Get Free Downloads
Start your GDPR today in just a few clicks
Get Free Downloads
Start your GDPR today in just a few clicks

What Is GDPR Personal Data?

by Adam Brogden
in Blog

28-Feb-2019 10:49

This might sound like a simple question but the answer is fundamentally important to how your address your GDPR. The GDPR and ICO provide useful advice on this:

  1. Personal data is information that relates to an identified or identifiable individual.

  2. What identifies an individual could be as simple as a name or a number or could include other identifiers such as an IP address or a cookie identifier, or other factors.

  3. If it is possible to identify an individual directly from the information you are processing, then that information may be personal data.

  4. If you cannot directly identify an individual from that information, then you need to consider whether the individual is still identifiable. You should take into account the information you are processing together with all the means reasonably likely to be used by either you or any other person to identify that individual.

  5. Even if an individual is identified or identifiable, directly or indirectly, from the data you are processing, it is not personal data unless it ‘relates to’ the individual.

  6. When considering whether information ‘relates to’ an individual, you need to take into account a range of factors, including the content of the information, the purpose or purposes for which you are processing it and the likely impact or effect of that processing on the individual.

  7. It is possible that the same information is personal data for one controller’s purposes but is not personal data for the purposes of another controller.

  8. Information which has had identifiers removed or replaced in order to pseudonymise the data is still personal data for the purposes of GDPR.

  9. Information which is truly anonymous is not covered by the GDPR.

  10. If information that seems to relate to a particular individual is inaccurate (ie it is factually incorrect or is about a different individual), the information is still personal data, as it relates to that individual.

Hopefully this will help you determine whether you process personal data, to be honest, most companies do, although all the information you process will not necessarily count as personal information. Bear in mind the key phrases, ‘identifiable’, ‘relates to’, and ‘purpose for which you are processing’. These might help you determine that you are not actually processing personal data and make your life a little easier.

Confused? Not sure? Call us!

Good luck all.