Personal data is any information relating to an identified or identifiable natural person, known as the data subject. Under data protection regimes such as the GDPR, identifiability can be direct (a name or identification number) or indirect (factors specific to a person’s physical, economic, cultural or social identity). Special categories such as health, biometric or political data attract heightened protection. The concept anchors most privacy and data governance obligations, determining when processing rules, consent requirements and individual rights apply.

Overview

  • The definition is deliberately broad: identifiers, online identifiers, location data and factors specific to a person’s identity all count.
  • Special categories of personal data (health, biometric, genetic, political, religious) are subject to stricter conditions for processing.
  • Whether information is personal data determines whether data protection law applies at all, making the concept a legal threshold rather than a technical one.

Key aspects

  • Identifiability: direct or indirect linkage to a natural person, assessed against means reasonably likely to be used.
  • Data subject rights: access, rectification, erasure (Right to be Forgotten), portability and objection.
  • Lawful basis: processing requires a valid ground such as consent, contract or legitimate interest.
  • Risk states: a Data Breach involving personal data triggers notification duties.

Mechanisms

Applications

  • Regulatory compliance programmes and privacy impact assessments.
  • Consent and preference platforms for marketing and analytics.
  • Self-sovereign and decentralised identity systems built on Identity and Data Sovereignty.
  • Surveillance governance and oversight of monitoring practices.

Provenance