Can your organisation confidently identify every piece of personal data it collects, stores, and processes? If the answer is uncertain, the risk of non-compliance is already present. Personal data under GDPR carries a broad and specific definition that extends far beyond names and email addresses. Misunderstanding this definition is one of the most common reasons businesses face regulatory action.
The General Data Protection Regulation (GDPR), enforced since May 2018, sets strict rules around how organisations handle information that relates to identifiable individuals. Whether you operate as a data controller, processor, or both, the regulation applies to every stage of the data lifecycle. From the moment data is collected to when it is erased, businesses must follow clear principles and legal obligations.
This blog covers the official definition of personal data under GDPR, the categories it includes, the rights of data subjects, lawful bases for processing, and the penalties for getting it wrong. Continue reading!
Personal data under the General Data Protection Regulation (GDPR) is defined broadly to cover any information that can identify a living individual, either directly or indirectly.
Many organisations treat GDPR training as a one-off onboarding task. That approach fails the moment regulations shift, or new data processing activities begin. Effective GDPR staff eTraining is ongoing, role-specific, and built around real scenarios employees encounter in their day-to-day work.
It covers areas such as lawful data processing, recognising data breaches, understanding data subject rights, and knowing when to escalate issues. The goal is not just awareness but competence.
Many organisations assume personal data only includes obvious identifiers like full names, email addresses, or phone numbers. Under GDPR, the scope is much wider. Vehicle registration numbers, employee ID codes, CCTV footage, and even pseudonymised data can qualify as personal data if re-identification is possible.
This broad scope means that almost every digital interaction a business has with individuals involves personal data. Website analytics, CRM records, support tickets, and HR databases all fall within the regulation. Recognising this early prevents gaps in compliance programmes.
Truly anonymous data falls outside the GDPR. However, the bar for anonymisation is high. If there is any reasonable possibility of re-identifying an individual, the data remains personal. Pseudonymised data, where identifiers are replaced with codes, is still classified as personal data because the original identity can be restored using additional information.
The GDPR distinguishes between general personal data and special category data, each carrying different levels of protection and processing rules.
General personal data includes any information relating to an identifiable individual. This covers names, postal addresses, email addresses, telephone numbers, dates of birth, national insurance numbers, passport numbers, financial account details, IP addresses, cookie identifiers, location data, and photographs. Even indirect identifiers like customer account numbers or employee reference codes qualify under this category.
Any data that could lead to the identification of a specific person, alone or in combination, is treated as personal data under GDPR. Organisations that handle sensitive personal information must apply additional safeguards to protect individuals from harm.
Special category data requires stricter handling because of its sensitive nature. Article 9 of the GDPR identifies these categories explicitly. They include data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership. Genetic data, biometric data used for identification, health data, and information about a person’s sex life or sexual orientation also fall under this classification.
Processing special category data is prohibited by default unless a specific condition under Article 9(2) applies. This means businesses must have both a lawful basis under Article 6 and a separate condition under Article 9 before processing this type of information.
Article 10 of the GDPR addresses personal data relating to criminal convictions and offences. This data can only be processed under the control of an official authority or when authorised by Union or Member State law. Employers conducting background checks or organisations in regulated sectors must ensure they have the correct legal authority before handling this information.
Article 5 of the GDPR establishes seven binding principles that govern how personal data must be handled throughout its lifecycle.
Every processing activity must have a valid legal basis. It must be fair, meaning it should not cause unnecessary harm to the data subject. Transparency requires that individuals are told clearly how their data will be used, who will access it, and for what purpose. Privacy notices and disclosure statements play a critical role here.
Personal data must only be collected for specified, explicit, and legitimate purposes. It cannot be further processed in a way that contradicts those purposes. Data minimisation means collecting only what is strictly necessary. An organisation running a newsletter subscription does not need a subscriber’s date of birth or home address. Understanding the opt-in vs opt-out distinction is essential when designing data collection forms that align with these principles.
Personal data must be accurate and kept up to date. Inaccurate records should be corrected or erased without delay. Storage limitation prevents organisations from keeping personal data longer than needed. Integrity and confidentiality require appropriate security measures, including encryption and access controls. Finally, the accountability principle makes the data controller responsible for demonstrating compliance with all these requirements.
Article 6 of the GDPR sets out six lawful bases that organisations must rely on before processing any personal data.
Consent must be freely given, specific, informed, and unambiguous. It requires a clear affirmative action from the individual. Pre-ticked boxes, silence, or inactivity do not count as valid consent. Organisations must also make it as easy to withdraw consent as it is to give it. Building proper user consent mechanisms is fundamental to lawful data processing.
