Personal Data
In short: Any information relating to an identified or identifiable natural person — a core concept of the GDPR, since it defines what is actually protected.
In more detail: The term is deliberately broad: name, email address, IP address, location data, but also indirectly identifying features count, as soon as a specific person can be derived from them (possibly in combination with other data). A subcategory is especially sensitive data (e.g. health data, religious beliefs), for which stricter requirements apply. Anonymised data (from which no conclusions about a person are possible any more) does NOT fall under the GDPR — pseudonymised data (where re-identification with additional knowledge remains possible), on the other hand, does.
In Depth
The distinction between the different “processing states” of data is central to the GDPR, because it determines which rules apply at all:
Personal data - person directly identifiable or identifiable with
reasonable effort (name, email, IP address,
device identifier)
-> GDPR applies in full
Pseudonymised - direct identifiers replaced by placeholders, but
re-identification still possible with an
additional (separately kept) key
-> GDPR still applies, but counts as a protective
measure
Anonymised - identifying the person is practically impossible
even with additional knowledge
-> GDPR no longer applies
In practice, the line between “personal” and “anonymised” is often harder to draw than it first appears: even seemingly harmless data sets (e.g. location data over time, or a combination of postcode, date of birth and gender) can, combined with other available information, make a person uniquely re-identifiable — genuinely robust anonymisation is therefore technically more demanding than simply removing the name from a data set.
A practical example of the distinction: an IP address alone already counts as personal data, because an internet provider (with the appropriate legal basis) could theoretically match it to a specific person — even if the operator of the visited website itself cannot make that match.
Relative personal reference
This IP address discussion illustrates a fundamental GDPR concept: “relative personal reference”. Whether information counts as personal data doesn’t depend only on the information itself, but on whether ANYONE (not necessarily the current processor) could establish a link to a person with reasonable effort. The European Court of Justice ruled on this in the 2016 “Breyer” judgment that even a dynamic IP address can be personal data for a website operator if the internet provider (as a third party) has legal means to determine the identity if needed — even if the website operator itself doesn’t have those means.
Special categories: stricter protection for sensitive data
Art. 9 GDPR defines a specially protected subcategory of personal data (in everyday language often called “sensitive” or “especially sensitive” data, see Sensitive data): health data, genetic and biometric data, sexual orientation, political opinions, religious/philosophical beliefs, trade union membership and ethnic origin. Processing these categories is fundamentally PROHIBITED unless one of the narrowly defined exceptions applies (e.g. explicit consent, medical necessity) — a considerably stricter standard than for “ordinary” personal data such as name or email address.
Practical challenges in classification
In software development, correctly classifying data fields is often more complex than expected: a seemingly harmless free-text field (e.g. “notes about the customer”) can suddenly contain especially sensitive data through what’s actually entered (e.g. if a support employee notes “customer mentioned a health condition”) — systems that structurally expect only “normal” personal data then in effect process such free-text content without the additional protective measures that would actually be required. Data protection impact assessments (Art. 35 GDPR) are mandatory for high-risk processing precisely for this reason — they force such risks to be systematically thought through BEFORE a system goes into productive use.
See also: GDPR, Sensitive data