---
title: "What Is (and Isn't) PII in a University — 2026 Guide | USC Data"
description: "2026 guide to PII vs non-PII in higher education — FERPA, GLBA, US state privacy laws, Australian Privacy Act reforms, recent breaches, and how Priivacy protects student and staff data."
lang: en-US
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "What Is (and Isn't) PII in a University — 2026 Guide",
      "description": "A 2026 guide for higher education leaders on what counts as PII, what doesn't, recent breaches, and how AI changes both the risk and the response.",
      "author": {
        "@type": "Organization",
        "name": "USC Data"
      },
      "publisher": {
        "@type": "Organization",
        "name": "USC Data",
        "logo": "https://uscdata.com/usc-data-logo.png"
      },
      "datePublished": "2024-03-07",
      "dateModified": "2026-04-28",
      "mainEntityOfPage": "https://uscdata.com/resources/university-pii",
      "image": "https://uscdata.com/og-image.png"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://uscdata.com/#organization",
      "name": "USC Data",
      "url": "https://uscdata.com/",
      "logo": "https://uscdata.com/usc-data-logo.png",
      "description": "USC Data helps organizations clean, govern, and restructure business data so AI, audits, automation, and compliance are safe — not risky.",
      "founder": {
        "@type": "Person",
        "name": "Shane Reid"
      },
      "sameAs": [
        "https://www.linkedin.com/company/usc-data"
      ],
      "areaServed": [
        {
          "@type": "Country",
          "name": "United States"
        },
        {
          "@type": "Country",
          "name": "Australia"
        },
        {
          "@type": "Country",
          "name": "United Kingdom"
        },
        {
          "@type": "Country",
          "name": "New Zealand"
        }
      ],
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "Sales",
          "email": "connect@uscdata.com",
          "availableLanguage": [
            "en"
          ]
        }
      ],
      "knowsAbout": [
        "Data Governance",
        "PII Discovery",
        "Data Quality",
        "Metadata Management",
        "Data Integration",
        "Data Migration",
        "Compliance",
        "AI Readiness"
      ],
      "parentOrganization": {
        "@type": "Organization",
        "name": "USC Data",
        "url": "https://uscdata.com/"
      }
    }
  ]
---

[connect@uscdata.com](mailto:connect@uscdata.com)

[![USC Data logo](/assets/header-logo-JqaV6ADN.png)](/)

Priivacy Services [BDOS](/bdos)[Discovery](/services/discovery)Resources Company

[Request a Risk Assessment](/contact)

Fast response. No obligation.

[Back to Resources](/resources)

Higher Education

# What Is (and Isn't) PII in a University — A 2026 Guide

Universities sit on some of the richest personal data in the economy: identity documents, health records, financial aid files, research participants, and increasingly — AI prompt logs. Knowing what counts as PII is the first defence.

Originally published March 2024 · Updated April 2026  6 min read 

![University campus at dusk with overlaid data nodes](/assets/blog-pii-universities-CAJGmlWF.jpg)

Personally identifiable information (PII) is data that can be used — on its own or combined with other data — to identify, contact, or locate an individual. In higher education that definition gets blurry fast: a student ID without context looks harmless, but combine it with a class schedule and a Wi-Fi access log and you've narrowed identification to one person.

## PII vs non-PII on a modern campus

**Clearly PII:**

-   Full name, date of birth, home address, personal email, phone number
-   Student ID, staff ID, government IDs (SSN, Medicare, TFN, NHS number, passport)
-   Financial aid records, loan information, payment details
-   Health and disability records, counselling notes
-   Biometric data — facial recognition templates, fingerprint logins, exam-proctoring video
-   Visa and immigration status for international students

**Usually non-PII (but watch the context):**

-   Aggregated enrolment numbers, course titles, faculty names
-   Anonymised research datasets (when re-identification risk is genuinely low)
-   Public event listings, general campus information
-   Job titles, departmental structures

The 2026 reality is that "non-PII" is a smaller category than it used to be. Modern re-identification attacks combine three or four innocuous attributes — postcode, date of birth, gender, course — to single out an individual with frightening accuracy. Treat context as part of the classification.

## The 2026 regulatory landscape

### 🇺🇸 United States

-   **FERPA** still governs student education records, but the U.S. Department of Education's 2024–2025 guidance explicitly extends it to AI vendors processing student data on behalf of institutions.
-   **GLBA Safeguards Rule (FTC)** applies to any university handling federal student aid — written information security program, designated qualified individual, MFA, and encryption are now mandatory.
-   **State privacy laws** — California (CCPA/CPRA), Virginia, Colorado, Texas, Oregon and a growing list of others now grant students and employees individual access and deletion rights.
-   **Colorado AI Act (Feb 2026)** brings high-risk AI systems — including admissions and academic-progression algorithms — under explicit governance.

