PII Principal
A PII principal is the individual person that a set of personally identifiable information (PII) is about. In privacy standards such as ISO 29100, this term corresponds to what the GDPR calls the 'data subject'.
Under ISO 29100, a PII principal is defined as the natural person to whom the personally identifiable information (PII) relates. The term functions as the ISO privacy framework's equivalent of the GDPR concept of 'data subject', identifying the individual whose personal data is being processed. PII in this context refers to any information that can be used, directly or indirectly, to distinguish, trace, or identify a specific individual. Related ISO standards (for example ISO 27018) impose obligations on organizations to co-operate in giving effect to PII principals' rights, though the precise scope and enforceability of those rights depend on the applicable legal regime rather than the standard alone.
Why it matters
The term 'PII principal' matters because it identifies the person at the center of any privacy obligation: the individual whose personal information is being collected, used, or shared. In the context of cookie consent and tracking technologies, the PII principal is the website visitor or app user whose device is accessed and whose data may be processed. Understanding who the principal is helps organizations frame their responsibilities correctly, since many privacy rights and duties are defined in relation to this individual rather than to the data in the abstract.
Because the ISO 29100 concept of 'PII principal' corresponds to what the GDPR calls the 'data subject', teams that work across both legal frameworks and technical standards need to recognize that these are two names for the same underlying idea. Conflating or confusing the terminology can lead to gaps when mapping standards-based controls (such as those in the ISO 27000 family) onto legal obligations under regimes like the GDPR. Related ISO standards, such as ISO 27018, impose obligations on organizations to co-operate in giving effect to PII principals' rights, but the precise scope and enforceability of those rights depend on the applicable legal regime rather than the standard alone.
For practitioners, keeping the PII principal clearly in view is a useful discipline: it centers compliance analysis on the real individual affected, and it reminds teams that adopting a privacy standard is not the same as satisfying a legal requirement. The rights available to any given individual will vary depending on jurisdiction and the facts of the processing, so the label 'PII principal' should be treated as a starting point for identifying obligations rather than a complete statement of them.
Who it's relevant to
Inside PII Principal
Common questions
Answers to the questions practitioners most commonly ask about PII Principal.

