
Personally Identifiable Information (PII)
Personally Identifiable Information (PII) is a category of sensitive information that is associated with an individual person, such as an employee, student, or donor. PII should be accessed only on a strict need-to-know basis and handled and stored with care.
PII is information that can be used to uniquely identify, contact, or locate a single person. Personal information that is “de-identified” (maintained in a way that does not allow association with a specific person) is not considered sensitive. Note that NetID numbers by themselves are not considered sensitive or private personal information.
University policies, contractual obligations, and federal and state laws and regulations require appropriate protection of PII that is not publicly available. These regulations apply to PII stored or transmitted via any type of media: electronic, paper, microfiche, and even verbal communication.
PII does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
Examples:
For Everyone at UNM:
- Social Security number (There are additional restrictions on where Social Security numbers can be stored and shared.)
- National ID number
- Passport number
- Visa permit number
- Driver's license number
- Bank and credit/debit card numbers
- Tax information (e.g., W-2, W-4, 1099)
- Disability information
- Ethnicity
- Gender
- The location of an individual at a particular time
- Web sites visited
- Materials downloaded
- Any other information reflecting preferences and behaviors of an individual
- Internet Protocol (IP) address (source and destination) in conjunction with other PII. IP address may identify an individual originating a transaction as well as the recipient.
For Employees:
- Biographic/demographic data
- Date and location of birth
- Country of citizenship
- Citizenship status
- Marital status
- Military status
- Criminal record
- Home address
- Grievance information
- Discipline information
- Leave-of-absence reason
- Payroll and benefits information
- Health information (There are additional restrictions on where Protected Health Information can be stored and shared.
Frequently Used by:
- Faculty
- Staff
- Students
- Researchers
Category
Sensitive
For Students:
For Donors:
- Biographic/demographic data
- Contact information
- Prospect data
- Gift and gift-planning data
Laws/Regulations/Policies:
Sensitive Data Policies and Regulatory ComplianceInstitutional Data Resource Management Policy (SPG 601.12)
Additional Resources:
Handbook for Safeguarding Sensitive Personally Identifiable InformationUsing Personally Identifiable Information (PII)
This list shows which services can and cannot be used to store and share Personally Identifiable Information (PII). Click any service for more details.
Key: Permission Levels
- Permitted
- Permitted with IA Consultation
- Not Permitted
Permitted
- Backup
- Database
- Virtual Machines
- Servers
- Endpoint
- Storage- CIFS
- Fileshare
Permitted with ISPO Consultation
- Software
- Licensed Applications
Not Permitted
- Cloud Storage
- Cayuse
- Google Drive
