Skip to main content
The state of ai impact assessment
Category: Consumer Privacy Rights

PII Principal

Also known as: Data Subject
Simply put

A PII principal is the individual person that a set of personally identifiable information (PII) is about. In privacy standards such as ISO 29100, this term corresponds to what the GDPR calls the 'data subject'.

Formal definition

Under ISO 29100, a PII principal is defined as the natural person to whom the personally identifiable information (PII) relates. The term functions as the ISO privacy framework's equivalent of the GDPR concept of 'data subject', identifying the individual whose personal data is being processed. PII in this context refers to any information that can be used, directly or indirectly, to distinguish, trace, or identify a specific individual. Related ISO standards (for example ISO 27018) impose obligations on organizations to co-operate in giving effect to PII principals' rights, though the precise scope and enforceability of those rights depend on the applicable legal regime rather than the standard alone.

Why it matters

The term 'PII principal' matters because it identifies the person at the center of any privacy obligation: the individual whose personal information is being collected, used, or shared. In the context of cookie consent and tracking technologies, the PII principal is the website visitor or app user whose device is accessed and whose data may be processed. Understanding who the principal is helps organizations frame their responsibilities correctly, since many privacy rights and duties are defined in relation to this individual rather than to the data in the abstract.

Because the ISO 29100 concept of 'PII principal' corresponds to what the GDPR calls the 'data subject', teams that work across both legal frameworks and technical standards need to recognize that these are two names for the same underlying idea. Conflating or confusing the terminology can lead to gaps when mapping standards-based controls (such as those in the ISO 27000 family) onto legal obligations under regimes like the GDPR. Related ISO standards, such as ISO 27018, impose obligations on organizations to co-operate in giving effect to PII principals' rights, but the precise scope and enforceability of those rights depend on the applicable legal regime rather than the standard alone.

For practitioners, keeping the PII principal clearly in view is a useful discipline: it centers compliance analysis on the real individual affected, and it reminds teams that adopting a privacy standard is not the same as satisfying a legal requirement. The rights available to any given individual will vary depending on jurisdiction and the facts of the processing, so the label 'PII principal' should be treated as a starting point for identifying obligations rather than a complete statement of them.

Who it's relevant to

Data protection and privacy officers
Privacy professionals who map controls from ISO standards such as ISO 29100 and ISO 27018 onto legal frameworks like the GDPR need to recognize that 'PII principal' and 'data subject' describe the same individual. This mapping is central to ensuring that standards-based programs align with the actual rights and obligations imposed by applicable law.
Legal and compliance counsel
Counsel reviewing contracts, standards references, or vendor documentation may encounter 'PII principal' where they expect 'data subject'. Recognizing the equivalence helps avoid misinterpretation, while remembering that the enforceable scope of any individual's rights depends on the applicable legal regime rather than on the standard alone.
Cloud service and vendor management teams
Teams evaluating cloud providers and processors that certify against standards like ISO 27018 should understand that such standards can impose obligations to co-operate regarding PII principals' rights. This is relevant when assessing whether a vendor can support the exercise of individual rights, though certification does not by itself guarantee legal compliance.
Developers and technical implementers
Engineers building consent and data-handling systems benefit from framing their designs around the individual the data is about, the PII principal, since many privacy obligations, including those tied to cookies and tracking technologies, are defined in relation to that person rather than to the data in the abstract.

Inside PII Principal

Definition and origin
PII Principal is a term drawn primarily from ISO/IEC privacy standards (notably the ISO/IEC 29100 family) referring to the natural person to whom personally identifiable information (PII) relates. It is broadly analogous to the 'data subject' concept used in the GDPR and many EU-derived frameworks, though the terminology and precise scope differ between the standards-based and statutory regimes.
Relationship to data subject
In practice the PII Principal maps closely to the GDPR's 'data subject' and to comparable roles such as the 'consumer' under certain US state privacy laws (for example California's CCPA/CPRA). These terms are not perfectly interchangeable, because each framework defines the scope of covered individuals and information differently, so the applicable regime should be identified before treating them as equivalent.
Role in the cookie consent context
When cookies, pixels, SDKs, local storage, or fingerprinting techniques collect information linked to an identifiable individual, that individual is the PII Principal (or data subject) whose information is being processed. Under EU law the ePrivacy rules govern the placing of and access to information on the person's device, while the GDPR governs any subsequent processing of personal data; the PII Principal is central to both, but the two obligations remain distinct.
Associated rights and expectations
Frameworks that use the PII Principal or data subject concept typically attach rights to that individual, which may include being informed about processing, and depending on the applicable regime, access, correction, deletion, or the ability to opt out. The specific rights available depend on the governing law and are not uniform across the EU, the UK, and individual US states.
Scope limitations
The concept applies only where information relates to an identified or identifiable natural person. Aggregated, fully anonymized, or non-personal data generally falls outside the PII Principal framing, though the line between pseudonymized and anonymized data is contested and fact-dependent.

Common questions

Answers to the questions practitioners most commonly ask about PII Principal.

