Yes, a phone number is personally identifiable information under most of the privacy laws that matter in the United States and Europe. HIPAA lists telephone numbers among its 18 protected identifiers, the Gramm-Leach-Bliley Act treats them as nonpublic personal information when a financial institution holds them, California’s CCPA sweeps them into its broad definition of personal information, and the GDPR covers them as personal data in Europe. The harder question, and the one worth understanding, is how much protection your number actually gets, because that depends on who is holding it and what else they know about you.
Why Context Decides the Answer
There is no single federal definition of PII. The most widely cited government version comes from the Office of Management and Budget, which describes PII as “information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other personal or identifying information that is linked or linkable to a specific individual.”1U.S. General Services Administration. Rules and Policies – Protecting PII – Privacy Act OMB adds that this “requires a case-by-case assessment of the specific risk that an individual can be identified.”
A personal cell phone number usually clears that bar on its own. Run it through a reverse-lookup service and you often get a name, address, and carrier. A generic business line is different: on its own it identifies an office, but paired with a name or a location it can narrow down to one person. NIST’s framework treats phone numbers as PII on a sliding scale of sensitivity, where a work number on an agency website sits low and a personal cell tied to medical records sits much higher.2National Institute of Standards and Technology. Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)
Where the Law Clearly Protects Your Phone Number
Different statutes reach phone numbers through different doors, but the effect is the same: an organization holding your number in one of these contexts has legal duties around how it stores and shares it.
HIPAA. The Privacy Rule names telephone numbers as one of 18 specific identifiers that must be removed from health information before that data counts as “de-identified.”3eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures If a healthcare provider or insurer holds your phone number alongside anything health-related, the combination is protected health information, and unauthorized disclosure can bring enforcement action from the Department of Health and Human Services.
Gramm-Leach-Bliley Act. The GLBA defines “nonpublic personal information” as personally identifiable financial information a consumer provides, that results from a transaction, or that a financial institution otherwise obtains.4Office of the Law Revision Counsel. 15 U.S. Code 6809 – Definitions The CFPB’s examination manual confirms this includes phone numbers alongside names, addresses, Social Security numbers, income, and credit score.5CFPB. GLBA Privacy – CFPB October 2016 A carve-out lets banks treat a number as “publicly available” if it appears in a public phone directory, but a list of customers’ numbers compiled from account records stays protected even when the same numbers happen to appear in a phone book, because the list itself came from the private banking relationship.
Privacy Act of 1974. When a federal agency holds your phone number in a system of records, the Privacy Act restricts how the agency can use and disclose it. The statute defines a “record” as information containing a person’s name or “the identifying number, symbol, or other identifying particular assigned to the individual.”6Office of the Law Revision Counsel. 5 U.S. Code 552a – Records Maintained on Individuals Phone numbers plainly fit that description.
California Consumer Privacy Act. The CCPA takes the broadest approach of any U.S. privacy law, covering anything that “identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.”7California Legislative Information. California Civil Code 1798.140 Its enumerated categories cross-reference California Civil Code § 1798.80(e), which explicitly lists telephone numbers. Californians can ask a covered business to disclose what it holds, delete it, or stop selling or sharing it.8State of California Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) Civil penalties reach $2,500 per violation, or $7,500 per intentional violation.
GDPR. Europe’s rule defines personal data as any information relating to an identified or identifiable natural person, and phone numbers fit squarely. Organizations that process phone numbers of EU residents have to meet requirements around lawful basis, data minimization, and individual rights. Serious violations can draw fines of up to €20 million or 4% of global annual revenue.
Where Protection Thins Out
Phone numbers do not carry the same weight as Social Security numbers or bank account numbers. NIST’s guidance says plainly that “an individual’s SSN, medical history, or financial account information is generally considered more sensitive than an individual’s phone number or ZIP code.”2National Institute of Standards and Technology. Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) On its own, an exposed phone number rarely enables identity theft or financial fraud.
That lower sensitivity has a real consequence. Most state data breach notification laws do not include phone numbers in the list of data elements that trigger mandatory notice. Those laws focus on Social Security numbers, financial account numbers, and driver’s license numbers. A breach that exposes only phone numbers typically will not require the company to tell affected people anything under most state laws.
The publicly available exception matters less than it used to. Under the GLBA, a directory-listed number is not protected as nonpublic information. Under the CCPA, publicly available information from government records falls outside the definition of personal information. Most cell phone numbers never appear in public directories, so this carve-out rarely applies to the numbers people actually carry today.
Why the TCPA Matters More Than PII Status Sometimes Does
Separate from data privacy statutes, the Telephone Consumer Protection Act protects your number from a different threat: unwanted contact. The TCPA restricts autodialed calls, prerecorded messages, and unsolicited texts to cell phones. A person who receives calls or texts in violation can sue for $500 per violation, tripled to $1,500 when the caller acted willfully.9FCC. Telephone Consumer Protection Act 47 USC 227
Those figures compound. A company that sends 10,000 unauthorized texts faces potential exposure of $5 million to $15 million in one lawsuit. This is where the PII label has real teeth for a consumer: your phone number is not just data to be protected from hackers, it is data that creates direct legal liability when a company uses it for marketing without consent.
What You Can Do
Your phone number is PII under the laws that matter, but it sits in a middle tier of sensitivity. Companies face real penalties for mishandling it, yet on its own it usually is not sensitive enough to force a breach notification in most states. The strongest protections kick in when your number sits next to health data, financial data, or gets used to contact you without permission.
The practical response is to be selective. Every form, app, and loyalty program that asks for your number adds another organization to the list holding your PII. In California and other states with similar laws, you can ask covered businesses what they have about you, request deletion, and opt out of sale or sharing. Those requests are one of the few tools that push some control back to your side of the transaction.