Processing is lawful when it is necessary to perform a contract with the data subject, such as delivering a purchased product. It is also lawful when required to comply with a legal obligation, like retaining employee tax records. The vital interests basis applies in life-or-death situations, such as sharing a patient’s medical data during a medical emergency.
Public task applies when processing is necessary to carry out a function in the public interest or under official authority. Legitimate interests are the most flexible basis but require a balancing test. The organisation must weigh its interests against the rights and freedoms of the individual. If the individual’s rights outweigh the organisation’s interest, this basis cannot be used.
The GDPR grants individuals a set of enforceable rights over their personal data, giving them control over how their information is used.
Data subjects can request confirmation of whether their data is being processed and obtain a copy of that data. This is known as a Subject Access Request (SAR). Organisations must respond within one calendar month. The right to rectification allows individuals to have inaccurate personal data corrected and incomplete data completed without unnecessary delay.
Often referred to as the “right to be forgotten,” the right to erasure allows individuals to request deletion of their personal data in certain circumstances. These include situations where the data is no longer necessary, consent has been withdrawn, or the data was processed unlawfully. The right to restrict processing allows individuals to limit how their data is used while a dispute or objection is being resolved.
Data portability gives individuals the right to receive their personal data in a structured, commonly used, machine-readable format and transfer it to another controller. The right to object applies to processing based on legitimate interests or a public task, including direct marketing. Individuals also have the right not to be subject to decisions based solely on automated processing, including profiling, where those decisions produce legal or similarly significant effects.
The GDPR assigns clear responsibilities to both controllers and processors, ensuring accountability throughout the data processing chain.
Data controllers determine the purposes and means of processing personal data. They bear primary responsibility for compliance. Controllers must maintain records of processing activities, conduct Data Protection Impact Assessments (DPIAs) for high-risk processing, appoint a Data Protection Officer (DPO) where required, and implement appropriate technical and organisational measures. Businesses operating in the software sector should review how GDPR for SaaS applies to their specific data handling practices.
Data processors act on the instructions of controllers. Under the GDPR, processors have direct compliance obligations. They must process data only as instructed, implement adequate security measures, assist controllers with data subject requests and breach notifications, and maintain their own records of processing activities. Processors can face direct enforcement and fines for non-compliance.
Article 28 requires a written contract between controllers and processors. This agreement must specify the subject matter, duration, nature, and purpose of processing. It must also outline the types of personal data involved and the obligations of both parties. Without a valid data processing agreement, the arrangement itself becomes a compliance risk.
The GDPR enforces a tiered penalty structure that reflects the severity of the violation and its impact on individuals.
The most serious violations attract fines of up to 20 million euros or 4% of global annual turnover, whichever is higher. These apply to breaches of core processing principles, conditions for consent, data subject rights, and rules around international data transfers. Supervisory authorities assess the nature, gravity, duration of the infringement, and whether the controller or processor acted intentionally or negligently.
Less severe violations carry fines of up to 10 million euros or 2% of global annual turnover. These cover failures related to record-keeping obligations, data protection by design and by default, DPIA requirements, and data breach notification duties. Even lower-tier fines represent significant financial exposure for most organisations.
Regulatory action is not limited to fines. Supervisory authorities can issue warnings, reprimands, and orders to comply. They can impose temporary or permanent bans on data processing, which can effectively halt business operations. Reputational damage from enforcement action often carries greater long-term costs than the fine itself. Investing in GDPR staff training is one of the most effective ways to reduce the risk of regulatory penalties.
Protecting personal data requires a combination of technical measures, organisational policies, and ongoing governance efforts.
Organisations must establish clear data protection policies and ensure staff are trained on GDPR requirements. Regular audits of data processing activities help identify gaps in compliance.
Maintaining an up-to-date Record of Processing Activities (ROPA) is a legal requirement under Article 30. Appointing a Data Protection Officer, where required, ensures dedicated oversight of compliance obligations.
Article 25 of the GDPR mandates that data protection must be built into systems and processes from the outset. This means organisations should embed privacy considerations into product development, system architecture, and business operations. By default, only the minimum amount of personal data necessary for each specific purpose should be processed. A cookie consent management platform helps embed these principles into website data collection practices.
Transferring personal data outside the European Economic Area (EEA) requires additional safeguards to maintain the level of protection guaranteed by the GDPR.
The European Commission can determine that a non-EEA country provides an adequate level of data protection. When an adequacy decision is in place, personal data can flow freely to that country without additional conditions. The Commission periodically reviews these decisions to ensure the standard is maintained.
In the absence of an adequacy decision, organisations can rely on Standard Contractual Clauses (SCCs) approved by the European Commission. These are pre-approved contractual terms that impose data protection obligations on the data importer. Binding Corporate Rules (BCRs) are another option, primarily used by multinational groups to govern intra-group transfers of personal data across borders.
