Personal Data
What is personal data according to the GDPR?
In the text of the GDPR, Article 4, Paragraph 1 provides the definition of “Personal Data.”
Let’s explore it together.
“Personal data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.”
Personal Data
- Refers to a natural person (not a company).
- B2B vs. B2C Context
If your company works with other companies (B2B), it is not exempt from GDPR.
This is because companies consist of natural persons, and the personal data of John Doe, who works at Corporation ABC ltd – for example, his work email address john.doe@corporationabc.com—is considered personal data.
- B2B vs. B2C Context
- Personal data is not limited to a name or email address but includes any information that can make a person identifiable.
- It identifies the individual directly or indirectly (e.g., identifiability through cross-referencing information).
- Example: An online identifier, even if it does not reveal the person’s identity, can, when cross-referenced with information from other sources, make them identifiable.
A practical example: an IP address. Alone, it does not reveal a person’s identity. However, when cross-referenced with an IP address database, it might reveal the exact location from which the user connects. This information could then be linked to a specific contract with an internet service provider, tied to a specific natural person.
- Example: An online identifier, even if it does not reveal the person’s identity, can, when cross-referenced with information from other sources, make them identifiable.
- Examples of personal data include:
- Name
- Identification number (e.g., social security number, vehicle license plate)
- Geographical location data
- Online identifiers (cookies, usernames, IP addresses, etc.)
- Characteristics of identity, such as:
- Physical
- Physiological
- Genetic
- Mental
- Economic
- Cultural
- Social
- This definition also includes so-called “special categories of data” (previously referred to as “sensitive data”).
Legal, ICT, Marketing: we understand your needs
We aim to relieve you from the headaches of managing customer consents and privacy.