Personal Data
Personal data is any information that relates to an identified or identifiable living person. This can include obvious identifiers such as a name or identification number, but also other pieces of information that, alone or combined with other data, could point to a specific individual. The precise legal meaning and its scope depend on the applicable law and jurisdiction, so readers should verify against the current official text.
Under the EU GDPR and the UK GDPR, 'personal data' is defined as any information relating to an identified or identifiable natural person, referred to as the 'data subject'. Identifiability may be direct (for example, via a name or an identification number) or indirect (via one or more factors that, alone or in combination with other information, single out an individual). The concept applies to living individuals and is central to data protection obligations; it is distinct from, though it may overlap with, defined categories of 'special category' or sensitive data, which are subject to additional conditions under the same regimes. Scope, thresholds for identifiability, and treatment of pseudonymised or anonymised data are matters of interpretation that continue to evolve and differ across jurisdictions (for example between the EU, the UK, and the United States), so application to specific facts requires professional judgment and verification against the latest authoritative text.
Why it matters
Personal data is the foundational concept on which most data protection regimes are built. Whether an obligation applies at all typically turns on whether the information in question qualifies as personal data relating to an identified or identifiable living individual. If it does, a body of rules — covering lawful basis, transparency, security, and individual rights — may be triggered; if it does not, those obligations generally fall away. For this reason, the classification exercise is often the first and most consequential step in any compliance assessment.
The stakes are heightened by the breadth of the concept. Under the EU GDPR and the UK GDPR, identifiability can be indirect, meaning that data which seems innocuous in isolation may become personal data when it can be combined with other information to single out an individual. This means organizations cannot safely assume that stripping obvious identifiers such as names removes information from scope. Misclassifying personal data as non-personal can leave processing activities without the safeguards the law requires and expose an organization to regulatory and contractual consequences.
The boundaries of the concept remain contested in practice. The treatment of pseudonymised and anonymised data, and the threshold at which information becomes 'identifiable', are matters of ongoing interpretation that differ across jurisdictions. Because these questions can determine whether a regime applies at all, they should be assessed against the latest authoritative text and, where the facts are complex, with professional judgment.
Who it's relevant to
Inside Personal Data
Common questions
Answers to the questions practitioners most commonly ask about Personal Data.

