What Is Data Leakage?
Data leakage is the unintended transmission of any sensitive data, not limited to personal information, to an unauthorized or unintended destination, such as a third-party tag, an incorrectly configured integration, or a misconfigured data layer event. PII leakage is the most legally consequential subset of this broader category.
Data leakage is the umbrella term; PII leakage is the specific, legally regulated instance of it that gets the most attention. Leakage can also involve internal business data that isn’t personal at all: pricing exposed in a URL, unreleased product names in a tag’s event data, session tokens sent somewhere they shouldn’t be. Both categories are caught the same way, through Payload Inspection, but only the PII Leakage subset carries direct regulatory exposure under laws like GDPR and CCPA.