Laws · GDPR ·art-4-par-1 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
How it connects
Cited by
- CJEU: Access requests cannot be denied on privacy grounds without specific case analysis
- CJEU: Mandatory communications metadata retention only justified for fighting serious
- CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020
- Guidelines 01/2022 on data subject rights - Right of access
All 160
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
- Guidelines 8/2020 on the targeting of social media users
- Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement
- Guidelines 02/2021 on virtual voice assistants
- Guidelines 03/2021 on the application of Article 65(1)(a) GDPR
- Digital Omnibus - First Legal Analysis
- HvJ EU 9 januari 2025, C‑394/23 (Mousse).
- One-Stop-Shop case digest on right of access
- Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation
- EDPB contribution to the EBA public consultation on draft regulatory technical standards on AML/CFT
- Guidelines 3/2025 on the interplay between the DSA and the GDPR
- EDPB contribution to the EBA public consultation on draft regulatory technical standards on AML/CFT
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- JH v Policejní prezidium
- Opinion 2/2026 on the Proposal for a Directive amending Directives (EU) 2016/2341 and 2016/97 as regards the strengthening of the framework for occupational retirement provision
- Google Spain SL and Google Inc. v AEPD and Mario Costeja González
- Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein
- UI v Österreichische Post AG
- VB v Natsionalna agentsia za prihodite
- Österreichische Datenschutzbehörde v CRIF
- Rb. Den Haag - C/09/689833
- OLG Köln - 15 W 55/26
- EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- Can the GPC standard eliminate consent banners in the EU?
- AKI (Estonia) - No. 2.1-1/24/397-890-38
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- Generative AI and data protection
- DSB (Austria) - 2026-0.016.479
- DSB (Austria) - 2025-0.968.031
- Garante per la protezione dei dati personali (Italy) - 471/2026
- AEPD fines DIGI Telecom for issuing duplicate SIM to impersonator without consent
- NAIH: School grades are personal data; failure to provide access in eKRÉTA system
- APD/GBA (Belgium) - 11/2022
- Belgian DPA: Roularta Media Group violated cookie consent rules
- EDPS: European Parliament is sole controller for COVID testing website and failed
- GC T-496/13 McCullough v Cedefop — access to internal meeting minutes refused under Reg
- GC T-318/24: EPSO access logs and Article 17 access requests under Regulation 2018/1725
- OVG Saarlouis - 2 A 165/24
- Norwegian Supreme Court: Legelisten.no has Art. 6(1)(f) legal basis for doctor reviews
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- Guidelines 01/2023 on Article 37 Law Enforcement Directive
- EDPB Annual Report 2022
- EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space
- EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)
- Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (LED) under Article 62
- Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data
- EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)
- Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications
- Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak
- Opinion 14/2019 on the draft Standard Contractual Clauses submitted by the DK SA (Article 28(8) GDPR)
- Court upholds €50,000 fine on Sociálna poisťovňa for sending sensitive data by ordinary
- X v Russmedia Digital SRL and Inform Media Press SRL
- IP v Quirin Privatbank AG
- European Data Protection Supervisor v Single Resolution Board
- European Parliament v TC
- Thomas Bindl v European Commission
- MK v K GmbH
- Nemzeti Adatvédelmi és Információszabadság Hatóság v UC
- Agentsia po vpisvaniyata v OL
- A v Patērētāju tiesību aizsardzības centrs
- ND v DR
- C.G. v Bezirkshauptmannschaft Landeck
- Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V
- AT and BT v PS GbR and Others
- JU and SO v Scalable Capital GmbH
- GP v juris GmbH
- Endemol Shine Finland Oy
- IAB Europe v Gegevensbeschermingsautoriteit
- ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts
- Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija
- Gesamtverband Autoteile-Handel e.V. v Scania CV AB
- RK v Ministerstvo zdravotnictví
- Proceedings brought by J.M
- European Commission v Republic of Poland
- Criminal proceedings against V.S
- VS v Inspektor v Inspektorata kam Visshia sadeben savet
- OT v Vyriausioji tarnybinės etikos komisija
- Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband eV
- Robert Roos and Others v European Parliament
- SIA 'SS' v Valsts ieņēmumu dienests
- Mircom International Content Management & Consulting (M.I.C.M.) Limited v Telenet BVBA
- Land Nordrhein-Westfalen v D.-H. T. as liquidator of J & S Service UG
- Maria Psara and Others v European Parliament
- Republic of Malta v European Commission
- European Commission v Patrick Breyer
- Tele2 Sverige AB v Post- och telestyrelsen and Secretary of State for the Home Department v Tom Watson and Others
- Verein für Konsumenteninformation v Amazon EU Sàrl
- Athanassios Oikonomopoulos v European Commission
- Judgment of the Court (Grand Chamber), 16 October 2012.#European Commission v Republic of Austria.#Failure of a Member State to fulfil obligations – Directive 95/46/EC – Processing of personal data and free movement of such data – Protection of natural persons – Article 28(1) – National supervisory authority – Independence – Supervisory authority and the Federal Chancellery – Personal and organisational links.#Case C‑614/10.
