Define: NPPI
In a contract, NPPI means nonpublic personally identifiable information, the private data that identifies a customer, consumer, or employee and is not publicly available. The clause defines which data counts as NPPI so the parties know exactly what must be protected, how it may be used, and what safeguards and breach obligations apply.
Legal accuracy standard set & glossary spot-checked by Imad Mohammed Nazar , Skadden-trained M&A lawyer, Legal Engineer at GenieAI
What NPPI means in a contract
NPPI stands for nonpublic personally identifiable information. It is private information that identifies an individual, such as a customer, consumer, or member of staff, and that is not lawfully available from public sources. In a contract the term marks a protected category of data: once information is defined as NPPI, the agreement's confidentiality, security, use, and breach clauses attach to it. The definition is the pivot on which the whole data protection framework of the contract turns, because everything downstream depends on what is inside the category and what is outside it.
How the term is defined and measured
A strong NPPI definition does two things: it describes the kinds of data covered, and it carves out what is not. Covered data typically includes identifiers combined with financial, account, or sensitive personal details that a person would reasonably expect to be kept private. The exclusion for genuinely public information matters, because data that is lawfully public is not NPPI even if it also identifies someone. The clause should state the test for "nonpublic" rather than assume it, since the line between public and private is where arguments start.
- The identifiers: name, account, and reference numbers tied to an individual.
- The sensitive detail: financial, account, or other private attributes linked to those identifiers.
- The exclusion: information lawfully available to the public is outside the category.
- The scope of subjects: customers, consumers, and personnel, as the contract specifies.
Where the term appears
NPPI is central to data handling obligations and appears in an information security policy, in release mechanisms such as a release of information form that authorizes disclosure, and in confidentiality undertakings, where the discipline of creating a non disclosure agreement shows how protected information is defined and fenced off. It is a standing concern for the compliance function responsible for how personal data is stored, used, and shared.
Why the exact wording matters
The wording sets the perimeter of protection. If the definition is too narrow, sensitive data falls outside the safeguards and the individual is exposed; if it is too broad, ordinary business information is dragged into onerous handling rules that slow operations. Disputes often turn on whether a particular field is NPPI, whether aggregated or de identified data still qualifies, and whether public availability removes protection. A precise definition, aligned with the safeguards and breach clauses that reference it, ensures the parties protect the same thing to the same standard.
Drafting considerations
Because mishandling protected data carries legal and reputational cost, the NPPI clause should be drafted to connect cleanly with the obligations that rely on it.
- Define both what is covered and what is excluded, and state the test for "nonpublic".
- Align the definition with the security, use limitation, retention, and breach notification clauses so they cover the same data.
- Address de identified or aggregated data expressly, since its status is frequently contested.
- Specify permitted purposes and prohibited uses, and the steps required on a suspected breach.
Under the law governing the contract, statutory privacy and data protection duties may apply on top of the contractual definition, so the clause should be read as a floor that supports those duties rather than a ceiling that replaces them. A carefully scoped NPPI definition gives both parties a shared, enforceable understanding of exactly which information must be guarded.
Relevant Circumstances
- When dealing with data collection, processing or storage.
- In scenarios where the exchange of personal information is required.
- In contexts requiring the strict protection of customer data.