Glossary · Privacy & regulation
Personal data
Personal data, under GDPR, is any information relating to an identified or identifiable natural person — a deliberately broad definition covering not just names and IDs but anything that can be linked back to someone, directly or in combination with other data.
GDPR Article 4(1) defines an identifiable person as one who can be identified, directly or indirectly, by reference to an identifier — a name, ID number, location data, an online identifier, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity. That "indirectly" and "in combination" language is what makes the definition wide: an IP address, a device fingerprint, or a hashed identifier can all be personal data if they can realistically be linked to a person, even if the organization holding them doesn’t itself know the name behind it.
A narrower subcategory, "special category" or sensitive personal data, covers information revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data used for identification, health data, or data about sex life or sexual orientation — processing these requires a higher bar than ordinary personal data, generally explicit consent or another narrowly defined legal basis.
Techniques like pseudonymization reduce risk but don’t remove data from GDPR’s scope, since the data remains re-identifiable with additional information held elsewhere; only true anonymization — where re-identification is no longer reasonably possible — takes data outside the definition entirely.