GDPR Explained: What Counts as Personal Data?

When the EU introduced the General Data Protection Regulation (GDPR), it placed personal data at the centre of modern privacy law. Yet many organisations — and many individuals — still struggle with a simple question: what exactly qualifies as personal data?

The GDPR doesn’t provide a neat checklist. Instead, it gives a broad definition that must be interpreted in context:

“Personal data means any information relating to an identified or identifiable natural person (‘data subject’).”

Put simply, personal data is any information that relates to a specific person. The scope is intentionally wide, and the regulation goes further to explain what “identifiable” means:

“An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”

This covers a huge range of information. Depending on the circumstances, details such as an IP address, job title, hair colour, or political opinions could all be considered personal data.

Context Matters

The phrase “in certain circumstances” is crucial. Whether a piece of information counts as personal data depends heavily on how it is collected, stored, and combined.

Organisations often gather multiple data points about individuals. A single piece of information might not identify someone on its own — but when combined with other data, it can become identifying.

For example:

  • Asking a user for their occupation is unlikely to identify them.

  • Asking which company they work for also may not identify them — unless they are the only employee.

  • But combining occupation and employer could narrow the field enough to identify someone in many cases.

On the other hand, some combinations remain too broad. Knowing someone is a barista at Starbucks doesn’t reveal much unless additional details — such as a name or location — are added.

Names Aren’t Always Personal Data (But Often Are)

It’s easy to assume a name is always personal data, but the GDPR takes a more nuanced view. The UK Information Commissioner’s Office (ICO) explains:

“By itself the name John Smith may not always be personal data because there are many individuals with that name. However, where the name is combined with other information (such as an address, a place of work, or a telephone number) this will usually be sufficient to clearly identify one individual.”

Equally, a name isn’t required to identify someone:

“Simply because you do not know the name of an individual does not mean you cannot identify them. Many of us do not know the names of all our neighbours, but we are still able to identify them.”

This reinforces the core principle: identifiability is about context, not just individual data points.

Why This Matters for Organisations

Understanding what counts as personal data is essential for GDPR compliance. If information can identify someone — directly or indirectly — it must be handled with care:

  • collected lawfully

  • stored securely

  • used transparently

  • and deleted when no longer needed

For businesses, this means reviewing not just obvious identifiers, but also any data that could become identifying when combined with other information.


Post a comment

Next Faster, Smarter, More Secure: Aegir Digital Moves to HTTP/2

Aegir Digital