, and customer records.
**Direct Identity and Government Identifiers**
• Full name, former name, alias, or signature
• Social Security number or other national identification number
• Passport, driver’s-license, taxpayer, or employee number
• Account number, customer number, policy number, or case reference
• A face photograph, fingerprint, voiceprint, or other biometric record
**Contact and Location Information**
• Home or postal address
• Personal email address and phone number
• Precise location or GPS history
• IP address, MAC address, device ID, cookie ID, or advertising ID when linked to a person
• Vehicle registration, license plate, VIN, or other vehicle identifier
**Financial and Employment Information**
• Bank account number, routing number, sort code, IBAN, or payment details
• Credit-card number and related payment information
• Bank balances, transaction history, payroll records, or tax information
• Salary, deductions, benefits, employer, job title, and employee ID
• Purchase history, invoice references, or payment-for-service records
**Personal, Educational, and Health-Related Information**
• Date and place of birth
• Race, religion, gender, family information, or demographic data
• School records, grades, attendance, or disability information
• Medical history, diagnosis, treatment, insurance, or healthcare-payment details
• Online account usernames, passwords, authentication answers, or recovery details
Not every item above identifies a person in every context. However, organizations should assess whether the information is linked or linkable to an individual and whether exposure could cause harm. Wisconsin’s education privacy guidance, for example, separates broad PII from higher-risk sensitive PII and emphasizes that classification depends on the surrounding information and circumstances. [2](https://dpi.wi.gov/wise/data-privacy/PII-examples)
Financial Document PII Examples
Financial documents often contain several PII fields on the same page. That makes them useful for verification but risky to share without minimization.
Bank Statement PII Examples
A bank statement may contain the account holder’s name, home address, account number, routing number, statement number, transaction descriptions, merchant names, balances, employer details, and QR or barcode data. The transaction history can also reveal a person’s location, habits, health-related purchases, subscriptions, or business relationships.
For a landlord, lender, or visa reviewer, you may need to show your name, bank branding, statement dates, deposits, and ending balance. You may not need to expose the full account number, routing number, unrelated purchases, internal transfer notes, or a complete home address. Before sharing, make a copy, remove unnecessary pages, and use a real redaction method rather than a simple drawing overlay. See [how to hide account numbers and routing numbers on a PDF](/blog/hide-account-number-routing-number-pdf).
Payslip PII Examples
A payslip can expose an employee’s name, address, employee ID, employer, pay period, gross and net pay, tax number, Social Security number, bank routing details, direct-deposit account, deductions, benefits, and leave information. A proof-of-income recipient may need the employer, pay period, and income figures, but not every banking, tax, or benefits field.
Ask the recipient which fields are required. Then redact unrelated identifiers and verify that the exported file does not allow the hidden text to be selected, copied, or searched. BankXLS also covers [redacted pay stub examples](/blog/redacted-pay-stub-example) and [how to redact a payslip for proof of income](/blog/how-to-redact-payslip-proof-of-income).
Invoice PII Examples
An invoice may include a customer or supplier name, billing address, email, phone number, tax or VAT ID, bank details, invoice number, payment reference, and itemized services. A company invoice is not automatically free of PII. It can contain personal data about an employee, customer, contractor, or sole trader.
If the purpose is reimbursement or proof of purchase, the recipient may only need the seller, date, amount, and transaction reference. Hide personal contact details, payment credentials, unrelated line items, and embedded metadata when they are not necessary. For a practical workflow, read the [BankXLS invoice and billing statement guide](/blog/redact-invoice-billing-statement-guide).
Which of the Following Is an Example of PII?
A name, personal email address, Social Security number, passport number, home address, bank account number, or biometric record is an example of PII. A bank statement containing an identifiable person’s name and account details is also a PII-containing document.
A useful test is this: Could a reasonable person use this information alone or with available data to identify the individual? If yes, treat it as PII and limit collection, access, retention, and sharing.
Which of the Following Is Not an Example of PII?
A truly anonymous statistic, a random value that cannot be linked back to a person, or information about a generic organization with no identifiable individual may not be PII. For example, “35% of respondents selected option A” is generally not PII if the survey responses cannot be connected to individuals.
