Personal data under GDPR includes any information relating to an identified or identifiable natural person, from names and emails to IP addresses and behavioral data.
Under GDPR, personal data is defined as any information relating to an identified or identifiable natural person (data subject). This definition is deliberately broad and encompasses much more than many organizations initially realize.
Direct identifiers include obvious personal information like names, addresses, phone numbers, email addresses, and national identification numbers. Indirect identifiers can identify someone when combined with other data, such as IP addresses, device IDs, location data, and even pseudonymized data if it can be linked back to an individual.
Special categories of personal data receive enhanced protection under Article 9. These include racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data used for identification, health data, and data concerning sex life or sexual orientation. Processing these requires explicit consent or specific legal grounds.
Online identifiers like cookies, RFID tags, and social media handles are also considered personal data. Even seemingly anonymous data can become personal data if it's possible to re-identify individuals through additional information or sophisticated analysis techniques.
The key test is whether the individual is identifiable, either directly or indirectly. As IT consultant Sylvia Beeckman from Esbee. IT Consultancy notes, organizations often underestimate the scope of personal data they process, particularly in digital environments where tracking and profiling are common.
For personalized guidance, consult a GDPR Compliance specialist on TinRate.
The following GDPR Compliance experts on TinRate Wiki can help with this topic:
| Expert | Role | Company | Country | Rate |
|---|---|---|---|---|
| Axel Desmet | Tech & Commercial Lawyer | Cresco | Belgium | EUR 150/hr |
| Bertil van Eden | Cyber Security Professional | van Eden Secure | Belgium | EUR 120/hr |
| Bob van Bouwel | Your Lead-Out Legal | Lead-Out Legal | Belgium | EUR 100/hr |
| Eveline Van den Abeele | Legal counsel | Rechtaan | Belgium | EUR 140/hr |
| Inge Van Noppen | Consultant in risk, internal control, compliance, GDPR | Konfident | Belgium | EUR 125/hr |
| Philippe Kimpe | Founder | Lucy | Belgium | EUR 150/hr |
| Sylvia Beeckman | IT Consultant | Esbee. IT Consultancy | Belgium | EUR 50/hr |