Personal data is any information relating to an identified or identifiable natural person, known as the data subject. Under data protection regimes such as the GDPR, identifiability can be direct (a name or identification number) or indirect (factors specific to a person’s physical, economic, cultural or social identity). Special categories such as health, biometric or political data attract heightened protection. The concept anchors most privacy and data governance obligations, determining when processing rules, consent requirements and individual rights apply.
- Personal data is any information relating to an identified or identifiable natural person. It is the foundational subject of Data Governance, Data Protection, Privacy and the GDPR, and connects to Identity and Data Sovereignty.
Overview
- The definition is deliberately broad: identifiers, online identifiers, location data and factors specific to a person’s identity all count.
- Special categories of personal data (health, biometric, genetic, political, religious) are subject to stricter conditions for processing.
- Whether information is personal data determines whether data protection law applies at all, making the concept a legal threshold rather than a technical one.
Key aspects
- Identifiability: direct or indirect linkage to a natural person, assessed against means reasonably likely to be used.
- Data subject rights: access, rectification, erasure (Right to be Forgotten), portability and objection.
- Lawful basis: processing requires a valid ground such as consent, contract or legitimate interest.
- Risk states: a Data Breach involving personal data triggers notification duties.
Mechanisms
- Consent Management records and governs the lawful basis for processing.
- Pseudonymisation reduces linkability while keeping data within scope; Anonymisation removes data from scope entirely.
- Personal Data Store architectures give individuals custody over their own data.
Applications
- Regulatory compliance programmes and privacy impact assessments.
- Consent and preference platforms for marketing and analytics.
- Self-sovereign and decentralised identity systems built on Identity and Data Sovereignty.
- Surveillance governance and oversight of monitoring practices.