However, be careful with claims that data is anonymous. Removing a name does not automatically anonymize a record. A combination of date of birth, location, employer, purchase history, or a unique event may still identify someone. A document with a redacted name can remain personal information if its other fields make the person reasonably identifiable.
PII and PHI: What Is the Difference?
PII and PHI overlap, but they are not the same thing. PII is the broader concept of information that identifies or can identify a person. PHI means protected health information under HIPAA: individually identifiable health information held or transmitted by a HIPAA covered entity or business associate, relating to a person’s health, healthcare, or payment for healthcare. HHS includes common identifiers such as a name, address, birth date, and Social Security number when they are connected to protected health information. [3](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html)
For example, a bank account number is PII but not PHI. A payslip is normally employment and financial PII, not PHI merely because it shows a health-insurance deduction. A medical bill containing a patient’s name and treatment information may be both PII and PHI when it is handled in the relevant HIPAA context.
This distinction matters because people often search for PII and PHI as if they were interchangeable. They are not. PHI has a specific healthcare and regulatory context, while PII can cover financial, employment, education, contact, technical, and identity data. When in doubt about a regulated record, consult the applicable privacy professional or regulator.
How to Protect PII Before Sharing a Document
Use this short checklist whenever someone requests a bank statement, payslip, invoice, tax form, or other personal record:
1. **Confirm the purpose.** Ask what the recipient needs to verify and whether a redacted copy is acceptable.
2. **Minimize the document.** Send only the necessary pages, date range, and fields.
3. **Redact high-risk fields.** Consider account numbers, routing numbers, government IDs, home addresses, signatures, QR codes, barcodes, and unrelated transactions.
4. **Use permanent redaction.** A black rectangle or highlighter can hide text visually while leaving the original text layer underneath. Read [what redacted text means and how to redact a PDF safely](/blog/redacted-text) and [why drawing black boxes on a PDF can fail](/blog/black-out-text).
5. **Inspect the exported file.** Try to select, copy, search, and extract text from the redacted area. Also check document properties and embedded attachments where relevant.
6. **Verify the recipient and channel.** Prefer an authenticated portal or controlled encrypted link. Do not post an unredacted financial document through a public link.
7. **Remove access after use.** If the platform supports expiration or revocation, use it. Keep the original in a restricted location and delete unnecessary copies.
BankXLS SafeShare processes supported documents in the browser and is designed to permanently flatten redacted pages before download. It can help you prepare a safer copy while keeping the original file on your device. Always review the result yourself and follow the recipient’s requirements.
FAQs About PII Examples
Here are clear, direct answers to common questions about personally identifiable information and document privacy:
What is PII information? “PII information” usually means personally identifiable information information, so the phrase is repetitive. The intended meaning is information that identifies or can reasonably be linked to a person, such as a name, government ID, address, account number, biometric record, or combined personal details.
What is PII data examples? PII data examples include names, email addresses, phone numbers, government IDs, bank-account details, IP addresses linked to people, employee records, medical records, and combinations such as birth date plus ZIP code plus employer.
Is an email address PII? A personal email address is generally treated as PII because it can identify or contact an individual. A generic company inbox may identify an organization rather than a person, but context can still make it personal information.
Is a bank statement PII? A bank statement is a document that commonly contains PII and sensitive financial information. It can include names, account numbers, balances, addresses, and transaction details, so share only the minimum needed for the stated purpose.
Is a Social Security number sensitive PII? Yes. A Social Security number is a direct government identifier and is typically treated as high-risk or sensitive PII. Do not share it unless the recipient has a legitimate need and an appropriate secure process.
Final Takeaway
The simplest answer to what is personally identifiable information is: data that identifies a person directly or through reasonable combination with other data. The best PII examples are not limited to obvious numbers. Bank statements, payslips, invoices, browser identifiers, transaction histories, and ordinary contact details can all become identifying in context.
Before you send a personal document, ask what the recipient truly needs, remove unrelated information, permanently redact high-risk fields, and verify the exported file. That approach protects privacy without making legitimate verification impossible.