What Counts as Personal Data Under GDPR, and the Six Things People Get Wrong
GDPR uses one sentence to define personal data. Article 4(1) calls it "any information relating to an identified or identifiable natural person". Everything else follows from that sentence, so it helps to read it slowly. Two words do the work. Identified means you already know who it is. Identifiable means you could work it out.
Things that count
The European Commission gives a plain list: a name and surname, a home address, an email address, an IP address, an identification card number, a cookie ID, and the advertising identifier of your phone. Video recording from CCTV is on the list too.
Things that do not count
A company registration number is not personal data. A generic mailbox such as info@company.com is not personal data. Truly anonymised information is outside GDPR, and only when the anonymisation cannot be reversed.
The six mix ups
- Assuming work emails are exempt. A named address like sarah.jones@company.com identifies a person, so it counts.
- Treating coded records as anonymous. If you hold the key, the data is still personal.
- Forgetting deceased individuals. GDPR does not protect their data, though other duties may.
- Missing the household exemption. Purely personal activity at home with no professional link sits outside the rules.
- Lumping sensitive data in with the rest. Health, biometric and genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life and sexual orientation are special category data under Article 9 and need a higher bar.
- Skipping the lawful basis. Consent is one of six options in Article 6, alongside contract, legal obligation, vital interests, public task and legitimate interests.
The longer version of this, with the seven processing principles and the full set of data subject rights, is set out in this guide to personal data under GDPR.
Where classification quietly goes wrong
Most breaches of this kind are not decisions. They are staff who never learned the difference between a marketing list and a health record. GDPR staff training from Seers AI fixes that in an afternoon, role by role, so the person handling the data knows what they are holding.
Then let the machine do the watching. Seers AI keeps a live map of the identifiers your site and apps collect and checks them against GDPR requirements as they change. Spreadsheets go stale. An AI that rescans every day does not.

Comments
Post a Comment