Personal data means any information relating to an identified or identifiable natural person. This covers far more than a name, address or date of birth. Customer numbers, location data or IP addresses can also be personal data if they can be attributed to a person. The processing of personal data is governed by the General Data Protection Regulation (GDPR).
What is personal data?
Under Art. 4(1) GDPR, personal data means any information relating to an identified or identifiable natural person. The term is deliberately broad and is a central point of reference in data protection law.
A person is identified if it is immediately clear who they are, for example where a record contains the person's full name.
It is sufficient, however, for a person to be merely identifiable. A piece of information therefore does not need to reveal on its own which specific person it concerns. If a link to a particular person can be established with the help of additional information, the information may also be personal data.
Which data is personal data?
Personal data can include, for example:
- First name and surname
- Address
- Date of birth
- Telephone number
- Email address
- Employee or customer number
- Bank account details
- Vehicle registration number
- Location data
- Income and asset information
- IP addresses
What matters is not whether a piece of information appears particularly confidential. The decisive question is whether it relates to an identified or identifiable natural person.
Information about a person's professional, financial or personal circumstances can therefore also be personal data.
When is a person identifiable?
A person does not have to be directly recognisable from a single piece of information alone. It can be sufficient if the information can be combined with other available information in a way that makes identification possible.
IP addresses are an important example. In its judgment of 19 October 2016 (C-582/14 – Breyer), the Court of Justice of the European Union (CJEU) held that even a dynamic IP address can constitute personal data for a website operator. The condition is that the operator has legal means available which enable it to have the person concerned identified with additional information held by the internet service provider.
The judgment shows that whether a person's name is already known is not the only factor that determines whether information is personal.
What is not personal data?
Not all information falls within the scope of the GDPR. The concept of personal data generally requires a link to a natural person.
Data relating purely to a legal person is therefore generally not personal data. This can include, for example, the general turnover or business figures of a limited company.
The position may be different where business information also allows conclusions to be drawn about a natural person. Personal data can therefore also be processed in a professional or business context.
Information that has been effectively anonymised is also generally no longer personal data if the person concerned is not or no longer identifiable. This must be distinguished from pseudonymised data, where the link to the person can in principle be restored with additional information.
Is some personal data specially protected?
Yes. Stricter requirements apply to certain personal data under Art. 9 GDPR. This includes, for example, health data, biometric data used to uniquely identify a person and information about religious or political beliefs.
This data is referred to as special categories of personal data and is subject to additional requirements for its processing.
Practical example: when is customer data personal?
An online retailer stores, for an order, the customer's name and address, their email address, a customer number, the products ordered and the related payment information.
In this case, the name and address are not the only personal data. The customer number, order history and payment information can also be attributed to a specific person and are therefore personal.
If the company merely removes the name from the record, the remaining information is not automatically anonymous. If the customer can still be identified through their customer number, for example, the link to the person remains.
Which legal provisions apply to personal data?
The following GDPR provisions are particularly relevant to the concept of personal data and how it is handled:
- Art. 4(1) GDPR
- Defines personal data and determines when a natural person is considered identifiable.
- Art. 4(2) GDPR
- Defines which operations constitute processing of personal data.
- Art. 5 GDPR
- Sets out the core principles for processing personal data, including purpose limitation and data minimisation.
- Art. 6 GDPR
- Governs the conditions under which processing of personal data is lawful.
- Art. 9 GDPR
- Contains specific requirements for processing special categories of personal data.
The CJEU judgment of 19 October 2016 (C-582/14 – Breyer) is also relevant to the question of when information can be attributed to a person. In that case, the Court considered whether dynamic IP addresses are personal data.
Frequently asked questions about personal data
Is an IP address personal data?
An IP address can be personal data. According to the case law of the CJEU, even a dynamic IP address can be personal data if there are legal means of identifying the person concerned with the help of additional information.
Is company data personal data?
Data relating purely to a legal person is generally not personal data within the meaning of the GDPR. However, if the information can also be attributed to a natural person, it may relate to that person.
May personal data be processed without consent?
Yes. Consent is only one of several possible legal bases for processing personal data. Art. 6 GDPR provides for other legal bases, for example where processing is necessary for the performance of a contract or is based on legitimate interests and the other statutory requirements are met.
What is the difference between anonymised and pseudonymised data?
With effectively anonymised data, the person concerned cannot or can no longer be identified. With pseudonymised data, by contrast, the link to the person can be restored with additional information that is kept separately. Pseudonymised data therefore generally remains personal data.
How long may personal data be stored?
There is no single retention period for personal data. How long it may be stored depends in particular on the purpose of the processing and on statutory retention obligations. Once the data is no longer needed for the original purpose and there is no other legal basis for storing it further, it must in principle be erased.