Personal data is any information that can identify a living individual, including names, email addresses, IP addresses, and even behavioral data patterns.
Under GDPR, personal data encompasses any information relating to an identified or identifiable natural person (data subject). This definition is deliberately broad and includes both direct and indirect identifiers that can be used alone or combined with other data to identify someone.
Direct identifiers include obvious personal information like names, addresses, phone numbers, email addresses, and government-issued ID numbers. However, GDPR also covers indirect identifiers such as IP addresses, device IDs, location data, and even pseudonymized data if it can be linked back to an individual.
Special categories of personal data receive enhanced protection under GDPR. These include racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data for identification purposes, health data, and data concerning sex life or sexual orientation.
The regulation also recognizes that combining seemingly anonymous data points can create personal data. For example, age, gender, and postal code together might identify specific individuals in small communities. Even behavioral patterns, purchase histories, and online activity can constitute personal data if they create unique digital fingerprints.
Organizations must carefully assess what data they collect and process, as the personal data definition determines GDPR's applicability. Tim Bracke from Trustbit often advises that when in doubt, treat data as personal data to ensure compliance.
For personalized guidance, consult a Data Protection specialist on TinRate.
The following Data Protection experts on TinRate Wiki can help with this topic:
| Expert | Role | Company | Country | Rate |
|---|---|---|---|---|
| Bob van Bouwel | Your Lead-Out Legal | Lead-Out Legal | Belgium | EUR 100/hr |
| Kenny Hietbrink | Hack-IT | Netherlands | EUR 110/hr | |
| Niels Vandezande | Data, AI, Cybersecurity, Tech and Crypto/Payments Lawyer | Timelex | Belgium | EUR 200/hr |
| Tim Bracke | CISO / Security Expert | Trustbit | Austria | EUR 95/hr |