Non-personally identifiable information (Non-PII)

Non-personally identifiable information (non-PII) is a piece of data that cannot be used on its own to trace or identify a person. This type of information is typically collected and used for various purposes such as analytics, research, or advertising targeting without revealing the individuals’ identity.

Examples of non-PII include, but are not limited to:

  • Aggregated statistics on the use of product / service
  • Partially or fully masked IP addresses
  • Types of devices (such as smartphones, tablets, and desktops)
  • Cookies or anonymous identifiers
  • Time spent on a website or app

While non-PII doesn’t directly identify individuals, there can still be privacy concerns associated with its collection, storage, and usage, especially when combined with other data sources or when certain patterns can lead to indirect identification. Therefore, organizations that collect non-PII need privacy policies and procedures to safeguard this information and ensure compliance with relevant regulations.

Here you’ll find the full comparison of personally identifiable information, non-personally identifiable information and personal data: What is PII, non-PII, and personal data? [UPDATED]


  • Privacy by design in practice: How “just enough” data beats “just in case” collection

    While collecting more data “just in case” feels safer, according to Matt Gershoff, it’s also one of the biggest sources of unnecessary compliance risk, analytical noise, and wasted organizational resources in the analytics industry today. His approach of “just enough” data collection is more intentional, more aligned with privacy regulation, and often more analytically effective.

  • 4 ways to make your analytics HIPAA-compliant: Implementation guide

    Healthcare organizations have four main approaches to achieving HIPAA-compliant analytics. Each has different trade-offs in cost, technical complexity, and analytics capabilities. This guide compares all four implementation methods – from using Google Analytics with workarounds to deploying fully HIPAA-compliant analytics platforms – so you can choose the right approach for your organization’s needs and resources.