Skip to main content
green back ground with gradient accents. The words "Your AI Agents Are Making Decisions. Can Your Security Team Explain Them?" And a "Download the Guide" button.
Category: Data Types & Classification

Personal Data

Also known as: Personal Information
Simply put

Personal data is any information that relates to an identified or identifiable living person. This can include obvious identifiers such as a name or identification number, but also other pieces of information that, alone or combined with other data, could point to a specific individual. The precise legal meaning and its scope depend on the applicable law and jurisdiction, so readers should verify against the current official text.

Formal definition

Under the EU GDPR and the UK GDPR, 'personal data' is defined as any information relating to an identified or identifiable natural person, referred to as the 'data subject'. Identifiability may be direct (for example, via a name or an identification number) or indirect (via one or more factors that, alone or in combination with other information, single out an individual). The concept applies to living individuals and is central to data protection obligations; it is distinct from, though it may overlap with, defined categories of 'special category' or sensitive data, which are subject to additional conditions under the same regimes. Scope, thresholds for identifiability, and treatment of pseudonymised or anonymised data are matters of interpretation that continue to evolve and differ across jurisdictions (for example between the EU, the UK, and the United States), so application to specific facts requires professional judgment and verification against the latest authoritative text.

Why it matters

Personal data is the foundational concept on which most data protection regimes are built. Whether an obligation applies at all typically turns on whether the information in question qualifies as personal data relating to an identified or identifiable living individual. If it does, a body of rules — covering lawful basis, transparency, security, and individual rights — may be triggered; if it does not, those obligations generally fall away. For this reason, the classification exercise is often the first and most consequential step in any compliance assessment.

The stakes are heightened by the breadth of the concept. Under the EU GDPR and the UK GDPR, identifiability can be indirect, meaning that data which seems innocuous in isolation may become personal data when it can be combined with other information to single out an individual. This means organizations cannot safely assume that stripping obvious identifiers such as names removes information from scope. Misclassifying personal data as non-personal can leave processing activities without the safeguards the law requires and expose an organization to regulatory and contractual consequences.

The boundaries of the concept remain contested in practice. The treatment of pseudonymised and anonymised data, and the threshold at which information becomes 'identifiable', are matters of ongoing interpretation that differ across jurisdictions. Because these questions can determine whether a regime applies at all, they should be assessed against the latest authoritative text and, where the facts are complex, with professional judgment.

Who it's relevant to

Data Protection Officers and Privacy Specialists
Determining whether information constitutes personal data is typically the starting point for assessing whether data protection obligations apply. DPOs and privacy teams rely on this classification to scope processing activities, distinguish ordinary personal data from special category data, and evaluate whether pseudonymisation or anonymisation measures affect the regime's application. Because identifiability can be indirect, careful analysis is generally required rather than reliance on the presence or absence of obvious identifiers.
Legal Counsel
Counsel advising on data protection matters must interpret the scope of 'personal data' against the applicable regime, which differs across the EU, the UK, and the United States. The threshold for identifiability and the treatment of pseudonymised or anonymised data remain matters of evolving interpretation, so counsel should assess specific facts against the current authoritative text rather than treating any single formulation as universal.
Information Security Professionals
Whether a dataset qualifies as personal data often shapes the security expectations that attach to it, since data protection obligations under the EU and UK GDPR flow from that classification. Security teams should be aware that data which appears de-identified may still be personal data where individuals remain identifiable through combination with other information, which is relevant to how such data is protected and handled.
Auditors and Compliance Officers
Assessing an organization's data processing against data protection requirements depends on correctly identifying which information is personal data and which is special category or sensitive data attracting additional conditions. Auditors and compliance officers should note that classification is fact-specific and jurisdiction-dependent, and that findings should be tied to the definitions in the applicable current regime rather than a generic notion of personal information.

Inside Personal Data

Identifiers
Data that directly identifies a natural person, such as a name, identification number, or an online identifier. These allow a person to be singled out without further information.
Indirect or combinable data
Information that does not identify a person on its own but can do so when combined with other data reasonably likely to be used, such as location data or device identifiers. Identifiability is assessed by reference to the means reasonably likely to be used.
Factors specific to identity
Attributes relating to the physical, physiological, genetic, mental, economic, cultural, or social identity of a natural person that may contribute to identifiability.
Natural person scope
Under the GDPR, personal data relates only to living, identified or identifiable natural persons. It generally does not cover legal persons such as companies, though some jurisdictions treat certain business contact details differently.
Special categories
A distinct subset of personal data revealing, for example, health, biometric, genetic, racial or ethnic origin, or political or religious information, which the GDPR subjects to heightened protection. This is a narrower classification within, not separate from, personal data.

