Earlier quoted context omitted.
KYC data is by definition PII data, but the opposite is definitely not true. You can have PII data without it being relevant to nor mandated by KYC regulations. Please understand that the muddying of terms only harms your argument, instead of strengthening it.
That difference matters only to the institution. To the user, however, the risk and damage from the leak of any type of serious PII is one and the same in that it is a risk to be avoided. In other words, the technicality you state is the difference between the user getting punched in the guts versus in the gonads. Both are to be avoided.
Leaking PII like names and phone numbers, versus KYC specific PII like ID proofs is a completely different ball game.
This argument is not about levels of harm, just your lack of understanding of nuance tbh.