### 🇦🇺 Australia

-   **Privacy and Other Legislation Amendment Act 2024** introduced a statutory tort for serious invasions of privacy and lifted maximum civil penalties to **AU$50M** (or 30% of adjusted turnover).
-   **Tranche 2 Privacy Act reforms (2025–2026)** remove the small business exemption, introduce a "fair and reasonable" handling test, and give individuals a direct right of action.
-   **Australian Privacy Principles (APPs)** — APP 11 (security) and APP 6 (use and disclosure) remain the day-to-day operating standard for universities.
-   **Notifiable Data Breaches scheme** still requires reporting eligible breaches to the OAIC and affected individuals "as soon as practicable."
-   **TEQSA** guidance now expects governance over generative AI used in teaching, assessment and research administration.

## Recent breaches — and the pattern

Higher education remained one of the most targeted sectors through 2024 and 2025. The MOVEit file-transfer compromise pulled in dozens of US and UK universities. In Australia, multiple Group of Eight institutions have disclosed third-party processor breaches affecting student records since 2023. Western Sydney University publicly confirmed multiple intrusions through 2024 affecting thousands of staff and students. The pattern is consistent: **the breach almost never starts with the university's own perimeter.** It starts with a vendor, an exposed cloud bucket, an unmanaged SaaS tool, or — increasingly — data pasted into a consumer AI assistant.

## AI changes both sides of the problem

Generative AI is now embedded in admissions triage, student support chatbots, research assistance, and every staff laptop. That creates two new exposure vectors:

-   **Prompt leakage** — staff pasting student records, scholarship applications or counselling notes into ChatGPT, Claude or Gemini.
-   **Shadow AI agents** — browser extensions and Copilot-style tools indexing SharePoint, OneDrive and Google Drive without classification.

The same technology is also the best defence. AI and ML can scan terabytes of unstructured campus data, classify it by sensitivity, flag PII the institution didn't know it held, and continuously monitor for anomalous access — at a scale no human team can match.

## How USC Data and Priivacy  help

Priivacy  is the managed PII discovery toolset USC Data deploys for higher education clients. It scans network shares, SharePoint, OneDrive, Google Workspace, Box, email archives and research repositories — **without extracting any data outside your firewall**. The output is a defensible inventory of what PII you hold, where it lives, who can access it, and which records are **redundant, obsolete or trivial (ROT)** and safe to remediate.

### Local-first, by design

USC Data's discovery tooling never sends university data to an external cloud for analysis. Scanning runs inside your environment; only metadata and aggregate findings leave the perimeter.

## Where to start this term

1.  Map every system that holds student or staff PII — including SaaS, research tools, and shadow AI.
2.  Run a scoped discovery scan to find PII you didn't know you held.
3.  Apply a one-page "do-not-paste" rule to every device with AI access.
4.  Remediate ROT — the safest record is the one you no longer hold.
5.  Brief the executive on residual risk, not just controls.

### Is your university AI-ready and audit-ready?

Book a 20-minute call. We'll map your highest-risk PII surfaces and show you the fastest path to a defensible inventory.

[Book a discovery call](/contact)

### Related reading

-   [PII Compliance in 2026: What Financial Services Firms Need to Know](/resources/pii-compliance-2026)
-   [GRC Trends 2026: How Governance Tech Is Reshaping PII](/resources/grc-trends-2026)
-   [Priivacy™ — managed PII discovery](/services/priivacy)

![USC Data — Unified. Secured. Connected.](/assets/usc-data-logo-white-tagline-zlFrNz8X.png)

USC Data helps growing and regulated organizations clean, govern, and restructure business data so AI, analytics and automation finally work — while hidden compliance risk disappears.

We deliver right-sized, phase-based data governance, privacy remediation, and AI readiness programs across the U.S., Australia, and the U.K.

#### Quick Links

-   [Services](/services)
-   [Discovery](/services/discovery)
-   [AI Readiness](/services/metadata)
-   [Privacy & Compliance](/services/priivacy)
-   [SharePoint & File Chaos](/services/data-integration)
-   [Data Cleanup](/services/data-cleanup)
-   [Case Studies](/case-studies)
-   [Resources](/resources)
-   [Privacy Policy](/privacy)
-   [Terms of Use](/terms)

![ISO 27001 Certified](/lovable-uploads/a3a9df20-c3b3-4cc8-a059-2400491a0dbb.png)

ISO 27001 Certified Data Governance & Privacy Programs

#### Get in touch

Get fast, no-obligation clarity on your data risk, privacy exposure, and AI readiness.

North America:  [+1 844 988 1444](tel:+18449881444)

Australia:  [+61 1300 80 95 80](tel:+611300809580)

[Request a Risk Assessment](/contact)

© 2026 USC Data. All rights reserved. An affiliate of the Umlaut Solutions Group — delivering trusted data governance and compliance programs since 2016.