Following the Schrems II ruling, organisations must conduct Transfer Impact Assessments (TIAs) to evaluate whether the laws of the recipient country provide adequate protection. If the assessment reveals deficiencies, supplementary measures such as encryption, data localisation, or contractual commitments may be needed. Organisations using a consent-based marketing approach should ensure their international data flows comply with these transfer rules.
Personal data under GDPR covers far more than names and email addresses. It spans every piece of information that can identify a living individual, directly or indirectly. Organisations that understand the full scope of this definition, apply the right lawful bases, respect data subject rights, and invest in proper safeguards will reduce regulatory risk and strengthen the trust individuals place in their brand.
Misclassifying personal data can expose your business to unnecessary compliance risks. Seers helps organisations simplify GDPR compliance with automated consent management, continuous compliance monitoring, and tools designed to support responsible data handling across your digital ecosystem.
START FREE TODAYAn IP address is considered personal data under GDPR when it can be used to identify an individual, either on its own or in combination with other data. Dynamic IP addresses assigned by internet service providers can still qualify as personal data if the provider holds additional information that allows identification. Organisations collecting IP addresses through website analytics or server logs should treat them as personal data and apply appropriate processing safeguards.
Processing personal data without a valid lawful basis under Article 6 is a direct violation of the GDPR. Supervisory authorities can impose fines of up to 20 million euros or 4% of global annual turnover. Beyond fines, regulators can order the organisation to stop processing entirely, which can disrupt operations and damage the relationship with customers and partners. Identifying the correct lawful basis before processing begins is a fundamental compliance requirement.
Pseudonymised data replaces direct identifiers with artificial codes or tokens, but the original identity can still be restored using separately held information. This means pseudonymised data remains personal data under GDPR and is subject to all its requirements. Anonymous data, on the other hand, cannot be linked back to an individual by any reasonable means. Only truly anonymous data falls outside the scope of the regulation.
Employee records are personal data under GDPR. This includes names, addresses, salary details, performance reviews, health records, absence data, and disciplinary information. Employers must have a valid lawful basis for processing each type of employee data, provide clear privacy notices, and respond to data subject requests from employees within the required timeframe. HR departments should maintain detailed records of processing activities related to staff data.
Marketing activities that involve personal data require a valid lawful basis, typically consent or legitimate interests. When relying on consent, it must be freely given, specific, and informed. Legitimate interests can be used for certain marketing purposes, but only after conducting a balancing test that confirms the individual’s rights are not overridden. Direct marketing by electronic means, such as email, usually requires explicit prior consent under the ePrivacy Directive.
A Data Protection Impact Assessment (DPIA) is a formal process for evaluating the risks that a data processing activity poses to individuals. It is required under Article 35 of the GDPR whenever processing is likely to result in a high risk to the rights and freedoms of data subjects. This includes large-scale processing of special category data, systematic monitoring of public areas, and automated decision-making with legal effects. The DPIA must describe the processing, assess necessity and proportionality, and outline measures to mitigate identified risks.
The GDPR applies specifically to the personal data of living individuals. Recital 27 of the regulation states that it does not cover the personal data of deceased persons. However, individual EU Member States have the authority to provide rules regarding the processing of personal data of deceased persons under their own national laws. Organisations operating across multiple jurisdictions should check local requirements to ensure they handle such data in accordance with applicable national rules.
A Data Protection Officer (DPO) is responsible for monitoring GDPR compliance within an organisation, advising on data protection obligations, and acting as a contact point for supervisory authorities. Under Article 37, appointing a DPO is mandatory for public authorities, organisations that carry out large-scale systematic monitoring, and those processing special category data on a large scale. The DPO must operate independently and report directly to the highest level of management.
The GDPR does not prescribe specific retention periods. Instead, Article 5(1)(e) requires that personal data be kept only for as long as necessary for the purpose it was collected. Organisations must define and document their own retention periods based on the purpose of processing and any legal requirements that mandate longer storage. Once the retention period expires, the data must be securely erased or anonymised. A clear retention policy is essential for demonstrating compliance.
A data controller determines why and how personal data is processed, while a data processor handles data on behalf of the controller. For example, a company collecting customer orders is the controller, and the cloud hosting provider storing that data is the processor. Both have direct obligations under the GDPR, including maintaining security measures and supporting data subject rights. A written data processing agreement under Article 28 must be in place between them.
Rimsha ZafarRimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.
Take our Free Cookie Audit and find out
Join 50,000+ websites using Seers.Ai to turn compliance into trust, insights, & measurable business growth.