Common questions

Answers to the questions practitioners most commonly ask about Personal Data.

Is personal data the same as personally identifiable information (PII)?
Not exactly. "Personal data" is the term used under the GDPR and generally refers to any information relating to an identified or identifiable natural person. "Personally identifiable information" (PII) is a term more common in US contexts and various frameworks, and its scope can be narrower, often focusing on identifiers that directly single out an individual. The two concepts overlap substantially but are not interchangeable, and the precise boundaries depend on the specific law, framework, or jurisdiction involved. Readers should confirm which definition applies to their situation against the relevant authoritative text.
Does data stop being personal data once it has been anonymized or pseudonymized?
These two are treated differently. Data that is truly anonymized—such that the individual can no longer be identified, directly or indirectly, by any reasonably likely means—generally falls outside the definition of personal data under regimes like the GDPR. Pseudonymized data, however, is generally still personal data, because the individual can be re-identified using additional information kept separately. Whether a given dataset qualifies as genuinely anonymized is a fact-specific assessment that depends on the techniques used and the risk of re-identification, and interpretations continue to evolve. Verify against current guidance before treating data as out of scope.
How do we determine whether a specific data element counts as personal data?
The general test is whether the information relates to a natural person who is identified or identifiable, directly or indirectly, taking account of all means reasonably likely to be used to identify them. This means the assessment considers not only the data element in isolation but also other information that could be combined with it. Because identifiability is context-dependent, the same element may be personal data in one setting and not in another. This is a qualitative assessment requiring professional judgment, and organizations should document their reasoning against the definitions in the applicable law.
Does the concept of personal data cover special or sensitive categories differently?
Many regimes distinguish ordinary personal data from categories that warrant heightened protection—for example, data revealing health, biometric identifiers used for identification, or other categories designated as sensitive under the applicable law. Where such categories apply, additional conditions or restrictions generally attach to their processing. The specific categories and the obligations that follow vary by jurisdiction and framework, so identifying whether data falls into a special category, and what that triggers, should be checked against the current official text for the relevant regime.
When mapping our data, how should we treat identifiers like IP addresses, cookie IDs, or device identifiers?
Such online identifiers may qualify as personal data where they can be linked, directly or indirectly, to an identifiable individual, particularly when combined with other available information. Whether a given identifier is personal data in a specific context is a fact-specific determination rather than a fixed rule, and treatment can differ across jurisdictions. As a practical matter, organizations often assess these identifiers on a risk basis and document their conclusions. Verify the applicable standard for your jurisdiction, as interpretations in this area continue to develop.
How does the scope of personal data affect which obligations apply to our organization?
Identifying what constitutes personal data is typically the starting point for scoping compliance obligations, because most data protection requirements are triggered by the processing of personal data. Whether specific obligations apply, however, generally also depends on factors such as the applicable jurisdiction, the role the organization plays, the category of data, and the nature and risk of the processing. Determining the correct scope is a fact-specific exercise, and this entry defines the concept rather than advising on any particular situation; application to specific circumstances requires professional judgment.

Common misconceptions

Anonymized and pseudonymized data are the same and both fall outside the rules.
These are distinct. Pseudonymized data can be re-attributed to a person using additional information and generally remains personal data subject to the GDPR. Data is treated as anonymized only where re-identification is not reasonably possible; truly anonymized data falls outside the regime, but the threshold is high and assessment is fact-specific.
Only obviously identifying details like names count as personal data.
Identifiability can arise indirectly. Online identifiers, location data, and combinations of otherwise non-identifying attributes may constitute personal data where a person can be singled out by means reasonably likely to be used.
The GDPR definition of personal data applies universally across all jurisdictions.
The concept described here reflects the EU GDPR, which governs processing within its territorial and extraterritorial scope. Other jurisdictions, such as the United States and the United Kingdom, use their own definitions and terminology that may differ in breadth and application, so the applicable regime must be identified for the specific context.

Best practices

Assess identifiability in context, considering the means reasonably likely to be used to single out or re-identify an individual, rather than relying solely on whether a name is present.
Distinguish pseudonymized data from anonymized data in your records and data flows, and treat pseudonymized data as personal data unless a robust assessment supports genuine anonymization.
Identify and flag special category data separately, applying the heightened conditions that generally attach to such data before processing begins.
Confirm which jurisdiction's definition applies to each processing activity, as EU, UK, US, and other regimes differ in scope and terminology, and note where extraterritorial reach may apply.
Maintain an inventory mapping data elements to whether they constitute personal data, indirect identifiers, or special categories, and review it as datasets and combinations change.
Verify classifications against the current authoritative text of the applicable regulation and seek professional judgment for borderline or evolving cases, since interpretations and enforcement practice continue to develop.
Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.