Personal Data
Personal data is any information that relates to a specific, identifiable person, whether it identifies them directly (like a name or email address) or indirectly (like an IP address that can be linked back to an individual). The exact scope of what counts as personal data depends on the applicable law or jurisdiction, so definitions can vary in practice.
Personal data is commonly defined as any information relating to an identified or identifiable natural person. Under the GDPR, it is framed as 'any information which is related to an identified or identifiable natural person,' and some formulations extend this to information that is 'linked or reasonably linkable' to such a person, thereby encompassing both direct identifiers (e.g., name, email address) and indirect identifiers (e.g., IP address) that permit identification when combined with other data. The precise boundaries are jurisdiction- and instrument-specific; terms such as 'personal information' and 'personally identifiable information' are frequently used interchangeably in practice but may carry distinct statutory meanings, so practitioners should verify the definition applicable to the governing legal framework rather than assume a single universal standard.
Why it matters
Personal data is the pivot on which most data protection and privacy obligations turn: whether a given piece of information counts as personal data typically determines whether a legal framework applies to its processing at all. Because the scope is defined by the applicable law rather than by a single universal standard, the same data element can trigger obligations in one jurisdiction and fall outside them in another. For organizations deploying AI systems trained on or making inferences about people, misclassifying data as non-personal can leave processing activities without the consent, transparency, or safeguarding controls the governing framework expects.
The distinction between direct and indirect identifiers is where practitioners most often err. Information such as an IP address may not name a person on its own, yet can become personal data when it is reasonably linkable to an individual in combination with other data. Under the GDPR, personal data is framed as any information relating to an identified or identifiable natural person, and some formulations extend the concept to information that is 'linked or reasonably linkable' to such a person. Treating only obvious identifiers like names and email addresses as in scope understates the breadth of the concept and can create compliance gaps.
The interchangeable use of 'personal data,' 'personal information,' and 'personally identifiable information' compounds the risk. These terms are frequently used as synonyms in practice but may carry distinct statutory meanings depending on the instrument. Assuming a single definition travels across borders or across regulatory regimes is a common source of error; the operative definition should be verified against the specific governing legal framework rather than inferred from general usage.
Who it's relevant to
Inside Personal Data
Common questions
Answers to the questions practitioners most commonly ask about Personal Data.