Personal Data
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Information relating to identified or identifiable natural persons
Overview
28 sources · Aug 27, 2026Legal Framework
The right to protection of personal data is constitutionally anchored in Article 16 of the EU Charter, which empowers the EU legislature to lay down rules on the processing of personal data and its free movement. The operational core of this framework is the GDPR, whose Article 4(1) defines the material scope of protection:
This definition is deliberately broad, encompassing both directly identified individuals and those identifiable through identifiers such as names, location data, online identifiers, or factors specific to physical, economic, cultural, or social identity. Pseudonymised data remains personal data under Article 4(5), since re-identification is possible with additional information.
Once information qualifies as personal data, the processing principles in Article 5(1) apply in full: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and security. Processing must additionally rest on at least one lawful basis under Article 6(1), whether consent, contractual necessity, legal obligation, vital interests, public task, or legitimate interests.
Key Developments
Enforcement decisions have sharpened the practical boundaries of what constitutes lawful processing of personal data. The Swedish DPA's decision against a school in Skellefteå illustrates the threshold for valid consent in sensitive-data contexts:
"consent can not be applied since students and their guardians cannot freely decide if they/their children want to be monitored for attendance purposes"
— Skellefteå school decision
The case involved facial recognition for attendance monitoring — biometric data triggering Article 9 — and the DPA found the measure disproportionate even though attendance monitoring itself can be lawful. The Baden-Wuerttemberg DPA similarly sanctioned a police officer who queried licence plate owner data without official cause, confirming that a valid legal basis for access does not authorise processing for unrelated personal purposes.
The Danish DPA's enforcement against IDdesign addressed storage limitation under Article 5(1)(e), where the company retained approximately 385,000 customers' data beyond the period necessary for the original purpose. The court reduced the fine based on the company's own turnover and mitigating factors, but confirmed the underlying violation.
Status of the Debate
The definition of personal data is settled in its core: any information relating to an identified or identifiable natural person falls within scope. What remains actively contested is the outer boundary — specifically, whether certain categories of data (dynamic IP addresses, hashed identifiers, device fingerprints) qualify as personal data in contexts where re-identification requires disproportionate effort. The CJEU's line of reasoning from Breyer through Schrems II suggests a context-dependent, risk-based approach, but courts diverge on how to weigh the means reasonably likely to be used for identification. No single post-GDPR ruling has definitively resolved this threshold question. A future CJEU reference on whether pseudonymised data in a specific technical configuration remains identifiable would provide needed clarity.
Practical Guidance
- Classify data at the point of collection. Determine whether each data element, alone or combined with others, can identify a natural person under Article 4(1). When in doubt, treat it as personal data.
- Anchor every processing operation in a specific lawful basis under Article 6(1). Document the basis at the time of collection and reassess it when purposes change.
- Apply data minimisation rigorously. The Skellefteå and AEPD CCTV cases confirm that even a valid purpose does not justify disproportionate data collection; choose the least intrusive means.
- Set and enforce retention deadlines. The IDdesign decision demonstrates that failing to establish deletion timelines — and failing to execute them — constitutes a standalone violation of Article 5(1)(e).
- Verify consent quality, not just existence. Consent must be freely given, specific, and revocable. In contexts of power imbalance (schools, employment), consent will likely fail as a lawful basis, as the Skellefteå decision confirms.
Why here This provision directly regulates the obligations of controllers when processing personal data not obtained directly from the data subject, which is a central aspect of personal data protection under the GDPR.
the text this rests on
Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
Why here The provision directly defines the criteria for personal data, which is the subject of the topic.
the text this rests on
1. Personal data shall be:
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
Why here The document defines what constitutes a breach of personal data, which is central to the concept of personal data.
the text this rests on
a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Why here The document explicitly discusses what constitutes personal data in the context of connected vehicles, directly relevant to the concept of personal data.
the text this rests on
most of which can be considered personal data since they will relate to drivers or passengers
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Why here The provision repeatedly references 'personal data breach', which is a concept within the scope of personal data protection, but the article itself is about notification obligations, not the definition or handling of personal data.
the text this rests on
In the case of a personal data breach, the controller shall without undue delay
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
Why here The article regulates a specific subset of personal data, but it presupposes and partly defines what counts as personal data in this context.
the text this rests on
Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
Why here The document focuses on breaches of personal data, thus supporting the concept of personal data as the subject matter, though it does not define personal data itself beyond the breach definition.
the text this rests on
The GDPR defines a “personal data breach” in Article 4(12) as “a breach of security leading to...
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Why here It explains when video footage constitutes personal data.
the text this rests on
collection and retention of pictorial or audio - visual information on all persons entering the monitored space that are identifiable
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Why here While the provision repeatedly mentions 'data subject' and 'processing', it does not define or substantively regulate personal data itself; it only operates in the context where such data is already being processed.
the text this rests on
any communication under Articles 15 to 22 and 34 relating to processing to the data subject
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
Why here The provision operationalizes the concept of personal data by specifying how data subjects can access their own data, but it does not define or scope the concept of personal data itself.
the text this rests on
access to the personal data and the following information
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
Why here The provision concerns personal data, but its specific subject is criminal data, not personal data generally; it touches on personal data only as a subset.
the text this rests on
Processing of personal data relating to criminal convictions and offences
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
Why here The document references the definition of personal data to define the scope of access, but it is not the main focus.
the text this rests on
The scope of the right of access is determined by the scope of the concept of personal data as defined in Art. 4(1) GDPR.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Why here The document defines consent in relation to personal data processing, but does not focus on defining personal data itself.
the text this rests on
any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Why here The document focuses on delisting of personal data but does not define or analyze the concept of personal data itself.
the text this rests on
the processing of personal data carried out in the context of the activity of the search engine provider
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Nothing of this type on this topic.
This is the top of each pile — all 201 Laws · all 442 Guidance · all 430 Case Law · all 2403 Enforcement · all 343 News · all 116 Literature