Personal Data
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Information relating to identified or identifiable natural persons
Overview
21 sources · Jul 15, 2026Legal Framework
Personal data under the GDPR encompasses any information relating to an identified or identifiable natural person, as defined in Article 4(1). The Regulation's material scope, governed by Article 2, extends to the wholly or partly automated processing of such data, as well as non-automated processing within structured filing systems. Article 3 establishes territorial scope: the GDPR applies to controllers established in the Union processing data in the context of that establishment's activities, regardless of whether processing occurs within the EU. An "establishment" requires effective and actual activity through stable arrangements—even minimal activity suffices, including through a commercial agent collecting payments for an internet service. The Regulation also reaches non-EU controllers offering goods or services to, or monitoring, data subjects within the Union.
Article 6 provides the six lawful bases for processing, with consent under Article 6(1)(a) requiring that the data subject exercise genuine, free will—consent is invalid where the subject lacks a real choice or cannot refuse or withdraw without detriment (Recital 42). Separate consent must be obtainable for distinct processing operations. Article 10 imposes stricter conditions for data relating to criminal convictions, permitting processing only under official authority control or via Union/Member State law with appropriate safeguards. Articles 13 and 14 specify transparency obligations when collecting personal data, while Article 34 mandates notifying data subjects of breaches likely to result in high risk.
Key Developments
The CJEU's judgment in Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems (Schrems II) confirmed that national supervisory authorities bear independent responsibility for verifying whether transfers to third countries comply with GDPR requirements, even where an adequacy decision exists. The Court invalidated the Privacy Shield, emphasizing that protections must be assessed against the reality of third-country government surveillance practices.
In Google LLC v. CNIL, the CJEU addressed the territorial reach of de-referencing obligations, holding that while EU law does not currently require global de-referencing, it does not prohibit it either. National authorities retain competence to weigh privacy rights against freedom of information under national fundamental rights standards.
Enforcement actions confirm regulators' focus on security obligations. The Romanian DPA fined SSG SELECT SOLUTIONS €2,000 under Articles 29 and 32 for insufficient technical and organizational measures, and imposed a €5,000 fine on Poșta Română for comparable security deficiencies.
Practical Guidance
Verify establishment nexus carefully: Assess whether any EU-based activity—even through agents or subsidiaries—constitutes a stable arrangement triggering Article 3 territorial scope, particularly where advertising or payment collection occurs within the Union.
Audit consent mechanisms against the freedom requirement: Ensure consent is granular, separately obtainable for distinct purposes, and revocable without penalty, per Recital 42 and the doctrinal interpretation of Articles 3:33 and 3:35 of the Dutch Civil Code applied by analogy.
Apply Article 10 restrictions to criminal records data: Confirm that any processing of conviction data occurs exclusively under official authority control or pursuant to Member State law providing explicit safeguards; comprehensive conviction registers require official authority oversight.
Implement breach notification readiness: Establish protocols to assess whether a breach is likely to result in high risk to data subjects, triggering Article 34 notification obligations, and prepare communication templates in advance.
Monitor emerging regulatory guidance on AI: The Dutch DPA's July 2026 guidance on generative AI under the GDPR signals increased scrutiny of how AI systems process personal data—assess training data and output generation against Article 6 lawful bases and Article 13 transparency requirements.