Blog

What is “personal data”?

GDPR defines personal data as:

“any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person”.

To help understand the definition of personal data further I’m going to take you through what some of the words mean within this GDPR definition.

Identifiable

Remember you must be able to identify and distinguish an individual from other individuals. Having their name along with other information about them, its fairly obvious you’re going to be able to identify them.

Although having the name of an individual is a good way to identify someone, you also need to consider the context. Can someone be truly identified.  E.g. the name ‘John Smith’ may not always be personal data. The reason being is there are probably many individuals in the UK with that name. However, when you take their name and combine it with other information it will usually be enough to clearly identify just one individual. E.g. name combined with an address, or a telephone number.

Identifier

GDPR gives examples of common identifiers that can allow the identification of an individual. These include name, identification number, location data, and online identifiers.

We’ve just seen that a name needs to have context for it to be truly identifiable data. But what about the other identifiers, what can they include (and do remember these lists are non-exhaustive):

ID numbers

  • Passport number;
  • Social Security number;
  • Driver’s license number; or
  • Any other number that can directly identify and individual.

Location data

  • Address of where someone lives or works;
  • Geographical position of terminal equipment the individual uses, such as laptop or mobile phone; or
  • GPS tracking, such as tracking on company vehicles or mobile devices.

Online identifiers

  • Internet protocol (IP) addresses;
  • Cookies;
  • Radio frequency identification (RFID) tags;
  • Advertising IDs;
  • MAC addresses;
  • Pixel tags;
  • Account handles; or
  • Device fingerprints.

Directly or Indirectly

GDPR states that an individual can either be identified directly or indirectly. 

Being able to identify someone directly means it will be very clear who the person is. You can clearly identify someone from an identifier such as a passport number or a name and address.  You could also directly identify someone from their business email address. E.g. johnsmith@dunwelldataprotection.com, as this gives you their name and lets you know where they work.

You can also identify an individual indirectly.  This is when you combine data with other data that you hold in order to identify someone. E.g. combing a post code with vehicle registration number can identify an individual.  If it is possible for you to identify someone from the data you hold by matching it to another dataset then you will be processing personal data.

Conclusion

As you can see there is a lot to understand within the definition of personal data. But, what do you do if you are unsure whether data is personal data or not? My advice, err on the side of caution and assume it is!