[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-pii::en":3,"gloss-cluster-pii::en":23,"gloss-next-pii::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"pii","security","Personally Identifiable Information (PII)","PII is any data that can identify a specific person — name, email, phone number, address, IP address, government IDs, or combinations that together single someone out. It's the category regulators care most about: GDPR, CCPA, and similar laws impose obligations on how you collect, store, and delete it. For SaaS builders, knowing exactly what PII flows through your system is the foundation of privacy compliance and a recurring question on every data-processing agreement. It matters even more with AI features: sending customer PII to an LLM provider means that data leaves your boundary, so you need the right data-processing terms and often a way to redact or avoid it. Practical note: minimize what you collect, encrypt sensitive fields, and be able to find and delete a given person's data on request (the \"right to erasure\"). Tag PII fields in your schema early — retrofitting a data map across a mature codebase is painful.","PII is any data identifying a specific person — name, email, phone, address, IP, ID numbers — and the category GDPR and CCPA obligations hang on.",null,[11,14,17,20],{"slug":12,"name":13},"audit-log","Audit Log (Audit Trail)",{"slug":15,"name":16},"encryption-at-rest","Encryption at Rest",{"slug":18,"name":19},"gdpr","GDPR (General Data Protection Regulation)",{"slug":21,"name":22},"hipaa","HIPAA",[24,26,30,34,37,40,43,46,49,52,55,58],{"slug":12,"category":5,"name":13,"updated_at":25},"2026-08-24T02:46:37+00:00",{"slug":27,"category":5,"name":28,"updated_at":29},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":31,"category":5,"name":32,"updated_at":33},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":35,"category":5,"name":36,"updated_at":33},"bridge-letter","Bridge Letter",{"slug":38,"category":5,"name":39,"updated_at":33},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":41,"category":5,"name":42,"updated_at":25},"byok","Bring Your Own Key (BYOK)",{"slug":44,"category":5,"name":45,"updated_at":33},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":47,"category":5,"name":48,"updated_at":29},"data-classification","Data Classification",{"slug":50,"category":5,"name":51,"updated_at":33},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":53,"category":5,"name":54,"updated_at":33},"data-minimization","Data Minimization",{"slug":56,"category":5,"name":57,"updated_at":33},"data-poisoning","Data Poisoning",{"slug":59,"category":5,"name":60,"updated_at":33},"data-processing-agreement","Data Processing Agreement (DPA)"]