Personally identifiable information (PII)
Personally identifiable information (PII) is any data that identifies a specific person, directly or in combination — names, emails, phone numbers, badge IDs, photos, and at events, behavioural traces like scan histories or meeting records that can be linked back to an individual attendee or exhibitor contact.
Events generate PII at unusual density: a single attendee produces registration details, a badge ID, scan events at stands and sessions, meeting records, app behaviour, and often photographs — all linkable to one named person. Knowing what counts as PII decides which of your datasets fall under privacy law, which vendors need DPAs, and what you can safely share with exhibitors and sponsors. The trap is combination: a dataset with no names can still be PII if its fields together point to one person, and at niche B2B events they often do — "female CTO, aerospace supplier, Belgium" may be exactly one attendee. That's why "we removed the names" isn't the safe harbour teams assume it is. In practice, organizers manage PII by mapping where it lives (registration, app, badge system, spreadsheets on laptops — usually the scariest one), restricting access to need, and setting retention limits instead of hoarding every edition forever. The common mistake is the informal export: the full attendee list emailed to a sponsor "just this once," untracked and unprotected, is how most event data incidents actually happen. One honest nuance: behavioural data is the PII organizers forget. Scan trails and meeting histories feel like analytics, but attached to a badge ID they're personal data, with everything that implies.
Direct answer
Personally identifiable information (PII) is any data that identifies a specific person, directly or in combination — names, emails, phone numbers, badge IDs, photos, and at events, behavioural traces like scan histories or meeting records that can be linked back to an individual attendee or exhibitor contact.
More terms
No related terms yet.