Is "PII Principal" the same thing as a GDPR data subject?
The two concepts are closely related but originate from different frameworks and should not be treated as interchangeable. "PII principal" is terminology used in ISO/IEC privacy standards (such as ISO/IEC 29100) to describe the natural person to whom personally identifiable information relates, whereas "data subject" is the term defined and used under the GDPR and other EU data protection law. In practice they often refer to the same individual, but the precise scope, defined rights, and legal obligations attach to the framework-specific term. When making compliance decisions, you should rely on the definitions that apply to your governing legal regime rather than assuming equivalence across frameworks.
Does the PII principal concept only matter for cookies that store obvious identifiers like names or email addresses?
No. A person can be a PII principal in relation to identifiers that are not obviously personal, including data collected through cookies, pixels, local storage, SDKs, or fingerprinting techniques. Under EU law, information such as online identifiers, device characteristics, and other data that can single out or be linked to an individual may constitute personal data even where no name or email is involved. The absence of a directly identifying field does not by itself mean an individual is not identifiable, so the scope of who counts as a PII principal should be assessed on the facts rather than on the surface appearance of the data.
How do we identify who the PII principal is when we deploy cookies and similar technologies?
In practice, the PII principal is the natural person whose device is accessed or whose data is processed through the cookie, pixel, or similar technology. Identifying that person conceptually does not require knowing their name; it is enough that the individual can be singled out or linked to the data. Reviewing your data flows to map which technologies collect which identifiers, and whether those identifiers relate to an identifiable individual, helps establish where PII principal considerations apply. Where identifiability is uncertain, it is generally prudent to treat the data as relating to an identifiable person unless a documented assessment supports otherwise.
How does the PII principal concept relate to the consent we collect through a CMP?
A consent management platform (CMP) typically records and manages the choices made by the individual who is the PII principal in relation to the relevant technologies. The CMP supports compliance by capturing consent signals, storing records, and enforcing preferences, but it does not by itself determine whether the person qualifies as a PII principal or whether consent is legally valid. Under EU law, valid consent must be freely given, specific, informed, and unambiguous through a clear affirmative action, and that legal assessment sits alongside, not within, the tooling. The CMP is an operational component; the legal judgment about the PII principal's rights and the lawfulness of processing remains separate.
What records should we keep regarding a PII principal's choices?
Record-keeping practices generally involve logging the consent or preference choices associated with the PII principal, together with information sufficient to demonstrate what was presented and how the choice was made. The specific record-keeping expectations depend on the governing regime and the applicable regulatory guidance, which can evolve, so you should align your logging with the requirements of the jurisdictions in which you operate. The precise retention periods, data fields, and formats are not fixed by the concept of PII principal itself and should be determined with reference to your legal obligations.
Do a PII principal's choices differ depending on where they are located?
They can. The obligations owed to a PII principal, and the mechanism through which they exercise choice, vary between legal regimes. In most EU jurisdictions, prior opt-in consent is typically required before non-exempt cookies and similar technologies are used, whereas several US state frameworks often rely on an opt-out model, and other regimes take different approaches. This means the same individual may be handled differently depending on the applicable law and where the obligations arise. Determining which regime governs a given PII principal is a fact-specific and sometimes contested question that should be resolved with reference to the relevant legal scope rather than assumed to be uniform.

Common misconceptions

PII Principal and GDPR data subject are exactly the same and can be used interchangeably in all documentation.
They are closely analogous but originate from different sources: PII Principal comes largely from ISO/IEC privacy standards, while 'data subject' is a GDPR term. The scope of covered individuals and information can differ between standards-based and statutory frameworks, so the applicable regime should be confirmed rather than assumed equivalent.
Obtaining consent from the PII Principal to place cookies automatically satisfies all privacy obligations relating to that person.
In most EU jurisdictions the ePrivacy rules on placing or accessing information on a device and the GDPR rules on processing personal data are separate. Consent addressing one does not necessarily satisfy the other, and non-EU regimes such as US state laws may rely on an opt-out rather than opt-in model entirely.
The rights of a PII Principal are the same everywhere, so one process can serve all users.
The rights attached to the PII Principal or data subject vary by jurisdiction across the EU, the UK, and individual US states. A single global workflow may not meet every regime's specific requirements, and obligations should be mapped to the applicable law for each user population.

Best practices

Identify the governing legal regime for each user population before mapping the PII Principal concept, since the scope and rights differ between the EU, the UK, and individual US states.
Treat the placing of and access to information on a device (ePrivacy) and the processing of personal data (GDPR) as distinct obligations, and design consent and disclosure flows that address each rather than assuming one covers the other.
Recognize that pixels, SDKs, local storage, and fingerprinting can implicate the same PII Principal even though they are not literally cookies, and account for them in your consent and record-keeping processes.
Where EU law applies, ensure consent tied to the PII Principal meets the standard of being freely given, specific, informed, and unambiguous through a clear affirmative action, avoiding pre-ticked boxes, implied consent, and cookie walls that are widely considered non-compliant.
Maintain clear records of the basis on which information relating to each PII Principal is collected and processed, using a CMP or similar tooling to support but not replace legal judgment.
Document where a technology processes aggregated or anonymized data outside the PII Principal framing, while noting that the pseudonymized-versus-anonymized distinction is contested and should be assessed on the facts.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.