- Patrick Kelly v National University of Ireland (University College, Dublin)
- The Bavarian Lager Co. Ltd v Commission of the European Communities
- Facial Detection and Smart Billboards: Analysing the ‘Identified’ Criterion of Personal Data in the GDPR
- Perlindungan Hukum terhadap Inferred data dalam Automated Decision-Making: Studi Perbandingan GDPR dan UU PDP
- BVwG - W254 2253353-1
- DSB (Austria) - 2026-0.043.390
- CJEU - C‑258/23 to C‑260/23 - Imagens Médicas Integradas
- NAIH (Hungary) - NAIH-11443-3/2026
- HDPA 23/2020: Complaint against HEDNO S.A. for denial of employment certificate
- DSB (Austria) - 2025-0.950.759
- AEPD fines El Español for publishing video of minor assailant without anonymization
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- BGH - VI ZR 97/22
- HDPA (Greece) - 7/2026
- Garante per la protezione dei dati personali (Italy) - 462/2026
- Garante fines Lusha Systems Inc. over unauthorized B2B contact database
- Council of State: Enschede Wi-Fi pedestrian tracking unlawful; DPA €600 fine upheld
- Health insurer must disclose aggregated patient treatment data under Free Access to
- DSB (Austria) - 2025-1.049.138
- Austrian FAC rules on publishing full court judgment naming witness on social media
- NAIH (Hungary) - NAIH-450-7-2026
- Austrian VwGH: hotel listings and user reviews on travel platform serve legitimate
- DSB (Austria) - 2025-0.960.016
- BVwG - W211 2281442-1
- BAG - 8 AZR 169/25
- NAIH (Hungary) - NAIH-4462-5-2026
- BVwG - W214 2235505-1
- VG Berlin - 42 K 73/25
- HDPA: Hellenic Open University found to have met breach notification duties after
- AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor
- DSB (Austria) - DSB-D124.5337
- UODO reprimands mayor for disclosing data subject's data to company without legal basis
- NSS - 4749/2026
- Finnish DPA examines anti-doping organization's GDPR compliance over public suspension
- Federal Administrative Court: retention of job applicant data for potential legal claims
- DSB (Austria) - DSB-D124.2437/25
- High Court examines DPA inquiry into Meta's refusal of raw data access and portability
- AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded
- BVwG - W137 2334047-1
- VG Munich: university may be GDPR controller for professors' editorial work emails
- HDPA (Greece) - 15/2026
- AEPD (Spain) - ps-00256-2025
- Persónuvernd (Iceland) - 2025010364
- IP Slovenia: Controller breached Art. 15(1)(d) and 15(3) GDPR by denying storage info and
- BVwG - W254 2253351-1
- BVwG - W605 2289290-2/18E
- Garante per la protezione dei dati personali (Italy) - 551/2026
- BVwG - W292 2292202-1
- Francesco Gagliardi: Non-compliance with general data processing principles
- BVwG - W292 2298015-1
- Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive
- AEPD: CaixaBank requested excessive inheritance documentation from heirs
- Den Haag District Court: 51 gamblers sue Unibet operator Risepoint over unanswered GDPR
- BVwG - W298 2314952-1
- Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security
- FTT: Kent County Council FOIA refusal of Kent Test scores and DOB upheld
- European Commission v Hungary
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or
- BGH: GDPR not exhaustive on injunctive relief; online store data transfer case remanded
- Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to
- Icelandic DPA: City of Reykjavik cannot request bank statements from NPA disabled service
- AEPD (Spain) - ps-00287-2025
Related across sources
C-604/22 IAB Europe v Gegevensbeschermingsautoriteit In Case C-604/22, the Court of Justice of the European Union ruled on a preliminary reference from the Brussels Court of Appeal in proceedings between IAB Europe and the Belgian… Fourth Chamber Mar 7, 2024 IP Address Controllers Personal Data
HvJ EU 9 januari 2025, C‑394/23 (Mousse) Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20… HvJ EU 9 januari 2025, C‑394/23 (Mousse). Jan 9, 2025 IP Address Retention Period Identification
C-659/22 RK v Ministerstvo zdravotnictví The Court of Justice of the European Union issued a preliminary ruling in Case C-659/22, RK v Ministerstvo zdravotnictví, addressing whether the use of a mobile application to… Eighth Chamber Oct 5, 2023 IP Address Material scope (GDPR) Personal Data
C-579/21 Proceedings brought by J.M In Case C-579/21, the Court of Justice of the European Union ruled on a preliminary reference from the Itä-Suomen hallinto-oikeus (Administrative Court of Eastern Finland)… First Chamber Jun 22, 2023 Right of Access Personal Data Right to Restriction
C-311/18 Data Protection Commissioner v Facebook Ireland and Maximillian Schrems C-311/18 (Schrems II) Jul 16, 2020 Privacy Shield Processing Agreement International Transfer
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest