Skip to main content

PII (Personally Identifiable Information)

Personally identifiable information (PII) is any data that can identify a specific individual, directly or indirectly: names, national ID and iqama numbers, contact details, photographs, location records, device identifiers, and any combination of attributes that singles one person out of a population. Under the PDPL, the operative legal term is personal data, defined in similarly broad terms, with a stricter subset of sensitive data covering categories such as health data, genetic and biometric data, credit data, criminal and security data, and data revealing ethnic origin or religious belief.

The distinction matters because obligations scale with sensitivity: sensitive data demands stronger safeguards and explicit consent in most cases, and its exposure carries the law's harshest consequences.

For a Saudi DMO, the difficulty is rarely defining PII — it is finding it. Personal data hides in inconsistently named columns across legacy systems, in free-text fields, in copies landed in data lakes, and in extracts shared for analytics long ago. Mature programs treat PII discovery as a continuous process: profiling and pattern detection to flag candidate columns, steward review to confirm, classification tags recorded in the data catalog, and propagation of those tags to downstream copies through lineage. Once tagged, PII metadata becomes the backbone of everything else — access control, consent enforcement, transfer assessments, and data subject request fulfillment.

In the product