Glossary: PII (Personally Identifiable Information)

PII is information that identifies a person or can reasonably be combined with other data to do so. In crypto analytics, wallet addresses may become identifying when linked to account, device, or behavioral data.

What is personally identifiable information (PII)?

Personally identifiable information, or PII, is information that identifies a person or can reasonably be combined with other information to identify them. Examples can include a person’s name, email address, government identifier, account details, precise location, or a combination of indirect identifiers. The exact scope depends on the law, organization, and context; privacy regimes often use the broader term “personal data” or “personal information.”

PII and crypto analytics

A blockchain address is generally a pseudonymous identifier rather than a person’s name. However, an address can become linkable to an individual through account registration, wallet connection, public disclosures, transaction patterns, IP or device data, or third-party enrichment. Once linked, associated onchain history may reveal sensitive behavioral or financial information. Public visibility alone does not settle whether data is personal information under a particular law.

How to handle PII in analytics

Collect only data needed for a clear purpose, document its source and retention period, restrict access, and avoid storing direct identifiers alongside wallet histories unless necessary. Use aggregation or pseudonymization where suitable, protect re-identification keys separately, honor applicable user rights, and assess vendors and cross-border transfers. Pseudonymized data can still be personal data if it can be relinked.

Examples

  • An email address tied to a connected wallet is direct identifying data linked to an onchain identifier.

  • An IP address combined with timestamps and wallet activity may allow a person to be singled out.

  • A public wallet address with no reasonably available identity link may be pseudonymous, but context can change that assessment.

Common mistakes

Do not assume public data is automatically outside privacy law. Do not call pseudonymization anonymization when re-identification remains possible. Do not treat one jurisdiction’s definition of PII as universal; map the data and processing to the laws that apply.

Related reading

Explore Cookie, IP Address, Identity Resolution, Server-side Tracking, and Formo’s Privacy Policy.

FAQs

Is a wallet address PII?

It depends on the law and context. A public address is pseudonymous, but may be personal information when it can reasonably be linked to an identifiable person, alone or with other data.

Is PII the same as personal data?

The terms overlap, but their definitions vary. PII is common in US privacy discussions; personal data is used in laws such as GDPR and can have a broader scope.

Can public blockchain data be PII?

Public availability does not automatically remove privacy obligations. If an organization links onchain activity to an identifiable person or uses it to make decisions about them, legal and policy analysis may be needed.

The data platform onchain apps

Get actionable analytics and attribution for crypto and DeFi.